Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency webpack to v5.76.0 [security] #1598

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Mar 15, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
webpack 5.74.0 -> 5.76.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2023-28154

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.


Release Notes

webpack/webpack (webpack)

v5.76.0

Compare Source

Bugfixes

Features

Security

Repo Changes

New Contributors

Full Changelog: webpack/webpack@v5.75.0...v5.76.0

v5.75.0

Compare Source

Bugfixes

  • experiments.* normalize to false when opt-out
  • avoid NaN%
  • show the correct error when using a conflicting chunk name in code
  • HMR code tests existance of window before trying to access it
  • fix eval-nosources-* actually exclude sources
  • fix race condition where no module is returned from processing module
  • fix position of standalong semicolon in runtime code

Features

  • add support for @import to extenal CSS when using experimental CSS in node
  • add i64 support to the deprecated WASM implementation

Developer Experience

  • expose EnableWasmLoadingPlugin
  • add more typings
  • generate getters instead of readonly properties in typings to allow overriding them

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from 89e7201 to f5f7be0 Compare March 20, 2023 12:53
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from f5f7be0 to bd2b94c Compare March 24, 2023 16:57
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from bd2b94c to 25d1a09 Compare April 10, 2023 11:11
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from 6c20804 to bff5899 Compare April 18, 2023 15:17
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 4 times, most recently from 548973d to 4167bc6 Compare May 4, 2023 08:53
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 4167bc6 to b58d54d Compare May 8, 2023 11:46
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from 6c53aba to c232e01 Compare May 20, 2023 08:35
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 3 times, most recently from d35eb66 to 79d3762 Compare May 28, 2023 06:01
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 79d3762 to 64688f0 Compare June 4, 2023 08:10
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 3 times, most recently from b8be737 to b5d8547 Compare June 18, 2023 12:30
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 3 times, most recently from 267a3b7 to 11ffd2e Compare June 29, 2023 12:00
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from 637ef77 to aeba4bd Compare July 9, 2023 11:43
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from ac68c35 to 8a8673a Compare July 19, 2023 10:37
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from 1dac772 to ff56aef Compare August 1, 2023 16:17
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from ff56aef to 5c487e4 Compare August 9, 2023 14:04
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from 9c4d75f to 8577889 Compare August 27, 2023 09:39
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 3 times, most recently from 60308fe to 776729f Compare September 24, 2023 06:49
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from 49d5dde to 3b7d9d7 Compare September 28, 2023 16:07
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 3b7d9d7 to b58fe14 Compare October 7, 2023 05:38
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from 9d61596 to a56b3f2 Compare October 19, 2023 20:23
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from a56b3f2 to 965ad52 Compare October 23, 2023 12:48
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 965ad52 to 467282b Compare November 6, 2023 07:07
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from 250de43 to 941462b Compare November 16, 2023 11:01
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 941462b to 4b4829c Compare December 3, 2023 10:12
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 4b4829c to 30bc2c8 Compare December 10, 2023 21:19
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 30bc2c8 to 86d4468 Compare January 28, 2024 09:12
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from 39a1ed3 to 1275c5a Compare February 8, 2024 09:37
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 1275c5a to 3bee8d3 Compare February 25, 2024 11:07
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from dd9115d to 42efa51 Compare March 16, 2024 14:15
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 3 times, most recently from d62367a to 0ec3aae Compare March 24, 2024 13:27
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch 2 times, most recently from 04762d0 to ae6124c Compare April 21, 2024 08:56
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from ae6124c to 4f5f116 Compare April 25, 2024 12:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants