Repository navigation
chore(release): new release - #2406
Open
github-actions[bot] wants to merge 1 commit into
Open
github-actions[bot] wants to merge 1 commit into
github-actions[bot] wants to merge 1 commit into
Conversation
github-actions
Bot
force-pushed
the
changeset-release/main
branch
6 times, most recently
from
September 23, 2026 10:38
6c779e5 to
4ee071a
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
9 times, most recently
from
September 26, 2026 15:28
8edb030 to
c4f9ffd
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
14 times, most recently
from
September 30, 2026 11:39
2c25530 to
a702738
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
from
September 30, 2026 12:38
a702738 to
5dfd2aa
Compare
|
ok |
github-actions
Bot
force-pushed
the
changeset-release/main
branch
24 times, most recently
from
October 6, 2026 13:36
bcbaa5b to
73bcdbc
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
from
October 6, 2026 15:02
73bcdbc to
d3ef740
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.
Releases
webpack-dev-middleware@8.4.0
Minor Changes
The client posts build events to the page the way webpack-dev-server's does (
webpackOk,webpackErrors,webpackCloseand the rest), logsDisconnected!when the connection drops and clears the build's problems from the overlay until it is back.progressaccepts"circular"or"linear". Reloads skip a page that is already navigating away, use the nearest ancestor with a url of its own inside anabout:blankiframe, and inapply: "reload"follow a sibling compilation's build too. (by @alexander-akait in #2425)Grouped
etag,lastModified,cacheControlandcacheImmutableintocache.*, andmimeTypesandmimeTypeDefaultintomime.*; the old names warn and keep working until the next major release, and the grouped name wins when both are set. Media types now resolve throughmime-dbdirectly, andmime.typesbelongs to its own middleware instead of being written into the tablemime-typesshares with the whole process.instance.context.optionsis a copy of the options passed,cache.controlincluded. (by @alexander-akait in #2455)hot.client.apply("hmr","hmr-only","reload"or"nothing") says what a build does to the page, so a project without HMR still reloads on a change; a single page can choose its own mode with?webpack-dev-middleware-apply=, and publishing{ action: "reload" }reloads every page.hot.client.connect(false, or{ retries, timeout }) controls connecting and reconnecting, withretrieshonoured on both transports. Thehot,liveReload,reload,autoConnect,reconnectandtimeoutoptions they replace still work with a deprecation warning until the next major release. (by @alexander-akait in #2458)Added
hot.client, which sets the browser runtime's options on the middleware under the same names the entry query takes, so a configuration no longer needs a hand-written query string.pathaccepts a url or its parts ({ port: 8080 }) and resolves the rest in the page, andloggingaccepts{ level, name }so an embedding package can label the console with its own name. (by @alexander-akait in #2436)Added
hot.corsto choose which origins may reach the hot endpoint: Server-Sent Events still allow every origin until the next major release, while the new WebSocket transport allows only local origins and refuses others with403before the handshake. Addedhot.token, a secret the injected client carries and the endpoint requires, for the case where a browser sends noOrigin; it is off by default. (by @alexander-akait in #2444)hotnow adds the client andHotModuleReplacementPluginto the compilation itself, so enabling it is all a webpack configuration needs;hot.inject: falseturns this off for anyone wiring it by hand. Web workers get a client too, nothing is injected into a non-browser target, and the HMR plugin is left out whenhot.client.applyisreloadornothing. (by @alexander-akait in #2430)The instance gains
attach(server),handleUpgrade(req, socket, head),onConnect(fn)(now given the request as well as the client),publish(payload)andpublishTo(client, payload), so a server can own the upgrade, decide who may listen and put payloads of its own on the stream, such asProgressPluginticks. The client understands{ action: "error", message }, logging the reason a server refused it and posting it to the page aswebpackError. (by @alexander-akait in #2431)hot.transportchooses how events reach the browser: Server-Sent Events (the default),"ws"for a WebSocket, or a transport of your own, which only needsonConnect,publish,publishToandclose. The client speaks both built-in wires, also exported aswebpack-dev-middleware/client/sseandwebpack-dev-middleware/client/ws, and behaves the same on either. (by @alexander-akait in #2420)overlay.idnames the overlay element, so a package embedding it can keep the id its users already query. The newwebpack-dev-middleware/client/problemexport formats one of webpack's errors or warnings withformatProblem, andshowProblemsaccepts webpack's objects as well as strings. (by @alexander-akait in #2438)Patch Changes
Bound the internal url and
Rangeheader caches, which grew for the life of the process and were never released, even byclose(). (by @alexander-akait in #2405)The client exports ship type declarations and are marked as the ES modules they are. The client logs through webpack's
Loggerwithoutwebpack/lib/logging/runtime.js, souniversaland["web", "node"]bundles no longer pull in a node builtin and a page enforcing Trusted Types needs no guard. A module that re-exports the client can hand it its options through__webpack_dev_middleware_client_query__, and?autoConnectis read like every other boolean. (by @alexander-akait in #2428)Deprecated
hot.progress, which keeps working until the next major release: a server that appliesProgressPluginitself ended up with two on one compiler. Remove it, apply the plugin yourself and hand its ticks topublish; the browser-sidehot.client.progressis unaffected. (by @alexander-akait in #2451)The overlay takes focus when it opens and gives it back when it closes, keeps an uncaught runtime error through a successful build, passes a rejected value to
runtimeErrorsfilters aserror.cause, and no longer shows an empty card or leaves the building indicator up after a multi-compiler build. File references in absolute, Windows andfile://stack frames are now clickable. The ANSI-to-HTML conversion is built in, droppingansi-html-communityand fixing its handling of combined, short and unbalanced sequences. (by @alexander-akait in #2437)Validate options with a precompiled schema to cut ~155ms from startup. (by @alexander-akait in #2413)
Hardened the path-traversal guards in
getFilenameFromUrl: the remainder left after thepublicPathprefix is stripped is checked for..on its own, before it is joined onto the output root. A..that leaves the output root and comes back into it, such as/assets../dist/file.js, is now refused rather than served. (by @alexander-akait in #2445)