Skip to content

build(deps-dev): Bump morgan from 1.11.0 to 1.12.1 - #672

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/morgan-1.12.0
Open

build(deps-dev): Bump morgan from 1.11.0 to 1.12.1#672
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/morgan-1.12.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 10, 2026

Copy link
Copy Markdown
Contributor

Bumps morgan from 1.11.0 to 1.12.1.

Release notes

Sourced from morgan's releases.

1.12.1

Important

What's Changed

New Contributors

Full Changelog: expressjs/morgan@1.12.0...1.12.1

1.12.0

What's Changed

New Contributors

Full Changelog: expressjs/morgan@1.11.0...1.12.0

Changelog

Sourced from morgan's changelog.

1.12.1

1.12.0

  • Security fix for CVE-2026-15603(GHSA-jxfw-x594-9x9m)
  • Allow format functions to return objects for streams in objectMode
  • Respect the NO_COLOR environment variable in the dev format
Commits
  • b1272e7 1.12.1 (#386)
  • 4b695ed fix: escape double quotes in log fields
  • 0f74eca build(deps): bump github/codeql-action/analyze from 4.37.4 to 4.37.9 (#384)
  • e399e3c build(deps): bump github/codeql-action/init from 4.37.4 to 4.37.9 (#383)
  • 1e86b34 build(deps): bump github/codeql-action/autobuild from 4.37.4 to 4.37.9 (#382)
  • 87c0afd build(deps): bump github/codeql-action/upload-sarif to 4.37.9 (#381)
  • 286b000 test: run CI on Windows and macOS (#379)
  • 5a5902a docs: fix typos across documentation (#378)
  • 063f084 1.12.0 (#376)
  • fbf9383 fix: escape all token values in log output
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for morgan since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 10, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 10, 2026 03:13
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 10, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/morgan-1.12.0 branch 2 times, most recently from f60631d to 68481a1 Compare September 10, 2026 23:58
@dependabot dependabot Bot changed the title build(deps-dev): Bump morgan from 1.11.0 to 1.12.0 build(deps-dev): Bump morgan from 1.11.0 to 1.12.1 Sep 11, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/morgan-1.12.0 branch 2 times, most recently from dbefcfa to eeca29e Compare September 11, 2026 19:43
@lindsnguyen

Copy link
Copy Markdown

/azp run FluidHelloWorld

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

Bumps [morgan](https://github.com/expressjs/morgan) from 1.11.0 to 1.12.1.
- [Release notes](https://github.com/expressjs/morgan/releases)
- [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md)
- [Commits](expressjs/morgan@1.11.0...1.12.1)

---
updated-dependencies:
- dependency-name: morgan
  dependency-version: 1.12.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/morgan-1.12.0 branch from eeca29e to 39fd961 Compare September 11, 2026 21:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant