Skip to content

chore(deps): update dependency webpack to v5.109.0 - #201

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/webpack-5.x-lockfile
Open

chore(deps): update dependency webpack to v5.109.0#201
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/webpack-5.x-lockfile

Conversation

@renovate

@renovate renovate Bot commented Feb 14, 2025

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
webpack 5.97.15.109.0 age confidence

Release Notes

webpack/webpack (webpack)

v5.109.0

Compare Source

Minor Changes
  • Default experiments.typescript to "auto", enabling built-in TypeScript support on Node.js >= 22.6 when no TypeScript loader is registered. (by @​alexander-akait in #​21477)

  • Default experiments.css, experiments.html and experiments.asyncWebAssembly to "auto", enabling built-in support unless a loader is registered for those files; modules with inline or hook-injected loaders (e.g. html-webpack-plugin templates) keep being parsed as JavaScript. (by @​alexander-akait in #​21477)

  • Add output.resourceHints to emit resource hints (preload/prefetch/modulepreload/preconnect), on by default for ESM output, plus module.parser.<type>.urlHints, css.fontPreload and javascript.dynamicImportCssPreload. (by @​alexander-akait in #​21477)

  • Add built-in build progress via infrastructureLogging.progress, plus estimatedTime, phaseTimings, progress bar width and progressBar: "auto" on ProgressPlugin. (by @​alexander-akait in #​21477)

  • Concatenate CommonJS modules with statically analyzable exports; opt out via optimization.concatenateModules: { commonjs: false }. (by @​alexander-akait in #​21477)

  • Wrap "weird" CommonJS modules into module concatenation instead of bailing out. (by @​alexander-akait in #​21477)

  • Add output.html.inline (true | "script" | "style") and the webpackInline magic comment to inline chunk content into HTML. (by @​alexander-akait in #​21477)

  • Add output.html.inject to control where chunk tags are injected. (by @​alexander-akait in #​21477)

  • Add output.html.title, output.html.meta and output.html.base options for head generation. (by @​alexander-akait in #​21477)

  • Support per-icon link attributes (sizes, media, color, type, crossorigin) and arrays in output.html.favicon. (by @​alexander-akait in #​21487)

  • Add output.html.manifest to generate and link a web app manifest with hashed icons. (by @​alexander-akait in #​21487)

  • Add output.html.csp to inject a Content-Security-Policy meta with inline-content hashes and an optional nonce. (by @​alexander-akait in #​21487)

  • Add the output.html injectTags compilation hook to inject tags (script/link/meta/…) with injectTo placement. (by @​alexander-akait in #​21487)

  • Add the output.html transformTags compilation hook to mutate, remove, or move (between <head> and <body>) a page's existing <script>/<link>/<style>/<meta> tags. (by @​alexander-akait in #​21487)

  • Extend the HTML pipeline with html link sources (bundled as their own emitted page) and rel="preload"/"prefetch" links bundled as chunks. (by @​alexander-akait in #​21477)

  • Recognize more asset-bearing HTML sources: the twitter:player:stream meta, legacy SVG references, and Web App Manifest icons/screenshots/shortcuts URLs. (by @​alexander-akait in #​21477)

  • Add module.parser.html.as to parse HTML as a document or an element fragment. (by @​alexander-akait in #​21477)

  • Allow disabling a built-in HTML parser source via type: false in sources. (by @​alexander-akait in #​21477)

  • Export webpack.html.HtmlModulesPlugin with transformHtml/htmlEmitted compilation hooks. (by @​alexander-akait in #​21477)

  • Resolve @custom-media (including media-type values) and @custom-selector in native CSS. (by @​alexander-akait in #​21477)

  • Scope view-transition-name/-group/-class names and ::view-transition-*() pseudo references in CSS modules under customIdents. (by @​alexander-akait in #​21486)

  • Add import.meta.glob support, with a caseSensitive option and consistent hidden/node_modules matching. (by @​alexander-akait in #​21477)

  • Resolve import.meta.resolve("./asset") to the emitted asset URL via the importMeta.resolve parser option. (by @​alexander-akait in #​21477)

  • Add import.meta.env defaults: MODE, DEV, PROD, SSR and BASE_URL. (by @​alexander-akait in #​21477)

  • Add fine-grained import.meta parser options. (by @​alexander-akait in #​21477)

  • Deprecate the importMetaContext parser option in favor of importMeta.webpackContext. (by @​alexander-akait in #​21477)

  • Emit analyzable new URL(…, import.meta.url), worker/worklet URL and import() references with literal specifiers for ESM module output. (by @​alexander-akait in #​21477)

  • Compile async modules to generators for targets without async/await. (by @​alexander-akait in #​21477)

  • Evaluate and validate the second argument of dynamic import(specifier, options). (by @​alexander-akait in #​21477)

  • Add module.parser.javascript.worklet to bundle Worklet addModule() entries. (by @​alexander-akait in #​21477)

  • Add ?raw, ?url, ?inline and ?no-inline asset query suffixes under experiments.futureDefaults. (by @​alexander-akait in #​21477)

  • Add an interop ("default" | "esModule") hint for object externals to control default-export interop. (by @​alexander-akait in #​21477)

  • Add an amd-async externals type that loads AMD externals without an AMD library wrapper. (by @​alexander-akait in #​21477)

  • Support cache.compression: "zstd" for the filesystem cache. (by @​alexander-akait in #​21477)

  • Warn on strict-mode-only syntax and semantic hazards in ES module output, configurable via the strictModeViolations parser option. (by @​alexander-akait in #​21477)

  • Support parsers without location APIs: locations derive from node offsets and AST nodes no longer carry loc. (by @​alexander-akait in #​21477)

  • Attach the original DOM event to ChunkLoadError and ScriptExternalLoadError as error.event. (by @​alexander-akait in #​21477)

  • Add output.wasmStreamingFallback for wasm fallback on a wrong MIME type. (by @​alexander-akait in #​21477)

  • Show why a module was marked as not cacheable in stats output. (by @​alexander-akait in #​21477)

  • Expose the active MultiWatching on MultiCompiler.watching. (by @​alexander-akait in #​21477)

  • Resolve git merge conflicts when parsing the build-http lockfile. (by @​alexander-akait in #​21477)

Patch Changes

v5.108.4

Compare Source

Patch Changes

v5.108.3

Compare Source

Patch Changes

v5.108.2

Compare Source

Patch Changes

v5.108.1

Compare Source

Patch Changes
  • Fix invalid property access for escaped namespace imports with multi-character mangled export names. (by @​xiaoxiaojx in #​21280)

  • Add frames to ProfilingPlugin TracingStartedInBrowser event so the trace loads in Chrome DevTools. (by @​alexander-akait in #​21269)

v5.108.0

Compare Source

Minor Changes
  • Treat top-level await and import.meta as ES module markers, matching Node.js syntax detection so no explicit module type is needed. (by @​alexander-akait in #​21218)

  • Add a bun target that emits ESM and externalizes bun:* and node.js built-in modules. (by @​alexander-akait in #​21248)

  • Support CommonJS reexports via Object.defineProperty value and getter descriptors. (by @​alexander-akait in #​21129)

  • Support JSON Schema const when generating CLI flags from a schema. (by @​alexander-akait in #​21087)

  • Support JSON Schema if/then/else when generating CLI flags from a schema. (by @​alexander-akait in #​21087)

  • Skip import specifiers, require() and import() calls in dead conditional branches gated by inlined imported constants (isDEV ? A : B), evaluated via getCondition. (by @​hai-x in #​21136)

  • CSS localIdentName [hash] now resolves to the local ident hash (matching css-loader); use [modulehash] for the module hash. (by @​alexander-akait in #​21259)

  • Add CSS parser as option and resolve url() inside HTML style attributes. (by @​alexander-akait in #​21157)

  • Add dedicated module classes for all built-in module types. (by @​alexander-akait in #​21164)

  • Support .html/.css for the default ./src entry under the html/css experiments. (by @​alexander-akait in #​21039)

  • Add defineConfig helper for typed configuration files. (by @​alexander-akait in #​21169)

  • Add a deno target (with versions, e.g. deno, deno2, deno1.40) that emits ESM, resolves node.js built-ins via the required node: specifier, and keeps Deno's own import protocols (npm:, jsr:, node:, http(s)://) external. (by @​alexander-akait in #​21247)

  • Use module-import for electron externals when the target supports ESM. (by @​alexander-akait in #​21184)

  • Add output.environment.logicalAssignment to emit ||= in runtime code when the target supports logical assignment operators. (by @​bjohansebas in #​21219)

  • Resolve and rewrite asset URLs inside <iframe srcdoc> in HTML modules. (by @​bjohansebas in #​21226)

  • Add HMR support for HTML modules with body/title DOM patching on update. (by @​alexander-akait in #​21011)

  • Add css-url html source type extracting url() references from CSS-valued attributes. (by @​alexander-akait in #​21250)

  • Add module.parser.html.sources option to disable or customize URL-attribute extraction for HTML modules, with script / script-module / stylesheet / stylesheet-inline types for custom attributes (by @​alexander-akait in #​21022)

  • Add module.parser.html.template option to transform HTML module source before parsing. (by @​alexander-akait in #​21055)

  • Extract more source URLs in HTML modules (SVG, legacy and obsolete attributes). (by @​alexander-akait in #​21241)

  • Inline export default <const> when the default-exported value is a primitive constant. (by @​hai-x in #​21189)

  • Support optimization.inlineExports for better tree-shaking. (by @​hai-x in #​20973)

  • Re-encode inline hash digests ([contenthash]/[chunkhash]/[fullhash]/[modulehash]) from the full content hash, so they carry full entropy and work under optimization.realContentHash and in dynamically-loaded chunk filenames; also preserve leading zero bytes in base-N digests. (by @​alexander-akait in #​21267)

  • Allow tree-shaking unused calls to /*#__NO_SIDE_EFFECTS__*/-annotated (pure) exports across module boundaries. (by @​hai-x in #​20907)

  • Defer building unused re-export targets of side-effect-free barrel modules. (by @​hai-x in #​21165)

  • Keep export mangling enabled for modules whose namespace object is used as a whole value, by materializing a decoupled namespace object that keeps the original export names. (by @​alexander-akait in #​21234)

  • Add output.environment.let option (paired with target's let capability) and emit let/const instead of var in generated runtime code wherever it is safe. Bindings that may be wrapped in runtime-condition if blocks (harmony imports, ConcatenatedModule external imports) continue to use var to preserve function scoping. (by @​alexander-akait in #​21010)

  • Add output.html to emit an HTML file per entrypoint, injecting its JS/CSS chunks (including dependOn shared chunks). (by @​alexander-akait in #​21215)

  • Add module.parser.javascript.pureFunctions to mark top-level names as side-effect-free for tree shaking. (by @​hai-x in #​21063)

  • Add universal to compiler.platform, true for universal targets ("universal" or ["web", "node"]). (by @​bjohansebas in #​21252)

  • Add output.strictModuleResolution to gate the runtime MODULE_NOT_FOUND guard. (by @​hai-x in #​21067)

  • Support an inline digest in hash path placeholders, e.g. [contenthash:base64:8]. (by @​alexander-akait in #​21259)

  • Support [uniqueName] and its [uniquename] alias in template paths. (by @​alexander-akait in #​21155)

  • Support CSS in Node for universal targets, collecting styles for SSR. (by @​alexander-akait in #​21208)

  • Improve commonjs, node-commonjs and global externals for universal targets. (by @​alexander-akait in #​21187)

  • Add a universal target preset (browser + web worker + Node.js + Electron + NW.js) that always outputs ECMAScript modules. (by @​alexander-akait in #​21214)

  • Support new Worker(new URL(...)) in universal (node + web) targets by resolving the Worker constructor from worker_threads when no global Worker exists. (by @​alexander-akait in #​21195)

  • Add output.workerChunkFilename and entry.worker for worker chunk filenames. (by @​alexander-akait in #​21128)

Patch Changes

v5.107.2

Compare Source

Patch Changes
  • Reduce per-file overhead in ContextModuleFactory.resolveDependencies by batching alternativeRequests hook calls. Previously the hook was invoked once per file in the context (with a single-item array), paying per-call overhead (closure allocation, resolverFactory.get, intermediate arrays in RequireContextPlugin) for every file. The hook is now invoked once per directory with all matched files in one batch — RequireContextPlugin's tap already iterates the items array, so the output is unchange

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@bolt-new-by-stackblitz

Copy link
Copy Markdown

Review PR in StackBlitz Codeflow Run & review this pull request in StackBlitz Codeflow.

@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.98.0 chore(deps): update dependency webpack to v5.98.0 - autoclosed Feb 14, 2025
@renovate renovate Bot closed this Feb 14, 2025
@renovate
renovate Bot deleted the renovate/webpack-5.x-lockfile branch February 14, 2025 06:42
@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.98.0 - autoclosed chore(deps): update dependency webpack to v5.98.0 Feb 14, 2025
@renovate renovate Bot reopened this Feb 14, 2025
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch 2 times, most recently from 3a31003 to 142fca4 Compare February 14, 2025 14:12
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 142fca4 to 3251c3f Compare March 3, 2025 11:47
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch 3 times, most recently from 66dcfaf to 1ec9e14 Compare March 17, 2025 17:49
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 1ec9e14 to 1cf350b Compare March 24, 2025 13:04
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 1cf350b to b893ba2 Compare April 1, 2025 13:44
@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.98.0 chore(deps): update dependency webpack to v5.99.0 Apr 7, 2025
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch 2 times, most recently from 4160f26 to 38f6dd5 Compare April 7, 2025 23:09
@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.99.0 chore(deps): update dependency webpack to v5.99.1 Apr 7, 2025
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 38f6dd5 to 7b8fc37 Compare April 8, 2025 10:36
@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.99.1 chore(deps): update dependency webpack to v5.99.2 Apr 8, 2025
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 7b8fc37 to 7e3f46d Compare April 8, 2025 17:14
@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.99.2 chore(deps): update dependency webpack to v5.99.3 Apr 8, 2025
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 7e3f46d to 20ad586 Compare April 8, 2025 22:32
@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.99.3 chore(deps): update dependency webpack to v5.99.4 Apr 8, 2025
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 20ad586 to 26e3ab7 Compare April 9, 2025 01:36
@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.99.4 chore(deps): update dependency webpack to v5.99.5 Apr 9, 2025
@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.99.5 chore(deps): update dependency webpack to v5.99.6 Apr 18, 2025
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch 3 times, most recently from f199d28 to 80e63bc Compare April 25, 2025 11:59
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 1a67e3a to 4eb80fd Compare July 15, 2025 17:15
@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.100.1 chore(deps): update dependency webpack to v5.100.2 Jul 15, 2025
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 4eb80fd to 39fd868 Compare July 28, 2025 20:24
@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.100.2 chore(deps): update dependency webpack to v5.101.0 Jul 28, 2025
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch 2 times, most recently from 516e24c to e8e981c Compare August 12, 2025 14:49
@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.101.0 chore(deps): update dependency webpack to v5.101.1 Aug 12, 2025
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from e8e981c to fb52e52 Compare August 13, 2025 14:27
@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.101.1 chore(deps): update dependency webpack to v5.101.2 Aug 14, 2025
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch 2 times, most recently from fc94a63 to 5c1ec06 Compare August 18, 2025 15:35
@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.101.2 chore(deps): update dependency webpack to v5.101.3 Aug 18, 2025
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 5c1ec06 to 62ff772 Compare August 19, 2025 18:04
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 62ff772 to b0ce480 Compare August 31, 2025 13:53
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch 2 times, most recently from 04b5629 to 42152a9 Compare September 29, 2025 22:35
@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.101.3 chore(deps): update dependency webpack to v5.102.0 Sep 29, 2025
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 42152a9 to 2b0e0ff Compare October 8, 2025 01:45
@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.102.0 chore(deps): update dependency webpack to v5.102.1 Oct 8, 2025
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 2b0e0ff to 3fdaee9 Compare October 21, 2025 15:41
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 3fdaee9 to 3a840dc Compare November 10, 2025 23:47
@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.102.1 chore(deps): update dependency webpack to v5.103.0 Nov 18, 2025
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 3a840dc to 614aa45 Compare November 18, 2025 19:55
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 614aa45 to 5f265cf Compare December 3, 2025 19:11
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 5f265cf to 53ca79d Compare December 16, 2025 18:57
@renovate renovate Bot changed the title chore(deps): update dependency webpack to v5.103.0 chore(deps): update dependency webpack to v5.104.0 Dec 16, 2025
@renovate
renovate Bot force-pushed the renovate/webpack-5.x-lockfile branch from 53ca79d to 60e28e6 Compare December 18, 2025 13:58
@socket-security

socket-security Bot commented Mar 13, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm webpack is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/webpack@5.109.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/webpack@5.109.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@socket-security

socket-security Bot commented Jun 25, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedwebpack@​5.109.0821009398100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants