Skip to content

fix(deps): upgrade winston to 3.19.0#83

Closed
wayne-grant wants to merge 2 commits intomainfrom
snyk-upgrade-dbb115b3e47a08243f494be22e462a6f
Closed

fix(deps): upgrade winston to 3.19.0#83
wayne-grant wants to merge 2 commits intomainfrom
snyk-upgrade-dbb115b3e47a08243f494be22e462a6f

Conversation

@wayne-grant
Copy link
Contributor

snyk-top-banner

Snyk has created this PR to upgrade winston from 3.17.0 to 3.19.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 5 versions ahead of your current version.

  • The recommended version was released 3 months ago.

Breaking Change Risk

Merge Risk: Low

Notice: This assessment is enhanced by AI.

Release notes
Package name: winston from winston GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Snyk has automatically assigned this pull request, set who gets assigned.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

@wayne-grant wayne-grant requested a review from a team as a code owner March 4, 2026 11:13
@wayne-grant
Copy link
Contributor Author

Merge Risk: Low

This minor version upgrade for winston includes bug fixes, dependency updates, and one notable change to its TypeScript definitions.

  • TypeScript Definition Change: In version 3.19.0, the LogCallback type was removed. According to the release notes, this callback was not functionally supported by the library, so any code relying on it was not being executed. This change may cause build failures in TypeScript projects that reference this type, but it should not impact runtime behavior.
  • Other Changes: The releases between 3.17.0 and 3.19.0 consist of bug fixes and dependency updates, including a security fix for a transitive dependency in v3.18.0.

Recommendation:
If you are using TypeScript and referencing the LogCallback type, you will need to remove those references. Otherwise, no action is required.

Source: GitHub Releases

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@snyk-io
Copy link

snyk-io bot commented Mar 4, 2026

Snyk checks have passed. No issues have been found so far.

Status Scanner Critical High Medium Low Total (0)
🔚 Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@dragos-cojocari dragos-cojocari deleted the snyk-upgrade-dbb115b3e47a08243f494be22e462a6f branch March 5, 2026 11:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants