Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

chore(deps): bump webpack-dev-server, @angular-devkit/build-angular and @rspack/dev-server#204

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Open
dependabot wants to merge1 commit intomain
base:main
Choose a base branch
Loading
fromdependabot/npm_and_yarn/multi-c1cd7c3194

Conversation

@dependabot
Copy link
Contributor

@dependabotdependabotbot commented on behalf ofgithubAug 22, 2025

Bumpswebpack-dev-server to 5.2.2 and updates ancestor dependencieswebpack-dev-server,@angular-devkit/build-angular and@rspack/dev-server. These dependencies need to be updated together.

Updateswebpack-dev-server from 5.2.0 to 5.2.2

Release notes

Sourced fromwebpack-dev-server's releases.

v5.2.2

5.2.2 (2025-06-03)

Bug Fixes

  • "Overlay enabled" false positive (18e72ee)
  • do not crush when error is null for runtime errors (#5447) (309991f)
  • remove unnecessary headerX_TEST (#5451) (64a6124)
  • respect theallowedHosts option for cross-origin header check (#5510) (03d1214)

v5.2.1

5.2.1 (2025-03-26)

Security

  • cross-origin requests are not allowed unless allowed byAccess-Control-Allow-Origin header
  • requests with an IP addresses in theOrigin header are not allowed to connect to WebSocket server unless configured byallowedHosts or it different from theHost header

The above changes may make the dev server not work if you relied on such behavior, but unfortunately they carry security risks, so they were considered as fixes.

Bug Fixes

  • prevent overlay for errors caught by React error boundaries (#5431) (8c1abc9)
  • take the first network found instead of the last one, this restores the same behavior as 5.0.4 (#5411) (ffd0b86)
Changelog

Sourced fromwebpack-dev-server's changelog.

5.2.2 (2025-06-03)

Bug Fixes

  • "Overlay enabled" false positive (18e72ee)
  • do not crush when error is null for runtime errors (#5447) (309991f)
  • remove unnecessary headerX_TEST (#5451) (64a6124)
  • respect theallowedHosts option for cross-origin header check (#5510) (03d1214)

5.2.1 (2025-03-26)

Security

  • cross-origin requests are not allowed unless allowed byAccess-Control-Allow-Origin header
  • requests with an IP addresses in theOrigin header are not allowed to connect to WebSocket server unless configured byallowedHosts or it different from theHost header

The above changes may make the dev server not work if you relied on such behavior, but unfortunately they carry security risks, so they were considered as fixes.

Bug Fixes

  • prevent overlay for errors caught by React error boundaries (#5431) (8c1abc9)
  • take the first network found instead of the last one, this restores the same behavior as 5.0.4 (#5411) (ffd0b86)
Commits
  • 195a7e6 chore(release): 5.2.2
  • 620bef1 chore(deps): update (#5511)
  • 03d1214 fix: respect theallowedHosts option for cross-origin header check (#5510)
  • 5ba862e chore(deps-dev): bump the dependencies group across 1 directory with 7 update...
  • f7fec94 chore: fix typo (#5508)
  • 6ee8cd0 ci: add Node.js v24 (#5492)
  • d30f963 chore: update http-proxy-middleware to ^2.0.9 (#5503)
  • 66cf033 chore(deps-dev): bump the dependencies group with 2 updates (#5504)
  • 4367a5c refactor: use 'String#startsWith' & replace if-then-else (#5501)
  • 8e6604f chore(deps): bump the dependencies group across 1 directory with 4 updates (#...
  • Additional commits viewable incompare view

Updates@angular-devkit/build-angular from 19.2.14 to 19.2.15

Release notes

Sourced from@​angular-devkit/build-angular's releases.

19.2.15

@​angular-devkit/build-angular

CommitDescription
fix - b120e1411update dependency webpack-dev-server to v5.2.2
Changelog

Sourced from@​angular-devkit/build-angular's changelog.

19.2.15 (2025-06-11)

@​angular-devkit/build-angular

CommitTypeDescription
b120e1411fixupdate dependency webpack-dev-server to v5.2.2

18.2.20 (2025-06-11)

@​angular-devkit/build-angular

CommitTypeDescription
f048078fixupdate dependency webpack-dev-server to v5.2.2

20.0.1 (2025-06-04)

@​angular/cli

CommitTypeDescription
0883248cbfiximprove Node.js version check and error messages

@​schematics/angular

CommitTypeDescription
525ddcbd2fixonly overwrite JSON file if actually changed
83c820e5afixremove karma config devkit package usages during application migration
87266b38afixskip zone.js dependency for zoneless applications

@​angular/build

CommitTypeDescription
e5efdc577fixalso disable outputMode in vitest unit-tests
5814393dbfixresolve junit karma reporter output to workspace root

... (truncated)

Commits
  • 101c875 release: cut the v19.2.15 release
  • b120e14 fix(@​angular-devkit/build-angular): update dependency webpack-dev-server to v...
  • See full diff incompare view

Updates@rspack/dev-server from 1.1.2 to 1.1.4

Release notes

Sourced from@​rspack/dev-server's releases.

v1.1.4

What's Changed

New Contributors

Full Changelog:web-infra-dev/rspack-dev-server@v1.1.3...v1.1.4

v1.1.3

What's Changed

New Contributors

Full Changelog:web-infra-dev/rspack-dev-server@v1.1.2...v1.1.3

Commits
  • 956960f release: 1.1.4 (#47)
  • b6a4fd8 chore: remove npmrc cleanup in release script (#46)
  • c6585c7 chore(workflow): enable npm trusted publishing (#45)
  • 6c45ea1 chore: update rspack and update snapshot (#43)
  • 89d1f0f test: fix eco ci (#42)
  • 738b8a2 release v1.1.3
  • c7e7217 fix(deps): update dependency http-proxy-middleware to v2.0.9 [security] (#41)
  • d7c8256 fix(deps): update webpack-dev-server to 5.2.2 [security] (#39)
  • 19d1d98 chore(deps): update dependency css-loader to v7 (#37)
  • 12e603f chore: update rspack and tests snapshots (#34)
  • Additional commits viewable incompare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for@​rspack/dev-server since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting@dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from theSecurity Alerts page.

…nd @rspack/dev-serverBumps [webpack-dev-server](https://github.com/webpack/webpack-dev-server) to 5.2.2 and updates ancestor dependencies [webpack-dev-server](https://github.com/webpack/webpack-dev-server), [@angular-devkit/build-angular](https://github.com/angular/angular-cli) and [@rspack/dev-server](https://github.com/web-infra-dev/rspack-dev-server). These dependencies need to be updated together.Updates `webpack-dev-server` from 5.2.0 to 5.2.2- [Release notes](https://github.com/webpack/webpack-dev-server/releases)- [Changelog](https://github.com/webpack/webpack-dev-server/blob/master/CHANGELOG.md)- [Commits](webpack/webpack-dev-server@v5.2.0...v5.2.2)Updates `@angular-devkit/build-angular` from 19.2.14 to 19.2.15- [Release notes](https://github.com/angular/angular-cli/releases)- [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md)- [Commits](angular/angular-cli@19.2.14...19.2.15)Updates `@rspack/dev-server` from 1.1.2 to 1.1.4- [Release notes](https://github.com/web-infra-dev/rspack-dev-server/releases)- [Commits](web-infra-dev/rspack-dev-server@v1.1.2...v1.1.4)---updated-dependencies:- dependency-name: webpack-dev-server  dependency-version: 5.2.2  dependency-type: indirect- dependency-name: "@angular-devkit/build-angular"  dependency-version: 19.2.15  dependency-type: direct:development- dependency-name: "@rspack/dev-server"  dependency-version: 1.1.4  dependency-type: indirect...Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotbot added dependenciesPull requests that update a dependency file javascriptPull requests that update javascript code labelsAug 22, 2025
@sonarqubecloud
Copy link

@nx-cloud
Copy link

nx-cloudbot commentedAug 22, 2025
edited
Loading

View yourCI Pipeline Execution ↗ for commit9fb2209

CommandStatusDurationResult
nx run-many --target=test --coverage✅ Succeeded1m 6sView ↗

☁️Nx Cloud last updated this comment at2025-08-22 02:04:07 UTC

Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

No reviews

Assignees

No one assigned

Labels

dependenciesPull requests that update a dependency filejavascriptPull requests that update javascript code

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

1 participant


[8]ページ先頭

©2009-2025 Movatter.jp