This repository was archived by the owner on Jun 2, 2022. It is now read-only.
Update dependency webpack-dev-server to v3 [SECURITY] #92
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.4.1->3.1.11GitHub Vulnerability Alerts
CVE-2018-14732
Versions of
webpack-dev-serverbefore 3.1.10 are missing origin validation on the websocket server. This vulnerability allows a remote attacker to steal a developer's source code because the origin of requests to the websocket server that is used for Hot Module Replacement (HMR) are not validated.Recommendation
For
webpack-dev-serverupdate to version 3.1.11 or later.Release Notes
webpack/webpack-dev-server
v3.1.11Compare Source
Bug Fixes
options.color) (#1555) (55398b5)spdyv3.4.1...4.0.0 (assertion error) (#1491) (#1563) (7a3a257)nodeversion checks (#1543) (927a2b3)v3.1.10Compare Source
Bug Fixes
writeToDiskoption to schema (#1520) (d2f4902)sockjs-clientv1.1.5...1.3.0 (url-parsevulnerability) (#1537) (e719959)tls.DEFAULT_ECDH_CURVEto'auto'(#1531) (c12def3)v3.1.9Compare Source
3.1.9 (2018-09-24)
v3.1.8Compare Source
Bug Fixes
yargssecurity vulnerability (dependencies) (#1492) (8fb67c9)quietalways takes precedence (options.quiet) (#1486) (7a6ca47)v3.1.7Compare Source
Bug Fixes
spdyonnode >= v10.0.0(#1451) (8ab9eb6)v3.1.6Compare Source
Bug Fixes
processsignals correctly when the server isn't ready yet (#1432) (334c3a5)open-pageexample (#1401) (df30727)outputfilename to be a{Function}(#1409) (e2220c4)v3.1.5Compare Source
Progressevent in the client so plugins can use it (#1427)sockjs-clientto fix infinite reconnection loop (#1434)v3.1.4Compare Source
logLeveloptionsilentnot being accepted by schema validation (#1372)v3.1.3Compare Source
v3.1.2Compare Source
v3.1.1Compare Source
Bug Fixes
v3.1.0Compare Source
Updates
webpack-logis now used for logging to the terminal (webpack-dev-middleware was already using this).logLeveloption is added for more fine-grained control over the logging.Bugfixes
v3.0.0Compare Source
Updates
Bugfixes
Huge thanks to all the contributors!
Please note that webpack-serve will eventually be the successor of webpack-dev-server. The core features already work so if you're brave enough give it a try!
v2.11.5Compare Source
v2.11.4Compare Source
v2.11.3Compare Source
v2.11.2Compare Source
v2.11.1Compare Source
Our third attempt to fix compatibility with old browsers (#1273), this time we'll get it right.
v2.11.0Compare Source
Version 2.11.0 adds the transpilation of the client scripts via babel to ES5 which restores backwards compatibility (that was removed in 2.8.0) to very old or out of date browsers.
v2.10.1Compare Source
v2.10.0Compare Source
Version 2.10.0 adds the transpilation of the client scripts via babel to ES5 which restores backwards compatibility (that was removed in 2.8.0) to very old or out of date browsers.
Important webpack-dev-server has entered a maintenance-only mode. We won't be accepting any new features or major modifications. We'll still welcome pull requests for fixes however, and will continue to address any bugs that arise. Announcement with specifics pending.
Bugfixes
reportTimeoption (#1209)Updates
ce30460)markedversion for ReDos vuln (#1255)v2.9.7Compare Source
v2.9.6Compare Source
Bugfixes
v2.9.5Compare Source
Updates
6b2d7a0)v2.9.4Compare Source
Bugfixes
v2.9.3Compare Source
Bugfixes
sockjs-clientinstead of module source (#1148)v2.9.2Compare Source
Bugfixes
Changed property descriptor for Array.includes polyfill (#1134)
Updates
Remove header additional property validation (#1115)
Allow explicitly setting the protocol from the public option (#1117)
Updates readme with support, usage, and caveats (outlines no support for old IE)
v2.9.1Compare Source
Patch release to resolve an errant log message in
setupv2.9.0Compare Source
Note: Minor release due to addition of
beforeandafterhooksFeatures
Deprecate setup in favor of before and after hooks (#1108)
Bugfixes
Fixed check for webpack/hot/log when setting HMR log level. (#1096)
fixes #1109: internal-ip update breaks useLocalIp option
Fix quote style to satisfy ESLint (#1098)
Updates
Made error overlay translucent. (#1097)
v2.8.2Compare Source
Bugfixes
fixes #1087: yargs@8 causes error output with [email protected]
fixes #1084: template literals causing errors on IE (#1089) …
fixes #1086: promise configs fix and example
Updates
add promise-config example
v2.8.1Compare Source
Bugfixes
fixes #1081, closes #1079. addDevServerEndpoints needs app stub for createDomain
fixes #1080 - jQuery update caused live bundle iframe issue
clean up progress option typo and options def
v2.8.0Compare Source
Features
Bugfixes
Updates
--openoption to specify the browser to use (#825)subjectAltNamefield in self-signed cert (#987)v2.7.1Compare Source
v2.6.1Compare Source
loglevelfrom devDependencies to dependencies #1001v2.6.0Compare Source
clientLogLevel(#921).quietis set totrue(#970).--disable-host-check(#980).v2.5.1Compare Source
Bugfixes
Fix peer dependencies to support webpack 3 ( #946 ) ( Fixes #932 )
v2.5.0Compare Source
Security
Don't provide a SSL cert, but generate one on demand. Unique for each developer.
https://medium.com/[@​mikenorth/961572624c54](https://togithub.com/mikenorth/961572624c54) by Mike North
Bugfixes
allowedHostsoptionopenPageoption to open a specific page--bonjourlanoption, which listen on lan ip by defaultv2.4.5Compare Source
Bugfixes
v2.4.4Compare Source
Bugfixes:
disableHostCheckto schemav2.4.3Compare Source
Security fix:
This version contains a security fix, which is also breaking change if you have an insecure configuration.
We are releasing this breaking change as patch version to protect you from attacks.
Sorry if this breaks your setup, but the fix is easy.
We added a check for the correct
Hostheader to the webpack-dev-server.This allowed evil websites to access your assets.
The
Hostheader of the request have to match the listening adress or the host provided in thepublicoption.Make sure to provide correct values here.
The response will contain a note when using an incorrect
Hostheader.For usage behind a Proxy or similar setups we also added a
disableHostCheckoption to disable this check.Only use it when you know what you do. Not recommended.
This version also includes this security fix for webpack-dev-middleware: https://github.com/webpack/webpack-dev-middleware/releases/tag/v1.10.2
Note: This only affect the development server and middleware. webpack and built bundles are not affected.
Credits to Ed Morley from Mozilla for reporting the issue.
Bugfixes:
Hostdoesn't match listening host orpublicoption.localhostor127.0.0.1are not blocked.Features:
disableHostCheckoption to disable the host checkv2.4.2Compare Source
entrynot working when it was a function (#802).contentBaseas an array did not work when used via CLI (#832).Configuration
📅 Schedule: "" in timezone America/New_York.
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.