Skip to content
This repository was archived by the owner on Feb 3, 2023. It is now read-only.

Conversation

@mend-for-github-com
Copy link

@mend-for-github-com mend-for-github-com bot commented Jun 7, 2022

This PR contains the following updates:

Package Type Update Change
morgan dependencies minor 1.7.0 -> 1.9.0

By merging this PR, the issue #48 will be automatically resolved and closed:

Severity CVSS Score CVE
High High 9.8 CVE-2019-5413
Medium Medium 5.3 CVE-2017-16137

Release Notes

expressjs/morgan

v1.9.0

Compare Source

==================

  • Use res.headersSent when available
  • deps: basic-auth@~2.0.0
    • Use safe-buffer for improved Buffer API
  • deps: debug@2.6.9
  • deps: depd@~1.1.1
    • Remove unnecessary Buffer loading

v1.8.2

Compare Source

==================

  • deps: debug@2.6.8
    • Fix DEBUG_MAX_ARRAY_LENGTH
    • deps: ms@2.0.0

v1.8.1

Compare Source

==================

  • deps: debug@2.6.1
    • Fix deprecation messages in WebStorm and other editors
    • Undeprecate DEBUG_FD set to 1 or 2

v1.8.0

Compare Source

==================

  • Fix sending unnecessary undefined argument to token functions
  • deps: basic-auth@~1.1.0
  • deps: debug@2.6.0
    • Allow colors in workers
    • Deprecated DEBUG_FD environment variable
    • Fix error when running under React Native
    • Use same color for same namespace
    • deps: ms@0.7.2
  • perf: enable strict mode in compiled functions

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Jun 7, 2022
@mend-for-github-com mend-for-github-com bot changed the title Update dependency morgan to v1.9.1 Update dependency morgan to v1.9.0 Nov 20, 2022
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/morgan-1.x branch from 16b40f7 to b0f700a Compare November 20, 2022 19:18
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants