🚨 [security] Update webpack 5.1.0 → 5.105.0 (minor)#117
Open
depfu[bot] wants to merge 1 commit into+master+master+master+from
Open
🚨 [security] Update webpack 5.1.0 → 5.105.0 (minor)#117depfu[bot] wants to merge 1 commit into+master+master+master+from
depfu[bot] wants to merge 1 commit into+master+master+master+from
Conversation
|
Unable to locate .performanceTestingBot config file |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Welcome to Depfu đź‘‹
This is one of the first three pull requests with dependency updates we've sent your way. We tried to start with a few easy patch-level updates. Hopefully your tests will pass and you can merge this pull request without too much risk. This should give you an idea how Depfu works in general.
After you merge your first pull request, we'll send you a few more. We'll never open more than seven PRs at the same time so you're not getting overwhelmed with updates.
Let us know if you have any questions. Thanks so much for giving Depfu a try!
🚨 Your current dependencies have known security vulnerabilities 🚨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
✳️ webpack (5.1.0 → 5.105.0) · Repo · Changelog
Security Advisories 🚨
🚨 Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS
🚨 Cross-realm object access in Webpack 5
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Sorry, we couldn't find anything useful about this release.
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by 27 commits:
v27.5.1chore: update changelog for releaseci(jest-changed-files): enable `mercurial` related test on CI (#12327)chore: remove unnecessary checkschore: avoid backticks without template in strings (#12328)chore: remove `@babel/plugin-proposal-class-properties`chore(jest-config): remove unused dev dep (#12319)Revert "chore: remove unused import from test" (#12321)chore: run prettierdocs: added info about modern and legacy timers (#12317)docs: update `toHaveBeenCalledWith` to include type of equality check (#12222)docs(GettingStarted): separate TypeScript sections (#12306)docs: adds details to test results processor config option (#12206)fix(jest-config): replace `jsonlint` with `parse-json` (#12316)fix: binary scripts should use package exports (#12315)chore: also clean out dist/ directorychore: prepare ignorefiles for dist/ directory (#12314)fix: point to correctly exported files in `jest-repl` (#12311)chore: avoid using anonymous default exports (#12313)chore: read package.json less during build (#12310)feat(pretty-format): expose `ConvertAnsi` plugin (#12308)fix(expect): add type definitions for asymmetric `closeTo` matcher (#12304)chore: do not escape strings in snapshots (#12303)chore: use Node 16 more on CI (#12007)chore: update snapshotchore: roll new version of docschore: update lockfile after releaseRelease Notes
4.3.1
4.3.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 30 commits:
chore(release): 4.3.1refactor: logicrefactor: commentsperf: speed up resource parsing (#83)refactor: update eslint config (#82)fix: always set `resource`, `resourcePath`, `resourceQuery` and `resourceFragment` to empty string when they are unavaliable (#81)chore: migrate to eslint-config-webpack (#78)Merge pull request #76 from webpack/dependabot/npm_and_yarn/es5-ext-0.10.63Bump es5-ext from 0.10.53 to 0.10.63Merge pull request #73 from webpack/dependabot/npm_and_yarn/handlebars-4.7.8Bump handlebars from 4.7.6 to 4.7.8Merge pull request #72 from webpack/dependabot/npm_and_yarn/word-wrap-1.2.4Bump word-wrap from 1.2.3 to 1.2.4Merge pull request #59 from olleolleolle/patch-1Merge pull request #69 from webpack/dependabot/npm_and_yarn/minimatch-3.1.2Bump minimatch from 3.0.4 to 3.1.2Merge pull request #63 from CommanderRoot/rm-deprecated-substr4.3.0rename to mainMerge pull request #66 from vankop/add-more-arguments-to-processResourceadd more arguments to processResource callbackchore: replace deprecated String.prototype.substr()README: fix typos4.2.0Merge pull request #50 from webpack/ci/remove-travisMerge pull request #47 from webpack/feature/process-resourceremove travisadd processResource option to control if resource is added as dependencyMerge pull request #49 from webpack/ci/actionsadd github actions workflowRelease Notes
2.3.0
2.2.3
2.2.2
2.2.1
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 33 commits:
chore(release): 2.3.0feat(types): added `TypedHookMap` type (#195)chore(release): 2.2.3style: fix (#194)test: morefix: async hook catch an error when reject a falsy value (#193)chore(deps): update (#192)fix: support to pass return type for waterfall hooks (#191)fix: types for waterfall hooks (#190)chore: migrate to eslint-config-webpack (#189)chore(release): 2.2.2ci: fix (#188)chore: fix gitignorechore: setup test envdocs: fix readme grammar issues (#153)fix: add interceptors type to hook classdocs: fix HookMap description (#178)2.2.1Merge pull request #161 from chengcyber/feat-hook-typeadd taps type to hook classMerge pull request #157 from iguessitsokay/types-withoptionsomit promise field and fix lintingfix: set withConfig return type to include correct properties2.2.0Merge pull request #151 from webpack/feature/browser-supportflag function in good path for eager parsingallow to use tapable in browser2.1.1Merge pull request #148 from webpack/bugfix/js-workaroundadd workaround for jsdoc-style typescript bug2.1.0Merge pull request #147 from webpack/types/fixes-customallow to add custom properties to tap optionsSecurity Advisories 🚨
🚨 Terser insecure use of regular expressions leads to ReDoS
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
🆕 @​jridgewell/gen-mapping (added, 0.3.13)
🆕 @​jridgewell/resolve-uri (added, 3.1.2)
🆕 @​jridgewell/source-map (added, 0.3.11)
🆕 @​jridgewell/sourcemap-codec (added, 1.5.5)
🆕 @​jridgewell/trace-mapping (added, 0.3.31)
🆕 @​webassemblyjs/helper-numbers (added, 1.13.2)
🆕 acorn-import-phases (added, 1.0.4)
🆕 ajv-formats (added, 2.1.1)
🆕 baseline-browser-mapping (added, 2.9.19)
🆕 es-module-lexer (added, 2.0.0)
🆕 fast-uri (added, 3.1.0)
🆕 picocolors (added, 1.1.1)
🆕 require-from-string (added, 2.0.2)
🆕 update-browserslist-db (added, 1.2.3)
🗑️ @​webassemblyjs/helper-code-frame (removed)
🗑️ @​webassemblyjs/helper-fsm (removed)
🗑️ @​webassemblyjs/helper-module-context (removed)
🗑️ @​webassemblyjs/wast-parser (removed)
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands