Skip to content

Conversation

mend-for-github-com[bot]
Copy link

@mend-for-github-com mend-for-github-com bot commented Aug 4, 2025

This PR contains the following updates:

Package Type Update Change
morgan dependencies minor ~1.9.0 -> ~1.10.1

By merging this PR, the issue #6 will be automatically resolved and closed:

Severity CVSS Score Vulnerability Reachability
Critical Critical 9.8 CVE-2019-5413
Low Low 3.4 CVE-2025-7339

Release Notes

expressjs/morgan (morgan)

v1.10.1

Compare Source

===================

v1.10.0

Compare Source

===================

  • Add :total-time token
  • Fix trailing space in colored status code for dev format
  • deps: basic-auth@~2.0.1
    • deps: safe-buffer@​5.1.2
  • deps: depd@~2.0.0
    • Replace internal eval usage with Function constructor
    • Use instance methods on process to check for listeners
  • deps: on-headers@~1.0.2
    • Fix res.writeHead patch missing return value

v1.9.1

Compare Source

==================

  • Fix using special characters in format
  • deps: depd@~1.1.2
    • perf: remove argument reassignment

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Aug 4, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/main-morgan-1.x branch from 0d94b8b to e6ff642 Compare October 5, 2025 09:27
@mend-for-github-com mend-for-github-com bot changed the title Update dependency morgan to ~1.9.1 (main) Update dependency morgan to ~1.10.1 (main) Oct 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants