
Security News
Package Maintainers Call for Improvements to GitHub’s New npm Security Plan
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.
winston-tagged-http-logger
Advanced tools
Sets up logging to a TaggedLogger for important http.Server events
Pipes events from a node HTTP server (vanilla OR express!) to a tagged-logger for winston.
npm install winston-tagged-http-logger
This will create a new winston logger and a new tagged-logger, and use a tagged-console-target to write the output to the console in all the colours of the rainbow.
var server = require('http').createServer();
// create our winston logger
var winston = require('winston');
var winstonLogger = new winston.Logger();
// create a transport so our logs have somewhere to go
var TaggedConsoleTarget = require('tagged-console-target');
winston.add(new TaggedConsoleTarget());
// make a new tagged logger to generate tagged log messages
var TaggedLogger = require('tagged-logger');
var logger = new TaggedLogger(winstonLogger, ['my amazing server']);
// Use this module to pipe the events from an http server to the logger
require('winston-tagged-http-logger')(server, log);
// All done! Events from `server` are now being piped to our `logger`!
Why, take a look! Here's an example of a log:
19:35:53.255 2013-06-26 Wednesday
19:35:53.589 [kvass, http] Listening on 0.0.0.0:9506
19:36:06.359 [kvass, http, 127.0.0.1:50230] GET /user/active 200 12ms
Broken down, these are the parts of a request log:
19:36:06.359
the time on the server at which the request was received[kvass, http,
tags that have been assigned to this logger127.0.0.1:50230]
a tag representing the origin of the requestGET
the request method/user/active
the requested path200
the response status code12ms
the time it took to respond to the requestFAQs
Sets up logging to a TaggedLogger for important http.Server events
We found that winston-tagged-http-logger demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.
Product
Socket Firewall is a free tool that blocks malicious packages at install time, giving developers proactive protection against rising supply chain attacks.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.