Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

deps: Update dependency webpack to v5.76.0 [SECURITY] #3195

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Mar 16, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
webpack 5.74.0 -> 5.76.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2023-28154

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.


Release Notes

webpack/webpack (webpack)

v5.76.0

Compare Source

Bugfixes

Features

Security

Repo Changes

New Contributors

Full Changelog: webpack/webpack@v5.75.0...v5.76.0

v5.75.0

Compare Source

Bugfixes

  • experiments.* normalize to false when opt-out
  • avoid NaN%
  • show the correct error when using a conflicting chunk name in code
  • HMR code tests existance of window before trying to access it
  • fix eval-nosources-* actually exclude sources
  • fix race condition where no module is returned from processing module
  • fix position of standalong semicolon in runtime code

Features

  • add support for @import to extenal CSS when using experimental CSS in node
  • add i64 support to the deprecated WASM implementation

Developer Experience

  • expose EnableWasmLoadingPlugin
  • add more typings
  • generate getters instead of readonly properties in typings to allow overriding them

Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Berlin, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Mar 16, 2023
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 50a1f21 to 6c048d7 Compare March 23, 2023 23:47
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 6c048d7 to a13748c Compare April 3, 2023 09:00
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from a13748c to 9a09a93 Compare April 17, 2023 10:18
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 9a09a93 to 191b110 Compare May 28, 2023 09:17
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 191b110 to f0375c7 Compare June 4, 2023 12:17
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 3 times, most recently from f898e4c to 55aa24e Compare June 19, 2023 13:30
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from eec179f to 456f069 Compare July 6, 2023 12:02
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from c347612 to 8689daa Compare July 19, 2023 12:09
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 8689daa to ee6b56d Compare July 27, 2023 20:25
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from ee6b56d to e251cfb Compare August 9, 2023 14:43
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from a08e220 to 5faa9bf Compare September 26, 2023 12:22
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from 4d377ef to ed3449e Compare October 15, 2023 15:16
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from ed3449e to 4762dc4 Compare October 21, 2023 02:15
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 4762dc4 to 4426674 Compare November 6, 2023 06:36
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 4426674 to 47487c3 Compare November 16, 2023 10:17
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 47487c3 to 5381528 Compare January 28, 2024 09:30
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 5381528 to c5a21a5 Compare February 4, 2024 11:36
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from c5a21a5 to 3a044af Compare February 25, 2024 10:57
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 3a044af to 19940f9 Compare March 12, 2024 11:55
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from 364407a to 1597e60 Compare March 24, 2024 15:00
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from 6bcb995 to 68d1fa3 Compare April 21, 2024 10:31
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 68d1fa3 to 080474f Compare April 25, 2024 08:01
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 080474f to 85c15e0 Compare June 4, 2024 10:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants