winstonjs/winston
61.9
Adequate · 1 October 2026
3.7k
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
This system is the Winston logging library, a modular JavaScript tool for capturing and managing application logs. It provides a flexible API for configuring log levels, formatting output, and routing messages to various transports such as files, consoles, and HTTP endpoints. The library also includes dedicated handlers for managing uncaught exceptions and unhandled promise rejections.
How it got here
2010 — Winston 3.0 major rewrite
6 changes.
The project underwent a comprehensive architectural overhaul to release Winston version 3.0, restructuring the core logging API into modular packages like logform and winston-transport. This migration involved replacing legacy APIs and transports with modern, composable alternatives and updating the entire development infrastructure, including test runners and linting tools.
2011–2022 — v3 testing and dependency centralization
9 changes.
This period focused on establishing comprehensive test infrastructure for winston v3, including unit, integration, and TypeScript definition tests alongside new mock helpers and fixtures. Concurrently, logging configuration and colorization logic were refactored to rely on external dependencies like logform and triple-beam, centralizing format-related functionality.
Features
Added comprehensive logging examples for winston v3
The \examples\ directory has been populated with a new set of demonstration scripts illustrating winston v3 usage patterns. These include quick-start guides, custom level and color configurations, file and stream transports, and specific format behaviors such as string interpolation, splatting, metadata handling, and error logging. The examples also cover advanced features like the \finish\ event, exception handling, and dynamic content formatting, providing users with ready-to-use code for common logging scenarios.
examples · high confidence
Removals
Removal of internal clone utility
The internal \clone\ helper function, previously exported from \lib/winston/utils/index.js\, has been removed. This function was used for deep cloning pure JSON objects within the library's utility layer.
lib/winston/utils · high confidence
Architecture
Project infrastructure and configuration overhaul
The repository has been restructured with new configuration files to standardize development workflows and build processes. A Babel configuration (.babelrc) using @babel/preset-env has been added to handle JavaScript transpilation, while a Prettier configuration (.prettierrc) enforces consistent code formatting. Linting is now managed via a new ESLint configuration (eslint.config.cjs) extending @dabh/eslint-config-populist. TypeScript support is formalized with a tsconfig.json and a comprehensive index.d.ts type definition file. Additionally, the test runner has been configured via jest.config.js, and various repository metadata files (CODE\_OF\_CONDUCT.md, CONTRIBUTING.md, SECURITY.md, publishing.md) have been introduced to guide contributors and maintainers.
(repo-wide) · high confidence
Behavioural changes
Logging configuration and colorization logic moved to external dependencies
The default logging configurations (CLI, npm, syslog) and the \addColors\ method are no longer defined internally; they are now sourced from the \logform\ and \triple-beam\ packages. This change centralizes format-related functionality and level definitions in external libraries, meaning updates to logging behavior or color schemes will depend on those dependency versions rather than winston's internal code.
lib/winston/config · high confidence
Winston 3.0 core architecture and API overhaul
Winston has been rewritten for version 3.0.0, introducing a new \createLogger\ factory that generates optimized logger prototypes and a \Container\ for managing named logger instances. The logging pipeline now relies on \logform\ for formatting, replacing legacy options like \colors\ and \padLevels\ with composable format functions. Exception handling is split into dedicated \ExceptionHandler\ and \RejectionHandler\ classes to manage \uncaughtException\ and \unhandledRejection\ events, while the profiler now logs duration in milliseconds without callbacks. Legacy APIs such as \winston.Logger\ constructor, \winston.transports\ registry, and \winston.hash\ have been removed in favor of the new modular structure.
lib/winston · high confidence
Winston 3.0 major API overhaul and modularization
This release introduces a significant breaking change by restructuring the core logging API and decoupling functionality into separate packages. The default logger is now accessed via \winston.createLogger()\ rather than instantiating \winston.Logger\ directly, and the top-level module exposes a new \loggers\ container for managing multiple logger instances. Format-related functionality has been moved to the \logform\ package, while transport logic is handled by \winston-transport\. Deprecated methods like \addRewriter\ and \addFilter\ have been removed, and exception handling is now managed through dedicated \exceptions\ and \rejections\ properties on the default logger instance.
lib · high confidence
Winston transports rewritten for v3.0 with new APIs and removed legacy transports
The transport implementations in lib/winston/transports have been completely rewritten to align with the v3.0 architecture. The File, Console, Http, and Stream transports now extend the standard \winston-transport\ class and use the \triple-beam\ MESSAGE symbol for log objects, replacing the previous legacy API. The Console transport now supports granular control over output streams via \stderrLevels\ and \consoleWarnLevels\ options, while the File transport introduces features like log rotation (\maxsize\, \maxFiles\), zipped archives, and configurable end-of-line characters. The legacy Loggly and Riak transports have been removed from this package to be maintained separately. TypeScript definitions have been added to \index.d.ts\ to reflect these new options and interfaces.
lib/winston/transports · high confidence
Test coverage
Added TypeScript definition validation and Jest test infrastructure; Added comprehensive unit tests for core logging components and transports; Added integration tests for color formatting and Logger export; Added mock transport helpers for testing; Added test fixtures for exception and rejection handling scripts; Added test fixtures for webhook HTTPS and log storage; Added test helpers for exception and rejection handlers.
Dependencies
Winston upgraded to v3.19.0 with modernized dependencies and test infrastructure
Winston has been updated from version 0.1.0 to 3.19.0, marking a major release that modernizes the library's dependency stack and tooling. The core dependencies have shifted from legacy packages like \eyes\ and \riak-js\ to modern, maintained libraries such as \@colors/colors\, \logform\, \triple-beam\, and \winston-transport\. The test runner has migrated from Vows to Jest, and the build process now uses Babel 7 to transpile code for Node.js versions 12.0.0 and above. Development dependencies include updated versions of ESLint (v10), TypeScript types, and various utility libraries, ensuring better type safety and linting support for the project.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 59 → 62 (+3.3)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 58 → 58 (+0.0)
- Architecture 90 → 92 (+1.5)
- Maturity 52 → 53 (+0.6)
- Readiness 74 → 75 (+0.7)
- Security 61 → 76 (+14.2)
- Performance 100 (new)
Resolved (9)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Hotspot: lib/winston/logger.js (lib/winston/logger.js)
- Hotspot: lib/winston/transports/file.js (lib/winston/transports/file.js)
New (10)
- Documentation: no project overview (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Outdated (npm): @colors/colors
- Outdated (npm): @dabh/diagnostics
- Outdated (npm): is-stream
- Outdated (npm): readable-stream
- Outdated (npm): stack-trace
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
winstonjs/winston was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit ff0b79de8562bb322c390fbc82fe71c11f373428 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.