Skip to content

Vulnerabilities in transitive dependencies of dayjs (karma, semver, rollup, moment) #3225

Description

@deepbytelab

When using dayjs@1.11.19 in our project, our SCA security scan found multiple vulnerabilities in its transitive dev dependencies, including karma, semver, rollup and moment.

Note: These are devDependencies only, not runtime dependencies, but they block our security compliance gate.

Vulnerability List

  1. karma@2.0.2
    • Severity: Medium
    • Recommendation: Upgrade karma to 6.3.16
    • CVE: CVE-2021-23495, CVE-2022-22065
    • Description: Open redirect vulnerability, attacker may redirect users to malicious websites.
  2. semver@6.3.0
    • Severity: High
    • Recommendation: Upgrade semver to 6.3.1
    • Dependency chain: less -> semver@6.3.0
  3. rollup@2.45.1
    • Severity: Medium
    • Recommendation: Upgrade rollup to 3.29.5
  4. moment@2.29.2
    • Severity: High
    • Recommendation: Upgrade moment to 2.29.4

Context

Our project uses dayjs@1.11.19. The above packages are pulled in as transitive dev dependencies of dayjs.
Our security scanning system marks these as vulnerable packages and blocks release pipeline.

Request

Could you please update the devDependencies in dayjs repository to bump these packages to fixed versions in next patch release?
This will help downstream projects pass SCA vulnerability check.

Thanks a lot.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions