Skip to content

Update dependency webpack-dev-server to v6 - #634

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/webpack-dev-server-6.x
Open

Update dependency webpack-dev-server to v6#634
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/webpack-dev-server-6.x

Conversation

@renovate

@renovate renovate Bot commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
webpack-dev-server ^5.2.5^6.0.0 age adoption passing confidence

Release Notes

webpack/webpack-dev-server (webpack-dev-server)

v6.0.0

Compare Source

Major Changes
  • Bump Express to v5. See the Express 5 migration guide for the full list of breaking changes. (by @​bjohansebas in #​5674)

  • Bump the webpack peer dependency range from ^5.0.0 to ^5.101.0. (by @​bjohansebas in #​5674)

  • Drop support for Node.js < 22.15.0. (by @​bjohansebas in #​5674)

  • Convert the source to native ES modules. The package keeps "type": "module" and now exposes both an ESM and a CommonJS build via the exports field: ESM consumers import the native lib/, while CommonJS consumers require() a transpiled dist/ build — so the package works from both ESM and CommonJS, including environments where require(ESM) is not supported. (by @​bjohansebas in #​5674)

  • Remove CLI flags. Use the serve command from webpack-cli together with a configuration file or the programmatic API instead. (by @​bjohansebas in #​5674)

  • Remove the internalIP and internalIPSync static methods from Server. Resolve the local IP yourself if you need it. (by @​bjohansebas in #​5674)

  • Remove the bypass option from proxy configuration. Use the router or context options provided by http-proxy-middleware instead. (by @​bjohansebas in #​5674)

  • Remove SockJS support. The webSocketServer option no longer accepts "sockjs"; use the default "ws" transport instead. (by @​bjohansebas in #​5674)

  • Remove the spdy dependency. Use the built-in node:http2 module via the server option for HTTP/2 support. (by @​bjohansebas in #​5674)

  • Update http-proxy-middleware to v4. See the http-proxy-middleware v3 release notes and v4 release notes for the full list of breaking changes. (by @​bjohansebas in #​5674)

  • Update webpack-dev-middleware to v8 and sync originalUrl for middleware compatibility. server.middleware.getFilenameFromUrl() is now asynchronous and resolves to { filename, extra: { stats, outputFileSystem } }. See the webpack-dev-middleware v8 release notes for details. (by @​bjohansebas in #​5674)

Minor Changes
  • Add plugin support. webpack-dev-server can now be used as a webpack plugin, integrating with the compiler lifecycle without explicitly passing a compiler, preventing multiple server starts on recompilation, ensuring clean shutdown, and supporting MultiCompiler setups with multiple independent plugin servers. (by @​bjohansebas in #​5674)

  • Enable the compression middleware for HTTP/2 connections. (by @​bjohansebas in #​5674)

  • Remove the colorette dependency in favor of native ANSI styling. (by @​bjohansebas in #​5674)

  • Update chokidar to v5 and extend watchFiles.options.ignored to support glob string patterns via tinyglobby. (by @​bjohansebas in #​5674)

  • Use compiler.platform to determine the target environment instead of inspecting the resolved target string. Universal targets ("universal" or ["web", "node"], where compiler.platform.universal is true since webpack 5.108.0) are treated as web targets so the client runtime is injected. (by @​bjohansebas in #​5674)

  • Use the WHATWG URL API instead of the deprecated url.parse. (by @​bjohansebas in #​5674)

Patch Changes
  • Bump production dependencies, notably open to v11 and p-retry to v8. (by @​bjohansebas in #​5674)

  • Reject cross-site requests to the internal open-editor and invalidate endpoints. They performed state-changing actions (opening a file in the editor, forcing a recompilation) on any GET request, so a page the developer visited could trigger them. They now require a same-origin request, validated via Sec-Fetch-Site with an Origin/Host fallback. (by @​bjohansebas in #​5691)

  • Treat loopback aliases (127.0.0.1, ::1, localhost) as equivalent in isSameOrigin so the WebSocket client does not reject valid same-origin connections. (by @​bjohansebas in #​5674)

  • Migrate the test suite from Jest to node:test and set up the jsdom environment. (by @​bjohansebas in #​5674)

  • Update webpack-cli to v7.0.2. (by @​bjohansebas in #​5674)


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@netlify

netlify Bot commented Jul 6, 2026

Copy link
Copy Markdown

Deploy Preview for firefox-performance-dashboard ready!

Name Link
🔨 Latest commit 8ddabb6
🔍 Latest deploy log https://app.netlify.com/projects/firefox-performance-dashboard/deploys/6a7f81303188880008613c97
😎 Deploy Preview https://deploy-preview-634--firefox-performance-dashboard.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@codecov

codecov Bot commented Jul 6, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 63.46%. Comparing base (89a7715) to head (8ddabb6).

Additional details and impacted files
@@           Coverage Diff           @@
##           master     #634   +/-   ##
=======================================
  Coverage   63.46%   63.46%           
=======================================
  Files          12       12           
  Lines         323      323           
  Branches       48       48           
=======================================
  Hits          205      205           
  Misses        103      103           
  Partials       15       15           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@renovate
renovate Bot force-pushed the renovate/webpack-dev-server-6.x branch 3 times, most recently from d8cbce4 to 323b1bc Compare July 12, 2026 11:15
@renovate
renovate Bot force-pushed the renovate/webpack-dev-server-6.x branch from 323b1bc to 0b2e8eb Compare July 16, 2026 15:12
@renovate
renovate Bot force-pushed the renovate/webpack-dev-server-6.x branch 2 times, most recently from a3f0a42 to 1697238 Compare July 30, 2026 18:02
@kala-moz

kala-moz commented Aug 3, 2026

Copy link
Copy Markdown
Collaborator

@renovate-bot rebase

@renovate
renovate Bot force-pushed the renovate/webpack-dev-server-6.x branch from 1697238 to 72e49ee Compare August 12, 2026 01:50
@renovate
renovate Bot force-pushed the renovate/webpack-dev-server-6.x branch from 72e49ee to 8ddabb6 Compare August 14, 2026 20:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant