Skip to content

chore: Bump webpack-dev-middleware from 7.4.5 to 8.3.0 - #6400

Closed
dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/npm_and_yarn/webpack-dev-middleware-8.2.0
Closed

dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/npm_and_yarn/webpack-dev-middleware-8.2.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps webpack-dev-middleware from 7.4.5 to 8.3.0.

Release notes

Sourced from webpack-dev-middleware's releases.

v8.3.0

Minor Changes

  • Added a hot option that enables hot module replacement, replacing the need for webpack-hot-middleware. Pass hot: true to enable with defaults, or hot: { path, heartbeat, progress, statsOptions } to customize. The client runtime is served by the middleware itself. (by @​bjohansebas in #2370)

  • Take the diagnostics a hot payload carries from the stats option, so one setting governs what a build reports in the terminal and in the browser: stats: "errors-only" keeps warnings out of both, and stats: false keeps errors and warnings out of both, the client's error overlay included — reach for the client's ?logging= or ?overlay= to quiet the browser alone. hot.statsOptions is deprecated and will be removed in the next major release; its hash, timings and children keys are now ignored, because they could leave a payload without the hash the client compares, or carry a child compilation's hash instead, which stopped updates applying and forced a full page reload on every rebuild. (by @​alexander-akait in #2392)

Patch Changes

  • Fixed a crash when calling invalidate() in plugin mode (isPlugin = true). Since the host (webpack-cli, webpack-dev-server, etc.) owns compiler.watch(), the middleware now invalidates the host's watching instead (each child compiler's one for a MultiCompiler on webpack < 5.109). When nothing is watching it logs a warning and completes the callback, as close() does, rather than leaving invalidate(callback) waiting on a build that never runs. (by @​bjohansebas in #2378)

  • Reject with 403 Forbidden the requests whose resolved filename falls outside outputPath (GHSA-g84c-rxfj-3j2c). With a publicPath without a trailing slash, a sibling path sharing its prefix (/assets../secret) escaped the output root once the prefix was stripped and joined. (by @​bjohansebas in #2404)

  • Update the changelog generator to the @changesets/get-github-info 1.0 API. (by @​alexander-akait in #2396)

  • Update dependencies. (by @​alexander-akait in #2394)

v8.2.0

Minor Changes

  • Added a hot option that enables hot module replacement, replacing the need for webpack-hot-middleware. Pass hot: true to enable with defaults, or hot: { path, heartbeat, progress, statsOptions } to customize. The client runtime ships with the package and is added as a webpack entry. (by @​bjohansebas in #2322)

v8.1.1

Patch Changes

  • Fixed a crash when calling close() in plugin mode (isPlugin = true). Since the host (webpack-cli, webpack-dev-server, etc.) owns compiler.watch(), the middleware has no watching of its own to close, so close() now just calls the callback instead of throwing. (by @​bjohansebas in #2347)

v8.1.0

Minor Changes

  • Reuse an already active MultiCompiler watching session instead of starting a duplicate one (requires webpack >= 5.109). (by @​bjohansebas in #2371)

v8.0.4

Patch Changes

  • Replace the on-finished dependency with Node.js built-in stream.finished. (by @​bjohansebas in #2346)

v8.0.3

Patch Changes

  • Respect req.url when modified by middleware such as connect-history-api-fallback. (by @​bjohansebas in #2304)

v8.0.2

Patch Changes

v8.0.1

Patch Changes

... (truncated)

Changelog

Sourced from webpack-dev-middleware's changelog.

8.3.0

Minor Changes

  • Added a hot option that enables hot module replacement, replacing the need for webpack-hot-middleware. Pass hot: true to enable with defaults, or hot: { path, heartbeat, progress, statsOptions } to customize. The client runtime is served by the middleware itself. (by @​bjohansebas in #2370)

  • Take the diagnostics a hot payload carries from the stats option, so one setting governs what a build reports in the terminal and in the browser: stats: "errors-only" keeps warnings out of both, and stats: false keeps errors and warnings out of both, the client's error overlay included — reach for the client's ?logging= or ?overlay= to quiet the browser alone. hot.statsOptions is deprecated and will be removed in the next major release; its hash, timings and children keys are now ignored, because they could leave a payload without the hash the client compares, or carry a child compilation's hash instead, which stopped updates applying and forced a full page reload on every rebuild. (by @​alexander-akait in #2392)

Patch Changes

  • Fixed a crash when calling invalidate() in plugin mode (isPlugin = true). Since the host (webpack-cli, webpack-dev-server, etc.) owns compiler.watch(), the middleware now invalidates the host's watching instead (each child compiler's one for a MultiCompiler on webpack < 5.109). When nothing is watching it logs a warning and completes the callback, as close() does, rather than leaving invalidate(callback) waiting on a build that never runs. (by @​bjohansebas in #2378)

  • Reject with 403 Forbidden the requests whose resolved filename falls outside outputPath (GHSA-g84c-rxfj-3j2c). With a publicPath without a trailing slash, a sibling path sharing its prefix (/assets../secret) escaped the output root once the prefix was stripped and joined. (by @​bjohansebas in #2404)

  • Update the changelog generator to the @changesets/get-github-info 1.0 API. (by @​alexander-akait in #2396)

  • Update dependencies. (by @​alexander-akait in #2394)

8.2.0

Minor Changes

  • Added a hot option that enables hot module replacement, replacing the need for webpack-hot-middleware. Pass hot: true to enable with defaults, or hot: { path, heartbeat, progress, statsOptions } to customize. The client runtime ships with the package and is added as a webpack entry. (by @​bjohansebas in #2322)

8.1.1

Patch Changes

  • Fixed a crash when calling close() in plugin mode (isPlugin = true). Since the host (webpack-cli, webpack-dev-server, etc.) owns compiler.watch(), the middleware has no watching of its own to close, so close() now just calls the callback instead of throwing. (by @​bjohansebas in #2347)

8.1.0

Minor Changes

  • Reuse an already active MultiCompiler watching session instead of starting a duplicate one (requires webpack >= 5.109). (by @​bjohansebas in #2371)

8.0.4

Patch Changes

  • Replace the on-finished dependency with Node.js built-in stream.finished. (by @​bjohansebas in #2346)

8.0.3

Patch Changes

  • Respect req.url when modified by middleware such as connect-history-api-fallback. (by @​bjohansebas in #2304)

8.0.2

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for webpack-dev-middleware since your current version.


@dependabot @github

dependabot Bot commented on behalf of github Sep 6, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot can't resolve your JavaScript dependency files. Because of this, Dependabot cannot update this pull request.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/webpack-dev-middleware-8.2.0 branch from 1ec3d1a to 99cc5e5 Compare September 6, 2026 00:35
@dependabot dependabot Bot changed the title chore: Bump webpack-dev-middleware from 7.4.5 to 8.2.0 chore: Bump webpack-dev-middleware from 7.4.5 to 8.3.0 Sep 9, 2026
Bumps [webpack-dev-middleware](https://github.com/webpack/webpack-dev-middleware) from 7.4.5 to 8.3.0.
- [Release notes](https://github.com/webpack/webpack-dev-middleware/releases)
- [Changelog](https://github.com/webpack/webpack-dev-middleware/blob/main/CHANGELOG.md)
- [Commits](webpack/webpack-dev-middleware@v7.4.5...v8.3.0)

---
updated-dependencies:
- dependency-name: webpack-dev-middleware
  dependency-version: 8.2.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/webpack-dev-middleware-8.2.0 branch from 99cc5e5 to 9a446e4 Compare September 9, 2026 00:27
@dependabot @github

dependabot Bot commented on behalf of github Sep 13, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #6411.

@dependabot dependabot Bot closed this Sep 13, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/webpack-dev-middleware-8.2.0 branch September 13, 2026 00:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants