Skip to content

build(deps): bump morgan from 1.11.0 to 1.12.0 - #11885

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/morgan-1.12.0
Open

build(deps): bump morgan from 1.11.0 to 1.12.0#11885
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/morgan-1.12.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Contributor

Bumps morgan from 1.11.0 to 1.12.0.

Release notes

Sourced from morgan's releases.

1.12.0

What's Changed

New Contributors

Full Changelog: expressjs/morgan@1.11.0...1.12.0

Changelog

Sourced from morgan's changelog.

1.12.0

  • Security fix for CVE-2026-15603(GHSA-jxfw-x594-9x9m)
  • Allow format functions to return objects for streams in objectMode
  • Respect the NO_COLOR environment variable in the dev format
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for morgan since your current version.


@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
1 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

A .chronus changelog entry for the dependency bump is missing per repository PR requirements.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Updates the workspace dependency catalog to use morgan ^1.12.0 (from ^1.11.0), and refreshes the lockfile so workspace consumers resolve the new version (including upstream security fixes in morgan@1.12.0).

Changes:

  • Bump morgan in the pnpm catalog from ^1.11.0 to ^1.12.0.
  • Update pnpm-lock.yaml to reflect resolution of morgan@1.12.0 across importers.
File summaries
File Description
pnpm-workspace.yaml Updates the workspace catalog entry for morgan to ^1.12.0.
pnpm-lock.yaml Updates resolved morgan version/integrity and importer entries to 1.12.0.
Review details

Files not reviewed (1)

  • pnpm-lock.yaml: Generated file
  • Files reviewed: 1/2 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread pnpm-workspace.yaml
monaco-editor: ^0.56.0
monaco-editor-core: ^0.56.0
morgan: ^1.11.0
morgan: ^1.12.0
Bumps [morgan](https://github.com/expressjs/morgan) from 1.11.0 to 1.12.0.
- [Release notes](https://github.com/expressjs/morgan/releases)
- [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md)
- [Commits](expressjs/morgan@1.11.0...1.12.0)

---
updated-dependencies:
- dependency-name: morgan
  dependency-version: 1.12.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Copilot AI review requested due to automatic review settings September 9, 2026 19:02
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/morgan-1.12.0 branch from d2c8567 to 2bf2911 Compare September 9, 2026 19:02

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

A .chronus/changes/* entry is needed to record the dependency bump per the repo’s PR/changelog conventions.

Review details

Files not reviewed (1)

  • pnpm-lock.yaml: Generated file

Suppressed comments (1)

pnpm-workspace.yaml:127

  • This dependency bump should be accompanied by a .chronus/changes/* entry (changeKind dependencies) per the repo PR instructions (.github/copilot-instructions.md:129-133). This catalog entry impacts at least @typespec/spector (dependency at packages/spector/package.json:54) and @typespec/http-server-js (devDependency at packages/http-server-js/package.json:87), so the release notes should record the morgan update (dependencies is a valid kind per .chronus/config.yaml:14-18).
  morgan: ^1.12.0
  • Files reviewed: 1/2 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant