When using dayjs@1.11.19 in our project, our SCA security scan found multiple vulnerabilities in its transitive dev dependencies, including karma, semver, rollup and moment.
Note: These are devDependencies only, not runtime dependencies, but they block our security compliance gate.
Vulnerability List
- karma@2.0.2
- Severity: Medium
- Recommendation: Upgrade karma to 6.3.16
- CVE: CVE-2021-23495, CVE-2022-22065
- Description: Open redirect vulnerability, attacker may redirect users to malicious websites.
- semver@6.3.0
- Severity: High
- Recommendation: Upgrade semver to 6.3.1
- Dependency chain: less -> semver@6.3.0
- rollup@2.45.1
- Severity: Medium
- Recommendation: Upgrade rollup to 3.29.5
- moment@2.29.2
- Severity: High
- Recommendation: Upgrade moment to 2.29.4
Context
Our project uses dayjs@1.11.19. The above packages are pulled in as transitive dev dependencies of dayjs.
Our security scanning system marks these as vulnerable packages and blocks release pipeline.
Request
Could you please update the devDependencies in dayjs repository to bump these packages to fixed versions in next patch release?
This will help downstream projects pass SCA vulnerability check.
Thanks a lot.
When using
dayjs@1.11.19in our project, our SCA security scan found multiple vulnerabilities in its transitive dev dependencies, includingkarma,semver,rollupandmoment.Vulnerability List
Context
Our project uses
dayjs@1.11.19. The above packages are pulled in as transitive dev dependencies of dayjs.Our security scanning system marks these as vulnerable packages and blocks release pipeline.
Request
Could you please update the devDependencies in dayjs repository to bump these packages to fixed versions in next patch release?
This will help downstream projects pass SCA vulnerability check.
Thanks a lot.