-
Notifications
You must be signed in to change notification settings - Fork 5
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): update dependency webpack to v5.76.0 [security] #1138
base: master
Are you sure you want to change the base?
Conversation
47ebd7f
to
6e1477e
Compare
6e1477e
to
30d899b
Compare
You have successfully added a new SonarCloud configuration ``. As part of the setup process, we have scanned this repository and found no existing alerts. In the future, you will see all code scanning alerts on the repository Security tab. |
30d899b
to
875d4bb
Compare
875d4bb
to
f7f350f
Compare
f7f350f
to
5fa2abe
Compare
e0fb5c2
to
9876b13
Compare
9876b13
to
e25f158
Compare
73bb4db
to
20acbad
Compare
3b934a9
to
8de3248
Compare
d394895
to
1c83d8c
Compare
1c83d8c
to
90f2af3
Compare
7aeb21c
to
d09cc29
Compare
d09cc29
to
fd121ae
Compare
a1e7181
to
554e251
Compare
dbb33f0
to
3ab33f5
Compare
3ab33f5
to
fc7bd8c
Compare
fc7bd8c
to
2d8d44a
Compare
2d8d44a
to
8840515
Compare
ef22411
to
fdb9087
Compare
Kudos, SonarCloud Quality Gate passed! |
0ca123a
to
d8a9688
Compare
d8a9688
to
4a4d96a
Compare
4a4d96a
to
1d2ff32
Compare
4f129be
to
a1e0ff8
Compare
8304b91
to
7658f23
Compare
7658f23
to
7b31355
Compare
|
7b31355
to
af5d3af
Compare
|
af5d3af
to
fc23832
Compare
fc23832
to
286fd7b
Compare
286fd7b
to
350e9c3
Compare
350e9c3
to
095cee5
Compare
095cee5
to
c4bf59d
Compare
|
c4bf59d
to
da02fc1
Compare
1afd5a2
to
a5c1167
Compare
a5c1167
to
23809f9
Compare
|
This PR contains the following updates:
5.70.0
->5.76.0
GitHub Vulnerability Alerts
CVE-2023-28154
Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.
Release Notes
webpack/webpack (webpack)
v5.76.0
Compare Source
Bugfixes
generatedCode
info to fix bug in asset module cache restoration by @ryanwilsonperkin in https://github.com/webpack/webpack/pull/16703hashRegExp
lookup by @ryanwilsonperkin in https://github.com/webpack/webpack/pull/16759Features
target
toLoaderContext
type by @askoufis in https://github.com/webpack/webpack/pull/16781Security
Repo Changes
New Contributors
Full Changelog: webpack/webpack@v5.75.0...v5.76.0
v5.75.0
Compare Source
Bugfixes
experiments.*
normalize tofalse
when opt-outNaN%
window
before trying to access iteval-nosources-*
actually exclude sourcesFeatures
@import
to extenal CSS when using experimental CSS in nodei64
support to the deprecated WASM implementationDeveloper Experience
EnableWasmLoadingPlugin
v5.74.0
Compare Source
Features
resolve.extensionAlias
option which allows to alias extensions.js
extension to imports when the file really has a.ts
extension (typescript +"type": "module"
)ProvidePlugin
Bugfixes
shareScope
option forModuleFederationPlugin
"use-credentials"
also for same origin scriptsPerformance
Extensibility
HarmonyImportDependency
for pluginsv5.73.0
Compare Source
Features
dynamicImportMode
and prefetch and preloadimport { createRequire } from "module"
in source codeBugfixes
return"field"in Module
Developer Experience
PathData
in typingsv5.72.1
Compare Source
Bugfixes
__webpack_nonce__
with HMRin
operator in some casesthis.importModule
v5.72.0
Compare Source
Features
Bugfixes
in
operator with nested exportsv5.71.0
Compare Source
Features
uniqueName
when using aoutput.library
which includes placeholdersin
of a imported bindingBugfixes
chunkLoading
option in module moduleevaluateExpression
returnsnull
lazy-once
Context modulesrunAsChild
callbackConfiguration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.