Skip to content

Bump webpack to 5.105.4#277

Merged
smfeest merged 1 commit intomainfrom
webpack-update
Mar 3, 2026
Merged

Bump webpack to 5.105.4#277
smfeest merged 1 commit intomainfrom
webpack-update

Conversation

@smfeest
Copy link
Owner

@smfeest smfeest commented Mar 3, 2026

This is to resolve a security vulnerability in serialize-javascript 6.0.2 [1], which we had as a transitive dependency through webpack > terser-webpack-plugin.

As it happens the fix for in terser-webpack-plugin 5.3.17 was to remove the dependency on serialize-javascript completely [2].

[1] yahoo/serialize-javascript#207
[2] webpack/terser-webpack-plugin#654

This is to resolve a security vulnerability in serialize-javascript
6.0.2 [1], which we had as a transitive dependency through webpack >
terser-webpack-plugin.

As it happens the fix for in terser-webpack-plugin 5.3.17 was to remove
the dependency on serialize-javascript completely [2].

[1] yahoo/serialize-javascript#207
[2] webpack/terser-webpack-plugin#654
@smfeest smfeest merged commit 23a2774 into main Mar 3, 2026
5 checks passed
@smfeest smfeest deleted the webpack-update branch March 3, 2026 23:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant