Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency webpack-dev-server to v5 [SECURITY] #16

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Apr 26, 2021

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
webpack-dev-server ^1.14.0 -> ^5.0.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2018-14732

Versions of webpack-dev-server before 3.1.10 are missing origin validation on the websocket server. This vulnerability allows a remote attacker to steal a developer's source code because the origin of requests to the websocket server that is used for Hot Module Replacement (HMR) are not validated.

Recommendation

For webpack-dev-server update to version 3.1.11 or later.


Release Notes

webpack/webpack-dev-server (webpack-dev-server)

v5.1.0

Compare Source

Features
  • add visual progress indicators (a8f40b7)
  • added the app option to be Function (by default only with connect compatibility frameworks) (3096148)
  • allow the server option to be Function (#​5275) (02a1c6d)
  • http2 support for connect and connect compatibility frameworks which support HTTP2 (#​5267) (6509a3f)
Bug Fixes
5.0.4 (2024-03-19)
Bug Fixes
5.0.3 (2024-03-12)
Bug Fixes
5.0.2 (2024-02-16)
Bug Fixes
5.0.1 (2024-02-13)
Bug Fixes

v5.0.4

Compare Source

v5.0.3

Compare Source

v5.0.2

Compare Source

v5.0.1

Compare Source

v5.0.0

Compare Source

Migration Guide and Changes.

4.15.1 (2023-06-09)
Bug Fixes

v4.15.2

Compare Source

4.15.2 (2024-03-20)
Bug Fixes
  • security: bump webpack-dev-middleware (4116209)

v4.15.1

Compare Source

v4.15.0

Compare Source

Features

v4.14.0

Compare Source

Features
4.13.3 (2023-04-15)
Bug Fixes
4.13.2 (2023-03-31)
Bug Fixes
  • prevent open 0.0.0.0 in browser due windows problems (04e74f2)
4.13.1 (2023-03-18)
Bug Fixes

v4.13.3

Compare Source

v4.13.2

Compare Source

v4.13.1

Compare Source

v4.13.0

Compare Source

Features
  • added client.overlay.runtimeErrors option to control runtime errors (#​4773) (dca2366)

v4.12.0

Compare Source

Features
Bug Fixes
4.11.1 (2022-09-19)
Bug Fixes

v4.11.1

Compare Source

v4.11.0

Compare Source

Features
  • make allowedHosts accept localhost subdomains by default (#​4357) (0a33e6a)
Bug Fixes
4.10.1 (2022-08-29)
Bug Fixes

v4.10.1

Compare Source

v4.10.0

Compare Source

Features
  • allow to configure more client options via resource URL (#​4274) (216e3cb)
Bug Fixes
4.9.3 (2022-06-29)
Bug Fixes
  • avoid creation unnecessary stream for static sockjs file (#​4482) (049b153)
  • history-api-fallback now supports HEAD requests and handles them the same as GET (8936082)
4.9.2 (2022-06-06)
Bug Fixes
4.9.1 (2022-05-31)
Bug Fixes

v4.9.3

Compare Source

v4.9.2

Compare Source

v4.9.1

Compare Source

v4.9.0

Compare Source

Features
Bug Fixes
4.8.1 (2022-04-06)
Bug Fixes

v4.8.1

Compare Source

v4.8.0

Compare Source

Features
Bug Fixes
4.7.4 (2022-02-02)
Bug Fixes
4.7.3 (2022-01-11)
Security
  • update selfsigned to 2.0.0 version
4.7.2 (2021-12-29)
Bug Fixes
  • apply onAfterSetupMiddleware after setupMiddlewares (as behavior earlier) (f6bc644)
4.7.1 (2021-12-22)
Bug Fixes
  • removed url package, fixed compatibility with future webpack defaults (#​4132) (4e5d8ea)

v4.7.4

Compare Source

v4.7.3

Compare Source

v4.7.2

Compare Source

v4.7.1

Compare Source

v4.7.0

Compare Source

Features
  • added the setupMiddlewares option and deprecated onAfterSetupMiddleware and onBeforeSetupMiddleware options (#​4068) (c13aa56)
  • added types (8f02c3f)
  • show deprecation warning for cacert option (#​4115) (c73ddfb)
Bug Fixes

v4.6.0

Compare Source

Features
Bug Fixes

v4.5.0

Compare Source

Features
Bug Fixes

v4.4.0

Compare Source

Features
  • added the server option, now you can pass server options, example { server: { type: 'http', options: { maxHeaderSize: 32768 } } }, available options for http and https, note - for http2 is used spdy, options specified in the server.options option take precedence over https/http2 options (#​3940) (a70a7ef)
  • added the client.reconnect option (#​3912) (5edad76)
  • improve error handling within startCallback and endCallback (#​3969) (b0928ac)
Bug Fixes
4.3.1 (2021-10-04)
Bug Fixes

v4.3.1

Compare Source

v4.3.0

Compare Source

Features
Bug Fixes
4.2.1 (2021-09-13)
Bug Fixes
4.2.0 (2021-09-09)
Features
  • added the http.ca option (CLI option added too) (should be used instead cacert, because we will remove it in the next major release in favor the https.ca option)
  • added the https.crl option (CLI options added too), more information
  • https.ca/https.cacert/ https.cert/https.crl/https.key/https.pfx options are now accept Arrays of Buffer/string/Path to file, using --https-*-reset CLI options you can reset these options
  • https.pfx/https.key can be Object[], more information
  • https options can now accept custom options, you can use:
module.exports = {
  // Other options
  devServer: {
    https: {
      // Allow to set additional TSL options https://nodejs.org/api/tls.html#tls_tls_createsecurecontext_options
      minVersion: "TLSv1.1",
      ca: path.join(httpsCertificateDirectory, "ca.pem"),
      pfx: path.join(httpsCertificateDirectory, "server.pfx"),
      key: path.join(httpsCertificateDirectory, "server.key"),
      cert: path.join(httpsCertificateDirectory, "server.crt"),
      passphrase: "webpack-dev-server",
    },
  }
};
Bug Fixes
4.1.1 (2021-09-07)
Bug Fixes

v4.2.1

Compare Source

v4.2.0

Compare Source

v4.1.1

Compare Source

v4.1.0

Compare Source

Features
  • added the magicHtml option (#​3717) (4831f58)
  • allow to set hot and live-reload for client using search params (1c57680)
  • show warning when the hot option is enabled with the HMR plugin in config (#​3744) (6cb1e4e)
Bug Fixes
  • change log type of Disconnected! to info (fde27f5)
  • handle --allowed-hosts all correctly (#​3720) (326ed56)
  • output documentation link on errors (#​3680) (e16221b)
  • respect the bypass option with target/router options for proxy (b5dd568)

v4.0.0

Compare Source

v3.11.3

Compare Source

3.11.3 (2021-11-08)
Bug Fixes

v3.11.2

Compare Source

3.11.2 (2021-01-13)
Bug Fixes
  • cli arguments for serve command (a5fe337)

v3.11.1

Compare Source

3.11.1 (2020-12-29)
Bug Fixes

v3.11.0

Compare Source

Features
Bug Fixes
3.10.3 (2020-02-05)
Bug Fixes
3.10.2 (2020-01-31)
Bug Fixes
3.10.1 (2019-12-19)
Bug Fixes

v3.10.3

Compare Source

v3.10.2

Compare Source

v3.10.1

Compare Source

v3.10.0

Compare Source

Features
  • client: allow sock port to use location's port (sockPort: 'location') (#​2341) (dc10d06)
  • server: add contentBasePublicPath option (#​2150) (cee700d)
Bug Fixes

v3.9.0

Compare Source

Bug Fixes
Features
3.8.2 (2019-10-02)
Security
  • update selfsigned package
3.8.1 (2019-09-16)
Bug Fixes

v3.8.2

Compare Source

v3.8.1

Compare Source

v3.8.0

Compare Source

Bug Fixes
Features
Potential Breaking changes

We have migrated serverMode and clientMode to transportMode as an experimental option. If you want to use this feature, you have to change your settings.

Related PR: https://github.com/webpack/webpack-dev-server/pull/2116

3.7.2 (2019-06-17)
Bug Fixes
3.7.1 (2019-06-07)
Bug Fixes
  • retry finding port when port is null and get ports in sequence (#​1993) (bc57514)

v3.7.2

Compare Source

v3.7.1

Compare Source

v3.7.0

Compare Source

Bug Fixes

v3.6.0

Compare Source

Bug Fixes
Features
3.5.1 (2019-06-01)
Bug Fixes

v3.5.1

Compare Source

v3.5.0

Compare Source

Bug Fixes
Features
3.4.1 (2019-05-17)
Bug Fixes

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot changed the title Pin dependency webpack-dev-server to v1.16.5 [SECURITY] Pin dependency webpack-dev-server to 1.16.5 [SECURITY] May 9, 2021
@renovate renovate bot changed the title Pin dependency webpack-dev-server to 1.16.5 [SECURITY] Pin dependency webpack-dev-server to v1.16.5 [SECURITY] May 15, 2021
@renovate renovate bot changed the title Pin dependency webpack-dev-server to v1.16.5 [SECURITY] Pin dependency webpack-dev-server to v [SECURITY] Mar 7, 2022
@renovate renovate bot changed the title Pin dependency webpack-dev-server to v [SECURITY] Pin dependency webpack-dev-server to v1.16.5 [SECURITY] Sep 25, 2022
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from e237ec3 to 05fd871 Compare November 20, 2022 15:33
@renovate renovate bot changed the title Pin dependency webpack-dev-server to v1.16.5 [SECURITY] Update dependency webpack-dev-server to v4 [SECURITY] Nov 20, 2022
@renovate renovate bot changed the title Update dependency webpack-dev-server to v4 [SECURITY] Update dependency webpack-dev-server to v3 [SECURITY] Mar 27, 2023
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 05fd871 to fae32cb Compare March 27, 2023 16:53
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from fae32cb to cd50edc Compare May 29, 2023 17:53
@renovate renovate bot changed the title Update dependency webpack-dev-server to v3 [SECURITY] Update dependency webpack-dev-server to v4 [SECURITY] May 29, 2023
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from cd50edc to f09f323 Compare June 1, 2023 16:09
@renovate renovate bot changed the title Update dependency webpack-dev-server to v4 [SECURITY] Update dependency webpack-dev-server to v3 [SECURITY] Jun 1, 2023
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from f09f323 to 04129a9 Compare June 8, 2023 06:00
@renovate renovate bot changed the title Update dependency webpack-dev-server to v3 [SECURITY] Update dependency webpack-dev-server to v4 [SECURITY] Jun 8, 2023
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 04129a9 to e7c47fc Compare June 10, 2023 11:19
@renovate renovate bot changed the title Update dependency webpack-dev-server to v4 [SECURITY] Update dependency webpack-dev-server to v3 [SECURITY] Jun 10, 2023
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from e7c47fc to b9e917d Compare June 14, 2023 02:27
@renovate renovate bot changed the title Update dependency webpack-dev-server to v3 [SECURITY] Update dependency webpack-dev-server to v4 [SECURITY] Jun 14, 2023
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from b9e917d to 899fbd0 Compare June 17, 2023 05:21
@renovate renovate bot changed the title Update dependency webpack-dev-server to v4 [SECURITY] Update dependency webpack-dev-server to v3 [SECURITY] Jun 17, 2023
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 899fbd0 to 694f0e5 Compare June 18, 2023 11:58
@renovate renovate bot changed the title Update dependency webpack-dev-server to v3 [SECURITY] Update dependency webpack-dev-server to v4 [SECURITY] Jun 18, 2023
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 694f0e5 to 2f2aa89 Compare June 22, 2023 23:12
@renovate renovate bot changed the title Update dependency webpack-dev-server to v4 [SECURITY] Update dependency webpack-dev-server to v3 [SECURITY] Jun 22, 2023
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 2f2aa89 to f522784 Compare June 30, 2023 02:33
@renovate renovate bot changed the title Update dependency webpack-dev-server to v3 [SECURITY] Update dependency webpack-dev-server to v4 [SECURITY] Jun 30, 2023
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from f522784 to 30d7dfe Compare July 1, 2023 00:46
@renovate renovate bot changed the title Update dependency webpack-dev-server to v4 [SECURITY] Update dependency webpack-dev-server to v3 [SECURITY] Jul 1, 2023
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 30d7dfe to 6990797 Compare July 7, 2023 20:41
@renovate renovate bot changed the title Update dependency webpack-dev-server to v3 [SECURITY] Update dependency webpack-dev-server to v4 [SECURITY] Jul 7, 2023
@renovate renovate bot changed the title Update dependency webpack-dev-server to v3 [SECURITY] Update dependency webpack-dev-server to v5 [SECURITY] May 9, 2024
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 48d8c2b to b547a25 Compare May 10, 2024 05:44
@renovate renovate bot changed the title Update dependency webpack-dev-server to v5 [SECURITY] Update dependency webpack-dev-server to v3 [SECURITY] May 10, 2024
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from b547a25 to dbe5d3c Compare May 22, 2024 23:54
@renovate renovate bot changed the title Update dependency webpack-dev-server to v3 [SECURITY] Update dependency webpack-dev-server to v5 [SECURITY] May 22, 2024
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from dbe5d3c to 8cf2cef Compare May 23, 2024 11:49
@renovate renovate bot changed the title Update dependency webpack-dev-server to v5 [SECURITY] Update dependency webpack-dev-server to v3 [SECURITY] May 23, 2024
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 8cf2cef to f80b08d Compare June 5, 2024 02:41
@renovate renovate bot changed the title Update dependency webpack-dev-server to v3 [SECURITY] Update dependency webpack-dev-server to v5 [SECURITY] Jun 5, 2024
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from f80b08d to 90fcbcb Compare June 6, 2024 05:40
@renovate renovate bot changed the title Update dependency webpack-dev-server to v5 [SECURITY] Update dependency webpack-dev-server to v3 [SECURITY] Jun 6, 2024
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 90fcbcb to abd07b6 Compare June 28, 2024 02:46
@renovate renovate bot changed the title Update dependency webpack-dev-server to v3 [SECURITY] Update dependency webpack-dev-server to v5 [SECURITY] Jun 28, 2024
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from abd07b6 to 4088d5b Compare June 29, 2024 08:41
@renovate renovate bot changed the title Update dependency webpack-dev-server to v5 [SECURITY] Update dependency webpack-dev-server to v3 [SECURITY] Jun 29, 2024
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 4088d5b to 88c1b52 Compare July 14, 2024 20:40
@renovate renovate bot changed the title Update dependency webpack-dev-server to v3 [SECURITY] Update dependency webpack-dev-server to v5 [SECURITY] Jul 14, 2024
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 88c1b52 to 5fe6111 Compare July 15, 2024 05:55
@renovate renovate bot changed the title Update dependency webpack-dev-server to v5 [SECURITY] Update dependency webpack-dev-server to v3 [SECURITY] Jul 15, 2024
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 5fe6111 to c1e32fe Compare July 22, 2024 14:47
@renovate renovate bot changed the title Update dependency webpack-dev-server to v3 [SECURITY] Update dependency webpack-dev-server to v5 [SECURITY] Jul 22, 2024
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from c1e32fe to da63cc8 Compare July 24, 2024 08:43
@renovate renovate bot changed the title Update dependency webpack-dev-server to v5 [SECURITY] Update dependency webpack-dev-server to v3 [SECURITY] Jul 24, 2024
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from da63cc8 to 0bb1c44 Compare July 28, 2024 18:00
@renovate renovate bot changed the title Update dependency webpack-dev-server to v3 [SECURITY] Update dependency webpack-dev-server to v5 [SECURITY] Jul 28, 2024
@renovate renovate bot changed the title Update dependency webpack-dev-server to v5 [SECURITY] Update dependency webpack-dev-server to v3 [SECURITY] Jul 29, 2024
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 0bb1c44 to ec8bd78 Compare July 29, 2024 05:20
@renovate renovate bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from ec8bd78 to 632207b Compare October 10, 2024 09:00
@renovate renovate bot changed the title Update dependency webpack-dev-server to v3 [SECURITY] Update dependency webpack-dev-server to v5 [SECURITY] Oct 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants