
Security News
Node.js Drops Bug Bounty Rewards After Funding Dries Up
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.
grayconsole
Advanced tools
Grayconsole is a browser and nodejs compatible library which intercepts calls to console.<level> and sends them to Graylog using GELF over HTTP(S).
Call the configure function in the grayconsole package during the startup phase of your
application/page to start logging to Graylog. The example below will log all calls of level
info or above (i.e. console.info(...), console.warn(...) and console.error(...)) to
Graylog. The static fields version and is_cordova will be attached to every call with the
given values.
import { configure as configureGrayconsole } from "grayconsole";
configureGrayconsole({
endpoint: "https://mygraylogserver:12201/gelf",
host: "myproductname",
level: "info",
staticProperties: {
version: "1.5",
is_cordova: true
}
});
If the first argument of the call to console.<level> is a string then this is the message logged to Graylog. All following arguments are objects which are combined into a single object and sent to Graylog as fields.
console.info("I am a message");
console.info("User logged in", { name: "Dave" });
console.info("Can't find file", { filename: "missing.json" }, someRelevantObject, someOtherRelevantObject)
FAQs
Wrap console logging functions so that they send to a Graylog2 server
We found that grayconsole demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.