[Snyk] Upgrade morgan from 1.5.3 to 1.10.0 #5
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade morgan from 1.5.3 to 1.10.0.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-MORGAN-72579
Why? Proof of Concept exploit, Has a fix available, CVSS 6.8
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: morgan
:total-time
tokendev
formateval
usage withFunction
constructorprocess
to check for listenersres.writeHead
patch missing return valueres.headersSent
when availablesafe-buffer
for improved Buffer APIBuffer
loadingDEBUG_MAX_ARRAY_LENGTH
DEBUG_FD
set to1
or2
undefined
argument to token functionsDEBUG_FD
environment variabledigits
argument toresponse-time
tokenmorgan.compile(format)
exportdev
formatresponse-time
token to not include response latencystatus
token incorrectly displaying before response indev
formatundefined
or a stringreq
andres
tokensres.getHeader
inres
tokenCONNECT
requestsUpgrade
requestsdev
formatskip
optionisFinished(req)
when data bufferedCommit messages
Package name: morgan
Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs