Tag
moment-js
Safeguard articles tagged "moment-js" — guides, analysis, and best practices for software supply chain and application security.
2 articles
Open Source
The moment npm Package in 2025: Security Review and Safe Usage
The moment npm package is in maintenance mode, not abandoned. Here is what that means for security, when it is fine to keep, and what to migrate to when it is not.
Jul 8, 20255 min read
Vulnerabilities
CVE-2017-18214: Why an Old CVE Still Shows Up in Scans
CVE-2017-18214 is a ReDoS bug in Moment.js patched back in 2017, yet it keeps surfacing in scans years later because bundled copies and stale lockfiles never got the memo.
Apr 9, 20244 min read
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.