Skip to content

Conversation

@snyk-bot
Copy link

@snyk-bot snyk-bot commented Apr 7, 2022

Snyk has created this PR to upgrade winston from 3.2.1 to 3.6.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 9 versions ahead of your current version.
  • The recommended version was released 2 months ago, on 2022-02-12.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-COLORSTRING-1082939
372/1000
Why? Proof of Concept exploit, CVSS 5.3
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: winston from winston GitHub release notes
Commit messages
Package name: winston
  • b2fde9d 3.6.0
  • 5e72485 Changelog updates for v3.6.0
  • 93077ef Update dependencies, including latest logform (#2071)
  • 035f94a Update to @ colors/colors (#2069)
  • 7665d88 Bump @ babel/core from 7.16.12 to 7.17.2 (#2068)
  • e658389 Bump @ babel/cli from 7.16.8 to 7.17.0 (#2064)
  • 30d260d chore: add editorconfig (#2058)
  • 40ef309 Add search terms field to bug report template (#2067)
  • c9b7579 Bump @ types/node from 17.0.13 to 17.0.15 (#2062)
  • 2b8cd55 Chore: Organize and restructure tests (#2049)
  • 2017c50 Bump to latest winston-transport
  • f741383 Memory leak fix: do not wait for `process.nextTick` to clear pending callbacks (#2057)
  • 438cb73 Update linter dependencies and config (#2059)
  • 7f6a6f2 Bump @ types/node from 17.0.10 to 17.0.13 (#2051)
  • 22bb31a Revert pr 1896 (#2052) for rerelease
  • a320b0c Revert "typed level type" (#2050)
  • 237534a Release 3.5.0 (#2045)
  • d18198d chore: use safe stringify in http transport (#2043)
  • 8a1735b Update README.md (#2027)
  • 278c492 Bump @ babel/preset-env from 7.16.8 to 7.16.11 (#2040)
  • 609a84b Bump @ babel/core from 7.16.7 to 7.16.12 (#2041)
  • f2d7e06 Bump @ types/node from 17.0.9 to 17.0.10 (#2042)
  • 3b48008 Bump @ babel/cli from 7.16.7 to 7.16.8 (#2034)
  • 4a0ed4f Bump @ types/node from 17.0.8 to 17.0.9 (#2035)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants