Skip to content

chore(release): new release - #2406

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
changeset-release/main
Open

github-actions[bot] wants to merge 1 commit into
mainfrom
changeset-release/main

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 3, 2026 •

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

webpack-dev-middleware@8.4.0

Minor Changes

  • The client posts build events to the page the way webpack-dev-server's does (webpackOk, webpackErrors, webpackClose and the rest), logs Disconnected! when the connection drops and clears the build's problems from the overlay until it is back. progress accepts "circular" or "linear". Reloads skip a page that is already navigating away, use the nearest ancestor with a url of its own inside an about:blank iframe, and in apply: "reload" follow a sibling compilation's build too. (by @alexander-akait in #2425)

  • Grouped etag, lastModified, cacheControl and cacheImmutable into cache.*, and mimeTypes and mimeTypeDefault into mime.*; the old names warn and keep working until the next major release, and the grouped name wins when both are set. Media types now resolve through mime-db directly, and mime.types belongs to its own middleware instead of being written into the table mime-types shares with the whole process. instance.context.options is a copy of the options passed, cache.control included. (by @alexander-akait in #2455)

  • hot.client.apply ("hmr", "hmr-only", "reload" or "nothing") says what a build does to the page, so a project without HMR still reloads on a change; a single page can choose its own mode with ?webpack-dev-middleware-apply=, and publishing { action: "reload" } reloads every page. hot.client.connect (false, or { retries, timeout }) controls connecting and reconnecting, with retries honoured on both transports. The hot, liveReload, reload, autoConnect, reconnect and timeout options they replace still work with a deprecation warning until the next major release. (by @alexander-akait in #2458)

  • Added hot.client, which sets the browser runtime's options on the middleware under the same names the entry query takes, so a configuration no longer needs a hand-written query string. path accepts a url or its parts ({ port: 8080 }) and resolves the rest in the page, and logging accepts { level, name } so an embedding package can label the console with its own name. (by @alexander-akait in #2436)

  • Added hot.cors to choose which origins may reach the hot endpoint: Server-Sent Events still allow every origin until the next major release, while the new WebSocket transport allows only local origins and refuses others with 403 before the handshake. Added hot.token, a secret the injected client carries and the endpoint requires, for the case where a browser sends no Origin; it is off by default. (by @alexander-akait in #2444)

  • hot now adds the client and HotModuleReplacementPlugin to the compilation itself, so enabling it is all a webpack configuration needs; hot.inject: false turns this off for anyone wiring it by hand. Web workers get a client too, nothing is injected into a non-browser target, and the HMR plugin is left out when hot.client.apply is reload or nothing. (by @alexander-akait in #2430)

  • The instance gains attach(server), handleUpgrade(req, socket, head), onConnect(fn) (now given the request as well as the client), publish(payload) and publishTo(client, payload), so a server can own the upgrade, decide who may listen and put payloads of its own on the stream, such as ProgressPlugin ticks. The client understands { action: "error", message }, logging the reason a server refused it and posting it to the page as webpackError. (by @alexander-akait in #2431)

  • hot.transport chooses how events reach the browser: Server-Sent Events (the default), "ws" for a WebSocket, or a transport of your own, which only needs onConnect, publish, publishTo and close. The client speaks both built-in wires, also exported as webpack-dev-middleware/client/sse and webpack-dev-middleware/client/ws, and behaves the same on either. (by @alexander-akait in #2420)

  • overlay.id names the overlay element, so a package embedding it can keep the id its users already query. The new webpack-dev-middleware/client/problem export formats one of webpack's errors or warnings with formatProblem, and showProblems accepts webpack's objects as well as strings. (by @alexander-akait in #2438)

Patch Changes

  • Bound the internal url and Range header caches, which grew for the life of the process and were never released, even by close(). (by @alexander-akait in #2405)

  • The client exports ship type declarations and are marked as the ES modules they are. The client logs through webpack's Logger without webpack/lib/logging/runtime.js, so universal and ["web", "node"] bundles no longer pull in a node builtin and a page enforcing Trusted Types needs no guard. A module that re-exports the client can hand it its options through __webpack_dev_middleware_client_query__, and ?autoConnect is read like every other boolean. (by @alexander-akait in #2428)

  • Deprecated hot.progress, which keeps working until the next major release: a server that applies ProgressPlugin itself ended up with two on one compiler. Remove it, apply the plugin yourself and hand its ticks to publish; the browser-side hot.client.progress is unaffected. (by @alexander-akait in #2451)

  • The overlay takes focus when it opens and gives it back when it closes, keeps an uncaught runtime error through a successful build, passes a rejected value to runtimeErrors filters as error.cause, and no longer shows an empty card or leaves the building indicator up after a multi-compiler build. File references in absolute, Windows and file:// stack frames are now clickable. The ANSI-to-HTML conversion is built in, dropping ansi-html-community and fixing its handling of combined, short and unbalanced sequences. (by @alexander-akait in #2437)

  • Validate options with a precompiled schema to cut ~155ms from startup. (by @alexander-akait in #2413)

  • Hardened the path-traversal guards in getFilenameFromUrl: the remainder left after the publicPath prefix is stripped is checked for .. on its own, before it is joined onto the output root. A .. that leaves the output root and comes back into it, such as /assets../dist/file.js, is now refused rather than served. (by @alexander-akait in #2445)

@github-actions
github-actions Bot force-pushed the changeset-release/main branch 6 times, most recently from 6c779e5 to 4ee071a Compare September 23, 2026 10:38
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 9 times, most recently from 8edb030 to c4f9ffd Compare September 26, 2026 15:28
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 14 times, most recently from 2c25530 to a702738 Compare September 30, 2026 11:39
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from a702738 to 5dfd2aa Compare September 30, 2026 12:38
@otobe711

Copy link
Copy Markdown

ok

@github-actions
github-actions Bot force-pushed the changeset-release/main branch 24 times, most recently from bcbaa5b to 73bcdbc Compare October 6, 2026 13:36
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 73bcdbc to d3ef740 Compare October 6, 2026 15:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant