This issue is to simply update to capture the 2.29.4 patch in the underlying `moment.js` package where that patch closes new CVE-2022-31129. https://nvd.nist.gov/vuln/detail/CVE-2022-31129 This issue is similar to https://github.com/derekprior/momentjs-rails/issues/63 and if complete will address that issue as well, since `moment.js` v2.29.4 includes the patch in `moment.js` v2.29.3.