[buddypress-trac] [BuddyPress Trac] #8766: moment.js is outdated and has CVEs

buddypress-trac noreply at wordpress.org
Tue Nov 15 06:36:54 UTC 2022


#8766: moment.js is outdated and has CVEs
--------------------------+-----------------------
 Reporter:  thomaslhotta  |       Owner:  imath
     Type:  task          |      Status:  assigned
 Priority:  high          |   Milestone:  11.0.0
Component:  Core          |     Version:  10.6.0
 Severity:  normal        |  Resolution:
 Keywords:  has-patch     |
--------------------------+-----------------------
Changes (by prbot):

 * keywords:   => has-patch


Comment:

 ''This ticket was mentioned in
 [https://github.com/buddypress/buddypress/pull/39 PR #39] on
 [https://github.com/buddypress/buddypress/ buddypress/buddypress] by
 [https://profiles.wordpress.org/imath/ @imath].''
 This PR simply & softly deprecates `bp-moment` JS dependency. That being
 said, as `bp-moment` is only used by `bp-livestamp` to live update human
 dates/time diff on the website, we could simply remove this dependency and
 save ~ 740 KB (see
 https://github.com/buddypress/buddypress/tree/master/src/bp-core/js/vendor
 /moment-js). Consequence would be the people using a WordPress version <
 5.0 (a very limited population, see https://wordpress.org/about/stats/)
 would not enjoy this live updating feature anymore..

 Trac ticket: https://buddypress.trac.wordpress.org/ticket/8766

-- 
Ticket URL: <https://buddypress.trac.wordpress.org/ticket/8766#comment:4>
BuddyPress Trac <http://buddypress.org/>
BuddyPress Trac


More information about the buddypress-trac mailing list