chore(deps): update dependency webpack to v5.76.0 [security] #249
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.52.0→5.76.0GitHub Vulnerability Alerts
CVE-2023-28154
Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.
Release Notes
webpack/webpack (webpack)
v5.76.0Compare Source
Bugfixes
generatedCodeinfo to fix bug in asset module cache restoration by @ryanwilsonperkin in #16703hashRegExplookup by @ryanwilsonperkin in #16759Features
targettoLoaderContexttype by @askoufis in #16781Security
Repo Changes
New Contributors
Full Changelog: webpack/webpack@v5.75.0...v5.76.0
v5.75.0Compare Source
Bugfixes
experiments.*normalize tofalsewhen opt-outNaN%windowbefore trying to access iteval-nosources-*actually exclude sourcesFeatures
@importto extenal CSS when using experimental CSS in nodei64support to the deprecated WASM implementationDeveloper Experience
EnableWasmLoadingPluginv5.74.0Compare Source
Features
resolve.extensionAliasoption which allows to alias extensions.jsextension to imports when the file really has a.tsextension (typescript +"type": "module")ProvidePluginBugfixes
shareScopeoption forModuleFederationPlugin"use-credentials"also for same origin scriptsPerformance
Extensibility
HarmonyImportDependencyfor pluginsv5.73.0Compare Source
Features
dynamicImportModeand prefetch and preloadimport { createRequire } from "module"in source codeBugfixes
return"field"in ModuleDeveloper Experience
PathDatain typingsv5.72.1Compare Source
Bugfixes
__webpack_nonce__with HMRinoperator in some casesthis.importModulev5.72.0Compare Source
Features
Bugfixes
inoperator with nested exportsv5.71.0Compare Source
Features
uniqueNamewhen using aoutput.librarywhich includes placeholdersinof a imported bindingBugfixes
chunkLoadingoption in module moduleevaluateExpressionreturnsnulllazy-onceContext modulesrunAsChildcallbackv5.70.0Compare Source
Features
baseUritoentryoptions to configure a static base uri (the base ofnew URL())__webpack_exports_info__.name.canMangleexperiments.buildHttpimport.meta.webpackContextas ESM alternative torequire.contextBugfixes
globalto a variableexperiments.outputModuleandloaderContext.importModulewith multiple chunksoutput.cleanwill keep HMR assets for at least 10s to allow HMR to access them even when compilation is faster then the browserPerformance
Developer Experience
Contributing
v5.69.1Compare Source
Revert
v5.69.0Compare Source
Features
resolve.aliasorresolve.modules) when creating an context moduleutil/typesto node.js built-in modules__webpack_exports_info__.<name>.canMangleapiBugfixes
stageoption when instrumenting plugins for the ProfilingPlugin#in paths of loadersexperiments.buildHttpContributing
Developer Experience
v5.68.0Compare Source
Features
__webpack_module__and__webpack_module__.idto the apiBugfixes
v5.67.0Compare Source
Features
experiments.cssSyncModuleIdsPluginto sync module ids between server and client compilationDeterministicModuleIdsPluginto allow to generate equal idsDeveloper Experience
nullto errors in callbacksBugfixes
experiments.css|webpack-hot-middleware/clientfrom lazy compilationContributing
v5.66.0Compare Source
Features
output.library.type: "commonjs-static"to emit a statically analyse-able commonjs module (for node.js esm interop support)experiments.css(very experimental)Bugfixes
experiments.lazyCompilation[absolute-resource-path]for SourceMap module namingPerformance
watchOptions.aggregateTimeoutto 20msv5.65.0Compare Source
Features
undefinednowBugfixes
singletonflag withoutrequiredVersionin Module Federationwatchpackfor context time info bugfixPerformance
Developer Experience
output.globalObjectcontains a non-trival expressionscripttype external with invalid syntaxResolver,StatsOptionsandResolvePluginInstancePreparations for the future
hashDigestLengthwill default to 16 in webpack 6 (experiments.futureDefaults)v5.64.4Compare Source
Bugfixes
Performance
Developer Experience
v5.64.3Compare Source
Performance
Infinityis used in configurationv5.64.2Compare Source
Bugfixes
v5.64.1Compare Source
Bugfixes
require(...).propertyinrequire.ensureoutput.clean: trueunsafeCachewithinmanagedPaths(node_modules)v5.64.0Compare Source
Features
asyncChunks: booleanoption to disable creation of async chunksBugfixes
experiments.backCompat: falsePerformance
v5.63.0Compare Source
Features
chunkLoading: falseto disable on-demand loadingBugfixes
import 'single-quote'in esm build dependenciesv5.62.2Compare Source
Bugfixes
__system_context__injection when using thelibraryoption on entrypointexportsPresence: "error"by default infutureDefaultsexportPresence->exportsPresencetypoexperiments.cacheUnaffectedv5.62.1Compare Source
Bugfix
;v5.62.0Compare Source
Features
parser.javascript.reexportExportsPresence: falseallows to disable warnings for non-existing exports during the migration fromexport ... from "..."toexport type ... from "..."for type reexports in TypeScriptexperiments.backCompat: falseto disable some expensive deprecations for better performanceBugfixes
['catch']instead of.catchfor better ES3 supportnew (require("...")).Something(){ require }object literalssplitChunks.chunksoption is now correctly used forsplitChunks.fallbackCacheGroup.maxSizetoolistenoption, allow to omitportDeveloper Experience
/// <reference types="webpack/module" />to use the typings in typescript modules"types": [..., "webpack/module"]in tsconfigv5.61.0Compare Source
Bugfixes
pathsubmodules in the node.js default externalsPerformance
Contribution
v5.60.0Compare Source
Features
experiments.lazyCompilation. e. g. port, https stuffBugfixes
output.hashFunctionused to persistent caching toobuildDependenciesSet correctly when loaders are added inbeforeLoadershookv5.59.1Compare Source
Bugfixes
experiments.buildHttpv5.59.0Compare Source
Features
/*#__PURE__*/forObject()in generated codemanaged/immutablePathsexperiments.buildHttpsplitChunks.minSizeReductionoptionBugfixes
waitForwhen modules are unsafe cachedv5.58.2Compare Source
Bugfixes
Performance
v5.58.1Compare Source
Bugfixes
.webpack[]suffix to not execute rulesv5.58.0Compare Source
Features
diagnostics_channelto node builtinsPerformance
v5.57.1Compare Source
Bugfix
v5.57.0Compare Source
Performance
Bugfixes
v5.56.1Compare Source
Bugfix
v5.56.0Compare Source
Performance
v5.55.1Compare Source
Bugfixes
experiments.cacheUnaffectedv5.55.0Compare Source
Performance
experiments.cacheUnaffectedmodule.unsafeCachev5.54.0Compare Source
Features
&&||and??output.hashFunctionevalis used in a moduleBugfixes
Performance
output.hashFunction: "xxhash64"for a super fast wasm based hash functionexperiments.cacheUnaffectedwhich caches computations for modules that are unchanged and reference only unchanged modulesv5.53.0Compare Source
Features
node.__dirname/__filename: "warn-mock"which warns on usage (will be enabled in webpack 6 by default)Bugfixes
stream/webto Node.js externalsExperiments
experiments.futureDefaultsto enable defaults for webpack 6v5.52.1Compare Source
Performance
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.