Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Jul 1, 2022

Bumps winston from 3.5.1 to 3.8.1.

Release notes

Sourced from winston's releases.

v3.8.1

Patch-level changes

Dependency updates by @​dependabot + CI autotesting

Full Changelog: winstonjs/winston@v3.8.0...v3.8.1

v3.8.0

Added functionality

Dependency updates by @​dependabot + CI autotesting

  • Bump @​babel/core from 7.17.8 to 7.18.5
  • Bump eslint from 8.12.0 to 8.18.0
  • Bump @​types/node from 17.0.23 to 18.0.0
  • Bump @​babel/preset-env from 7.16.11 to 7.18.2
  • Bump @​babel/cli from 7.17.6 to 7.17.10

Updates facilitating repo maintenance & enhancing documentation

New Contributors

Full Changelog: winstonjs/winston@v3.7.2...v3.8.0

v3.7.2

What's Changed

Full Changelog: winstonjs/winston@v3.7.1...v3.7.2

The release announcement on GitHub is 24 days behind the NPM release in this case, sorry for the confusion!

v3.7.1

This change includes some minor updates to package-lock.json resolving npm audit failures: one in ansi-regex and another in minimist.

Full Changelog: winstonjs/winston@v3.7.0...v3.7.1

... (truncated)

Changelog

Sourced from winston's changelog.

v3.8.1

Patch-level changes

Dependency updates by @​dependabot + CI autotesting

v3.8.0 / 2022-06-23

Added functionality

Dependency updates by @​dependabot + CI autotesting

  • Bump @​babel/core from 7.17.8 to 7.18.5
  • Bump eslint from 8.12.0 to 8.18.0
  • Bump @​types/node from 17.0.23 to 18.0.0
  • Bump @​babel/preset-env from 7.16.11 to 7.18.2
  • Bump @​babel/cli from 7.17.6 to 7.17.10

Updates facilitating repo maintenance & enhancing documentation

Thanks especially to new contributors @​zizifn, @​arpad1337, @​domiins, & @​jeanpierrecarvalho!

v3.7.2 / 2022-04-04

This change reverts what should have been the feature-level update in 3.7.0 due to issue #2103 showing this to be breaking, unintentionally.

v3.7.1 / 2022-04-04

This change includes some minor updates to package-lock.json resolving npm audit failures: one in ansi-regex and another in minimist.

v3.7.0 / 2022-03-30

Feature-level updates:

Patch-level updates:

  • #2075 Fix: add missing types for batching options for HTTP Transport (thanks @​KylinDC)
  • Various dependencies updated, quality of life & maintainability changes, etc

v3.6.0 / 2022-02-12

  • #2057 Fix potential memory leak by not waiting for process.nextTick before clearing pending callbacks (thanks @​smashah!)
  • #2071 Update to logform 2.4.0, which includes changes such as new options for JsonOptions and some typo fixes regarding levels
  • Various other dependencies are updated, tests are reorganized and cleaned up, etc. (thanks @​wbt, @​Maverick1872, @​fearphage!)
Commits
  • 3998df0 v3.8.1 docs
  • 013799c Bump async from 3.2.3 to 3.2.4
  • 6217120 Replace new with constructor
  • afd389a Change interface to class in exported types
  • b892de9 Bump logform from 2.4.0 to 2.4.1
  • 5658ec3 Note 2nd place for version # update
  • 70ffba6 Another update of package #
  • 38c1c46 Update changelog & version # 3.8.0
  • 7b1917e Update publishing steps for easier drafting
  • 6e27faa Prettier Config File
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [winston](https://github.com/winstonjs/winston) from 3.5.1 to 3.8.1.
- [Release notes](https://github.com/winstonjs/winston/releases)
- [Changelog](https://github.com/winstonjs/winston/blob/master/CHANGELOG.md)
- [Commits](winstonjs/winston@v3.5.1...v3.8.1)

---
updated-dependencies:
- dependency-name: winston
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jul 1, 2022
@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Oct 1, 2022

Superseded by #28.

@dependabot dependabot bot closed this Oct 1, 2022
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/winston-3.8.1 branch October 1, 2022 09:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant