NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3 most downloaded on npm
Lightweight debugging utility for Node.js and the browser
Last release 1 years ago
13 Sep 2025
Ships unpredictably
gaps range from 3 weeks to 2.2 years
Rarely documented
notes for 13 of 60 stable releases
17 versions withdrawn
withdrawn after publishing
15 years old
77 releases · first in 2011
Functionally identical release to 4.4.1 .
Functionally identical release to 4.4.1.
Version 4.4.2 is compromised. Please see #1005.
fix(Issue-996): replace whitespaces in namespaces string with commas globally by @pdahal-cx in #997
Full Changelog: 4.4.0...4.4.1
One column per quarter.
Fixes (hopefully) the inefficient regex warnings in .enable() .
Fixes (hopefully) the inefficient regex warnings in .enable().
Minor version as this is invariably going to break certain users who misuse the .enable() API and expected it to work with regexes, which was never supported nor documented. That's on you, sorry - that functionality won't be added back.
Full Changelog: 4.3.7...4.4.0
Upgrade ms to version 2.1.3 by @realityking in #819
Avoid using deprecated RegExp.$1 by @bluwy in #969
Thank you @calvintwr for the fix.
Replace deprecated String.prototype.substr() by @CommanderRoot in #876
Full Changelog: 4.3.3...4.3.4
This is a documentation-only release. Further, the repository was transferred. Please see notes below.
This is a documentation-only release. Further, the repository was transferred. Please see notes below.
Thank you to @taylor1791 and @kristofkalocsai for their contributions.
I've formatted this as a FAQ, please feel free to open an issue for any additional question and I'll add the response here.
In most cases, you shouldn't notice any change.
The only exception I can think of is if you pull code directly from https://github.com/visionmedia/debug, e.g. via a "debug": "visionmedia/debug"-type version entry in your package.json - in which case, you should still be fine due to the automatic redirection Github sets up, but you should also update any references as soon as possible.
If you pull code directly from the old URL, you should update the URL to https://github.com/debug-js/debug as soon as possible. The old organization has many approved owners and thus a new repository could (in theory) be created at the old URL, circumventing Github's automatic redirect that is in place now and serving malicious code. I (@Qix-) also wouldn't have access to that repository, so while I don't think it would happen, it's still something to consider.
Even in such a case, however, the officially released package on npm (debug) would not be affected. That package is still very much under control (even more than it used to be).
Search the issues first to see if someone has already reported it, and then open a new issue if someone has not.
No, it shouldn't be breaking. The package on npm shouldn't be affected (aside from this patch release) and any references to the old repository should automatically redirect.
Thus, according to all of the "APIs" (loosely put) involved, nothing should have broken.
I understand there are a lot of edge cases so please open issues as needed so I can assist in any way necessary.
I'll just list them off in no particular order.
debug ecosystem intends to grow beyond a single package, and since new packages could not be created in the old org (nor did it make sense for them to live there), a new org made the most sense - especially from a security point of view.No.
Caches enabled statuses on a per-logger basis to speed up .enabled checks
Fixes a ReDOS regression ( #458 ) - see #797 for details.
Deprecated `debugInstance.destroy()`. Future major versions will not have this method; please remove it from your codebases as it currently does nothi…
debugInstance.destroy(). Future major versions will not have this method; please remove it from your codebases as it currently does nothing.Deprecated and later removed Changelog.md in lieu of releases page
console.debug in the browser only when it is available (#600)"engines" key to package.jsonselectColor (#747)supports-color as an optional peer dependencyThis backport fixes a bug in coveralls configuration as well as the .extend() function.
This backport fixes a bug in coveralls configuration as well as the .extend() function.
migrate Makefile to npm scripts
Massive thank you to @mblarsen and @outsideris for knocking out two long-awaited changes.
This patch restores browserify functionality as well as keeping the intended functionality with Unpkg.com.
This patch restores browserify functionality as well as keeping the intended functionality with Unpkg.com.
bump vulnerable packages: 853853f9f588044d76df3daf1959ca56c5f341b7
A long-awaited release to debug is available now: 4.0.0.
chrome.storage (or make the storage backend pluggable): 71d2aa77ff54c3c95a000bdead6b710b2a762c3fsupports-color@5: 285dfe10a5c06d4a86176b54bef2d7591eedaf40enable() (#517): ab5083f68a7e4c1ab474ff06cd5995d706abf143Huge thanks to @DanielRuf, @EirikBirkeland, @KyleStay, @Qix-, @abenhamdine, @alexey-pelykh, @DiegoRBaquero, @febbraro, @kwolfy, and @TooTallNate for their help!
Nothing published for this version
This backport fixes a 4x performance regression when debug is disabled.
This backport fixes a 4x performance regression when debug is disabled.
This patch restores browserify functionality as well as keeping the intended functionality with Unpkg.com.
This patch restores browserify functionality as well as keeping the intended functionality with Unpkg.com.
It is a backport of the 4.0.1 release.
> 3.2.4 is DEPRECATED. See https://github.com/visionmedia/debug/issues/603#issuecomment-420237335 for details.
3.2.4 is DEPRECATED. See https://github.com/visionmedia/debug/issues/603#issuecomment-420237335 for details.
This released fixed the missing files entry in package.json, mitigating the faulty 3.2.3 release.
This release mitigated the breaking changes introduced in 3.2.0 where ./node.js was removed, breaking a very select few users on older releases of bab…
3.2.3 is DEPRECATED. See https://github.com/visionmedia/debug/issues/603#issuecomment-420237335 for details.
This release mitigated the breaking changes introduced in 3.2.0 where ./node.js was removed, breaking a very select few users on older releases of babel-core, as well as users that used an undocumented require('debug/node').
./node.js was temporarily added to the repository at this time; however, this release failed to include node.js in the files key in package.json and thus didn't fix the issue. 3.2.4 rectified this issue.
This release mitigated the breaking changes introduced in 3.2.0 where ES6 features were being used on users of Node 4, causing crashes upon inclusion.
3.2.2 is DEPRECATED. See https://github.com/visionmedia/debug/issues/603#issuecomment-420237335 for details.
This release mitigated the breaking changes introduced in 3.2.0 where ES6 features were being used on users of Node 4, causing crashes upon inclusion.
It employed a temporary Babel pass on the entire codebase in lieu of a hard reversion (so this version is, effectively, a backport of the fixes and features ultimately introduced in 4.0.0).
> 3.2.1 is DEPRECATED. See https://github.com/visionmedia/debug/issues/603#issuecomment-420237335 for details.
3.2.1 is DEPRECATED. See https://github.com/visionmedia/debug/issues/603#issuecomment-420237335 for details.
This release, along with 3.2.0, were subsequently released together as 4.0.0 (a major bump). You can review the complete changes in that release's details.
A quick hotfix to address Browser builds - debug is now compiled down to IE8-compatible code via Babel upon release.
CDNs that honor the "browser": key in package.json should now reflect these changes (previously, they would serve the non-bundled ES6 version).
This release was intended to be the next release of Debug but introduced breaking changes that were overlooked at the time of release. As such it has…
3.2.0 is DEPRECATED. See https://github.com/visionmedia/debug/issues/603#issuecomment-420237335 for details.
This release was intended to be the next release of Debug but introduced breaking changes that were overlooked at the time of release. As such it has been deprecated on npm and should not be used.
This release, along with 3.2.1, were subsequently released together as 4.0.0 (a major bump). You can review the included changes in that release's details.
Ignore package-lock.json: e7e568a24736486721882282eb21beb31c741647
component.json: 47747f329fe159e94262318b52b87a48f6c0acd4DEBUG_HIDE_DATE env var: #486%o formatter: #504Huge thanks to @amejiarosario and @zhuangya for their help!
Nothing published for this version
Make millisecond timer namespace specific and allow 'always enabled' output: #408
<img width="521" src="https://user-images.githubusercontent.com/71256/29092181-47f6a9e6-7c3a-11e7-9a14-1928d8a711cd.png">
DEBUG_FD: #406Date#toISOString() instead to Date#toUTCString() when output is not a TTY: #418enabled() updates existing debug instances: #440destroy() function: #440enabled flag: #465Huge thanks to @gtjoseph, @timruffles and @FantasticFiasco for their help!
Remove ReDoS regexp in %o formatter: #504
%o formatter: #504Huge thanks to @zhuangya for their help!
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →