Skip to content

build(deps): bump morgan from 1.12.0 to 1.12.1 - #12058

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/morgan-1.12.1
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/morgan-1.12.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Bumps morgan from 1.12.0 to 1.12.1.

Release notes

Sourced from morgan's releases.

1.12.1

Important

What's Changed

New Contributors

Full Changelog: expressjs/morgan@1.12.0...1.12.1

Changelog

Sourced from morgan's changelog.

1.12.1

Commits
  • b1272e7 1.12.1 (#386)
  • 4b695ed fix: escape double quotes in log fields
  • 0f74eca build(deps): bump github/codeql-action/analyze from 4.37.4 to 4.37.9 (#384)
  • e399e3c build(deps): bump github/codeql-action/init from 4.37.4 to 4.37.9 (#383)
  • 1e86b34 build(deps): bump github/codeql-action/autobuild from 4.37.4 to 4.37.9 (#382)
  • 87c0afd build(deps): bump github/codeql-action/upload-sarif to 4.37.9 (#381)
  • 286b000 test: run CI on Windows and macOS (#379)
  • 5a5902a docs: fix typos across documentation (#378)
  • See full diff in compare view

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
1 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The dependency and lockfile updates are consistent and narrowly scoped.

Review effort: Balanced
Findings: None

What changed in this PR

Updates Morgan to the security-fixed 1.12.1 release.

Changes:

  • Bumps the workspace catalog dependency.
  • Updates lockfile resolutions for both consumers.
File Description
pnpm-workspace.yaml Updates Morgan to ^1.12.1.
pnpm-lock.yaml Records the 1.12.1 resolution.
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/morgan-1.12.1 branch from 905e298 to 043cc47 Compare September 29, 2026 01:36
Copilot AI review requested due to automatic review settings September 29, 2026 01:36

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The generated server dependency map remains stale, and required package-specific changelog entries are missing.

Review effort: Balanced
Findings: 1 High severity · 1 Low severity

Open (2)
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

Comment thread pnpm-workspace.yaml
monaco-editor: ^0.56.0
monaco-editor-core: ^0.56.0
morgan: ^1.12.0
morgan: ^1.12.1
Comment thread pnpm-workspace.yaml
monaco-editor: ^0.56.0
monaco-editor-core: ^0.56.0
morgan: ^1.12.0
morgan: ^1.12.1
Copilot AI balanced review requested due to automatic review settings October 5, 2026 14:25
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/morgan-1.12.1 branch from 043cc47 to 8fa956e Compare October 5, 2026 14:25

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Separate dependency changelog entries are missing for the two affected packages.

Review effort: Balanced
Findings: 1 High severity · 1 Low severity

Open (2)
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

Copilot AI balanced review requested due to automatic review settings October 7, 2026 13:16
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/morgan-1.12.1 branch from 8fa956e to bc150e0 Compare October 7, 2026 13:16

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

A transitive dependency still resolves the vulnerable Morgan 1.12.0 release.

Review effort: Balanced
Findings: 2 High severity · 1 Low severity

Open (3)
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

Comment thread pnpm-workspace.yaml
monaco-editor: ^0.56.0
monaco-editor-core: ^0.56.0
morgan: ^1.12.0
morgan: ^1.12.1
Copilot AI balanced review requested due to automatic review settings October 7, 2026 13:29
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/morgan-1.12.1 branch from bc150e0 to f202a43 Compare October 7, 2026 13:29

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

A dependency changeset for @typespec/spector is missing.

Review effort: Balanced
Findings: 2 High severity · 1 Low severity

Open (3)
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

Bumps [morgan](https://github.com/expressjs/morgan) from 1.12.0 to 1.12.1.
- [Release notes](https://github.com/expressjs/morgan/releases)
- [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md)
- [Commits](expressjs/morgan@1.12.0...1.12.1)

---
updated-dependencies:
- dependency-name: morgan
  dependency-version: 1.12.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Copilot AI balanced review requested due to automatic review settings October 8, 2026 00:00
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/morgan-1.12.1 branch from f202a43 to 469861c Compare October 8, 2026 00:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The HTTP server scaffold remains on the vulnerable range, and the required Chronus entry is missing.

3 open findings
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant