[Snyk] Upgrade winston from 3.2.1 to 3.4.0 #24
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade winston from 3.2.1 to 3.4.0.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-COLORSTRING-1082939
Why? Proof of Concept exploit, CVSS 5.3
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: winston
-
3.4.0 - 2022-01-10
- ties up a loose end by including [#1973] to go with [#1824]
- adds a missing http property in NpmConfigSetColors [#2004] (thanks @ SimDaSong)
- fixes a minor issue in the build/release process [#2014]
- pins the version of the testing framework to avoid an issue with a test incorrectly failing [#2017]
-
3.3.4 - 2022-01-10
- [#1964] Added documentation for how to use a new externally maintained Seq transport.
- [#1712] Add default metadata when calling log with string level and message.
- [#1824] Unbind event listeners on close
- [#1961] Handle undefined rejections
- [#1878] Correct boolean evaluation of empty-string value for eol option
- [#1977] Improved consistency of object parameters for better test reliability
-
3.3.3 - 2020-06-23
- Prepare for 3.3.3 c416e3a
- revert Fix bugs in type (#1807) (#1820) 35b0774
- Fix issue #1817 (#1819) bc6f681
-
3.3.2 - 2020-06-22
- [#1814] Use fork of diagnostics on NPM to avoid making Docker images require git 0752614
-
3.3.1 - 2020-06-22
- Prep for 3.3.1 faac066
- Add space between
- Fix bugs in
- Fix typing for Profile.start (was Date, should be Number) (#1803) 0e1c812
- Merge branch 'master' of github.com:winstonjs/winston 9e7bd71
- [#1813] Use fork of diagnostics, avoiding indirect storage-engine dependency 67cd9b5
- remove emitErrs note from README (its no longer supported) (#1810) 6545a7e
-
3.3.0 - 2020-06-21
-
3.2.1 - 2019-01-29
from winston GitHub release notesv3.4.0 / 2022-01-10
Yesterday's release was done with a higher sense of urgency than usual due to vandalism in the
colorspackage. This release:The biggest change in this release, motivating the feature-level update, is [#2006] Make winston more ESM friendly, thanks to @ miguelcobain.
Thanks also to @ DABH, @ wbt, and @ fearphage for contributions and reviews!
Compared to v3.3.3, this version fixes some issues and includes some updates to project infrastructure,
such as replacing Travis with Github CI and dependabot configuration.
There have also been several relatively minor improvements to documentation, and incorporation of some updated dependencies.
Dependency updates include a critical bug fix [#2008] in response to self-vandalism by the author of a dependency.
v3.3.2...v3.3.3
v3.3.1...v3.3.2
info.messageandmeta.message(#1740) 227ca0acreateLoggertype (#1807) ef97171v3.3.0...v3.3.1
Read more
Version 3.2.1
Commit messages
Package name: winston
Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:

🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs