Skip to content

build(deps): bump moment from 2.30.1 to 2.31.0 - #31

Open
dependabot[bot] wants to merge 41 commits into
masterfrom
dependabot/npm_and_yarn/moment-2.31.0
Open

dependabot[bot] wants to merge 41 commits into
masterfrom
dependabot/npm_and_yarn/moment-2.31.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown

Bumps moment from 2.30.1 to 2.31.0.

Release notes

Sourced from moment's releases.

2.31.0

Released Sep 14, 2026

Security fixes

Bug fixes

  • #6376 Prevent object prototype properties from being used as format tokens
  • #6386 Normalize lazy-loaded locale names
  • #6404 Fix parsing issue with eHHmm format
  • #6433 Ignore non-Moment arguments in min and max
  • #6434 Fix inherited lowercase long date formats
  • #6436 Reset locale parsing caches after updates
  • #6437 Fix weekday mismatch when the format only has part of a date
  • #6442 Fix locale('__proto__') corrupting the global locale
  • #6443 Avoid Object.assign in duration.humanize
  • #6446 Validate range when parsing a time zone offset
  • #6447 Include metadata in all-locales bundle
  • #6448 Apply postformat to locale relative time methods
  • #6450 Add stack traces to conditional deprecation warnings

New features

  • #6451 Add internal date-default hook for Moment Timezone
New locales

Updates to existing locales

  • #5404 Portuguese (Brazil) ('pt-br'): Fix wrong plural usage for time
  • #6197 Indonesian ('id'): Correct the abbreviation for August
  • #6217 Georgian ('ka') and Dutch (Belgium) ('nl-be'): Correct L date formats
  • #6289 Swedish ('sv'): Correct the abbreviation for Thursday
  • #6306 Catalan ('ca'): Use typographic apostrophes in relative time
  • #6347 Swahili ('sw'): Correct the spelling of hour in calendar output
  • #6360 Ukrainian ('uk'): Use ISO week numbering
  • #6370 Ukrainian ('uk'): Use U+02BC apostrophes in Friday names
  • #6371 Hungarian ('hu'): Preserve numeric values in relative seconds
  • #6391 Swahili ('sw'): Fix weekday and relative-time grammar
  • #6396 German ('de', 'de-at', 'de-ch'): Parse short months without trailing dots
  • #6409 Uzbek ('uz', 'uz-latn'): Fix past relative-time formatting
  • #6410 Polish ('pl'): Use genitive month names in dotted day formats
Changelog

Sourced from moment's changelog.

2.31.0

Released Sep 14, 2026

Security fixes

Bug fixes

  • #6376 Prevent object prototype properties from being used as format tokens
  • #6386 Normalize lazy-loaded locale names
  • #6404 Fix parsing issue with eHHmm format
  • #6433 Ignore non-Moment arguments in min and max
  • #6434 Fix inherited lowercase long date formats
  • #6436 Reset locale parsing caches after updates
  • #6437 Fix weekday mismatch when the format only has part of a date
  • #6442 Fix locale('__proto__') corrupting the global locale
  • #6443 Avoid Object.assign in duration.humanize
  • #6446 Validate range when parsing a time zone offset
  • #6447 Include metadata in all-locales bundle
  • #6448 Apply postformat to locale relative time methods
  • #6450 Add stack traces to conditional deprecation warnings

New features

  • #6451 Add internal date-default hook for Moment Timezone
New locales

Updates to existing locales

  • #5404 Portuguese (Brazil) ('pt-br'): Fix wrong plural usage for time
  • #6197 Indonesian ('id'): Correct the abbreviation for August
  • #6217 Georgian ('ka') and Dutch (Belgium) ('nl-be'): Correct L date formats
  • #6289 Swedish ('sv'): Correct the abbreviation for Thursday
  • #6306 Catalan ('ca'): Use typographic apostrophes in relative time
  • #6347 Swahili ('sw'): Correct the spelling of hour in calendar output
  • #6360 Ukrainian ('uk'): Use ISO week numbering
  • #6370 Ukrainian ('uk'): Use U+02BC apostrophes in Friday names
  • #6371 Hungarian ('hu'): Preserve numeric values in relative seconds
  • #6391 Swahili ('sw'): Fix weekday and relative-time grammar
  • #6396 German ('de', 'de-at', 'de-ch'): Parse short months without trailing dots
  • #6409 Uzbek ('uz', 'uz-latn'): Fix past relative-time formatting
  • #6410 Polish ('pl'): Use genitive month names in dotted day formats
Commits
  • 15b45d4 [pkg] Build 2.31.0 (#6452)
  • 631cd81 [pkg] Update changelog for upcoming release (#6394)
  • 6caff9e Merge commit from fork
  • 710703b [feature] Add internal date-default hook for Moment Timezone (#6451)
  • 863ed94 [bugfix] Add stack traces to conditional deprecation warnings (#6450)
  • 2c7abe1 [bugfix] Apply postformat to locale relative time methods (#6448)
  • 9c45ac3 [bugfix] Include metadata in all-locales bundle (#6447)
  • f6eefc5 [bugfix] Validate timezone offset range (#6446)
  • 136b441 [bugfix] Avoid Object.assign in duration.humanize (#6443)
  • 0d10504 [bugfix] Fix locale('proto') corrupting the global locale (#6442)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for moment since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

vzakaznikov and others added 30 commits August 1, 2026 09:48
Place 512px line icons beside each Why card title, themed via CSS mask.

Co-authored-by: Cursor <cursoragent@cursor.com>
Hero: sharper copy ("structured steps … Written for the humans. Loved by the
AI agents.") and a second ghost CTA ("Read the handbook") in a flex
.banner-actions row. Footer: muted section headings, text-tone links (less
accent). New .banner-cta-ghost + tokens already defined.
Sessions refresh PROACTIVELY (shell rotates the cookie on boot when refreshDue,
while still valid); the 401->refresh->retry is only a best-effort fallback and
can't refresh an already-expired cookie. The old comment overstated it.
(Re-stamps the portal module graph — content-hash token changed.)
Hero goes from a 2-column grid to a stacked flex column (text over visual,
centered links) at all sizes — simpler and consistent; H1 wraps "Not a
typical / framework". Drops the grid template + its responsive overrides.
friendlyApiError now surfaces an authored 403 detail (e.g. the sign-up
allowlist denial, "account not active") instead of the generic "Not allowed
right now.", falling back to generic only for a bare code / no message.
Pairs with the machine-api registration allowlist.
Hero copy expanded (properties, behavior models, combinatorial + autonomous
exploration); banner is full-viewport only on desktop (>=992px), hugs content
on mobile. Code-typing animation is now opt-in per panel via .index-code-animate
(added to the Write + steps code panels) instead of auto-detecting test.py.
Account dashboard gains a Devices panel: lists active login sessions (device
label from User-Agent — Chrome/Safari/macOS/iOS/"machine CLI on <host>", IP,
last-active, signed-in, this-device flagged) via GET /account/devices, with a
per-row Sign out (DELETE /account/devices/{session_id}); revoking the current
device clears the session hint and returns to login. api.getDevices/revokeDevice;
new account/devices.js; nav option + sidebar link + panel.
Lowercase "handbook" in the CTAs (home/about/footer), shorten a blog CTA, and a
round of grammar fixes in the handbook intro (allowing you to…, across, becomes,
"If a test fails", "use your browser's back button", …). Regenerated docs/.
parseDt treated the API's naive UTC datetimes as LOCAL (new Date on a bare
timestamp), skewing every "ago" by the viewer's offset — all rows read "just
now" on a machine behind UTC. Treat naive as UTC (matches CLI/TUI _parse_dt).
Also: portal-dev now forwards User-Agent so a browser login through the dev
proxy is captured with the real device label, not "Python-urllib".
secondsUntil() parsed the API's naive UTC expires_at with Date.parse (LOCAL),
skewing the session-hint cookie Max-Age by the viewer's offset. Treat naive as
UTC, matching the parseDt fix. Last spot in the portal that parsed an API
timestamp as local — sweep complete.
Bring the portal activity table to parity with the CLI statement: add Rate,
Duration, Cost, Period columns mirroring client/core/transactions.py
(_rate/_duration/_cost/_period), reusing compactDatetime/elapsed/duration/eur.
All timestamp cells route through the (UTC-fixed) format helpers.
Add a pager to the activity panel: probe page-size + 1 to detect a following
page, Previous/Next step by offset, "Showing N–M" label, and a filter or
page-size change resets to the first page. Rename the "Limit" control to
"Page size". Keep the dense statement rows from wrapping
(.portal-table--activity) with horizontal scroll on the wrap.
…ur client

Parse the OS off the machine-cli User-Agent so the CLI shows "Client on Linux"
(parallel to "Chrome on Linux"; Darwin -> macOS), and drop the stale python-*
mapping so a browser is never labelled "Client". Mark the current row
"· current" (was "· this session"). Update the portal-dev comment to match.
Portal side of the account-list pagination (Machine offset API deployed as
260802-g7c296f9), plus the account-dashboard UX refactor done alongside it:

- Pagination: one shared Previous/Next pager (pager.js) on Activity, Orders,
  and Invoices via a limit+1 has-next probe; Invoices surfaces an explicit
  note when Stripe's scan ceiling is hit. The pager disables its buttons while
  a page loads, so a double-click can't skip a page.
- Busy indicator: the Refresh button spins for account work; pages without it
  (login/signup) get an inline status spinner. Reduced-motion safe.
- Section chrome (title/lead) painted before fetches so it shows immediately.
- Shared empty-state row (table.js); no misleading "empty" flash before load.
- Shell no longer blocks list views on getAccount.
- Layout: drop the Bootstrap .container on the dashboard; device panel header
  tidy; "Client on <OS>" labels with the "· current" marker.
…homepage typewriter)

Respect the OS "reduce motion" setting across the three site animations:
- Handbook "Back to top": instant scroll under reduced-motion (was always smooth).
- Contact step-2 reveal: skip the slide/fade (element stays visible — it has
  display:block and default opacity:1, so animation:none leaves it shown).
- Homepage test.py typewriter: reverse the old opt-out and honor
  prefers-reduced-motion, showing the static final content instead of animating.

Regenerated only the affected pages (cache-bust ?v bumped where the changed
assets are linked); unrelated pages' timestamps left untouched.
…h on mobile

Desktop: cap the wide table panels (activity/orders/invoices/devices/keys) at
`100vw - sidebar` instead of a 75vw heuristic that could overflow, and raise the
ceiling to 80rem. Mobile: mirror the desktop :has() selector list so the override
is specificity-matched and actually wins, letting tables use the full width.
…wording

- Prefix each row with a device-kind icon (desktop / web / unknown) via a
  new deviceLabelCell.
- Add a "sign out everywhere" block that revokes all sign-in tokens
  (logout(everywhere=true)), then clears the local session and redirects;
  non-401 failures fall back to a local sign-out + delayed redirect.
- Reword the per-row action to "Revoke" and add a "Showing 1–N of N" summary.
- CSS: table-in-block styling, sign-out-everywhere row, device-label icon,
  and reuse .portal-pager-label for the summary without disturbing the pagers.
renderBuy now takes the account and fetches it alongside the catalog: the plan
matching account.tier renders as "Subscribed" (accent badge + dimmed card, no
Subscribe button), and the fetched account is shared back via ctx.onAccount.
Make the plans/packs section wrappers borderless so the product cards aren't
nested cards-in-a-card.
Billing panel: replace the flat button grid + free-text plan input with
structured action rows and modal flows — a Plan section (current plan +
period-ends, Upgrade/Downgrade/Cancel gated on a paid tier; switch targets
computed from the catalog by tier rank and picked via a radio modal) and a
Billing portal section. New modal.js (runConfirm / runPlanPick) with Escape +
backdrop dismiss and a Tab focus-trap; the two dialogs live in account.md.
Buy: show each plan's price (EUR / month) from the catalog, not only its
included credits. Upgrade/Downgrade buttons disable during load so a
double-click can't re-open the shared dialog.
Buy: subscribing to a plan you already differ from now routes correctly — a
plan above your current tier is an Upgrade and one below is a Downgrade
(through the Stripe portal; a fresh Subscribe 409'd "conflicts with the current
state"); no paid plan yet stays a plain Subscribe. Extract the shared tier-rank
helper (plans.js) used by billing.js and buy.js. Status dock: wrap a long
message to two lines (line-clamp) instead of truncating to one.
New static /machine/portal/purchase/ page for CLI/TUI buyers (their browser has
no portal session): shows Payment received / Checkout cancelled / All set from
?status, with a Sign In button. Account boot reads ?purchase=success|cancelled
(browser buyers), shows a status note, and scrubs the param (boot already
reloads fresh). Pairs with the API return-URL change.
- Account: sync pre-paint auth gate (portal_auth_gate → head.ejs) redirects to
  login before the dashboard can flash.
- Modal: stacking guard, focus save/restore, danger focuses Cancel, dismissOnly
  single-OK mode for info dialogs, focus-trap excludes hidden nodes.
- Billing: panel-wide setBusy (disable every action button during an op,
  keeping unpaid buttons base-disabled); no-lower-plan downgrade routes to
  cancel-at-period-end; "Credits renew" copy.
- Buy: setBusy across product buttons; refreshAfterPurchase keeps
  Subscribed/Upgrade labels current after a purchase.
- Devices: styled runConfirm instead of window.confirm.
Move the four TestFlows Machine legal docs (Terms of Service, Privacy Policy,
Acceptable Use, Usage Credit) from machine-api /legal onto
testflows.com/machine/legal/* (frontmatter + rewritten cross-links). Add site
legal under /legal/*: Website Terms of Use, Privacy Policy, and Copyright and
Content Use — written as succinct prose in the Machine docs' style (no bullet
lists, no em-dashes), scoped to the site and cross-linking the Machine service
legal. Footer gains Terms/Privacy/Copyright links; the contact form's privacy
line now links to /legal/privacy/.

The three /legal/* site docs are drafts pending legal review. Repointing the
Stripe/client legal links and a machine-api /legal redirect are a follow-up.
…re-release

Follow-up to the legal restructure:

- Site Terms §8 governing law: name Ontario + federal Canada (match Machine ToS)
- Machine AUP: add §3 Prohibited technical use (malware/C2, scanning/DoS,
  open relays, cryptomining, CSAM); scoped to outward abuse so it doesn't
  repeat §4 Platform integrity. Bump AUP date to 2 Aug.
- Site Privacy: add §4 International transfers (SCCs where required)
- Add /machine/legal/ index hub linking the four Machine docs (no Machine
  landing page yet)
- Machine not released: drop the three site-legal -> machine-legal hyperlinks,
  keep the carve-out prose ("governed by its own separate terms"). Machine
  legal stays published but unlinked from the public site.
- Copy: "cloud service" -> "service" across all legal docs (product name
  already disambiguates)
Machine (portal, purchase, legal) has not launched. Its pages resolve by direct
URL for checkout and CLI links, but must not be advertised to search engines.

hexo-generator-sitemap has no path-glob exclude (its skip_render list would stop
the pages rendering entirely), and mutating page.sitemap in before_generate is
lost because Warehouse hands the generator fresh Page instances. So a scripts/
filter post-processes the generated sitemap routes in after_generate — where
route.set is the final word before flush — dropping every /machine/ <url> block
and txt line. Delete the script when Machine launches.
… page

- New `legal` layout (themes/.../legal.ejs + legal.css): every legal page gets a
  sidebar rail listing its family's docs (Website vs Machine, via `legal_family`),
  with active-state (aria-current) and a Machine->Website back-link. Machine pages
  still carry no inbound link from the public site.
- Legal index pages: new /legal/ (site) and reworked /machine/legal/ hubs.
- Contact blocks collapsed to "Katteli Inc." + emails — street address and
  location removed everywhere (registered office is already public record; keeps
  postal-spam surface off the site). Governing-law/jurisdiction references kept.
- Copyright-infringement notices now route to legal@ (was abuse@); abuse@ stays
  the AUP/network-abuse channel.
- Footer Company column: single "Legal" link (Credits + per-doc links removed).
- Removed the old Credits page (source/credits.md, docs/credits.html).
- head.ejs loads legal.css site-wide; sitemap still excludes pre-release /machine/*.
Surface the Machine legal docs in-context where an account is created/entered —
the service surface, not the public site. Signup reads "By creating an account
you agree to…"; login reads "Use is governed by…". New .portal-legal style
(muted, small) matches the portal footer link treatment.
New Sessions panel: name, state (tone-coded), CPUs, class, €/hour, live
duration, and accrued cost, with a total row and entry-count summary. Wired
into the account nav/select/panels; api.js gains getSessions() (GET /sessions,
the full quota-bounded list — no paging).

- Extract a shared secondsBetween() into format.js so duration display
  (elapsed) and accrued cost (cost_so_far) parse a span through one code path
  and can't disagree.
- Harmonize list-panel load-error handling: sessions/activity/invoices/orders
  now clear the table and surface the error in the status line (matching
  devices), instead of painting a misleading empty-state label.
Replace native window.confirm() with runConfirm() (danger variant) for delete
API key, cancel order, and the two account-close steps — consistent styling and
keyboard/focus handling instead of the browser dialog.

Extend the portal button styles to .portal-modal: modals render outside
.portal-page, so without it the modal's Cancel/OK fall back to Bootstrap .btn
and vanish in dark theme.
vzakaznikov and others added 11 commits August 3, 2026 13:26
- login: add a "Resend code" button (sendCode(resend) shares the submit path;
  distinct "New code sent" status).
- api keys: expiry in days, not raw ISO. Create form takes "never"/N days;
  each key gets Set expiry (prompt → step-up) and Clear expiry (only when set);
  list shows CLI-parity "when (N days)" via expiresWithDays; secret box gains a
  Hide button.
- modal: add runPrompt() — a validated text-input dialog on the confirm shell,
  extracted into confirmShell()/bind/unbind so runConfirm and runPrompt share it.
- ui: drive the busy indicator off an explicit .portal-status--dock class
  (dashboard = Refresh icon; login/signup/modals = inline spinner) instead of
  probing for the Refresh button; modal-local busy no longer spins the page.
…osures

The closing panel now uses the AccountCloseProgress it fetches instead of
discarding it, and drives teardown the way the CLI does:

- Render progress in a block above the actions: "Waiting for N session(s) to
  stop." or "Waiting for plan cancel to finish." Gate Confirm on `ready`
  (disabled + tooltip until sessions AND plan cancel are done). Surface
  portal_url as a Manage billing link (_blank + noopener noreferrer).
- Resume teardown: refreshClose POSTs /account/close/start (no code while
  already closing) — GET only reads, so a GET-only portal could never cancel the
  plan and stalled subscription accounts. Auto-poll every 5s while closing &&
  !ready, self-cancelling via a document.contains(closeBlock) guard.
- Generation token (closeGen) + post-await clear so a late poll can't repaint
  stale "closing" over a newer state; Cancel invalidates the poll up front and
  the cancel-failure path re-arms it.
- Disclosures match the CLI: start warns work loss / key revocation / plan
  cancel-at-period-end / 90-day retention; confirm warns sign-out + sign-in
  disabled; cancel notes revoked keys stay revoked and a still-scheduled plan.
- Fix stale "eventually deletes data" copy (soft-close retains).
Replace the action-row rebuild with a fixed 4-step stepper (Stop machines →
Revoke API keys → Cancel plan → Confirm close) built once and patched in place
each poll: step state, detail text, Confirm gate, and billing URL only — focus
stays put while the account closes.

- closePhase() maps AccountCloseProgress to the current step; ready lights the
  Confirm step ("Ready when you are.").
- aria-current on the active step; aria-live on each step detail so screen
  readers hear progression.
- clearCloseChrome() tears the stepper down on exit (active/closed) and rebuilds
  on re-entry; poll/gen/resume/cancel logic unchanged.
solve() fans disjoint nonce subsequences across min(cores, 8) module workers
(shared rand, start=i/stride=count, first stamp wins, rest terminated), off the
main thread so the step-up spinner stays responsive. Falls back to the yielding
loop (solveInline) when Worker is unavailable or construction/onerror fails.

- solveRange(): synchronous shard search (no yielding — worker context), with a
  stride>=1 guard so a bad caller fails loudly instead of hanging.
- hashcash.worker.js imports the shared solveRange (single-source hash, mirrors
  client/api + cloud/api) and carries hashcash.js's ?v= cache key onto the
  Worker URL so a code change busts both together.
- Reuse one TextEncoder in the hash inner loop (was allocated per hash).

No server or difficulty change; stamp format is unchanged. Attacker cost is set
by difficulty, not the client solver — this is a pure legit-user speedup.
…page

machine-api confirm links now redirect to /machine/portal/login/?signup=... or
?email=..., so the login page surfaces the outcome (activated / reopened /
email changed / invalid / etc.) via a generic showConfirmStatus() that shows the
note in portal-login-status and scrubs the param. Replaces the machine-api HTML
success pages.
…edirect

The confirm redirect now carries ?addr=<email>, so the sign-in note reads
"Your account <email> is activated…" / "Your email is changed to <email>…" and
the email field is pre-filled (saved email only fills if still empty). No-addr
outcomes keep the generic message.
Redraw the closing-workflow markers with CSS: hollow ring (pending), accent
ring + inner disc with a soft pulse (in progress), solid accent + halo (ready),
and a filled marker with a trailing check on the label (done). Connecting rail
greens only between accent-marked steps via :has(); pulse respects
prefers-reduced-motion.
Add the pre-release Machine surface: /machine/ landing page + hero,
/machine/contact/ early-access page with a contact form, and the
/machine/portal/signup entry. Make the footer surface-aware
(isMachineSurface): machine pages get machine Contact/Legal + Create
account / Request early access; public pages are unchanged
(pip3 install / Read the handbook, /contact.html, /legal/). Nav, hero
type animation, and machine.css assets included.

/machine stays private / direct-link-only: no public page links into
it (footer machine links are gated to machine surfaces) and the whole
/machine/* tree remains excluded from the sitemap.
Embed the boot log in the page (data-boot-log) so deploy no longer depends
on a gitignored .log fetch, switch the hero to JPEG, and enlarge the
terminal overlay slightly.
The homepage Why card masks were clipping (partial circle, open grid
frame). Swap in the fixed assets in source and docs.
Bumps [moment](https://github.com/moment/moment) from 2.30.1 to 2.31.0.
- [Release notes](https://github.com/moment/moment/releases)
- [Changelog](https://github.com/moment/moment/blob/develop/CHANGELOG.md)
- [Commits](moment/moment@2.30.1...2.31.0)

---
updated-dependencies:
- dependency-name: moment
  dependency-version: 2.31.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant