Skip to content

Update dependency morgan to v1.11.0 - #349

Open
mend-for-github-com[bot] wants to merge 2 commits into
mainfrom
whitesource-remediate/morgan-1.x-lockfile
Open

Update dependency morgan to v1.11.0#349
mend-for-github-com[bot] wants to merge 2 commits into
mainfrom
whitesource-remediate/morgan-1.x-lockfile

🤖 Auto-generate tutorial environment [skip ci]: Update dependency mor…

7f7505c
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / WhiteSource Security Check failed Jul 27, 2026 in 19m 52s

Security Report

4 new vulnerabilities were introduced in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2026-4926

Dependency Hierarchy:

-> express-5.2.1.tgz (Root Library)

   -> router-2.2.0.tgz

     -> ❌ path-to-regexp-8.3.0.tgz (Vulnerable Library)

High 7.5 Transitive path-to-regexp-8.3.0.tgz express-5.2.1.tgz Transitive path-to-regexp - 8.4.0 #⁠99
CVE-2026-4923

Dependency Hierarchy:

-> express-5.2.1.tgz (Root Library)

   -> router-2.2.0.tgz

     -> ❌ path-to-regexp-8.3.0.tgz (Vulnerable Library)

Medium 5.9 Transitive path-to-regexp-8.3.0.tgz express-5.2.1.tgz Transitive path-to-regexp - 8.4.0 #⁠99
CVE-2026-8723

Dependency Hierarchy:

-> express-5.2.1.tgz (Root Library)

   -> ❌ qs-6.14.1.tgz (Vulnerable Library)

Medium 5.3 Transitive qs-6.14.1.tgz express-5.2.1.tgz Transitive 6.15.2 #⁠99
CVE-2026-2391

Dependency Hierarchy:

-> express-5.2.1.tgz (Root Library)

   -> ❌ qs-6.14.1.tgz (Vulnerable Library)

Low 3.7 Transitive qs-6.14.1.tgz express-5.2.1.tgz Transitive 6.14.2 #⁠99

Base branch total remaining vulnerabilities: 99
Base branch commit: 71adadcb393bd7ba474ecb8d75bdfc87e08860a0


Total libraries scanned: 1768

Scan token: ac6078fcea634877affd6c9cb8d37f19