Snyk has created this PR to upgrade winston from 3.3.3 to 3.5.0.
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 3 versions ahead of your current version.
The recommended version was released 23 days ago, on 2022-01-27.
Snyk has created this PR to upgrade winston from 3.3.3 to 3.5.0.
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-COLORSTRING-1082939
Why? Proof of Concept exploit, CVSS 5.3
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: winston
This release includes the following, in sequence by first merge in group:
Feature updates:
Patch-level updates:
.rejections
(#1842, #1929, #2021; thanks @ vanflux, @ svaj, @ glensc, & others!)stringify
, e.g. to avoid issues from circular structures, in the http transport (#2043, thanks @ karlwir!)Updates to the repo & project which don’t actually affect the running code:
Thanks also to maintainers @ DABH, @ fearphage, @ Maverick1872, and @ wbt for issue/PR shepherding and help across multiple parts of the release!
If somebody got missed in the list of thanks, please forgive the accidental oversight and/or feel free to open a PR on the changelog.
v3.4.0 / 2022-01-10
Yesterday's release was done with a higher sense of urgency than usual due to vandalism in the
colors
package. This release:The biggest change in this release, motivating the feature-level update, is [#2006] Make winston more ESM friendly, thanks to @ miguelcobain.
Thanks also to @ DABH, @ wbt, and @ fearphage for contributions and reviews!
Version 3.3.4
v3.3.2...v3.3.3
Commit messages
Package name: winston
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs