Repository navigation
build(deps): bump morgan from 1.12.0 to 1.12.1 - #12058
Open
dependabot[bot] wants to merge 1 commit into
Open
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
dependabot
Bot
requested review from
Mark Cowlishaw (markcowl) and
Timothee Guerin (timotheeguerin)
as code owners
September 29, 2026 00:22
dependabot
Bot
requested review from
catalinaperalta,
iscai-msft and
Laurent Mazuel (lmazuel)
as code owners
September 29, 2026 00:22
|
Azure Pipelines: Successfully started running 1 pipeline(s). 1 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The dependency and lockfile updates are consistent and narrowly scoped.
Review effort: Balanced
Findings: None
What changed in this PR
Updates Morgan to the security-fixed 1.12.1 release.
Changes:
- Bumps the workspace catalog dependency.
- Updates lockfile resolutions for both consumers.
| File | Description |
|---|---|
pnpm-workspace.yaml |
Updates Morgan to ^1.12.1. |
pnpm-lock.yaml |
Records the 1.12.1 resolution. |
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/morgan-1.12.1
branch
from
September 29, 2026 01:36
905e298 to
043cc47
Compare
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The generated server dependency map remains stale, and required package-specific changelog entries are missing.
Review effort: Balanced
Findings: 1
Open (2)
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
| monaco-editor: ^0.56.0 | ||
| monaco-editor-core: ^0.56.0 | ||
| morgan: ^1.12.0 | ||
| morgan: ^1.12.1 |
| monaco-editor: ^0.56.0 | ||
| monaco-editor-core: ^0.56.0 | ||
| morgan: ^1.12.0 | ||
| morgan: ^1.12.1 |
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/morgan-1.12.1
branch
from
October 5, 2026 14:25
043cc47 to
8fa956e
Compare
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/morgan-1.12.1
branch
from
October 7, 2026 13:16
8fa956e to
bc150e0
Compare
| monaco-editor: ^0.56.0 | ||
| monaco-editor-core: ^0.56.0 | ||
| morgan: ^1.12.0 | ||
| morgan: ^1.12.1 |
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/morgan-1.12.1
branch
from
October 7, 2026 13:29
bc150e0 to
f202a43
Compare
Bumps [morgan](https://github.com/expressjs/morgan) from 1.12.0 to 1.12.1. - [Release notes](https://github.com/expressjs/morgan/releases) - [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md) - [Commits](expressjs/morgan@1.12.0...1.12.1) --- updated-dependencies: - dependency-name: morgan dependency-version: 1.12.1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/morgan-1.12.1
branch
from
October 8, 2026 00:00
f202a43 to
469861c
Compare
Contributor
There was a problem hiding this comment.
🔵 Needs a closer look
The HTTP server scaffold remains on the vulnerable range, and the required Chronus entry is missing.
3 open findings
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Bumps morgan from 1.12.0 to 1.12.1.
Release notes
Sourced from morgan's releases.
Changelog
Sourced from morgan's changelog.
Commits
b1272e71.12.1 (#386)4b695edfix: escape double quotes in log fields0f74ecabuild(deps): bump github/codeql-action/analyze from 4.37.4 to 4.37.9 (#384)e399e3cbuild(deps): bump github/codeql-action/init from 4.37.4 to 4.37.9 (#383)1e86b34build(deps): bump github/codeql-action/autobuild from 4.37.4 to 4.37.9 (#382)87c0afdbuild(deps): bump github/codeql-action/upload-sarif to 4.37.9 (#381)286b000test: run CI on Windows and macOS (#379)5a5902adocs: fix typos across documentation (#378)