Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Mar 15, 2023

This PR contains the following updates:

Package Change Age Confidence
webpack 5.75.05.76.0 age confidence

GitHub Vulnerability Alerts

CVE-2023-28154

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.


Release Notes

webpack/webpack (webpack)

v5.76.0

Compare Source

Bugfixes

Features

Security

Repo Changes

New Contributors

Full Changelog: webpack/webpack@v5.75.0...v5.76.0


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 3b39956 to f51a949 Compare August 13, 2025 14:25
@renovate renovate bot changed the title chore(deps): update dependency webpack to v5.76.0 [security] chore(deps): update dependency webpack to v5.94.0 [security] Aug 13, 2025
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from f51a949 to 175264b Compare August 19, 2025 17:59
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 175264b to 41dd62b Compare August 31, 2025 10:29
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 41dd62b to 3d9094d Compare September 25, 2025 18:49
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 3d9094d to bc5930a Compare October 16, 2025 01:38
@renovate renovate bot changed the title chore(deps): update dependency webpack to v5.94.0 [security] chore(deps): update dependency webpack to v5.76.0 [security] Oct 16, 2025
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from bc5930a to 8f26280 Compare November 19, 2025 17:45
@renovate renovate bot changed the title chore(deps): update dependency webpack to v5.76.0 [security] chore(deps): update dependency webpack to v5.94.0 [security] Nov 19, 2025
@renovate renovate bot changed the title chore(deps): update dependency webpack to v5.94.0 [security] chore(deps): update dependency webpack to v5.76.0 [security] Nov 19, 2025
@renovate renovate bot force-pushed the renovate/npm-webpack-vulnerability branch from 8f26280 to 7e7e4fe Compare November 19, 2025 21:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant