NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #4692 most downloaded on npm
a JSON logging library for node.js services
Last release 6 years ago
no release in 18 months
Ships unpredictably
gaps range from 2 weeks to 2.9 years
Nearly every release is documented
notes for 54 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
15 years old
112 releases · first in 2012
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
[pull #575, #278] Change the default "req" serializer to accept expressjs's req.originalUrl for the "url" field per . (By @twelve17 and @kingcody.)
req.originalUrl for the "url" field per
https://expressjs.com/en/api.html#req.originalUrl. (By @twelve17 and
@kingcody.)[pull #558] Update minimum "moment" version to 2.19.3 for CVE-2017-18214.
os.EOL for newlines in bunyan output, which helps with
some Unix-EOL-naive apps like notepad. (By @bwknight877.)Fix a vulnerability from a crafted argument to 'bunyan -p ARG'
Fix a vulnerability from a crafted argument to 'bunyan -p ARG'
This was reported privately as: https://hackerone.com/reports/902739 bunyan - RCE via insecure command formatting
Previous to this version the 'bunyan' CLI was not escaping a given argument
to the '-p' option before executing ps -A -o pid,command | grep '$ARG'
which could lead to unintended execution.
[issue #444] Fix the bunyan CLI to not duplicate the "HTTP/1.1 ..." status line when serializing a "res" field.
bunyan CLI to not duplicate the "HTTP/1.1 ..." status
line when serializing a "res" field.[issue #504] The bunyan 1.x CLI adds a Host: $client_req.address[:$client_req.port] header when rendering a client_req field in a log record. Fix that
bunyan 1.x CLI adds a Host: $client_req.address[:$client_req.port]
header when rendering a client_req field in a log record. Fix that here to:
(a) not add it if client_req.headers already includes a host header; and
(b) not include the given port if it is 80 or 443 (assuming that is the
default port.
Note: bunyan 2.x CLI will stop adding this Host header because it is a guess
that can be wrong and misleading.Ensure that bunyan errors out if attempting to use -p PID and file args at the same time.
bunyan errors out if attempting to use -p PID and
file args at the same time.[pull #409, issue #246] Revert a change added to the bunyan CLI version 1.0.1 where SIGINT was ignored, such that Ctrl+C could not be used to terminat
bunyan CLI version
1.0.1 where SIGINT was ignored, such that Ctrl+C could not be used to
terminate bunyan. (By @zbjornson and @davepacheco.)"use strict;") error in some versions of
Safari.Fix breakage due to a silly last minute "fix 'make check'".
Note: *Bad release.* Use 1.8.8 or later.
Note: Bad release. Use 1.8.8 or later.
Note: *Bad release.* Use 1.8.7 or later.
Note: Bad release. Use 1.8.7 or later.
safeCycles is too slow when logging large objects.[issue #401] Improved performance when using disabled log levels.
[issue #454] Fix src usage with node v7.
src usage with node v7.[issue #450] Fix log.info(null) crash that resulted from #426 in v1.8.2.
log.info(null) crash that resulted from #426 in v1.8.2.[issue #449] Bump dtrace-provider dep to 0.7.0 to help avoid deprecation warnings with node v6 in some cases.
log.info({err: err}) results in a "msg" value, just
like log.info(err).[pull #386] Fix bad bug in rotation that could cause a crash with error message "cannot start a rotation when already rotating" (by Frankie O'Rourke).
Note: *Bad release.* An addition in this release broke 'rotating-file' usage. Use 1.8.1 or later.
Note: Bad release. An addition in this release broke 'rotating-file' usage. Use 1.8.1 or later.
bunyan -p ... (i.e. DTrace integration) on node
4.x and 5.x.[issue #332, pull #355] Ensure stream for type='stream' stream is a writable stream. (By Michael Nisi.)
[issue #332, pull #355] Ensure stream for type='stream' stream is a writable stream. (By Michael Nisi.)
[issue #344] Fix "rotating-file" Bunyan streams to not miss rotations when configured
for a period greater than approximately 25 days. Before this there was an issue
where periods greater than node.js's maximum setTimeout length would fail to rotate.
(By Martijn Schrage.)
[issue #234, pull #345] Improve bunyan CLI rendering of "res" field
HTTP responses to not show two blank lines for an empty body.
(By Michael Nisi.)
[pull #311, #302, #310] Improve the runtime environment detection to fix running under NW.js. Contributions by Adam Lynch, Jeremy Ruppel, and Aleksey
[pull #311, #302, #310] Improve the runtime environment detection to fix running under NW.js. Contributions by Adam Lynch, Jeremy Ruppel, and Aleksey Timchenko.
[pull #318] Add reemitErrorEvents optional boolean for streams added to a
Bunyan logger to control whether an "error" event on the stream will be
re-emitted on the Logger instance.
var log = bunyan.createLogger({
name: 'foo',
streams: [
{
type: 'raw',
stream: new MyCustomStream(),
reemitErrorEvents: true
}
]
});
Before this change, "error" events were re-emitted on file
streams only. The new
behaviour is as follows:
reemitErrorEvents not specified: file streams will re-emit error events
on the Logger instance.reemitErrorEvents: true: error events will be re-emitted on the Logger
for any stream with a .on() function -- which includes file streams,
process.stdout/stderr, and any object that inherits from EventEmitter.reemitErrorEvents: false: error events will not be re-emitted for any
streams.Dev Note: Bunyan Logger objects don't currently have a .close() method
in which registered error event handlers can be unregistered. That means
that a (presumably rare) situation where code adds dozens of Bunyan Logger
streams to, e.g. process.stdout, and with reemitErrorEvents: true, could
result in leaking Logger objects.
Original work for allowing "error" re-emitting on non-file streams is by Marc Udoff in pull #318.
[pull #304, issue #245] Use [Moment.js][momentjs.com] library to handle bunyan CLI time formatting in some cases, especially to fix display of local t
[pull #304, issue #245] Use [Moment.js][momentjs.com] library to handle
bunyan CLI time formatting in some cases, especially to fix display of
local time. It is now required for local time formatting (i.e. bunyan -L
or bunyan --time local). (By David M. Lee.)
[pull #252] Fix errant client_res={} in bunyan CLI rendering, and avoid
extra newlines in client_req rendering in some cases. (By Thomas Heymann.)
[pull #291, issue #303] Fix LOG.child(...) to not override the "hostname"
field of the parent. A use case is when one manually sets "hostname" to
something other than os.hostname(). (By github.com/Cactusbone.)
[issue #325] Allow one to set level: 0 in createLogger to turn on
logging for all levels. (Adapted from #336 by github.com/sometimesalready.)
Add guards (to resolveLevel) so that all "level" values are validated.
Before this, a bogus level like "foo" or -12 or ['some', 'array'] would
silently be accepted -- with undefined results.
Doc updates for #340 and #305.
Update make test to test against node 5, 4, 0.12 and 0.10.
[issue #296] Fix src: true, which was broken in v1.5.0.
src: true, which was broken in v1.5.0.Note: *Bad release.* The addition of 'use strict'; broke Bunyan's src: true feature. Use 1.5.1 instead.
Note: Bad release. The addition of 'use strict'; broke Bunyan's src: true
feature. Use 1.5.1 instead.
(Bumping minor ver b/c I'm wary of dtrace-provider changes. :)
(Bumping minor ver b/c I'm wary of dtrace-provider changes. :)
[issue #244] Make bunyan defensive on res.header=null.
bunyan defensive on res.header=null.[issue #233] Make bunyan defensive on res.header as a boolean.
bunyan defensive on res.header as a boolean.bunyan defensive on err.stack not being a string.Allow log.child(...) to work even if the logger is a *sub-class* of Bunyan's Logger class.
log.child(...) to work even if the logger is a sub-class
of Bunyan's Logger class.haveNonRawStreams on <logger>.addStream.[pull #127] Update to dtrace-provider 0.4.0, which gives io.js 1.x support for dtrace-y parts of Bunyan.
[pull #182] Fallback to using the optional 'safe-json-stringify' module if JSON.stringify throws -- possibly with an enumerable property getter than t
JSON.stringify throws -- possibly with an enumerable property
getter than throws. By Martin Gausby.Export bunyan.RotatingFileStream which is needed if one wants to customize it. E.g. see issue #194.
Export bunyan.RotatingFileStream which is needed if one wants to
customize it. E.g. see issue #194.
[pull #122] Source Map support for caller line position for the "src" field. This could be interesting for CoffeeScript users of Bunyan. By Manuel Schneider.
[issue #164] Ensure a top-level level given in bunyan.createLogger
is used for given streams. For example, ensure that the following
results in the stream having a DEBUG level:
var log = bunyan.createLogger({
name: 'foo',
level: 'debug',
streams: [
{
path: '/var/tmp/foo.log'
}
]
});
This was broken in the 1.0.1 release. Between that release and 1.3.0 the "/var/tmp/foo.log" stream would be at the INFO level (Bunyan's default level).
[issue #103] bunyan -L (or bunyan --time local) to show local time. Bunyan log records store time in UTC time. Sometimes it is convenient to display i
[issue #103] bunyan -L (or bunyan --time local) to show local time.
Bunyan log records store time in UTC time. Sometimes it is convenient
to display in local time.
[issue #205] Fix the "The Bunyan CLI crashed!" checking to properly warn of
the common failure case when -c CONDITION is being used.
[issue #210] Export bunyan.nameFromLevel and bunyan.levelFromName. It can be a pain for custom streams to have to reproduce that.
[issue #210] Export bunyan.nameFromLevel and bunyan.levelFromName. It can
be a pain for custom streams to have to reproduce that.
[issue #100] Gracefully handle the case of an unbound
Logger.{info,debug,...} being used for logging, e.g.:
myEmittingThing.on('data', log.info)
Before this change, bunyan would throw. Now it emits a warning to stderr once, and then silently ignores those log attempts, e.g.:
bunyan usage error: /Users/trentm/tm/node-bunyan/foo.js:12: attempt to log with an unbound log method: `this` is: { _events: { data: [Function] } }
[issue #184] Fix log rotation for rotation periods > ~25 days. Before this change, a rotation period longer than this could hit the maximum setTimeout
Drop the guard that a bunyan Logger level must be between TRACE (10) and FATAL (60), inclusive. This allows a trick of setting the level to FATAL + 1
FATAL + 1 to turn logging off. While the standard named log levels are
the golden path, then intention was not to get in the way of using
other level numbers.[issue #178, #181] Get at least dtrace-provider 0.3.1 for optionalDependencies to get a fix for install with decoupled npm (e.g. with homebrew's node
[issue #157] Restore dtrace-provider as a dependency (in "optionalDependencies").
[issue #157] Restore dtrace-provider as a dependency (in "optionalDependencies").
Dtrace-provider version 0.3.0 add build sugar that should eliminate the
problems from older versions:
The build is not attempted on Linux and Windows. The build spew is
not emitted by default (use V=1 npm install to see it); instead a
short warning is emitted if the build fails.
Also, importantly, the new dtrace-provider fixes working with node v0.11/0.12.
[issue #165] Include extra err fields in bunyan CLI output. Before this change only the fields part of the typical node.js error stack (err.stack, err
err fields in bunyan CLI output. Before
this change only the fields part of the typical node.js error stack
(err.stack, err.message, err.name) would be emitted, even though
the Bunyan library would typically include err.code and err.signal
in the raw JSON log record.Fix a breakage in log.info(err) on a logger with no serializers.
log.info(err) on a logger with no serializers.Note: *Bad release.* It breaks log.info(err) on a logger with no serializers. Use version 1.1.2.
Note: Bad release. It breaks log.info(err) on a logger with no serializers.
Use version 1.1.2.
log.info(err) to use the log Logger's err
serializer if it has one, instead of always using the core Bunyan err
serializer. (By Mihai Tomescu.)[issue #162] Preliminary support for browserify. See the section in the README.
[issues #105, #138, #151] Export .addStream(...) and .addSerializers(...) to be able to add them after Logger creation. Thanks @andreineculau!
[issues #105, #138, #151] Export <Logger>.addStream(...) and
<Logger>.addSerializers(...) to be able to add them after Logger creation.
Thanks @andreineculau!
[issue #159] Fix bad handling in construtor guard intending to allow
creation without "new": var log = Logger(...). Thanks @rmg!
[issue #156] Smaller install size via .npmignore file.
[issue #126, #161] Ignore SIGINT (Ctrl+C) when processing stdin. ...| bunyan
should expect the preceding process in the pipeline to handle SIGINT. While
it is doing so, bunyan should continue to process any remaining output.
Thanks @timborodin and @jnordberg!
[issue #160] Stop using ANSI 'grey' in bunyan CLI output, because of the
problems that causes with Solarized Dark themes (see
https://github.com/altercation/solarized/issues/220).
[issue #87] Backward incompatible change to `-c CODE` improving performance by over 10x (good!), with a backward incompatible change to semantics (unf…
[issue #87] Backward incompatible change to -c CODE improving
performance by over 10x (good!), with a backward incompatible change to
semantics (unfortunate), and adding some sugar (good!).
The -c CODE implementation was changed to use a JS function for processing
rather than vm.runInNewContext. The latter was specatularly slow, so
won't be missed. Unfortunately this does mean a few semantic differences in
the CODE, the most noticeable of which is that this is required to
access the object fields:
# Bad. Works with bunyan 0.x but not 1.x.
$ bunyan -c 'pid === 123' foo.log
...
# Good. Works with all versions of bunyan
$ bunyan -c 'this.pid === 123' foo.log
...
The old behaviour of -c can be restored with the BUNYAN_EXEC=vm
environment variable:
$ BUNYAN_EXEC=vm bunyan -c 'pid === 123' foo.log
...
Some sugar was also added: the TRACE, DEBUG, ... constants are defined, so one can:
$ bunyan -c 'this.level >= ERROR && this.component === "http"' foo.log
...
And example of the speed improvement on a 10 MiB log example:
$ time BUNYAN_EXEC=vm bunyan -c 'this.level === ERROR' big.log | cat >slow
real 0m6.349s
user 0m6.292s
sys 0m0.110s
$ time bunyan -c 'this.level === ERROR' big.log | cat >fast
real 0m0.333s
user 0m0.303s
sys 0m0.028s
The change was courtesy Patrick Mooney (https://github.com/pfmooney). Thanks!
Add bunyan -0 ... shortcut for bunyan -o bunyan ....
[issue #135] Backward incompatible. Drop dtrace-provider even from
optionalDependencies. Dtrace-provider has proven a consistent barrier to
installing bunyan, because it is a binary dep. Even as an optional dep it
still caused confusion and install noise.
Users of Bunyan on dtrace-y platforms (SmartOS, Mac, Illumos, Solaris) will
need to manually npm install dtrace-provider themselves to get Bunyan's
dtrace support
to work. If not installed, bunyan should stub it out properly.
[pull #125, pull #97, issue #73] Unref rotating-file timeout which was preventing processes from exiting (by https://github.com/chakrit and https://gi
[issue #139] Fix bunyan crash on a log record with res.header that is an object. A side effect of this improvement is that a record with res.statusCod
[issue #139] Fix bunyan crash on a log record with res.header that is an
object. A side effect of this improvement is that a record with res.statusCode
but no header info will render a response block, for example:
[2012-08-08T10:25:47.637Z] INFO: my-service/12859 on my-host: some message (...)
...
--
HTTP/1.1 200 OK
--
...
[pull #42] Fix bunyan crash on a log record with req.headers that is a string
(by https://github.com/aexmachina).
Drop node 0.6 support. I can't effectively npm install with a node 0.6
anymore.
[issue #85] Ensure logging a non-object/non-string doesn't throw (by https://github.com/mhart). This changes fixes:
log.info(<bool>) # TypeError: Object.keys called on non-object
log.info(<function>) # "msg":"" (instead of wanted "msg":"[Function]")
log.info(<array>) # "msg":"" (instead of wanted "msg":util.format(<array>))
Republish the same code to npm.
Note: Bad release. The published package in the npm registry got corrupted. Use 0.22.3 or later.
Note: Bad release. The published package in the npm registry got corrupted. Use 0.22.3 or later.
[issue #131] Allow log.info(<number>) and, most importantly, don't crash on that.
Update 'mv' optional dep to latest.
[issue #111] Fix a crash when attempting to use bunyan -p on a platform without dtrace.
[issue #111] Fix a crash when attempting to use bunyan -p on a platform without
dtrace.
[issue #101] Fix a crash in bunyan rendering a record with unexpected "res.headers".
[issue #104] log.reopenFileStreams() convenience method to be used with external log rotation.
log.reopenFileStreams() convenience method to be used with external log
rotation.[issue #96] Fix bunyan to default to paging (with less) by default in node 0.10.0. The intention has always been to default to paging for node >=0.8.
bunyan to default to paging (with less) by default in node 0.10.0.
The intention has always been to default to paging for node >=0.8.[issue #90] Fix bunyan -p '*' breakage in version 0.21.2.
bunyan -p '*' breakage in version 0.21.2.Note: Bad release. The switchrate change below broke bunyan -p '*' usage (see issue #90). Use 0.21.3 or later.
Note: Bad release. The switchrate change below broke bunyan -p '*' usage
(see issue #90). Use 0.21.3 or later.
[issue #88] Should be able to efficiently combine "-l" with "-p *".
Avoid DTrace buffer filling up, e.g. like this:
$ bunyan -p 42241 > /tmp/all.log
dtrace: error on enabled probe ID 3 (ID 75795: bunyan42241:mod-87ea640:log-trace:log-trace): out of scratch space in action #1 at DIF offset 12
dtrace: error on enabled probe ID 3 (ID 75795: bunyan42241:mod-87ea640:log-trace:log-trace): out of scratch space in action #1 at DIF offset 12
dtrace: 138 drops on CPU 4
...
From Bryan: "the DTrace buffer is filling up because the string size is so large... by increasing the switchrate, you're increasing the rate at which that buffer is emptied."
[pull #83] Support rendering 'client_res' key in bunyan CLI (by github.com/mcavage).
'make check' clean, 4-space indenting. No functional change here, just lots of code change.
period (by github.com/ricardograca).[Slight backward incompatibility] Fix serializer bug introduced in 0.18.3 (see below) to only apply serializers to log records when appropriate.
[Slight backward incompatibility] Fix serializer bug introduced in 0.18.3 (see below) to only apply serializers to log records when appropriate.
This also makes a semantic change to custom serializers. Before this change
a serializer function was called for a log record key when that value was
truth-y. The semantic change is to call the serializer function as long
as the value is not undefined. That means that a serializer function
should handle falsey values such as false and null.
Update to latest 'mv' dep (required for rotating-file support) to support node v0.10.0.
[Slight backward incompatibility] Change the default error serialization (a.k.a. bunyan.stdSerializers.err) to *not* serialize all additional attribut…
WARNING: This release includes a bug introduced in bunyan 0.18.3 (see below). Please upgrade to bunyan 0.20.0.
[Slight backward incompatibility] Change the default error serialization
(a.k.a. bunyan.stdSerializers.err) to not serialize all additional
attributes of the given error object. This is an open door to unsafe logging
and logging should always be safe. With this change, error serialization
will log these attributes: message, name, stack, code, signal. The latter
two are added because some core node APIs include those fields (e.g.
child_process.exec).
Concrete examples where this has hurt have been the "domain" change
necessitating 0.18.3 and a case where
node-restify uses an error object
as the response object. When logging the err and res in the same log
statement (common for restify audit logging), the res.body would be JSON
stringified as '[Circular]' as it had already been emitted for the err key.
This results in a WTF with the bunyan CLI because the err.body is not
rendered.
If you need the old behaviour back you will need to do this:
var bunyan = require('bunyan');
var errSkips = {
// Skip domain keys. `domain` especially can have huge objects that can
// OOM your app when trying to JSON.stringify.
domain: true,
domain_emitter: true,
domain_bound: true,
domain_thrown: true
};
bunyan.stdSerializers.err = function err(err) {
if (!err || !err.stack)
return err;
var obj = {
message: err.message,
name: err.name,
stack: getFullErrorStack(err)
}
Object.keys(err).forEach(function (k) {
if (err[k] !== undefined && !errSkips[k]) {
obj[k] = err[k];
}
});
return obj;
};
"long" and "bunyan" output formats for the CLI. bunyan -o long is the default
format, the same as before, just called "long" now instead of the cheesy "paul"
name. The "bunyan" output format is the same as "json-0", just with a more
convenient name.
WARNING: This release introduced a bug such that all serializers are applied to all log records even if the log record did not contain the key for tha
WARNING: This release introduced a bug such that all serializers are
applied to all log records even if the log record did not contain the key
for that serializer. If a logger serializer function does not handle
being given undefined, then you'll get warnings like this on stderr:
bunyan: ERROR: This should never happen. This is a bug in <https://github.com/trentm/node-bunyan> or in this application. Exception from "foo" Logger serializer: Error: ...
at Object.bunyan.createLogger.serializers.foo (.../myapp.js:20:15)
at Logger._applySerializers (.../lib/bunyan.js:644:46)
at Array.forEach (native)
at Logger._applySerializers (.../lib/bunyan.js:640:33)
...
and the following junk in written log records:
"foo":"(Error in Bunyan log "foo" serializer broke field. See stderr for details.)"
Please upgrade to bunyan 0.20.0.
Change the bunyan.stdSerializers.err serializer for errors to exclude
the "domain*" keys.
err.domain will include its assigned members which can arbitrarily large
objects that are not intended for logging.
Make the "dtrace-provider" dependency optional. I hate to do this, but installing bunyan on Windows is made very difficult with this as a required dep. Even though "dtrace-provider" stubs out for non-dtrace-y platforms, without a compiler and Python around, node-gyp just falls over.
Your coding agent can read these notes before it upgrades. Set up the MCP server →