-
-
Notifications
You must be signed in to change notification settings - Fork 433
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): update dependency webpack to v5.76.0 [security] - autoclosed #1598
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
89e7201
to
f5f7be0
Compare
f5f7be0
to
bd2b94c
Compare
bd2b94c
to
25d1a09
Compare
6c20804
to
bff5899
Compare
548973d
to
4167bc6
Compare
4167bc6
to
b58d54d
Compare
6c53aba
to
c232e01
Compare
d35eb66
to
79d3762
Compare
79d3762
to
64688f0
Compare
b8be737
to
b5d8547
Compare
267a3b7
to
11ffd2e
Compare
637ef77
to
aeba4bd
Compare
ac68c35
to
8a8673a
Compare
1dac772
to
ff56aef
Compare
ff56aef
to
5c487e4
Compare
49d5dde
to
3b7d9d7
Compare
3b7d9d7
to
b58fe14
Compare
9d61596
to
a56b3f2
Compare
a56b3f2
to
965ad52
Compare
965ad52
to
467282b
Compare
250de43
to
941462b
Compare
941462b
to
4b4829c
Compare
4b4829c
to
30bc2c8
Compare
30bc2c8
to
86d4468
Compare
39a1ed3
to
1275c5a
Compare
1275c5a
to
3bee8d3
Compare
dd9115d
to
42efa51
Compare
d62367a
to
0ec3aae
Compare
04762d0
to
ae6124c
Compare
ae6124c
to
4f5f116
Compare
4f5f116
to
4a6c071
Compare
4a6c071
to
79b5783
Compare
79b5783
to
9ab3837
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.74.0
->5.76.0
GitHub Vulnerability Alerts
CVE-2023-28154
Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.
Release Notes
webpack/webpack (webpack)
v5.76.0
Compare Source
Bugfixes
generatedCode
info to fix bug in asset module cache restoration by @ryanwilsonperkin in https://github.com/webpack/webpack/pull/16703hashRegExp
lookup by @ryanwilsonperkin in https://github.com/webpack/webpack/pull/16759Features
target
toLoaderContext
type by @askoufis in https://github.com/webpack/webpack/pull/16781Security
Repo Changes
New Contributors
Full Changelog: webpack/webpack@v5.75.0...v5.76.0
v5.75.0
Compare Source
Bugfixes
experiments.*
normalize tofalse
when opt-outNaN%
window
before trying to access iteval-nosources-*
actually exclude sourcesFeatures
@import
to extenal CSS when using experimental CSS in nodei64
support to the deprecated WASM implementationDeveloper Experience
EnableWasmLoadingPlugin
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.