Debian Package Tracker
Register | Log in
Subscribe

node-moment

Work with dates in JavaScript (Node.js module)

Choose email to subscribe with

general
  • source: node-moment (main)
  • version: 2.31.0+ds1-1
  • maintainer: Debian Javascript Maintainers (archive) (DMD)
  • uploaders: Julien Puydt [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.29.1+ds-2+deb11u2
  • oldstable: 2.29.4+ds-1
  • stable: 2.29.4+ds-1
  • testing: 2.30.1+ds1-3
  • unstable: 2.31.0+ds1-1
versioned links
  • 2.29.1+ds-2+deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.29.4+ds-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.30.1+ds1-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.31.0+ds1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libjs-moment
  • node-moment
action needed
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-17495: moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-name path-traversal guard. The guard assumes the input is a string, so an object whose match() method satisfies the check while its toString() returns a traversal path reaches an internal require() call with attacker-controlled path segments. This is an incomplete fix for CVE-2022-24785 and primarily affects npm (server-side) users that pass user-provided input directly to moment.locale(). The issue is fixed in moment 2.31.0, and users should upgrade to 2.31.0 or later. As a workaround, validate that any user-supplied input is a string before passing it to moment.locale().
Created: 2026-09-16 Last update: 2026-09-18 10:30
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-17495: moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-name path-traversal guard. The guard assumes the input is a string, so an object whose match() method satisfies the check while its toString() returns a traversal path reaches an internal require() call with attacker-controlled path segments. This is an incomplete fix for CVE-2022-24785 and primarily affects npm (server-side) users that pass user-provided input directly to moment.locale(). The issue is fixed in moment 2.31.0, and users should upgrade to 2.31.0 or later. As a workaround, validate that any user-supplied input is a string before passing it to moment.locale().
Created: 2026-09-16 Last update: 2026-09-18 10:30
A new upstream version is available: 2.31.0 high
A new upstream version 2.31.0 is available, you should consider packaging it.
Created: 2026-09-16 Last update: 2026-09-18 08:33
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-17495: (needs triaging) moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-name path-traversal guard. The guard assumes the input is a string, so an object whose match() method satisfies the check while its toString() returns a traversal path reaches an internal require() call with attacker-controlled path segments. This is an incomplete fix for CVE-2022-24785 and primarily affects npm (server-side) users that pass user-provided input directly to moment.locale(). The issue is fixed in moment 2.31.0, and users should upgrade to 2.31.0 or later. As a workaround, validate that any user-supplied input is a string before passing it to moment.locale().

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-09-16 Last update: 2026-09-18 10:30
testing migrations
  • excuses:
    • Migration status for node-moment (2.30.1+ds1-3 to 2.31.0+ds1-1): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for libminion-perl: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: Test triggered
    • ∙ ∙ Autopkgtest for moment-timezone.js: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: Test triggered
    • ∙ ∙ Autopkgtest for node-chart.js: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: Test triggered
    • ∙ ∙ Autopkgtest for node-ipydatagrid: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: Test triggered
    • ∙ ∙ Autopkgtest for node-mermaid: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: Test triggered
    • ∙ ∙ Autopkgtest for node-moment: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: Test triggered
    • ∙ ∙ Autopkgtest for node-rollup-plugin-license: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: Test triggered
    • ∙ ∙ Autopkgtest for sabnzbdplus: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: Test triggered
    • ∙ ∙ Lintian check waiting for test results - info
    • ∙ ∙ Too young, only 0 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/n/node-moment.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-09-18] Accepted node-moment 2.31.0+ds1-1 (source) into unstable (Xavier Guimard)
  • [2026-07-19] node-moment 2.30.1+ds1-3 MIGRATED to testing (Debian testing watch)
  • [2026-07-16] Accepted node-moment 2.30.1+ds1-3 (source) into unstable (Bastien Roucariès) (signed by: Bastien ROUCARIÈS)
  • [2026-07-16] Accepted node-moment 2.30.1+ds1-2 (source) into unstable (Bastien Roucariès) (signed by: Bastien ROUCARIÈS)
  • [2026-07-15] Accepted node-moment 2.30.1+ds1-1 (source) into unstable (Bastien Roucariès) (signed by: Bastien ROUCARIÈS)
  • [2026-03-26] node-moment 2.30.1+ds-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-23] Accepted node-moment 2.30.1+ds-1 (source) into unstable (Xavier Guimard)
  • [2023-01-28] Accepted node-moment 2.24.0+ds-1+deb10u1 (source) into oldstable (Utkarsh Gupta)
  • [2022-08-14] Accepted node-moment 2.29.1+ds-2+deb11u2 (source) into proposed-updates->stable-new, proposed-updates (Debian FTP Masters) (signed by: Xavier Guimard)
  • [2022-07-16] node-moment 2.29.4+ds-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-13] Accepted node-moment 2.29.4+ds-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2022-05-29] Accepted node-moment 2.29.1+ds-2+deb11u1 (source) into proposed-updates->stable-new, proposed-updates (Debian FTP Masters) (signed by: Xavier Guimard)
  • [2022-04-25] node-moment 2.29.3+ds-1 MIGRATED to testing (Debian testing watch)
  • [2022-04-22] Accepted node-moment 2.29.3+ds-1 (source) into unstable (Julien Puydt)
  • [2022-04-14] node-moment 2.29.2+ds-1 MIGRATED to testing (Debian testing watch)
  • [2022-04-12] Accepted node-moment 2.29.2+ds-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2021-09-07] node-moment 2.29.1+ds-3 MIGRATED to testing (Debian testing watch)
  • [2021-09-04] Accepted node-moment 2.29.1+ds-3 (source) into unstable (Julien Puydt)
  • [2020-11-12] node-moment 2.29.1+ds-2 MIGRATED to testing (Debian testing watch)
  • [2020-11-09] Accepted node-moment 2.29.1+ds-2 (source) into unstable (Julien Puydt)
  • [2020-10-13] node-moment 2.29.1+ds-1 MIGRATED to testing (Debian testing watch)
  • [2020-10-11] Accepted node-moment 2.29.1+ds-1 (source) into unstable (Julien Puydt)
  • [2020-09-28] node-moment 2.29.0+ds-1 MIGRATED to testing (Debian testing watch)
  • [2020-09-26] Accepted node-moment 2.29.0+ds-1 (source) into unstable (Julien Puydt)
  • [2020-09-20] node-moment 2.28.0+ds-1 MIGRATED to testing (Debian testing watch)
  • [2020-09-17] Accepted node-moment 2.28.0+ds-1 (source) into unstable (Julien Puydt)
  • [2020-07-02] node-moment 2.27.0+ds-1 MIGRATED to testing (Debian testing watch)
  • [2020-06-29] Accepted node-moment 2.27.0+ds-1 (source) into unstable (Julien Puydt)
  • [2020-05-27] node-moment 2.26.0+ds-1 MIGRATED to testing (Debian testing watch)
  • [2020-05-25] Accepted node-moment 2.26.0+ds-1 (source) into unstable (Julien Puydt)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.30.1+ds1-3

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing