Skip to content

Bump webpack-dev-middleware from 8.1.1 to 8.3.0 in /samples/webpack-vanilla-blazor in the npm_and_yarn group across 1 directory - #154

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/samples/webpack-vanilla-blazor/npm_and_yarn-2e92a1b9b7
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/samples/webpack-vanilla-blazor/npm_and_yarn-2e92a1b9b7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 1 update in the /samples/webpack-vanilla-blazor directory: webpack-dev-middleware.

Updates webpack-dev-middleware from 8.1.1 to 8.3.0

Release notes

Sourced from webpack-dev-middleware's releases.

v8.3.0

Minor Changes

  • Added a hot option that enables hot module replacement, replacing the need for webpack-hot-middleware. Pass hot: true to enable with defaults, or hot: { path, heartbeat, progress, statsOptions } to customize. The client runtime is served by the middleware itself. (by @​bjohansebas in #2370)

  • Take the diagnostics a hot payload carries from the stats option, so one setting governs what a build reports in the terminal and in the browser: stats: "errors-only" keeps warnings out of both, and stats: false keeps errors and warnings out of both, the client's error overlay included — reach for the client's ?logging= or ?overlay= to quiet the browser alone. hot.statsOptions is deprecated and will be removed in the next major release; its hash, timings and children keys are now ignored, because they could leave a payload without the hash the client compares, or carry a child compilation's hash instead, which stopped updates applying and forced a full page reload on every rebuild. (by @​alexander-akait in #2392)

Patch Changes

  • Fixed a crash when calling invalidate() in plugin mode (isPlugin = true). Since the host (webpack-cli, webpack-dev-server, etc.) owns compiler.watch(), the middleware now invalidates the host's watching instead (each child compiler's one for a MultiCompiler on webpack < 5.109). When nothing is watching it logs a warning and completes the callback, as close() does, rather than leaving invalidate(callback) waiting on a build that never runs. (by @​bjohansebas in #2378)

  • Reject with 403 Forbidden the requests whose resolved filename falls outside outputPath (GHSA-g84c-rxfj-3j2c). With a publicPath without a trailing slash, a sibling path sharing its prefix (/assets../secret) escaped the output root once the prefix was stripped and joined. (by @​bjohansebas in #2404)

  • Update the changelog generator to the @changesets/get-github-info 1.0 API. (by @​alexander-akait in #2396)

  • Update dependencies. (by @​alexander-akait in #2394)

v8.2.0

Minor Changes

  • Added a hot option that enables hot module replacement, replacing the need for webpack-hot-middleware. Pass hot: true to enable with defaults, or hot: { path, heartbeat, progress, statsOptions } to customize. The client runtime ships with the package and is added as a webpack entry. (by @​bjohansebas in #2322)
Changelog

Sourced from webpack-dev-middleware's changelog.

8.3.0

Minor Changes

  • Added a hot option that enables hot module replacement, replacing the need for webpack-hot-middleware. Pass hot: true to enable with defaults, or hot: { path, heartbeat, progress, statsOptions } to customize. The client runtime is served by the middleware itself. (by @​bjohansebas in #2370)

  • Take the diagnostics a hot payload carries from the stats option, so one setting governs what a build reports in the terminal and in the browser: stats: "errors-only" keeps warnings out of both, and stats: false keeps errors and warnings out of both, the client's error overlay included — reach for the client's ?logging= or ?overlay= to quiet the browser alone. hot.statsOptions is deprecated and will be removed in the next major release; its hash, timings and children keys are now ignored, because they could leave a payload without the hash the client compares, or carry a child compilation's hash instead, which stopped updates applying and forced a full page reload on every rebuild. (by @​alexander-akait in #2392)

Patch Changes

  • Fixed a crash when calling invalidate() in plugin mode (isPlugin = true). Since the host (webpack-cli, webpack-dev-server, etc.) owns compiler.watch(), the middleware now invalidates the host's watching instead (each child compiler's one for a MultiCompiler on webpack < 5.109). When nothing is watching it logs a warning and completes the callback, as close() does, rather than leaving invalidate(callback) waiting on a build that never runs. (by @​bjohansebas in #2378)

  • Reject with 403 Forbidden the requests whose resolved filename falls outside outputPath (GHSA-g84c-rxfj-3j2c). With a publicPath without a trailing slash, a sibling path sharing its prefix (/assets../secret) escaped the output root once the prefix was stripped and joined. (by @​bjohansebas in #2404)

  • Update the changelog generator to the @changesets/get-github-info 1.0 API. (by @​alexander-akait in #2396)

  • Update dependencies. (by @​alexander-akait in #2394)

8.2.0

Minor Changes

  • Added a hot option that enables hot module replacement, replacing the need for webpack-hot-middleware. Pass hot: true to enable with defaults, or hot: { path, heartbeat, progress, statsOptions } to customize. The client runtime ships with the package and is added as a webpack entry. (by @​bjohansebas in #2322)
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the npm_and_yarn group with 1 update in the /samples/webpack-vanilla-blazor directory: [webpack-dev-middleware](https://github.com/webpack/webpack-dev-middleware).


Updates `webpack-dev-middleware` from 8.1.1 to 8.3.0
- [Release notes](https://github.com/webpack/webpack-dev-middleware/releases)
- [Changelog](https://github.com/webpack/webpack-dev-middleware/blob/main/CHANGELOG.md)
- [Commits](webpack/webpack-dev-middleware@v8.1.1...v8.3.0)

---
updated-dependencies:
- dependency-name: webpack-dev-middleware
  dependency-version: 8.3.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies javascript Pull requests that update javascript code labels Sep 29, 2026
@github-actions

Copy link
Copy Markdown

Test Results

   10 files    122 suites   1m 46s ⏱️
1 083 tests 1 079 ✅  4 💤 0 ❌
3 109 runs  3 084 ✅ 25 💤 0 ❌

Results for commit 3d1bec8.

@github-actions

Copy link
Copy Markdown

BenchmarkDotNet v0.15.8, Linux Ubuntu 24.04.5 LTS (Noble Numbat)
AMD EPYC 7763 2.45GHz, 1 CPU, 4 logical and 2 physical cores
.NET SDK 10.0.401
  [Host]     : .NET 10.0.12 (10.0.12, 10.0.1226.42308), X64 RyuJIT x86-64-v3
  Job-MLTFGY : .NET 10.0.12 (10.0.12, 10.0.1226.42308), X64 RyuJIT x86-64-v3

InvocationCount=1  IterationCount=1  LaunchCount=10  
RunStrategy=ColdStart  UnrollFactor=1  WarmupCount=0  

Method Compilation ClassCount Mean Error StdDev Min Max
Generate AOT 0 17.70 ms 3.196 ms 2.114 ms 15.33 ms 21.87 ms
Generate AOT 1 45.51 ms 7.528 ms 4.980 ms 37.76 ms 49.77 ms
Generate AOT 10 44.23 ms 7.470 ms 4.941 ms 37.44 ms 52.23 ms
Generate AOT 25 62.42 ms 6.612 ms 4.373 ms 57.98 ms 69.21 ms
Generate AOT 50 88.04 ms 2.721 ms 1.800 ms 85.40 ms 91.50 ms
Generate AOT 100 143.22 ms 10.458 ms 6.917 ms 136.72 ms 159.04 ms
Generate AOT 200 232.51 ms 10.280 ms 6.799 ms 224.58 ms 244.19 ms
Generate JIT 0 46.44 ms 5.139 ms 3.399 ms 42.36 ms 52.50 ms
Generate JIT 1 1,003.21 ms 24.134 ms 15.963 ms 985.23 ms 1,038.35 ms
Generate JIT 10 1,007.36 ms 11.052 ms 7.310 ms 996.15 ms 1,019.09 ms
Generate JIT 25 1,059.71 ms 11.475 ms 7.590 ms 1,047.96 ms 1,071.77 ms
Generate JIT 50 1,133.70 ms 8.534 ms 5.645 ms 1,127.02 ms 1,145.91 ms
Generate JIT 100 1,327.53 ms 14.460 ms 9.565 ms 1,311.11 ms 1,340.40 ms
Generate JIT 200 1,656.52 ms 39.071 ms 25.843 ms 1,628.38 ms 1,708.52 ms

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants