Skip to content

chore(deps): bump winston from 3.5.1 to 3.7.2#54

Closed
dependabot[bot] wants to merge 1 commit intodevfrom
dependabot/npm_and_yarn/winston-3.7.2
Closed

chore(deps): bump winston from 3.5.1 to 3.7.2#54
dependabot[bot] wants to merge 1 commit intodevfrom
dependabot/npm_and_yarn/winston-3.7.2

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github May 1, 2022

Bumps winston from 3.5.1 to 3.7.2.

Release notes

Sourced from winston's releases.

v3.7.2

What's Changed

Full Changelog: winstonjs/winston@v3.7.1...v3.7.2

The release announcement on GitHub is 24 days behind the NPM release in this case, sorry for the confusion!

v3.7.1

This change includes some minor updates to package-lock.json resolving npm audit failures: one in ansi-regex and another in minimist.

Full Changelog: winstonjs/winston@v3.7.0...v3.7.1

v3.7.0

What's Changed

New Contributors

Full Changelog: winstonjs/winston@v3.6.0...v3.7.0

v3.6.0

  • Changelog updates for v3.6.0 5e72485
  • Update dependencies, including latest logform (#2071) 93077ef
  • Update to @​colors/colors (#2069) 035f94a
  • Bump @​babel/core from 7.16.12 to 7.17.2 (#2068) 7665d88
  • Bump @​babel/cli from 7.16.8 to 7.17.0 (#2064) e658389
  • chore: add editorconfig (#2058) 30d260d
  • Add search terms field to bug report template (#2067) 40ef309
  • Bump @​types/node from 17.0.13 to 17.0.15 (#2062) c9b7579
  • Chore: Organize and restructure tests (#2049) 2b8cd55
  • Bump to latest winston-transport 2017c50
  • Memory leak fix: do not wait for process.nextTick to clear pending callbacks (#2057) f741383
  • Update linter dependencies and config (#2059) 438cb73
  • Bump @​types/node from 17.0.10 to 17.0.13 (#2051) 7f6a6f2

... (truncated)

Changelog

Sourced from winston's changelog.

v3.7.2 / 2022-04-04

This change reverts what should have been the feature-level update in 3.7.0 due to issue #2103 showing this to be breaking, unintentionally.

v3.7.1 / 2022-04-04

This change includes some minor updates to package-lock.json resolving npm audit failures: one in ansi-regex and another in minimist.

v3.7.0 / 2022-03-30

Feature-level updates:

Patch-level updates:

  • #2075 Fix: add missing types for batching options for HTTP Transport (thanks @​KylinDC)
  • Various dependencies updated, quality of life & maintainability changes, etc

v3.6.0 / 2022-02-12

  • #2057 Fix potential memory leak by not waiting for process.nextTick before clearing pending callbacks (thanks @​smashah!)
  • #2071 Update to logform 2.4.0, which includes changes such as new options for JsonOptions and some typo fixes regarding levels
  • Various other dependencies are updated, tests are reorganized and cleaned up, etc. (thanks @​wbt, @​Maverick1872, @​fearphage!)
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [winston](https://github.com/winstonjs/winston) from 3.5.1 to 3.7.2.
- [Release notes](https://github.com/winstonjs/winston/releases)
- [Changelog](https://github.com/winstonjs/winston/blob/master/CHANGELOG.md)
- [Commits](winstonjs/winston@v3.5.1...v3.7.2)

---
updated-dependencies:
- dependency-name: winston
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels May 1, 2022
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Jul 1, 2022

Superseded by #65.

@dependabot dependabot bot closed this Jul 1, 2022
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/winston-3.7.2 branch July 1, 2022 04:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants