From b3a20d383298578b098b22bfe235654be6165271 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Wed, 7 Oct 2026 20:17:15 +0000 Subject: [PATCH] chore(release): new release --- .changeset/bound-memoize-caches.md | 5 --- .changeset/client-packaging.md | 7 ---- .changeset/client-page-feedback.md | 7 ---- .changeset/deprecate-hot-progress.md | 7 ---- .changeset/group-cache-and-mime.md | 7 ---- .changeset/hot-client-apply-and-connect.md | 7 ---- .changeset/hot-client-options.md | 7 ---- .changeset/hot-cors-and-token.md | 7 ---- .changeset/hot-inject.md | 7 ---- .changeset/hot-server-api.md | 7 ---- .changeset/hot-transports.md | 7 ---- .changeset/overlay-features.md | 7 ---- .changeset/overlay-fixes.md | 7 ---- .changeset/perf-precompiled-options-schema.md | 5 --- .changeset/traversal-remainder-guard.md | 5 --- CHANGELOG.md | 36 +++++++++++++++++++ package.json | 2 +- 17 files changed, 37 insertions(+), 100 deletions(-) delete mode 100644 .changeset/bound-memoize-caches.md delete mode 100644 .changeset/client-packaging.md delete mode 100644 .changeset/client-page-feedback.md delete mode 100644 .changeset/deprecate-hot-progress.md delete mode 100644 .changeset/group-cache-and-mime.md delete mode 100644 .changeset/hot-client-apply-and-connect.md delete mode 100644 .changeset/hot-client-options.md delete mode 100644 .changeset/hot-cors-and-token.md delete mode 100644 .changeset/hot-inject.md delete mode 100644 .changeset/hot-server-api.md delete mode 100644 .changeset/hot-transports.md delete mode 100644 .changeset/overlay-features.md delete mode 100644 .changeset/overlay-fixes.md delete mode 100644 .changeset/perf-precompiled-options-schema.md delete mode 100644 .changeset/traversal-remainder-guard.md diff --git a/.changeset/bound-memoize-caches.md b/.changeset/bound-memoize-caches.md deleted file mode 100644 index fec7c17bd..000000000 --- a/.changeset/bound-memoize-caches.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"webpack-dev-middleware": patch ---- - -Bound the internal url and `Range` header caches, which grew for the life of the process and were never released, even by `close()`. diff --git a/.changeset/client-packaging.md b/.changeset/client-packaging.md deleted file mode 100644 index ad7ac1b13..000000000 --- a/.changeset/client-packaging.md +++ /dev/null @@ -1,7 +0,0 @@ ---- -"webpack-dev-middleware": patch ---- - -pr: #2428 - -The client exports ship type declarations and are marked as the ES modules they are. The client logs through webpack's `Logger` without `webpack/lib/logging/runtime.js`, so `universal` and `["web", "node"]` bundles no longer pull in a node builtin and a page enforcing Trusted Types needs no guard. A module that re-exports the client can hand it its options through `__webpack_dev_middleware_client_query__`, and `?autoConnect` is read like every other boolean. diff --git a/.changeset/client-page-feedback.md b/.changeset/client-page-feedback.md deleted file mode 100644 index 8804a2164..000000000 --- a/.changeset/client-page-feedback.md +++ /dev/null @@ -1,7 +0,0 @@ ---- -"webpack-dev-middleware": minor ---- - -pr: #2425 - -The client posts build events to the page the way webpack-dev-server's does (`webpackOk`, `webpackErrors`, `webpackClose` and the rest), logs `Disconnected!` when the connection drops and clears the build's problems from the overlay until it is back. `progress` accepts `"circular"` or `"linear"`. Reloads skip a page that is already navigating away, use the nearest ancestor with a url of its own inside an `about:blank` iframe, and in `apply: "reload"` follow a sibling compilation's build too. diff --git a/.changeset/deprecate-hot-progress.md b/.changeset/deprecate-hot-progress.md deleted file mode 100644 index 302999118..000000000 --- a/.changeset/deprecate-hot-progress.md +++ /dev/null @@ -1,7 +0,0 @@ ---- -"webpack-dev-middleware": patch ---- - -pr: #2451 - -Deprecated `hot.progress`, which keeps working until the next major release: a server that applies `ProgressPlugin` itself ended up with two on one compiler. Remove it, apply the plugin yourself and hand its ticks to [`publish`](https://github.com/webpack/webpack-dev-middleware#publishpayload); the browser-side `hot.client.progress` is unaffected. diff --git a/.changeset/group-cache-and-mime.md b/.changeset/group-cache-and-mime.md deleted file mode 100644 index 9cd4be11d..000000000 --- a/.changeset/group-cache-and-mime.md +++ /dev/null @@ -1,7 +0,0 @@ ---- -"webpack-dev-middleware": minor ---- - -pr: #2455 - -Grouped `etag`, `lastModified`, `cacheControl` and `cacheImmutable` into `cache.*`, and `mimeTypes` and `mimeTypeDefault` into `mime.*`; the old names warn and keep working until the next major release, and the grouped name wins when both are set. Media types now resolve through `mime-db` directly, and `mime.types` belongs to its own middleware instead of being written into the table `mime-types` shares with the whole process. `instance.context.options` is a copy of the options passed, `cache.control` included. diff --git a/.changeset/hot-client-apply-and-connect.md b/.changeset/hot-client-apply-and-connect.md deleted file mode 100644 index dd730e7bf..000000000 --- a/.changeset/hot-client-apply-and-connect.md +++ /dev/null @@ -1,7 +0,0 @@ ---- -"webpack-dev-middleware": minor ---- - -pr: #2458 - -`hot.client.apply` (`"hmr"`, `"hmr-only"`, `"reload"` or `"nothing"`) says what a build does to the page, so a project without HMR still reloads on a change; a single page can choose its own mode with `?webpack-dev-middleware-apply=`, and publishing `{ action: "reload" }` reloads every page. `hot.client.connect` (`false`, or `{ retries, timeout }`) controls connecting and reconnecting, with `retries` honoured on both transports. The `hot`, `liveReload`, `reload`, `autoConnect`, `reconnect` and `timeout` options they replace still work with a deprecation warning until the next major release. diff --git a/.changeset/hot-client-options.md b/.changeset/hot-client-options.md deleted file mode 100644 index a7f6da3ac..000000000 --- a/.changeset/hot-client-options.md +++ /dev/null @@ -1,7 +0,0 @@ ---- -"webpack-dev-middleware": minor ---- - -pr: #2436 - -Added `hot.client`, which sets the browser runtime's options on the middleware under the same names the entry query takes, so a configuration no longer needs a hand-written query string. `path` accepts a url or its parts (`{ port: 8080 }`) and resolves the rest in the page, and `logging` accepts `{ level, name }` so an embedding package can label the console with its own name. diff --git a/.changeset/hot-cors-and-token.md b/.changeset/hot-cors-and-token.md deleted file mode 100644 index 7e607e70b..000000000 --- a/.changeset/hot-cors-and-token.md +++ /dev/null @@ -1,7 +0,0 @@ ---- -"webpack-dev-middleware": minor ---- - -pr: #2444 - -Added `hot.cors` to choose which origins may reach the hot endpoint: Server-Sent Events still allow every origin until the next major release, while the new WebSocket transport allows only local origins and refuses others with `403` before the handshake. Added `hot.token`, a secret the injected client carries and the endpoint requires, for the case where a browser sends no `Origin`; it is off by default. diff --git a/.changeset/hot-inject.md b/.changeset/hot-inject.md deleted file mode 100644 index 360605d49..000000000 --- a/.changeset/hot-inject.md +++ /dev/null @@ -1,7 +0,0 @@ ---- -"webpack-dev-middleware": minor ---- - -pr: #2430 - -`hot` now adds the client and `HotModuleReplacementPlugin` to the compilation itself, so enabling it is all a webpack configuration needs; `hot.inject: false` turns this off for anyone wiring it by hand. Web workers get a client too, nothing is injected into a non-browser target, and the HMR plugin is left out when `hot.client.apply` is `reload` or `nothing`. diff --git a/.changeset/hot-server-api.md b/.changeset/hot-server-api.md deleted file mode 100644 index b5a3bc345..000000000 --- a/.changeset/hot-server-api.md +++ /dev/null @@ -1,7 +0,0 @@ ---- -"webpack-dev-middleware": minor ---- - -pr: #2431 - -The instance gains `attach(server)`, `handleUpgrade(req, socket, head)`, `onConnect(fn)` (now given the request as well as the client), `publish(payload)` and `publishTo(client, payload)`, so a server can own the upgrade, decide who may listen and put payloads of its own on the stream, such as `ProgressPlugin` ticks. The client understands `{ action: "error", message }`, logging the reason a server refused it and posting it to the page as `webpackError`. diff --git a/.changeset/hot-transports.md b/.changeset/hot-transports.md deleted file mode 100644 index a1a53e772..000000000 --- a/.changeset/hot-transports.md +++ /dev/null @@ -1,7 +0,0 @@ ---- -"webpack-dev-middleware": minor ---- - -pr: #2420 - -`hot.transport` chooses how events reach the browser: Server-Sent Events (the default), `"ws"` for a WebSocket, or a transport of your own, which only needs `onConnect`, `publish`, `publishTo` and `close`. The client speaks both built-in wires, also exported as `webpack-dev-middleware/client/sse` and `webpack-dev-middleware/client/ws`, and behaves the same on either. diff --git a/.changeset/overlay-features.md b/.changeset/overlay-features.md deleted file mode 100644 index 46803b8c6..000000000 --- a/.changeset/overlay-features.md +++ /dev/null @@ -1,7 +0,0 @@ ---- -"webpack-dev-middleware": minor ---- - -pr: #2438 - -`overlay.id` names the overlay element, so a package embedding it can keep the id its users already query. The new `webpack-dev-middleware/client/problem` export formats one of webpack's errors or warnings with `formatProblem`, and `showProblems` accepts webpack's objects as well as strings. diff --git a/.changeset/overlay-fixes.md b/.changeset/overlay-fixes.md deleted file mode 100644 index 580d629ec..000000000 --- a/.changeset/overlay-fixes.md +++ /dev/null @@ -1,7 +0,0 @@ ---- -"webpack-dev-middleware": patch ---- - -pr: #2437 - -The overlay takes focus when it opens and gives it back when it closes, keeps an uncaught runtime error through a successful build, passes a rejected value to `runtimeErrors` filters as `error.cause`, and no longer shows an empty card or leaves the building indicator up after a multi-compiler build. File references in absolute, Windows and `file://` stack frames are now clickable. The ANSI-to-HTML conversion is built in, dropping `ansi-html-community` and fixing its handling of combined, short and unbalanced sequences. diff --git a/.changeset/perf-precompiled-options-schema.md b/.changeset/perf-precompiled-options-schema.md deleted file mode 100644 index 5f0a205b3..000000000 --- a/.changeset/perf-precompiled-options-schema.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"webpack-dev-middleware": patch ---- - -Validate options with a precompiled schema to cut ~155ms from startup. diff --git a/.changeset/traversal-remainder-guard.md b/.changeset/traversal-remainder-guard.md deleted file mode 100644 index e94c796ad..000000000 --- a/.changeset/traversal-remainder-guard.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"webpack-dev-middleware": patch ---- - -Hardened the path-traversal guards in `getFilenameFromUrl`: the remainder left after the `publicPath` prefix is stripped is checked for `..` on its own, before it is joined onto the output root. A `..` that leaves the output root and comes back into it, such as `/assets../dist/file.js`, is now refused rather than served. diff --git a/CHANGELOG.md b/CHANGELOG.md index c2908a774..91028b67c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,41 @@ # Changelog +## 8.4.0 + +### Minor Changes + +- The client posts build events to the page the way webpack-dev-server's does (`webpackOk`, `webpackErrors`, `webpackClose` and the rest), logs `Disconnected!` when the connection drops and clears the build's problems from the overlay until it is back. `progress` accepts `"circular"` or `"linear"`. Reloads skip a page that is already navigating away, use the nearest ancestor with a url of its own inside an `about:blank` iframe, and in `apply: "reload"` follow a sibling compilation's build too. (by [@alexander-akait](https://github.com/alexander-akait) in [#2425](https://github.com/webpack/webpack-dev-middleware/pull/2425)) + +- Grouped `etag`, `lastModified`, `cacheControl` and `cacheImmutable` into `cache.*`, and `mimeTypes` and `mimeTypeDefault` into `mime.*`; the old names warn and keep working until the next major release, and the grouped name wins when both are set. Media types now resolve through `mime-db` directly, and `mime.types` belongs to its own middleware instead of being written into the table `mime-types` shares with the whole process. `instance.context.options` is a copy of the options passed, `cache.control` included. (by [@alexander-akait](https://github.com/alexander-akait) in [#2455](https://github.com/webpack/webpack-dev-middleware/pull/2455)) + +- `hot.client.apply` (`"hmr"`, `"hmr-only"`, `"reload"` or `"nothing"`) says what a build does to the page, so a project without HMR still reloads on a change; a single page can choose its own mode with `?webpack-dev-middleware-apply=`, and publishing `{ action: "reload" }` reloads every page. `hot.client.connect` (`false`, or `{ retries, timeout }`) controls connecting and reconnecting, with `retries` honoured on both transports. The `hot`, `liveReload`, `reload`, `autoConnect`, `reconnect` and `timeout` options they replace still work with a deprecation warning until the next major release. (by [@alexander-akait](https://github.com/alexander-akait) in [#2458](https://github.com/webpack/webpack-dev-middleware/pull/2458)) + +- Added `hot.client`, which sets the browser runtime's options on the middleware under the same names the entry query takes, so a configuration no longer needs a hand-written query string. `path` accepts a url or its parts (`{ port: 8080 }`) and resolves the rest in the page, and `logging` accepts `{ level, name }` so an embedding package can label the console with its own name. (by [@alexander-akait](https://github.com/alexander-akait) in [#2436](https://github.com/webpack/webpack-dev-middleware/pull/2436)) + +- Added `hot.cors` to choose which origins may reach the hot endpoint: Server-Sent Events still allow every origin until the next major release, while the new WebSocket transport allows only local origins and refuses others with `403` before the handshake. Added `hot.token`, a secret the injected client carries and the endpoint requires, for the case where a browser sends no `Origin`; it is off by default. (by [@alexander-akait](https://github.com/alexander-akait) in [#2444](https://github.com/webpack/webpack-dev-middleware/pull/2444)) + +- `hot` now adds the client and `HotModuleReplacementPlugin` to the compilation itself, so enabling it is all a webpack configuration needs; `hot.inject: false` turns this off for anyone wiring it by hand. Web workers get a client too, nothing is injected into a non-browser target, and the HMR plugin is left out when `hot.client.apply` is `reload` or `nothing`. (by [@alexander-akait](https://github.com/alexander-akait) in [#2430](https://github.com/webpack/webpack-dev-middleware/pull/2430)) + +- The instance gains `attach(server)`, `handleUpgrade(req, socket, head)`, `onConnect(fn)` (now given the request as well as the client), `publish(payload)` and `publishTo(client, payload)`, so a server can own the upgrade, decide who may listen and put payloads of its own on the stream, such as `ProgressPlugin` ticks. The client understands `{ action: "error", message }`, logging the reason a server refused it and posting it to the page as `webpackError`. (by [@alexander-akait](https://github.com/alexander-akait) in [#2431](https://github.com/webpack/webpack-dev-middleware/pull/2431)) + +- `hot.transport` chooses how events reach the browser: Server-Sent Events (the default), `"ws"` for a WebSocket, or a transport of your own, which only needs `onConnect`, `publish`, `publishTo` and `close`. The client speaks both built-in wires, also exported as `webpack-dev-middleware/client/sse` and `webpack-dev-middleware/client/ws`, and behaves the same on either. (by [@alexander-akait](https://github.com/alexander-akait) in [#2420](https://github.com/webpack/webpack-dev-middleware/pull/2420)) + +- `overlay.id` names the overlay element, so a package embedding it can keep the id its users already query. The new `webpack-dev-middleware/client/problem` export formats one of webpack's errors or warnings with `formatProblem`, and `showProblems` accepts webpack's objects as well as strings. (by [@alexander-akait](https://github.com/alexander-akait) in [#2438](https://github.com/webpack/webpack-dev-middleware/pull/2438)) + +### Patch Changes + +- Bound the internal url and `Range` header caches, which grew for the life of the process and were never released, even by `close()`. (by [@alexander-akait](https://github.com/alexander-akait) in [#2405](https://github.com/webpack/webpack-dev-middleware/pull/2405)) + +- The client exports ship type declarations and are marked as the ES modules they are. The client logs through webpack's `Logger` without `webpack/lib/logging/runtime.js`, so `universal` and `["web", "node"]` bundles no longer pull in a node builtin and a page enforcing Trusted Types needs no guard. A module that re-exports the client can hand it its options through `__webpack_dev_middleware_client_query__`, and `?autoConnect` is read like every other boolean. (by [@alexander-akait](https://github.com/alexander-akait) in [#2428](https://github.com/webpack/webpack-dev-middleware/pull/2428)) + +- Deprecated `hot.progress`, which keeps working until the next major release: a server that applies `ProgressPlugin` itself ended up with two on one compiler. Remove it, apply the plugin yourself and hand its ticks to [`publish`](https://github.com/webpack/webpack-dev-middleware#publishpayload); the browser-side `hot.client.progress` is unaffected. (by [@alexander-akait](https://github.com/alexander-akait) in [#2451](https://github.com/webpack/webpack-dev-middleware/pull/2451)) + +- The overlay takes focus when it opens and gives it back when it closes, keeps an uncaught runtime error through a successful build, passes a rejected value to `runtimeErrors` filters as `error.cause`, and no longer shows an empty card or leaves the building indicator up after a multi-compiler build. File references in absolute, Windows and `file://` stack frames are now clickable. The ANSI-to-HTML conversion is built in, dropping `ansi-html-community` and fixing its handling of combined, short and unbalanced sequences. (by [@alexander-akait](https://github.com/alexander-akait) in [#2437](https://github.com/webpack/webpack-dev-middleware/pull/2437)) + +- Validate options with a precompiled schema to cut ~155ms from startup. (by [@alexander-akait](https://github.com/alexander-akait) in [#2413](https://github.com/webpack/webpack-dev-middleware/pull/2413)) + +- Hardened the path-traversal guards in `getFilenameFromUrl`: the remainder left after the `publicPath` prefix is stripped is checked for `..` on its own, before it is joined onto the output root. A `..` that leaves the output root and comes back into it, such as `/assets../dist/file.js`, is now refused rather than served. (by [@alexander-akait](https://github.com/alexander-akait) in [#2445](https://github.com/webpack/webpack-dev-middleware/pull/2445)) + ## 8.3.0 ### Minor Changes diff --git a/package.json b/package.json index 25e469b9d..bf593fa08 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "webpack-dev-middleware", - "version": "8.3.0", + "version": "8.4.0", "description": "A development middleware for webpack", "keywords": [ "webpack",