Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
Why? Confidentiality impact: None, Integrity impact: Low, Availability impact: None, Scope: Unchanged, Exploit Maturity: No data, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: High, Attack Vector: Network, EPSS: 0.01055, Social Trends: No, Days since published: 4, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: Medium, Package Popularity Score: 99, Impact: 2.35, Likelihood: 1.86, Score Version: V5
SNYK-JS-COOKIE-8163060
Why? Confidentiality impact: Low, Integrity impact: High, Availability impact: None, Scope: Unchanged, Exploit Maturity: No data, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: High, Attack Vector: Network, EPSS: 0.01055, Social Trends: No, Days since published: 0, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: High, Package Popularity Score: 99, Impact: 7.03, Likelihood: 1.86, Score Version: V5
SNYK-JS-ELLIPTIC-8172694
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: elliptic
6.5.6
6.5.5
6.5.4
6.5.3
Package name: engine.io
This release contains a bump of the
cookie
dependency.See also: GHSA-pxg6-pf52-xh8x
Dependencies
ws@~8.17.1
(no change)Bug Fixes
Performance Improvements
Dependencies
ws@~8.17.1
(no change)Diff: socketio/engine.io-client@6.5.3...6.6.0
Package name: react-middle-truncate
1.0.0
Package name: webpack
Announcement and changelog
Bugfixes
Bugfixes
getNumberOfMatchingSizeTypes
SideEffectsFlagPlugin
runtimeChunk
and Module Federationshared
Migration
Features
optimization.sideEffects
will detect simple cases of modules without side effects from the source code nowif
,while
,for
,switch
,export
,import
, function calls with pure flagBugfixes
Dependencies
Bugfixes
delete x.y.z
now also works in concatenated modules#
are now supportedFeatures
optimization.splitChunks.defaultSizeTypes
to specify size types considered for sizes when only a number is specifiedBugfixes
watch
option is used withoutcallback
and show a deprecation message instead.Breaking Changes
target: "browserslist"
as default when a browserslist config has been found, otherwise fallback totarget: "web"
as usualFeatures
target: "browserslist"
and more advanced optionsCompiler.watching
parser.worker
for javascript files to allow to modify which syntax is special for WebWorker supportoutput.chunkFilename
to be a function via schemawatchOptions.ignored
via schemaresolve.preferRelative
option, which allows to resolve module requests also as relative requestsMigration
splitChunks
name
to move modules to an parent chunkBugfixes
new URL("relative/file.png", import.meta.url)
to resolve relativeFull Changelog
Known Problems
delete x.y.z
doesn't work withoptimization.concatenateModules: true
yet.mini-css-extract-plugin
is not fully compatible and there a few problems.html-webpack-plugin
doesn't understand the new default automatic publicPath yet. Useoutput.publicPath: ""
instead.target
doesn't support individual browser versions yet. Use the general targets for now:target: ["web", "es2020"]
webpack-cli
shows too verbose output for schema validation problems.new URL
with string not starting with./
or../
works incorrectlyChanges
stats.warningsFilter
in favor ofignoreWarnings
hasWarnings()
Bugfixes
Features
output.publicPath
is now"auto"
by default when supported by targetoutput.publicPath: "auto"
to determine publicPath automaticallyBugfixes
Commit messages
Package name: elliptic
The new version differs by 10 commits.See the full diff
Package name: engine.io
The new version differs by 250 commits.See the full diff
Package name: react-middle-truncate
The new version differs by 12 commits.See the full diff
Package name: webpack
The new version differs by 250 commits.See the full diff
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
🛠 Adjust project settings
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Cross-site Scripting (XSS)