Skip to content

Commit ba74d7b

Browse files
chore(deps): Bump morgan from 1.10.0 to 1.11.0 (#22187)
Bumps [morgan](https://github.com/expressjs/morgan) from 1.10.0 to 1.11.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/expressjs/morgan/releases">morgan's releases</a>.</em></p> <blockquote> <h2>1.11.0</h2> <h2>What's Changed</h2> <ul> <li>feat: add :pid token by <a href="https://github.com/ganesh3367"><code>@​ganesh3367</code></a> in <a href="https://redirect.github.com/expressjs/morgan/pull/329">expressjs/morgan#329</a></li> </ul> <p>Security Fix:</p> <ul> <li>Escape control characters in <code>:remote-user</code> token to prevent log injection <ul> <li>Fixes <a href="https://www.cve.org/CVERecord?id=CVE-2026-5078">CVE-2026-5078</a> <a href="https://github.com/expressjs/morgan/security/advisories/GHSA-4vj7-5mj6-jm8m">GHSA-4vj7-5mj6-jm8m</a></li> </ul> </li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/inigomarquinez"><code>@​inigomarquinez</code></a> made their first contribution in <a href="https://redirect.github.com/expressjs/morgan/pull/291">expressjs/morgan#291</a></li> <li><a href="https://github.com/jonchurch"><code>@​jonchurch</code></a> made their first contribution in <a href="https://redirect.github.com/expressjs/morgan/pull/299">expressjs/morgan#299</a></li> <li><a href="https://github.com/bjohansebas"><code>@​bjohansebas</code></a> made their first contribution in <a href="https://redirect.github.com/expressjs/morgan/pull/301">expressjs/morgan#301</a></li> <li><a href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a> made their first contribution in <a href="https://redirect.github.com/expressjs/morgan/pull/300">expressjs/morgan#300</a></li> <li><a href="https://github.com/ctcpip"><code>@​ctcpip</code></a> made their first contribution in <a href="https://redirect.github.com/expressjs/morgan/pull/319">expressjs/morgan#319</a></li> <li><a href="https://github.com/ganesh3367"><code>@​ganesh3367</code></a> made their first contribution in <a href="https://redirect.github.com/expressjs/morgan/pull/329">expressjs/morgan#329</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/expressjs/morgan/compare/1.10.0...1.11.0">https://github.com/expressjs/morgan/compare/1.10.0...1.11.0</a></p> <h2>1.10.1</h2> <h2>What's Changed</h2> <ul> <li>renaming simple to sample in readme by <a href="https://github.com/ryhinchey"><code>@​ryhinchey</code></a> in <a href="https://redirect.github.com/expressjs/morgan/pull/237">expressjs/morgan#237</a></li> <li>adding installation instructions to readme by <a href="https://github.com/ryhinchey"><code>@​ryhinchey</code></a> in <a href="https://redirect.github.com/expressjs/morgan/pull/233">expressjs/morgan#233</a></li> <li>chore: add support for OSSF scorecard reporting by <a href="https://github.com/inigomarquinez"><code>@​inigomarquinez</code></a> in <a href="https://redirect.github.com/expressjs/morgan/pull/291">expressjs/morgan#291</a></li> <li>ci: replace travis with github actions by <a href="https://github.com/inigomarquinez"><code>@​inigomarquinez</code></a> in <a href="https://redirect.github.com/expressjs/morgan/pull/290">expressjs/morgan#290</a></li> <li>docs: add example output for log formats by <a href="https://github.com/jonchurch"><code>@​jonchurch</code></a> in <a href="https://redirect.github.com/expressjs/morgan/pull/299">expressjs/morgan#299</a></li> <li>ci: use ubuntu-latest by <a href="https://github.com/bjohansebas"><code>@​bjohansebas</code></a> in <a href="https://redirect.github.com/expressjs/morgan/pull/301">expressjs/morgan#301</a></li> <li>ci: apply OSSF Scorecard security best practices by <a href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a> in <a href="https://redirect.github.com/expressjs/morgan/pull/300">expressjs/morgan#300</a></li> <li>remove --bail by <a href="https://github.com/jonchurch"><code>@​jonchurch</code></a> in <a href="https://redirect.github.com/expressjs/morgan/pull/314">expressjs/morgan#314</a></li> <li>⬆️ bump on-headers by <a href="https://github.com/ctcpip"><code>@​ctcpip</code></a> in <a href="https://redirect.github.com/expressjs/morgan/pull/319">expressjs/morgan#319</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/inigomarquinez"><code>@​inigomarquinez</code></a> made their first contribution in <a href="https://redirect.github.com/expressjs/morgan/pull/291">expressjs/morgan#291</a></li> <li><a href="https://github.com/jonchurch"><code>@​jonchurch</code></a> made their first contribution in <a href="https://redirect.github.com/expressjs/morgan/pull/299">expressjs/morgan#299</a></li> <li><a href="https://github.com/bjohansebas"><code>@​bjohansebas</code></a> made their first contribution in <a href="https://redirect.github.com/expressjs/morgan/pull/301">expressjs/morgan#301</a></li> <li><a href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a> made their first contribution in <a href="https://redirect.github.com/expressjs/morgan/pull/300">expressjs/morgan#300</a></li> <li><a href="https://github.com/ctcpip"><code>@​ctcpip</code></a> made their first contribution in <a href="https://redirect.github.com/expressjs/morgan/pull/319">expressjs/morgan#319</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/expressjs/morgan/compare/1.10.0...1.10.1">https://github.com/expressjs/morgan/compare/1.10.0...1.10.1</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/expressjs/morgan/blob/master/HISTORY.md">morgan's changelog</a>.</em></p> <blockquote> <h1>1.11.0 / 2026-06-02</h1> <ul> <li>add <code>:pid</code> token</li> </ul> <p>Security Fix:</p> <ul> <li>Escape control characters in <code>:remote-user</code> token to prevent log injection <ul> <li>Fixes <a href="https://www.cve.org/CVERecord?id=CVE-2026-5078">CVE-2026-5078</a> <a href="https://github.com/expressjs/morgan/security/advisories/GHSA-4vj7-5mj6-jm8m">GHSA-4vj7-5mj6-jm8m</a></li> </ul> </li> </ul> <h1>1.10.1 / 2025-07-17</h1> <ul> <li>deps: on-headers@~1.1.0 <ul> <li>Fix <a href="https://www.cve.org/CVERecord?id=CVE-2025-7339">CVE-2025-7339</a> (<a href="https://github.com/expressjs/on-headers/security/advisories/GHSA-76c9-3jph-rj3q">GHSA-76c9-3jph-rj3q</a>)</li> </ul> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/expressjs/morgan/commit/e0e6f17574db56396f8e60ebb03bb7aaaeb9cc6f"><code>e0e6f17</code></a> Release 1.11.0 (<a href="https://redirect.github.com/expressjs/morgan/issues/350">#350</a>)</li> <li><a href="https://github.com/expressjs/morgan/commit/b3f5d9bdb388690dfae9c06ab966328f49b7982b"><code>b3f5d9b</code></a> Merge commit from fork</li> <li><a href="https://github.com/expressjs/morgan/commit/203c75852adadcc5e3a9ba23b0ef07a8e81c5af7"><code>203c758</code></a> build(deps): bump github/codeql-action from 4.32.4 to 4.35.2 (<a href="https://redirect.github.com/expressjs/morgan/issues/346">#346</a>)</li> <li><a href="https://github.com/expressjs/morgan/commit/002bc81f47a7641d86b7e16ee0f343e5eed81a6a"><code>002bc81</code></a> build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (<a href="https://redirect.github.com/expressjs/morgan/issues/347">#347</a>)</li> <li><a href="https://github.com/expressjs/morgan/commit/561b0d70bf4486245b311a02259d32ae45756331"><code>561b0d7</code></a> build(deps): bump actions/upload-artifact from 5.0.0 to 7.0.0 (<a href="https://redirect.github.com/expressjs/morgan/issues/338">#338</a>)</li> <li><a href="https://github.com/expressjs/morgan/commit/2db705ecf05eed5a2990da4be8731a1d7051692c"><code>2db705e</code></a> build(deps): bump github/codeql-action from 3.29.7 to 4.32.4 (<a href="https://redirect.github.com/expressjs/morgan/issues/337">#337</a>)</li> <li><a href="https://github.com/expressjs/morgan/commit/a373c5f25df88c7f31b4abb36306d7e025edcc8c"><code>a373c5f</code></a> build(deps): bump ossf/scorecard-action from 2.3.1 to 2.4.3 (<a href="https://redirect.github.com/expressjs/morgan/issues/327">#327</a>)</li> <li><a href="https://github.com/expressjs/morgan/commit/c8e72fa73c7e54a00f0e28db1bc6edbeb83dbbc0"><code>c8e72fa</code></a> build(deps): bump actions/checkout from 4.1.1 to 6.0.1 (<a href="https://redirect.github.com/expressjs/morgan/issues/324">#324</a>)</li> <li><a href="https://github.com/expressjs/morgan/commit/023300e37da5e2a3394a50171d07a0bb6860eab5"><code>023300e</code></a> build(deps): bump actions/upload-artifact from 4.3.1 to 4.6.2 (<a href="https://redirect.github.com/expressjs/morgan/issues/307">#307</a>)</li> <li><a href="https://github.com/expressjs/morgan/commit/9d8d6c099765b1d4722aadfb68dbf0a227ff8e64"><code>9d8d6c0</code></a> build(deps): bump coverallsapp/github-action from 1.2.5 to 2.3.6 (<a href="https://redirect.github.com/expressjs/morgan/issues/306">#306</a>)</li> <li>Additional commits viewable in <a href="https://github.com/expressjs/morgan/compare/1.10.0...1.11.0">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~ulisesgascon">ulisesgascon</a>, a new releaser for morgan since your current version.</p> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=morgan&package-manager=npm_and_yarn&previous-version=1.10.0&new-version=1.11.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/getsentry/sentry-javascript/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Lukas Stracke <lukas.stracke@sentry.io>
1 parent e9cfc12 commit ba74d7b

1 file changed

Lines changed: 5 additions & 10 deletions

File tree

yarn.lock

Lines changed: 5 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -21995,15 +21995,15 @@ mongoose@^6.13.6:
2199521995
sift "16.0.1"
2199621996

2199721997
morgan@^1.10.0:
21998-
version "1.10.0"
21999-
resolved "https://registry.yarnpkg.com/morgan/-/morgan-1.10.0.tgz#091778abc1fc47cd3509824653dae1faab6b17d7"
22000-
integrity sha512-AbegBVI4sh6El+1gNwvD5YIck7nSA36weD7xvIxG4in80j/UoK8AEGaWnnz8v1GxonMCltmlNs5ZKbGvl9b1XQ==
21998+
version "1.11.0"
21999+
resolved "https://registry.yarnpkg.com/morgan/-/morgan-1.11.0.tgz#98464b8538802f14e9e5374ebe23ac364cd617e8"
22000+
integrity sha512-zSkVu3t18r39pw4ixfBKvfZi3y2UOqr7d4WYwcj3m8nXpEQK4rPO6GLzs/CExoRgmX3y9EjmmcXqv6jq0SK46g==
2200122001
dependencies:
2200222002
basic-auth "~2.0.1"
2200322003
debug "2.6.9"
2200422004
depd "~2.0.0"
22005-
on-finished "~2.3.0"
22006-
on-headers "~1.0.2"
22005+
on-finished "~2.4.1"
22006+
on-headers "~1.1.0"
2200722007

2200822008
mout@^1.0.0:
2200922009
version "1.2.4"
@@ -23238,11 +23238,6 @@ on-finished@~2.3.0:
2323823238
dependencies:
2323923239
ee-first "1.1.1"
2324023240

23241-
on-headers@~1.0.2:
23242-
version "1.0.2"
23243-
resolved "https://registry.yarnpkg.com/on-headers/-/on-headers-1.0.2.tgz#772b0ae6aaa525c399e489adfad90c403eb3c28f"
23244-
integrity sha512-pZAE+FJLoyITytdqK0U5s+FIpjN0JP3OzFi/u8Rx+EV5/W+JTWGXG8xFzevE7AjBfDqHv/8vL8qQsIhHnqRkrA==
23245-
2324623241
on-headers@~1.1.0:
2324723242
version "1.1.0"
2324823243
resolved "https://registry.yarnpkg.com/on-headers/-/on-headers-1.1.0.tgz#59da4f91c45f5f989c6e4bcedc5a3b0aed70ff65"

0 commit comments

Comments
 (0)