Skip to main content
Introducing packages.sweber.dev
All posts
Release2 min read

Logarithm 0.3.0 released

Counts and breakdowns for dashboards, typed action catalogs, a MySQL and MariaDB store, and in Logarithm Pro alerts to Slack and Teams plus anomaly detection for unusual exports, deletions and failed logins.

By Seya Weber

Logarithm 0.3.0 is out. @sweberdev/logarithm and @sweberdev/logarithm-react are on npm, and the Logarithm Pro packages are updated for all customers. Nothing breaks: 0.2.0 code keeps working as it is.

Counts for dashboards

"How many logins today?" used to mean loading events and counting them yourself. audit.count() takes the same filters as query() and counts in the database. With groupBy it returns a breakdown per day, action or actor:

const total = await audit.count({ action: "user.login", from: startOfMonth })

const perDay = await audit.count({ action: "user.login", groupBy: "day" })
// [{ key: "2026-10-05", count: 412 }, { key: "2026-10-06", count: 388 }]

A log scoped with with({ tenantId }) only counts that tenant.

Typed action catalogs

Pass your actions as a type and TypeScript catches misspelled action names and wrong metadata at compile time, in record(), query() and count(). It is types only, with zero runtime cost:

type Actions = {
  "user.login": { method: "password" | "sso" }
  "project.deleted": { name: string }
}

const audit = createAuditLog<Actions>({ store })

await audit.record({ action: "project.deleted", metadata: { name: "Website" } })
await audit.record({ action: "project.delete" }) // compile error

MySQL and MariaDB

@sweberdev/logarithm/mysql joins the Postgres and SQLite stores. It works with mysql2, the mariadb driver or any client with query(sql, values), and the shared store tests run in CI against real MySQL 8.4 and MariaDB 11.4 servers. See the MySQL guide.

Logarithm Pro 0.3.0

  • Slack and Teams alerts. slackSink() and teamsSink() post selected events, filtered with patterns like api_key.* or *.deleted, to an incoming webhook. User content is escaped, so a name like <!channel> pings nobody, and errors never include the webhook URL.
  • Anomaly detection. detectAnomalies() runs from cron and alerts your team when an actor exports, deletes or fails to log in far more often than usual within a time window, counted per tenant. Thresholds are configurable; the defaults are 10 exports, 25 deletions and 5 failed logins per hour. With record: true each alert is also stored in the audit log and not sent twice.

Update

pnpm add @sweberdev/logarithm@latest @sweberdev/logarithm-react@latest

Pro customers update @weber-development/logarithm-export the same way. Logarithm Pro is available on the package page and is part of the Compliance Bundle.

Package in this post

Logarithm

A self-hosted audit log for SaaS apps: who changed what, and when. Field-level diffs in your own Postgres or SQLite, and a ready React view for your customers' admins.

pnpm add @sweberdev/logarithm @sweberdev/logarithm-react
View package

Related posts

Release

Logarithm 0.1.0 released

A self-hosted audit log for SaaS apps: who changed what, and when. Field-level diffs in your own Postgres or SQLite, and a ready React view for your customers' admins.

Logarithm
Release

Logarithm 0.2.0 released

Request context in one line, a compact activity feed for dashboards, and in Logarithm Pro signed checkpoints and legal holds.

Logarithm
Release

Vector 0.2.0: Ed25519 signatures, SQLite and MySQL

Vector can now sign webhooks with Ed25519, so your customers only hold a public key that cannot forge requests, and it keeps its data in SQLite or MySQL as well as PostgreSQL.

Vector