Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(Security): bump webpack from 4.44.2 to 5.11.0 #1805

Closed

Conversation

dependabot-preview[bot]
Copy link
Contributor

Bumps webpack from 4.44.2 to 5.11.0.

Release notes

Sourced from webpack's releases.

v5.11.0

Features

  • update typings to include undefined/null types (for strict type)
  • export WebpackError
  • export Asset and AssetInfo types
  • allow error configuration for validateSchema function

Bugfixes

  • fix typings for SourceMapSource
  • allow custom properties in AssetInfo
  • handle undefined values for rule conditions like empty strings

v5.10.3

Bugfixes

  • errors in initial cache no longer cause build dependencies to be ignored
  • manual side effects flagging should override automatic analysis
  • modules in dlls without entryOnly will no longer be dropped because of no side effects

v5.10.2

Bugfixes

  • add a few missing node.js libraries as externals in target: "node"
  • improve cache (de)serialization to allow larger cache files (>2GB) and increase performance for them

v5.10.1

Bugfixes

  • avoid duplicating chunk info in chunk loading global
  • allow executing chunks before runtime is loaded
  • avoid error when emitting assets with different query string but identical filename and content
  • fix duplicated asset name in processAssets with additionalAssets
  • add missing \ in module info header comment

v5.10.0

Bugfixes

  • Multiple fixes regarding the side effects optimization ("sideEffects": false) when reexports and concatenated modules are combined

Contributing

  • Typescript major 4
    • Improved internal structure of our typings

Performance

  • output.pathinfo: true (default in development) adds less verbose information (and is faster)
  • output.pathinfo: "verbose" adds more verbose information
Commits
  • f04328b 5.11.0
  • ed4694d Merge pull request #12225 from webpack/bugfix/undefined-conditions
  • 5b2fb32 Merge pull request #12224 from webpack/typings/missing
  • 8acebd2 treat undefined equal to not existing in rules
  • 16d5c35 reexport the schema validation function from schema-utils
  • 359b327 add missing argument to SourceMapSource
  • 745a583 export WebpackError
  • ec07eb0 update tooling
  • 63dda15 expose Asset and AssetInfo types
  • 41db807 Merge pull request #12216 from webpack/bugfix/query-data-url
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Note: This repo was added to Dependabot recently, so you'll receive a maximum of 5 PRs for your first few update runs. Once an update run creates fewer than 5 PRs we'll remove that limit.

You can always request more updates by clicking Bump now in your Dependabot dashboard.

Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in the .dependabot/config.yml file in this repo:

  • Update frequency
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

@dependabot-preview dependabot-preview bot added the Type: Devops DevOps/automation related label Dec 28, 2020
@codeclimate
Copy link

codeclimate bot commented Dec 28, 2020

Code Climate has analyzed commit 8da5839 and detected 0 issues on this pull request.

View more on Code Climate.

@codecov
Copy link

codecov bot commented Dec 28, 2020

Codecov Report

Merging #1805 (8da5839) into master (2dc22b6) will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##           master    #1805   +/-   ##
=======================================
  Coverage   97.73%   97.73%           
=======================================
  Files         239      239           
  Lines        2344     2344           
  Branches      614      614           
=======================================
  Hits         2291     2291           
  Misses         53       53           

@m7kvqbe1
Copy link
Collaborator

m7kvqbe1 commented Jan 4, 2021

A PR already exists for this work: #1614

Current status we are waiting on Storybook to upgrade as a pre-requisite.

Closing for now.

@m7kvqbe1 m7kvqbe1 closed this Jan 4, 2021
@dependabot-preview
Copy link
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot-preview dependabot-preview bot deleted the dependabot/npm_and_yarn/webpack-5.11.0 branch January 4, 2021 05:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Type: Devops DevOps/automation related
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant