Skip to content

Update dependency webpack to v5.76.0 [SECURITY]#1126

Merged
oliverchang merged 1 commit intogoogle:masterfrom
renovate-bot:renovate/npm-webpack-vulnerability
Mar 20, 2023
Merged

Update dependency webpack to v5.76.0 [SECURITY]#1126
oliverchang merged 1 commit intogoogle:masterfrom
renovate-bot:renovate/npm-webpack-vulnerability

Conversation

@renovate-bot
Copy link
Copy Markdown
Collaborator

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
webpack 5.75.0 -> 5.76.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2023-28154

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.


Release Notes

webpack/webpack

v5.76.0

Compare Source

Bugfixes

Features

Security

Repo Changes

New Contributors

Full Changelog: webpack/webpack@v5.75.0...v5.76.0


Configuration

📅 Schedule: Branch creation - "" in timezone Australia/Sydney, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@forking-renovate forking-renovate bot added the dependencies Pull requests that update a dependency file label Mar 14, 2023
@oliverchang oliverchang merged commit 1d8cf8c into google:master Mar 20, 2023
@renovate-bot renovate-bot deleted the renovate/npm-webpack-vulnerability branch March 20, 2023 04:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants