Skip to content
This repository was archived by the owner on Jul 6, 2024. It is now read-only.

[Snyk] Upgrade pino-http from 5.5.0 to 5.8.0 #2

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade pino-http from 5.5.0 to 5.8.0.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 3 versions ahead of your current version.
  • The recommended version was released 4 months ago, on 2021-09-21.
Release notes
Package name: pino-http
  • 5.8.0 - 2021-09-21

    What's Changed

    • Bump fastify/github-action-merge-dependabot from 2.4.0 to 2.5.0 by @ dependabot in #157
    • feature: quietReqLogger option for a quieter child logger available on the request object by @ darrenmce in #156

    New Contributors

    Full Changelog: v5.7.0...v5.8.0

  • 5.7.0 - 2021-08-21

    What's Changed

    Full Changelog: v5.6.0...v5.7.0

  • 5.6.0 - 2021-07-22

    📚 PR:

    • Fix README documentation typo for stream (#126)
    • ci: add nodejs v14 and v16 to test matrix (#128)
    • docs: details about .logger field (#127)
    • ci: add automerge job; add dependabot config (#129)
    • Bump actions/setup-node from v1 to v2.1.5 (#130)
    • Bump actions/cache from v1 to v2.1.5 (#131)
    • Bump standard from 14.3.4 to 16.0.3 (#132)
    • Bump pino-std-serializers from 2.5.0 to 3.2.0 (#133)
    • Bump autocannon from 4.6.0 to 7.3.0 (#135)
    • Bump actions/checkout from 2 to 2.3.4 (#136)
    • Bump fastify/github-action-merge-dependabot from 2.0.0 to 2.1.0 (#137)
    • Bump pino-std-serializers from 3.2.0 to 4.0.0 (#138)
    • Bump actions/cache from 2.1.5 to 2.1.6 (#139)
    • Bump fastify/github-action-merge-dependabot from 2.1.0 to 2.1.1 (#140)
    • Bump actions/setup-node from 2.1.5 to 2.2.0 (#141)
    • Bump fastify/github-action-merge-dependabot from 2.1.1 to 2.2.0 (#142)
    • Bump actions/setup-node from 2.2.0 to 2.3.0 (#143)
    • Use the second positional argument for pino.child() (#145)
    • tap v15 (#146)
  • 5.5.0 - 2021-02-04

    📚 PR:

    • either reqCustomProps or customProps are valid (#122)
from pino-http GitHub release notes
Commit messages
Package name: pino-http
  • d0627fb Bumped v5.8.0
  • fd635b3 feature: quietReqLogger option for a quieter child logger available on the request object (#156)
  • 7ee470c Bump fastify/github-action-merge-dependabot from 2.4.0 to 2.5.0 (#157)
  • c4261b6 Bumped v5.7.0
  • 7415dad add autologging ignore option (#153)
  • da8820e Bump fastify/github-action-merge-dependabot from 2.3.0 to 2.4.0 (#151)
  • a3165e6 Bump fastify/github-action-merge-dependabot from 2.2.0 to 2.3.0 (#150)
  • 8a769c8 Bump actions/setup-node from 2.3.0 to 2.3.2 (#148)
  • 2c68ad9 Bumped v5.6.0
  • a86037d tap v15 (#146)
  • 967f2a6 Use the second positional argument for pino.child() (#145)
  • 443a099 Bump actions/setup-node from 2.2.0 to 2.3.0 (#143)
  • d7759d3 Bump fastify/github-action-merge-dependabot from 2.1.1 to 2.2.0 (#142)
  • 6856a60 Bump actions/setup-node from 2.1.5 to 2.2.0 (#141)
  • c06dc96 Bump fastify/github-action-merge-dependabot from 2.1.0 to 2.1.1 (#140)
  • 930aac6 Bump actions/cache from 2.1.5 to 2.1.6 (#139)
  • f88e051 Bump pino-std-serializers from 3.2.0 to 4.0.0 (#138)
  • dc7edbc Bump fastify/github-action-merge-dependabot from 2.0.0 to 2.1.0 (#137)
  • 5ce4448 Bump actions/checkout from 2 to 2.3.4 (#136)
  • e0a146a Bump autocannon from 4.6.0 to 7.3.0 (#135)
  • fbee685 Bump pino-std-serializers from 2.5.0 to 3.2.0 (#133)
  • 7fe9ec1 Bump standard from 14.3.4 to 16.0.3 (#132)
  • 08f366f Bump actions/cache from v1 to v2.1.5 (#131)
  • bea5a6c Bump actions/setup-node from v1 to v2.1.5 (#130)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

# for free to subscribe to this conversation on GitHub. Already have an account? #.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant