You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Resolve aliases pointing at a package directory whose name ends with .js again. (by @alexander-akait in #21542)
Name CSS sources in source maps by their resource path, without the css prefix. (by @bjohansebas in #21536)
Delete no longer referenced files from the filesystem cache directory after storing the cache, age them by recorded time so restored caches are cleaned too, and collect every fully expired pack in one store instead of one per build. (by @bjohansebas in #21528)
Report "universal" as the loader context target for the universal target. (by @alexander-akait in #21540)
Skip require().prop in dead branches gated by inlined imported constants. (by @hai-x in #21517)
Annotate configuration options and public hooks in the generated types with the @since JSDoc tag. (by @bjohansebas in #21473)
Fix stray semicolon emitted before an imported call following a parenthesized sequence element. (by @alexander-akait in #21533)
Make require(esm)module.exports re-export analysis independent of module processing order. (by @alexander-akait in #21521)
Ignore ERR_SERVER_NOT_RUNNING on lazy-compilation backend dispose so compiler.close() succeeds on Bun. (by @alexander-akait in #21521)
Name the failing key when DefinePlugin fails to evaluate a typeof value. (by @alexander-akait in #21503)
Improve Deno compatibility: guard setNoDelay and force-close connections on lazy-compilation backend dispose, and return a real ArrayBuffer from the Node async/sync wasm loader so WebAssembly.instantiate accepts it. (by @alexander-akait in #21524)
Speed up the HTML parser and cut its peak memory: module-scope helpers/state and tokenizer callbacks, plus exact AST column pre-sizing. (by @alexander-akait in #21492)
Track CommonJS build dependencies by parsing sources when require.cache children are unavailable (e.g. Bun). (by @alexander-akait in #21531)
Cook common string-literal escapes on the JS parser fast path and own the tokenizer's cold-path readers. (by @alexander-akait in #21500)
Build the CSS parseA* AST on the SoA store instead of node classes, cutting parse memory and time. (by @alexander-akait in #21498)
Speed up and cut memory of the experimental CSS and HTML parsers: drop two derivable AST node columns, and scan long string, url, comment, and plaintext token bodies natively. (by @alexander-akait in #21504)
Speed up non-modules CSS parsing: skip redundant token re-reads, drop selector-prelude tokens without materializing nodes, allocate rule preludes lazily, and fast-path empty list seals. (by @alexander-akait in #21511)
Speed up stats generation and cut its peak memory: reuse cached sort comparators instead of thrashing the comparator caches on every sort, and drop redundant module-graph lookups and allocations in the extractors. (by @alexander-akait in #21506)
Speed up CSS parsing: byte-range function-name checks, indexed sibling lookahead. (by @bjohansebas in #21520)
Reduce allocations and redundant work across the code-generation, module-concatenation, exports/usage-analysis, hashing, and chunk-splitting hot paths. (by @alexander-akait in #21516)
Enable the Node.js compile cache in the webpack CLI entry point. (by @bjohansebas in #21523)
Encode the persistent cache with V8's value serializer. (by @avivkeller in #21514)
Speed up SplitChunksPlugin: reject non-subset chunk sets with 64-bit signatures, cache unnamed entry keys, and drop per-module closures. (by @avivkeller in #21529)
Initialize NormalModule._ast in the constructor so each instance keeps a single hidden-class shape. (by @alexander-akait in #21515)
Default experiments.typescript to "auto", enabling built-in TypeScript support on Node.js >= 22.6 when no TypeScript loader is registered. (by @alexander-akait in #21477)
Default experiments.css, experiments.html and experiments.asyncWebAssembly to "auto", enabling built-in support unless a loader is registered for those files; modules with inline or hook-injected loaders (e.g. html-webpack-plugin templates) keep being parsed as JavaScript. (by @alexander-akait in #21477)
Add output.resourceHints to emit resource hints (preload/prefetch/modulepreload/preconnect), on by default for ESM output, plus module.parser.<type>.urlHints, css.fontPreload and javascript.dynamicImportCssPreload. (by @alexander-akait in #21477)
Add built-in build progress via infrastructureLogging.progress, plus estimatedTime, phaseTimings, progress bar width and progressBar: "auto" on ProgressPlugin. (by @alexander-akait in #21477)
Concatenate CommonJS modules with statically analyzable exports; opt out via optimization.concatenateModules: { commonjs: false }. (by @alexander-akait in #21477)
Wrap "weird" CommonJS modules into module concatenation instead of bailing out. (by @alexander-akait in #21477)
Add output.html.inline (true | "script" | "style") and the webpackInline magic comment to inline chunk content into HTML. (by @alexander-akait in #21477)
Add output.html.inject to control where chunk tags are injected. (by @alexander-akait in #21477)
Add output.html.title, output.html.meta and output.html.base options for head generation. (by @alexander-akait in #21477)
Support per-icon link attributes (sizes, media, color, type, crossorigin) and arrays in output.html.favicon. (by @alexander-akait in #21487)
Add output.html.manifest to generate and link a web app manifest with hashed icons. (by @alexander-akait in #21487)
Add output.html.csp to inject a Content-Security-Policy meta with inline-content hashes and an optional nonce. (by @alexander-akait in #21487)
Add the output.htmlinjectTags compilation hook to inject tags (script/link/meta/…) with injectTo placement. (by @alexander-akait in #21487)
Add the output.htmltransformTags compilation hook to mutate, remove, or move (between <head> and <body>) a page's existing <script>/<link>/<style>/<meta> tags. (by @alexander-akait in #21487)
Extend the HTML pipeline with html link sources (bundled as their own emitted page) and rel="preload"/"prefetch" links bundled as chunks. (by @alexander-akait in #21477)
Recognize more asset-bearing HTML sources: the twitter:player:stream meta, legacy SVG references, and Web App Manifest icons/screenshots/shortcuts URLs. (by @alexander-akait in #21477)
Add module.parser.html.as to parse HTML as a document or an element fragment. (by @alexander-akait in #21477)
Allow disabling a built-in HTML parser source via type: false in sources. (by @alexander-akait in #21477)
Export webpack.html.HtmlModulesPlugin with transformHtml/htmlEmitted compilation hooks. (by @alexander-akait in #21477)
Resolve @custom-media (including media-type values) and @custom-selector in native CSS. (by @alexander-akait in #21477)
Scope view-transition-name/-group/-class names and ::view-transition-*() pseudo references in CSS modules under customIdents. (by @alexander-akait in #21486)
Add import.meta.glob support, with a caseSensitive option and consistent hidden/node_modules matching. (by @alexander-akait in #21477)
Resolve import.meta.resolve("./asset") to the emitted asset URL via the importMeta.resolve parser option. (by @alexander-akait in #21477)
Add import.meta.env defaults: MODE, DEV, PROD, SSR and BASE_URL. (by @alexander-akait in #21477)
Deprecate the importMetaContext parser option in favor of importMeta.webpackContext. (by @alexander-akait in #21477)
Emit analyzable new URL(…, import.meta.url), worker/worklet URL and import() references with literal specifiers for ESM module output. (by @alexander-akait in #21477)
Compile async modules to generators for targets without async/await. (by @alexander-akait in #21477)
Evaluate and validate the second argument of dynamic import(specifier, options). (by @alexander-akait in #21477)
Add module.parser.javascript.worklet to bundle Worklet addModule() entries. (by @alexander-akait in #21477)
Add ?raw, ?url, ?inline and ?no-inline asset query suffixes under experiments.futureDefaults. (by @alexander-akait in #21477)
Add an interop ("default" | "esModule") hint for object externals to control default-export interop. (by @alexander-akait in #21477)
Add an amd-async externals type that loads AMD externals without an AMD library wrapper. (by @alexander-akait in #21477)
Warn on strict-mode-only syntax and semantic hazards in ES module output, configurable via the strictModeViolations parser option. (by @alexander-akait in #21477)
Support parsers without location APIs: locations derive from node offsets and AST nodes no longer carry loc. (by @alexander-akait in #21477)
Attach the original DOM event to ChunkLoadError and ScriptExternalLoadError as error.event. (by @alexander-akait in #21477)
Add output.wasmStreamingFallback for wasm fallback on a wrong MIME type. (by @alexander-akait in #21477)
Show why a module was marked as not cacheable in stats output. (by @alexander-akait in #21477)
Fix deferred import evaluation: re-throw cached errors, guard forcing a still-evaluating module, keep re-exported deferred namespaces identical, and evaluate initial-chunk deferred context imports lazily. (by @alexander-akait in #21477)
Keep ESM live bindings for a module library's entry exports, including when the runtime is emitted as a separate chunk. (by @alexander-akait in #21477)
Fix SplitChunks merging undersized modules into the wrong result group. (by @alexander-akait in #21477)
Fix named id assignment reusing an already-used numbered suffix, which could produce duplicate module/chunk ids. (by @alexander-akait in #21477)
Fix inlined non-binary asset modules with encoding: false emitting "undefined" instead of their content. (by @alexander-akait in #21477)
Decode non-base64 data URIs as UTF-8 so multi-byte characters are preserved. (by @alexander-akait in #21477)
Keep required JSON data intact when a prototype method (e.g. arr.includes()) is called on it. (by @alexander-akait in #21477)
Recognize modern RegExp flags (d, s, u, v) when statically evaluating new RegExp(...). (by @alexander-akait in #21477)
Merge object-form and dotted DefinePlugin definitions so import.meta.env/process.env are consistent across direct, whole-object and destructured access. (by @alexander-akait in #21477)
Emit an error when an object external has no entry for the used externals type. (by @alexander-akait in #21477)
Fix a persistent cache restore crash when a content section starts exactly on a content-buffer boundary. (by @alexander-akait in #21477)
Restore missing internalSerializables entries (webpack/lib/Module and cold filesystem cache). (by @alexander-akait in #21477)
Fix watch rebuild crash when context symlink targets lack timestampHash. (by @alexander-akait in #21477)
Fix lazy compilation backend leaking idle module entries and hanging on exit. (by @alexander-akait in #21477)
Stop logging benign ECONNRESET client errors from the lazy compilation server. (by @alexander-akait in #21477)
Accept compilations from another webpack copy in getCompilationHooks again. (by @alexander-akait in #21477)
Fix output.html injection edge cases: escaping, head detection, duplicate meta tags, resource-hint/entry-tag retention with inject: false, and stylesheet placement. (by @alexander-akait in #21477)
Ignore a <base> inside an inert <template> when resolving HTML URLs. (by @alexander-akait in #21477)
Bust an HTML page's [contenthash] when its inlined chunk content changes. (by @alexander-akait in #21477)
Fix a dangling stylesheet <link> for a JS-only chunk in an HTML entry. (by @alexander-akait in #21477)
Fix a malformed HTML magic comment leaking a pending webpackInline directive onto the next element. (by @alexander-akait in #21477)
Fix off-by-one dropping the last character of an unterminated url(...) at end-of-input. (by @alexander-akait in #21477)
Consume the trailing whitespace of a CSS hex escape when unescaping identifiers. (by @alexander-akait in #21477)
Fix [fullhash] in output.webassemblyModuleFilename by dropping a stray brace and requesting the getFullHash runtime module. (by @alexander-akait in #21477)
Fix duplicated errors/warnings in stats output when detail-less entries exceed errorsSpace/warningsSpace. (by @alexander-akait in #21477)
Improve module parse errors with a babel-style code frame and the module type. (by @alexander-akait in #21485)
Fix formatSize rendering sizes of 1 TiB or larger as "undefined". (by @alexander-akait in #21477)
Skip the anonymous default export .name fix-up when name is non-configurable, instead of throwing on pre-ES2015 engines. (by @alexander-akait in #21477)
Escape ? and # in context module regexp identifiers so source map names are not truncated. (by @alexander-akait in #21477)
Resolve directory requests to their index module in scoped DllReferencePlugin. (by @alexander-akait in #21477)
Skip the hasSymbol check in the async module runtime when environment.symbol is set. (by @alexander-akait in #21477)
Use a shared __webpack_require__.cjs helper for wrapped CommonJS modules. (by @alexander-akait in #21477)
Derive ASI positions from source text instead of acorn's onInsertedSemicolon, so custom parsers need not collect semicolons. (by @alexander-akait in #21477)
Avoid a second full parse for auto source type by downgrading module to script in place on a top-level return. (by @alexander-akait in #21477)
Fix exponential-time side-effects analysis on cyclic module graphs by memoizing cycle-free results via Tarjan lowlink. (by @alexander-akait in #21477)
Speed up JavaScript parsing and AST walking and reduce parser memory usage. (by @alexander-akait in #21477)
Speed up CSS and HTML parsing and code generation and reduce parser memory usage. (by @alexander-akait in #21477)
Treat top-level await and import.meta as ES module markers, matching Node.js syntax detection so no explicit module type is needed. (by @alexander-akait in #21218)
Add a bun target that emits ESM and externalizes bun:* and node.js built-in modules. (by @alexander-akait in #21248)
Support CommonJS reexports via Object.defineProperty value and getter descriptors. (by @alexander-akait in #21129)
Support JSON Schema const when generating CLI flags from a schema. (by @alexander-akait in #21087)
Support JSON Schema if/then/else when generating CLI flags from a schema. (by @alexander-akait in #21087)
Skip import specifiers, require() and import() calls in dead conditional branches gated by inlined imported constants (isDEV ? A : B), evaluated via getCondition. (by @hai-x in #21136)
CSS localIdentName[hash] now resolves to the local ident hash (matching css-loader); use [modulehash] for the module hash. (by @alexander-akait in #21259)
Add CSS parser as option and resolve url() inside HTML style attributes. (by @alexander-akait in #21157)
Add a deno target (with versions, e.g. deno, deno2, deno1.40) that emits ESM, resolves node.js built-ins via the required node: specifier, and keeps Deno's own import protocols (npm:, jsr:, node:, http(s)://) external. (by @alexander-akait in #21247)
Use module-import for electron externals when the target supports ESM. (by @alexander-akait in #21184)
Add output.environment.logicalAssignment to emit ||= in runtime code when the target supports logical assignment operators. (by @bjohansebas in #21219)
Resolve and rewrite asset URLs inside <iframe srcdoc> in HTML modules. (by @bjohansebas in #21226)
Add HMR support for HTML modules with body/title DOM patching on update. (by @alexander-akait in #21011)
Add css-url html source type extracting url() references from CSS-valued attributes. (by @alexander-akait in #21250)
Add module.parser.html.sources option to disable or customize URL-attribute extraction for HTML modules, with script / script-module / stylesheet / stylesheet-inline types for custom attributes (by @alexander-akait in #21022)
Add module.parser.html.template option to transform HTML module source before parsing. (by @alexander-akait in #21055)
Extract more source URLs in HTML modules (SVG, legacy and obsolete attributes). (by @alexander-akait in #21241)
Inline export default <const> when the default-exported value is a primitive constant. (by @hai-x in #21189)
Support optimization.inlineExports for better tree-shaking. (by @hai-x in #20973)
Re-encode inline hash digests ([contenthash]/[chunkhash]/[fullhash]/[modulehash]) from the full content hash, so they carry full entropy and work under optimization.realContentHash and in dynamically-loaded chunk filenames; also preserve leading zero bytes in base-N digests. (by @alexander-akait in #21267)
Allow tree-shaking unused calls to /*#__NO_SIDE_EFFECTS__*/-annotated (pure) exports across module boundaries. (by @hai-x in #20907)
Defer building unused re-export targets of side-effect-free barrel modules. (by @hai-x in #21165)
Keep export mangling enabled for modules whose namespace object is used as a whole value, by materializing a decoupled namespace object that keeps the original export names. (by @alexander-akait in #21234)
Add output.environment.let option (paired with target's let capability) and emit let/const instead of var in generated runtime code wherever it is safe. Bindings that may be wrapped in runtime-condition if blocks (harmony imports, ConcatenatedModule external imports) continue to use var to preserve function scoping. (by @alexander-akait in #21010)
Add output.html to emit an HTML file per entrypoint, injecting its JS/CSS chunks (including dependOn shared chunks). (by @alexander-akait in #21215)
Add module.parser.javascript.pureFunctions to mark top-level names as side-effect-free for tree shaking. (by @hai-x in #21063)
Add universal to compiler.platform, true for universal targets ("universal" or ["web", "node"]). (by @bjohansebas in #21252)
Add output.strictModuleResolution to gate the runtime MODULE_NOT_FOUND guard. (by @hai-x in #21067)
Support an inline digest in hash path placeholders, e.g. [contenthash:base64:8]. (by @alexander-akait in #21259)
Support [uniqueName] and its [uniquename] alias in template paths. (by @alexander-akait in #21155)
Support CSS in Node for universal targets, collecting styles for SSR. (by @alexander-akait in #21208)
Improve commonjs, node-commonjs and global externals for universal targets. (by @alexander-akait in #21187)
Add a universal target preset (browser + web worker + Node.js + Electron + NW.js) that always outputs ECMAScript modules. (by @alexander-akait in #21214)
Support `new Worker(new URL(
✂ Note
PR body was truncated to here.
Configuration
📅 Schedule: (UTC)
Branch creation
At any time (no schedule defined)
Automerge
At any time (no schedule defined)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
If you want to rebase/retry this PR, check this box
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/npm@11.18.0. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
Warn
Obfuscated code: npm npm is 90.0% likely obfuscated
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/npm@11.18.0. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
Warn
Obfuscated code: npm webpack is 90.0% likely obfuscated
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/webpack@5.108.4. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.10.1→3.10.23.10.1→3.10.23.10.1→3.10.23.10.1→3.10.23.10.1→3.10.23.10.1→3.10.23.10.1→3.10.23.10.1→3.10.23.10.1→3.10.219.2.7→19.2.819.2.7→19.2.825.0.5→25.0.95.107.2→5.109.2Warning
Some dependencies could not be looked up. Check the warning logs for more information.
Release Notes
facebook/docusaurus (@docusaurus/core)
v3.10.2Compare Source
Backport and cherry-pick commits from main for v3.10.2 patch release:
@swc/html, fix StackBlitz playground #12055extractLeadingEmoji()edge cases #12100@types/gtag.js, upgrade@swc/html#12080docusaurus serveshould pass--hosttoserver.listen()#12127trustPolicydowngrade issue #12012@11ty/gray-matter#12181react/react (react)
v19.2.8: 19.2.8 (July 21st, 2026)Compare Source
React Server Components
(#37087 by @eps1lon)
semantic-release/semantic-release (semantic-release)
v25.0.9Compare Source
Bug Fixes
v25.0.8Compare Source
Bug Fixes
v25.0.7Compare Source
Bug Fixes
v25.0.6Compare Source
Bug Fixes
webpack/webpack (webpack)
v5.109.2Compare Source
Patch Changes
Resolve aliases pointing at a package directory whose name ends with
.jsagain. (by @alexander-akait in #21542)Name CSS sources in source maps by their resource path, without the
cssprefix. (by @bjohansebas in #21536)Delete no longer referenced files from the filesystem cache directory after storing the cache, age them by recorded time so restored caches are cleaned too, and collect every fully expired pack in one store instead of one per build. (by @bjohansebas in #21528)
Report
"universal"as the loader context target for the universal target. (by @alexander-akait in #21540)Skip
require().propin dead branches gated by inlined imported constants. (by @hai-x in #21517)Annotate configuration options and public hooks in the generated types with the
@sinceJSDoc tag. (by @bjohansebas in #21473)v5.109.1Compare Source
Patch Changes
Fix stray semicolon emitted before an imported call following a parenthesized sequence element. (by @alexander-akait in #21533)
Make
require(esm)module.exportsre-export analysis independent of module processing order. (by @alexander-akait in #21521)Ignore ERR_SERVER_NOT_RUNNING on lazy-compilation backend dispose so
compiler.close()succeeds on Bun. (by @alexander-akait in #21521)Name the failing key when DefinePlugin fails to evaluate a
typeofvalue. (by @alexander-akait in #21503)Improve Deno compatibility: guard
setNoDelayand force-close connections on lazy-compilation backend dispose, and return a realArrayBufferfrom the Node async/sync wasm loader soWebAssembly.instantiateaccepts it. (by @alexander-akait in #21524)Speed up the HTML parser and cut its peak memory: module-scope helpers/state and tokenizer callbacks, plus exact AST column pre-sizing. (by @alexander-akait in #21492)
Track CommonJS build dependencies by parsing sources when
require.cachechildren are unavailable (e.g. Bun). (by @alexander-akait in #21531)Cook common string-literal escapes on the JS parser fast path and own the tokenizer's cold-path readers. (by @alexander-akait in #21500)
Build the CSS
parseA*AST on the SoA store instead of node classes, cutting parse memory and time. (by @alexander-akait in #21498)Speed up and cut memory of the experimental CSS and HTML parsers: drop two derivable AST node columns, and scan long string, url, comment, and plaintext token bodies natively. (by @alexander-akait in #21504)
Speed up non-modules CSS parsing: skip redundant token re-reads, drop selector-prelude tokens without materializing nodes, allocate rule preludes lazily, and fast-path empty list seals. (by @alexander-akait in #21511)
Speed up stats generation and cut its peak memory: reuse cached sort comparators instead of thrashing the comparator caches on every sort, and drop redundant module-graph lookups and allocations in the extractors. (by @alexander-akait in #21506)
Speed up CSS parsing: byte-range function-name checks, indexed sibling lookahead. (by @bjohansebas in #21520)
Reduce allocations and redundant work across the code-generation, module-concatenation, exports/usage-analysis, hashing, and chunk-splitting hot paths. (by @alexander-akait in #21516)
Enable the Node.js compile cache in the webpack CLI entry point. (by @bjohansebas in #21523)
Encode the persistent cache with V8's value serializer. (by @avivkeller in #21514)
Speed up SplitChunksPlugin: reject non-subset chunk sets with 64-bit signatures, cache unnamed entry keys, and drop per-module closures. (by @avivkeller in #21529)
Initialize
NormalModule._astin the constructor so each instance keeps a single hidden-class shape. (by @alexander-akait in #21515)Reduce allocations in the binary serialization hot paths. (by @alexander-akait in #21526)
Deduplicate and simplify several lib modules and speed up AggressiveMergingPlugin. (by @alexander-akait in #21525)
Rename nested
const/let __webpack_require__and__webpack_exports__declarations in bundled webpack output. (by @hai-x in #21508)v5.109.0Compare Source
Minor Changes
Default
experiments.typescriptto"auto", enabling built-in TypeScript support on Node.js >= 22.6 when no TypeScript loader is registered. (by @alexander-akait in #21477)Default
experiments.css,experiments.htmlandexperiments.asyncWebAssemblyto"auto", enabling built-in support unless a loader is registered for those files; modules with inline or hook-injected loaders (e.g. html-webpack-plugin templates) keep being parsed as JavaScript. (by @alexander-akait in #21477)Add
output.resourceHintsto emit resource hints (preload/prefetch/modulepreload/preconnect), on by default for ESM output, plusmodule.parser.<type>.urlHints,css.fontPreloadandjavascript.dynamicImportCssPreload. (by @alexander-akait in #21477)Add built-in build progress via
infrastructureLogging.progress, plusestimatedTime,phaseTimings, progress barwidthandprogressBar: "auto"onProgressPlugin. (by @alexander-akait in #21477)Concatenate CommonJS modules with statically analyzable exports; opt out via
optimization.concatenateModules: { commonjs: false }. (by @alexander-akait in #21477)Wrap "weird" CommonJS modules into module concatenation instead of bailing out. (by @alexander-akait in #21477)
Add
output.html.inline(true | "script" | "style") and thewebpackInlinemagic comment to inline chunk content into HTML. (by @alexander-akait in #21477)Add
output.html.injectto control where chunk tags are injected. (by @alexander-akait in #21477)Add
output.html.title,output.html.metaandoutput.html.baseoptions for head generation. (by @alexander-akait in #21477)Support per-icon link attributes (
sizes,media,color,type,crossorigin) and arrays inoutput.html.favicon. (by @alexander-akait in #21487)Add
output.html.manifestto generate and link a web app manifest with hashed icons. (by @alexander-akait in #21487)Add
output.html.cspto inject a Content-Security-Policy meta with inline-content hashes and an optional nonce. (by @alexander-akait in #21487)Add the
output.htmlinjectTagscompilation hook to inject tags (script/link/meta/…) withinjectToplacement. (by @alexander-akait in #21487)Add the
output.htmltransformTagscompilation hook to mutate, remove, or move (between<head>and<body>) a page's existing<script>/<link>/<style>/<meta>tags. (by @alexander-akait in #21487)Extend the HTML pipeline with
htmllink sources (bundled as their own emitted page) andrel="preload"/"prefetch"links bundled as chunks. (by @alexander-akait in #21477)Recognize more asset-bearing HTML sources: the
twitter:player:streammeta, legacy SVG references, and Web App Manifesticons/screenshots/shortcutsURLs. (by @alexander-akait in #21477)Add
module.parser.html.asto parse HTML as a document or an element fragment. (by @alexander-akait in #21477)Allow disabling a built-in HTML parser source via
type: falseinsources. (by @alexander-akait in #21477)Export
webpack.html.HtmlModulesPluginwithtransformHtml/htmlEmittedcompilation hooks. (by @alexander-akait in #21477)Resolve
@custom-media(including media-type values) and@custom-selectorin native CSS. (by @alexander-akait in #21477)Scope
view-transition-name/-group/-classnames and::view-transition-*()pseudo references in CSS modules undercustomIdents. (by @alexander-akait in #21486)Add
import.meta.globsupport, with acaseSensitiveoption and consistent hidden/node_modulesmatching. (by @alexander-akait in #21477)Resolve
import.meta.resolve("./asset")to the emitted asset URL via theimportMeta.resolveparser option. (by @alexander-akait in #21477)Add
import.meta.envdefaults:MODE,DEV,PROD,SSRandBASE_URL. (by @alexander-akait in #21477)Add fine-grained
import.metaparser options. (by @alexander-akait in #21477)Deprecate the
importMetaContextparser option in favor ofimportMeta.webpackContext. (by @alexander-akait in #21477)Emit analyzable
new URL(…, import.meta.url), worker/worklet URL andimport()references with literal specifiers for ESM module output. (by @alexander-akait in #21477)Compile async modules to generators for targets without async/await. (by @alexander-akait in #21477)
Evaluate and validate the second argument of dynamic
import(specifier, options). (by @alexander-akait in #21477)Add
module.parser.javascript.workletto bundle WorkletaddModule()entries. (by @alexander-akait in #21477)Add
?raw,?url,?inlineand?no-inlineasset query suffixes underexperiments.futureDefaults. (by @alexander-akait in #21477)Add an
interop("default" | "esModule") hint for object externals to control default-export interop. (by @alexander-akait in #21477)Add an
amd-asyncexternals type that loads AMD externals without an AMD library wrapper. (by @alexander-akait in #21477)Support
cache.compression: "zstd"for the filesystem cache. (by @alexander-akait in #21477)Warn on strict-mode-only syntax and semantic hazards in ES module output, configurable via the
strictModeViolationsparser option. (by @alexander-akait in #21477)Support parsers without location APIs: locations derive from node offsets and AST nodes no longer carry
loc. (by @alexander-akait in #21477)Attach the original DOM event to
ChunkLoadErrorandScriptExternalLoadErroraserror.event. (by @alexander-akait in #21477)Add
output.wasmStreamingFallbackfor wasm fallback on a wrong MIME type. (by @alexander-akait in #21477)Show why a module was marked as not cacheable in stats output. (by @alexander-akait in #21477)
Expose the active
MultiWatchingonMultiCompiler.watching. (by @alexander-akait in #21477)Resolve git merge conflicts when parsing the build-http lockfile. (by @alexander-akait in #21477)
Patch Changes
Fix broken HMR with
output.moduleand non-importchunk loading by emitting a plain-JSON hot-update manifest. (by @alexander-akait in #21477)Fix unused CSS module exports leaking into the JS wrapper. (by @alexander-akait in #21477)
Fix deferred import evaluation: re-throw cached errors, guard forcing a still-evaluating module, keep re-exported deferred namespaces identical, and evaluate initial-chunk deferred context imports lazily. (by @alexander-akait in #21477)
Keep ESM live bindings for a module library's entry exports, including when the runtime is emitted as a separate chunk. (by @alexander-akait in #21477)
Fix SplitChunks merging undersized modules into the wrong result group. (by @alexander-akait in #21477)
Fix named id assignment reusing an already-used numbered suffix, which could produce duplicate module/chunk ids. (by @alexander-akait in #21477)
Fix inlined non-binary asset modules with
encoding: falseemitting "undefined" instead of their content. (by @alexander-akait in #21477)Decode non-base64 data URIs as UTF-8 so multi-byte characters are preserved. (by @alexander-akait in #21477)
Keep required JSON data intact when a prototype method (e.g.
arr.includes()) is called on it. (by @alexander-akait in #21477)Recognize modern RegExp flags (
d,s,u,v) when statically evaluatingnew RegExp(...). (by @alexander-akait in #21477)Merge object-form and dotted DefinePlugin definitions so
import.meta.env/process.envare consistent across direct, whole-object and destructured access. (by @alexander-akait in #21477)Emit an error when an object external has no entry for the used externals type. (by @alexander-akait in #21477)
Fix a persistent cache restore crash when a content section starts exactly on a content-buffer boundary. (by @alexander-akait in #21477)
Restore missing
internalSerializablesentries (webpack/lib/Module and cold filesystem cache). (by @alexander-akait in #21477)Fix watch rebuild crash when context symlink targets lack
timestampHash. (by @alexander-akait in #21477)Fix lazy compilation backend leaking idle module entries and hanging on exit. (by @alexander-akait in #21477)
Stop logging benign ECONNRESET client errors from the lazy compilation server. (by @alexander-akait in #21477)
Accept compilations from another webpack copy in
getCompilationHooksagain. (by @alexander-akait in #21477)Fix
output.htmlinjection edge cases: escaping, head detection, duplicate meta tags, resource-hint/entry-tag retention withinject: false, and stylesheet placement. (by @alexander-akait in #21477)Ignore a
<base>inside an inert<template>when resolving HTML URLs. (by @alexander-akait in #21477)Bust an HTML page's
[contenthash]when its inlined chunk content changes. (by @alexander-akait in #21477)Fix a dangling stylesheet
<link>for a JS-only chunk in an HTML entry. (by @alexander-akait in #21477)Fix a malformed HTML magic comment leaking a pending
webpackInlinedirective onto the next element. (by @alexander-akait in #21477)Fix off-by-one dropping the last character of an unterminated
url(...)at end-of-input. (by @alexander-akait in #21477)Consume the trailing whitespace of a CSS hex escape when unescaping identifiers. (by @alexander-akait in #21477)
Fix
[fullhash]inoutput.webassemblyModuleFilenameby dropping a stray brace and requesting thegetFullHashruntime module. (by @alexander-akait in #21477)Fix duplicated errors/warnings in stats output when detail-less entries exceed
errorsSpace/warningsSpace. (by @alexander-akait in #21477)Improve module parse errors with a babel-style code frame and the module type. (by @alexander-akait in #21485)
Fix
formatSizerendering sizes of 1 TiB or larger as "undefined". (by @alexander-akait in #21477)Skip the anonymous default export
.namefix-up whennameis non-configurable, instead of throwing on pre-ES2015 engines. (by @alexander-akait in #21477)Escape
?and#in context module regexp identifiers so source map names are not truncated. (by @alexander-akait in #21477)Resolve directory requests to their index module in scoped
DllReferencePlugin. (by @alexander-akait in #21477)Skip the
hasSymbolcheck in the async module runtime whenenvironment.symbolis set. (by @alexander-akait in #21477)Use a shared
__webpack_require__.cjshelper for wrapped CommonJS modules. (by @alexander-akait in #21477)Derive ASI positions from source text instead of acorn's
onInsertedSemicolon, so custom parsers need not collect semicolons. (by @alexander-akait in #21477)Avoid a second full parse for
autosource type by downgrading module to script in place on a top-level return. (by @alexander-akait in #21477)Fix exponential-time side-effects analysis on cyclic module graphs by memoizing cycle-free results via Tarjan lowlink. (by @alexander-akait in #21477)
Speed up JavaScript parsing and AST walking and reduce parser memory usage. (by @alexander-akait in #21477)
Speed up CSS and HTML parsing and code generation and reduce parser memory usage. (by @alexander-akait in #21477)
Speed up snapshot creation and reduce its memory usage. (by @alexander-akait in #21477)
Reduce allocations in JS codegen, concatenation, queues and parser setup. (by @alexander-akait in #21477)
Speed up stats generation on large builds by reusing the item context across array items. (by @alexander-akait in #21477)
Memoize loader resolution per compilation to avoid re-resolving the same loader for every matching module. (by @alexander-akait in #21477)
Reuse and harden webpack's shared resource parser in the loader runner. (by @alexander-akait in #21477)
Update webpack-sources to 3.5.1 and enhanced-resolve to 5.24.2 to cut peak memory. (by @alexander-akait in #21477)
Inline the loader-runner package into core. (by @alexander-akait in #21477)
Fix context hash crash on unsupported directory entries like FIFOs and sockets. (by @hai-x in #21484)
Verify internalSerializables in lint:special and regenerate it in fix:special. (by @alexander-akait in #21476)
v5.108.4Compare Source
Patch Changes
Speed up non-CSS-Modules parsing by not building unused selector AST nodes. (by @alexander-akait in #21324)
Speed up non-CSS-Modules CSS parsing by dropping value tokens nothing reads. (by @alexander-akait in #21324)
Resolve HTML asset URLs against the document
<base href>. (by @alexander-akait in #21329)Add HTML integration tests: generateError output, ignored src, null-char parse. (by @aryanraj45 in #21328)
Reduce CPU and memory overhead of HTML and CSS parsing and code generation. (by @alexander-akait in #21332)
Reduce HTML parser memory and CPU by skipping unused AST nodes. (by @alexander-akait in #21323)
Reduce HTML parser memory by storing the AST in struct-of-arrays form. (by @alexander-akait in #21331)
Key the provided-exports cache on a lazy barrel's still-lazy re-export targets. (by @hai-x in #21326)
Default
output.globalObjecttoglobalThisfor universal targets. (by @alexander-akait in #21314)Pass through
new URL(...)directory references instead of resolving them. (by @alexander-akait in #21312)v5.108.3Compare Source
Patch Changes
Speed up CSS parsing and reduce CSS AST node memory. (by @alexander-akait in #21285)
Fix HMR codegen crash for harmony accept with unresolved imports. (by @xiaoxiaojx in #21302)
Match harmony accept dependencies by module reference so HMR codegen handles imports without a module or chunk id. (by @alexander-akait in #21303)
v5.108.2Compare Source
Patch Changes
Fix lazy barrel deferral of ungrouped side-effect imports. (by @hai-x in #21291)
Respect the
node:prefix for node.js core modules used as externals. (by @alexander-akait in #21286)v5.108.1Compare Source
Patch Changes
Fix invalid property access for escaped namespace imports with multi-character mangled export names. (by @xiaoxiaojx in #21280)
Add frames to ProfilingPlugin TracingStartedInBrowser event so the trace loads in Chrome DevTools. (by @alexander-akait in #21269)
v5.108.0Compare Source
Minor Changes
Treat top-level await and
import.metaas ES module markers, matching Node.js syntax detection so no explicit module type is needed. (by @alexander-akait in #21218)Add a
buntarget that emits ESM and externalizesbun:*and node.js built-in modules. (by @alexander-akait in #21248)Support CommonJS reexports via
Object.definePropertyvalue and getter descriptors. (by @alexander-akait in #21129)Support JSON Schema
constwhen generating CLI flags from a schema. (by @alexander-akait in #21087)Support JSON Schema
if/then/elsewhen generating CLI flags from a schema. (by @alexander-akait in #21087)Skip import specifiers,
require()andimport()calls in dead conditional branches gated by inlined imported constants (isDEV ? A : B), evaluated viagetCondition. (by @hai-x in #21136)CSS
localIdentName[hash]now resolves to the local ident hash (matching css-loader); use[modulehash]for the module hash. (by @alexander-akait in #21259)Add CSS parser
asoption and resolveurl()inside HTMLstyleattributes. (by @alexander-akait in #21157)Add dedicated module classes for all built-in module types. (by @alexander-akait in #21164)
Support
.html/.cssfor the default./srcentry under the html/css experiments. (by @alexander-akait in #21039)Add
defineConfighelper for typed configuration files. (by @alexander-akait in #21169)Add a
denotarget (with versions, e.g.deno,deno2,deno1.40) that emits ESM, resolves node.js built-ins via the requirednode:specifier, and keeps Deno's own import protocols (npm:,jsr:,node:,http(s)://) external. (by @alexander-akait in #21247)Use
module-importfor electron externals when the target supports ESM. (by @alexander-akait in #21184)Add
output.environment.logicalAssignmentto emit||=in runtime code when the target supports logical assignment operators. (by @bjohansebas in #21219)Resolve and rewrite asset URLs inside
<iframe srcdoc>in HTML modules. (by @bjohansebas in #21226)Add HMR support for HTML modules with body/title DOM patching on update. (by @alexander-akait in #21011)
Add
css-urlhtml source type extractingurl()references from CSS-valued attributes. (by @alexander-akait in #21250)Add
module.parser.html.sourcesoption to disable or customize URL-attribute extraction for HTML modules, withscript/script-module/stylesheet/stylesheet-inlinetypes for custom attributes (by @alexander-akait in #21022)Add
module.parser.html.templateoption to transform HTML module source before parsing. (by @alexander-akait in #21055)Extract more source URLs in HTML modules (SVG, legacy and obsolete attributes). (by @alexander-akait in #21241)
Inline
export default <const>when the default-exported value is a primitive constant. (by @hai-x in #21189)Support
optimization.inlineExportsfor better tree-shaking. (by @hai-x in #20973)Re-encode inline hash digests (
[contenthash]/[chunkhash]/[fullhash]/[modulehash]) from the full content hash, so they carry full entropy and work underoptimization.realContentHashand in dynamically-loaded chunk filenames; also preserve leading zero bytes in base-N digests. (by @alexander-akait in #21267)Allow tree-shaking unused calls to
/*#__NO_SIDE_EFFECTS__*/-annotated (pure) exports across module boundaries. (by @hai-x in #20907)Defer building unused re-export targets of side-effect-free barrel modules. (by @hai-x in #21165)
Keep export mangling enabled for modules whose namespace object is used as a whole value, by materializing a decoupled namespace object that keeps the original export names. (by @alexander-akait in #21234)
Add
output.environment.letoption (paired with target'sletcapability) and emitlet/constinstead ofvarin generated runtime code wherever it is safe. Bindings that may be wrapped in runtime-conditionifblocks (harmony imports, ConcatenatedModule external imports) continue to usevarto preserve function scoping. (by @alexander-akait in #21010)Add
output.htmlto emit an HTML file per entrypoint, injecting its JS/CSS chunks (includingdependOnshared chunks). (by @alexander-akait in #21215)Add
module.parser.javascript.pureFunctionsto mark top-level names as side-effect-free for tree shaking. (by @hai-x in #21063)Add
universaltocompiler.platform, true for universal targets ("universal"or["web", "node"]). (by @bjohansebas in #21252)Add
output.strictModuleResolutionto gate the runtimeMODULE_NOT_FOUNDguard. (by @hai-x in #21067)Support an inline digest in hash path placeholders, e.g.
[contenthash:base64:8]. (by @alexander-akait in #21259)Support
[uniqueName]and its[uniquename]alias in template paths. (by @alexander-akait in #21155)Support CSS in Node for universal targets, collecting styles for SSR. (by @alexander-akait in #21208)
Improve commonjs, node-commonjs and global externals for universal targets. (by @alexander-akait in #21187)
Add a
universaltarget preset (browser + web worker + Node.js + Electron + NW.js) that always outputs ECMAScript modules. (by @alexander-akait in #21214)Support `new Worker(new URL(
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.