Skip to content

chore(deps-dev): bump webpack from 5.53.0 to 5.61.0 - #351

Closed
dependabot[bot] wants to merge 1 commit into
nextfrom
dependabot/npm_and_yarn/webpack-5.61.0
Closed

dependabot[bot] wants to merge 1 commit into
nextfrom
dependabot/npm_and_yarn/webpack-5.61.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Nov 1, 2021

Copy link
Copy Markdown
Contributor

Bumps webpack from 5.53.0 to 5.61.0.

Release notes

Sourced from webpack's releases.

v5.61.0

Bugfixes

  • use a wasm md4 implementation for node 17 support
  • include the path submodules in the node.js default externals

Performance

  • improve string to binary conversion performance for hashing

Contribution

  • CI runs on node.js 17

v5.60.0

Features

  • Allow to pass more options to experiments.lazyCompilation. e. g. port, https stuff

Bugfixes

  • fix output.hashFunction used to persistent caching too
  • Initialize buildDependencies Set correctly when loaders are added in beforeLoaders hook

v5.59.1

Bugfixes

  • fix regexp in managedPaths
  • fix hanging when trying to write lockfile for experiments.buildHttp

v5.59.0

Features

  • add /*#__PURE__*/ for Object() in generated code
  • add RegExp and function support for managed/immutablePaths
  • add hooks for multiple phases in module build
  • improvements to experiments.buildHttp
    • allow to share cache
    • add allowlist
  • add splitChunks.minSizeReduction option

Bugfixes

  • fix memory caching for Data URLs
  • fix crash in waitFor when modules are unsafe cached
  • fix bug in build cycle detection

v5.58.2

Bugfixes

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [webpack](https://github.com/webpack/webpack) from 5.53.0 to 5.61.0.
- [Release notes](https://github.com/webpack/webpack/releases)
- [Commits](webpack/webpack@v5.53.0...v5.61.0)

---
updated-dependencies:
- dependency-name: webpack
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Nov 1, 2021
@dependabot @github

dependabot Bot commented on behalf of github Nov 8, 2021

Copy link
Copy Markdown
Contributor Author

Superseded by #356.

@dependabot dependabot Bot closed this Nov 8, 2021
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/webpack-5.61.0 branch November 8, 2021 17:06
rafegoldberg pushed a commit that referenced this pull request Oct 30, 2024
## Version 7.8.0
### ✨ New & Improved

* compat parser ([#1004](#1004)) ([ead267e](ead267e))

### 🛠 Fixes & Updates

* bold in tables ([#1006](#1006)) ([bc481d9](bc481d9))
* **deps:** bump actions/setup-node from 3 to 4 ([#821](#821)) ([f96ea89](f96ea89)), closes [actions/setup-node#866](actions/setup-node#866) [actions/setup-node#868](actions/setup-node#868) [actions/setup-node#876](actions/setup-node#876) [actions/setup-node#868](actions/setup-node#868) [actions/setup-node#861](actions/setup-node#861) [actions/setup-node#859](actions/setup-node#859) [actions/setup-node#870](actions/setup-node#870) [actions/setup-node#872](actions/setup-node#872) [actions/setup-node#875](actions/setup-node#875) [actions/setup-node#831](actions/setup-node#831) [actions/setup-node#803](actions/setup-node#803) [actions/setup-node#809](actions/setup-node#809) [actions/setup-node#816](actions/setup-node#816) [actions/setup-node#794](actions/setup-node#794) [actions/setup-node#710](actions/setup-node#710) [actions/setup-node#812](actions/setup-node#812) [actions/setup-node#808](actions/setup-node#808) [actions/setup-node#804](actions/setup-node#804) [actions/setup-node#802](actions/setup-node#802) [actions/setup-node#807](actions/setup-node#807) [#876](#876) [#868](#868) [#866](#866)
* **deps:** bump actions/upload-artifact from 3 to 4 ([#846](#846)) ([5a72802](5a72802)), closes [actions/upload-artifact#464](actions/upload-artifact#464) [actions/upload-artifact#313](actions/upload-artifact#313) [actions/upload-artifact#436](actions/upload-artifact#436) [#374](#374) [#375](#375) [#351](#351) [actions/upload-artifact#327](actions/upload-artifact#327) [actions/toolkit#1095](actions/toolkit#1095) [actions/toolkit#1063](actions/toolkit#1063) [#515](#515) [#511](#511) [#509](#509) [#505](#505)
* **deps:** bump braces from 3.0.2 to 3.0.3 ([#907](#907)) ([6b017a7](6b017a7)), closes [#40](#40) [#37](#37) [#27](#27)
* **deps:** bump core-js from 3.36.1 to 3.38.1 ([#1013](#1013)) ([58ceef7](58ceef7)), closes [#1357](#1357) [#1361](#1361) [#1352](#1352) [#1345](#1345) [#1344](#1344) [#1361](#1361)
* **deps-dev:** bump css-loader from 6.11.0 to 7.1.2 ([#1015](#1015)) ([6be77cf](6be77cf)), closes [#1600](#1600) [#1590](#1590) [#1577](#1577) [#1600](#1600) [#1590](#1590) [#1577](#1577) [#1600](#1600) [#1596](#1596) [#1595](#1595) [#1591](#1591) [#1587](#1587) [#1586](#1586)
* **deps:** bump dset from 3.1.3 to 3.1.4 ([#1018](#1018)) ([be480d7](be480d7))
* **deps:** bump github/codeql-action from 2 to 3 ([#847](#847)) ([4b97fe6](4b97fe6)), closes [#2203](https://github.com/readmeio/markdown/issues/2203) [#2195](https://github.com/readmeio/markdown/issues/2195) [#2185](https://github.com/readmeio/markdown/issues/2185) [#2156](https://github.com/readmeio/markdown/issues/2156) [#2151](https://github.com/readmeio/markdown/issues/2151) [#2147](https://github.com/readmeio/markdown/issues/2147) [#2141](https://github.com/readmeio/markdown/issues/2141) [#2124](https://github.com/readmeio/markdown/issues/2124) [#2121](https://github.com/readmeio/markdown/issues/2121) [/github.com/github/codeql-action/blob/main/#3230---08-jan-2024](https://github.com/readmeio//github.com/github/codeql-action/blob/main//issues/3230---08-jan-2024) [#2106](https://github.com/readmeio/markdown/issues/2106) [#2083](https://github.com/readmeio/markdown/issues/2083) [#2096](https://github.com/readmeio/markdown/issues/2096) [#2073](https://github.com/readmeio/markdown/issues/2073) [#2079](https://github.com/readmeio/markdown/issues/2079) [#2200](https://github.com/readmeio/markdown/issues/2200) [#2198](https://github.com/readmeio/markdown/issues/2198) [#2197](https://github.com/readmeio/markdown/issues/2197)
* **deps-dev:** bump jest-puppeteer from 8.0.6 to 10.1.4 ([#1016](#1016)) ([33aa434](33aa434)), closes [#604](#604) [#602](#602) [#599](#599) [#586](#586) [#578](#578) [#576](#576) [#605](#605)
* **deps:** bump micromatch from 4.0.5 to 4.0.8 ([#1019](#1019)) ([7be267e](7be267e)), closes [#266](#266)
* **deps-dev:** bump mini-css-extract-plugin from 2.8.1 to 2.9.1 ([#1017](#1017)) ([9fb25da](9fb25da))
* **deps-dev:** bump semantic-release from 22.0.12 to 24.2.0 ([#1011](#1011)) ([443c843](443c843)), closes [#3462](https://github.com/readmeio/markdown/issues/3462) [#3460](https://github.com/readmeio/markdown/issues/3460) [#3436](https://github.com/readmeio/markdown/issues/3436) [#3423](https://github.com/readmeio/markdown/issues/3423) [#3462](https://github.com/readmeio/markdown/issues/3462) [#3489](https://github.com/readmeio/markdown/issues/3489) [#3488](https://github.com/readmeio/markdown/issues/3488) [#3486](https://github.com/readmeio/markdown/issues/3486) [#3487](https://github.com/readmeio/markdown/issues/3487) [#3485](https://github.com/readmeio/markdown/issues/3485) [#3483](https://github.com/readmeio/markdown/issues/3483) [#3450](https://github.com/readmeio/markdown/issues/3450) [#3481](https://github.com/readmeio/markdown/issues/3481) [#3424](https://github.com/readmeio/markdown/issues/3424)
* **deps-dev:** bump webpack from 5.91.0 to 5.95.0 ([#1014](#1014)) ([b9c8dd2](b9c8dd2))
* update conventional commits ([50a4be9](50a4be9))
* upgrade conventionalcommits ([3646513](3646513))

<!--SKIP CI-->
erunion added a commit that referenced this pull request Aug 26, 2026
| 🎫 Resolve n/a |
| :------------: |

## 🎯 What does this PR do?

Bumps declared dependencies that have a patched release in range, then
runs `npm update` on nested packages whose **parent ranges already
allow** a patched version. No new `overrides`.

`webpack-dev-server` goes `4.15.2` → **`6.0.0`**. The demo server config
already used the v4/v5 `devServer` API (`static`, `port`, `hot`). v6
requires Node `>= 22.15.0` (CI is already on 22.x) and drops SockJS,
which removes the remaining `[email protected]` copy.

### Direct updates

- **postcss** `8.5.6` → `8.5.26` —
[#267](https://github.com/readmeio/markdown/security/dependabot/267)
[#366](https://github.com/readmeio/markdown/security/dependabot/366)
[#369](https://github.com/readmeio/markdown/security/dependabot/369)
[#385](https://github.com/readmeio/markdown/security/dependabot/385)
- **mermaid** `11.12.1` → `11.17.2` —
[#284](https://github.com/readmeio/markdown/security/dependabot/284)
[#285](https://github.com/readmeio/markdown/security/dependabot/285)
[#287](https://github.com/readmeio/markdown/security/dependabot/287)
[#387](https://github.com/readmeio/markdown/security/dependabot/387)
[#388](https://github.com/readmeio/markdown/security/dependabot/388)
[#389](https://github.com/readmeio/markdown/security/dependabot/389)
[#390](https://github.com/readmeio/markdown/security/dependabot/390)
[#391](https://github.com/readmeio/markdown/security/dependabot/391)
- **vitest** / **@vitest/ui** / **@vitest/coverage-v8** `4.0.8` →
`4.1.11` —
[#305](https://github.com/readmeio/markdown/security/dependabot/305)
- **vite** `6.3.5` → `6.4.3` (declared so the lockfile actually takes
the patched 6.x; a bare `npm update vite` would jump to 8) —
[#148](https://github.com/readmeio/markdown/security/dependabot/148)
[#149](https://github.com/readmeio/markdown/security/dependabot/149)
[#154](https://github.com/readmeio/markdown/security/dependabot/154)
[#255](https://github.com/readmeio/markdown/security/dependabot/255)
[#256](https://github.com/readmeio/markdown/security/dependabot/256)
[#315](https://github.com/readmeio/markdown/security/dependabot/315)
[#316](https://github.com/readmeio/markdown/security/dependabot/316)
- **webpack** `5.95.0` → `5.109.2` —
[#183](https://github.com/readmeio/markdown/security/dependabot/183)
[#184](https://github.com/readmeio/markdown/security/dependabot/184)
- **webpack-cli** `5.1.4` → `7.2.2` (supported peer for
webpack-dev-server 6)
- **webpack-dev-server** `4.15.2` → `6.0.0` —
[#136](https://github.com/readmeio/markdown/security/dependabot/136)
[#137](https://github.com/readmeio/markdown/security/dependabot/137)
[#288](https://github.com/readmeio/markdown/security/dependabot/288)
[#325](https://github.com/readmeio/markdown/security/dependabot/325)
[#356](https://github.com/readmeio/markdown/security/dependabot/356)
[#357](https://github.com/readmeio/markdown/security/dependabot/357)
- **react-router-dom** `6.22.3` → `6.30.6` —
[#167](https://github.com/readmeio/markdown/security/dependabot/167)
[#300](https://github.com/readmeio/markdown/security/dependabot/300)
- **terser-webpack-plugin** `5.3.10` → `5.6.1` (this version no longer
depends on serialize-javascript)
- **semantic-release** `25.0.2` → `25.0.9` (pulls
`@semantic-release/[email protected]` → `@actions/core@3` →
`@actions/http-client@4` → `[email protected]`) —
[#222](https://github.com/readmeio/markdown/security/dependabot/222)
[#223](https://github.com/readmeio/markdown/security/dependabot/223)
[#330](https://github.com/readmeio/markdown/security/dependabot/330)
[#334](https://github.com/readmeio/markdown/security/dependabot/334)
[#336](https://github.com/readmeio/markdown/security/dependabot/336)
[#381](https://github.com/readmeio/markdown/security/dependabot/381)
[#382](https://github.com/readmeio/markdown/security/dependabot/382)
[#383](https://github.com/readmeio/markdown/security/dependabot/383)

### Nested `npm update` (parent range already allowed the patch)

- **axios** `1.13.6` → `1.20.0` —
[#260](https://github.com/readmeio/markdown/security/dependabot/260)
[#261](https://github.com/readmeio/markdown/security/dependabot/261)
[#270](https://github.com/readmeio/markdown/security/dependabot/270)
[#271](https://github.com/readmeio/markdown/security/dependabot/271)
[#272](https://github.com/readmeio/markdown/security/dependabot/272)
[#273](https://github.com/readmeio/markdown/security/dependabot/273)
[#274](https://github.com/readmeio/markdown/security/dependabot/274)
[#275](https://github.com/readmeio/markdown/security/dependabot/275)
[#276](https://github.com/readmeio/markdown/security/dependabot/276)
[#277](https://github.com/readmeio/markdown/security/dependabot/277)
[#281](https://github.com/readmeio/markdown/security/dependabot/281)
[#282](https://github.com/readmeio/markdown/security/dependabot/282)
[#294](https://github.com/readmeio/markdown/security/dependabot/294)
[#296](https://github.com/readmeio/markdown/security/dependabot/296)
[#297](https://github.com/readmeio/markdown/security/dependabot/297)
[#301](https://github.com/readmeio/markdown/security/dependabot/301)
[#302](https://github.com/readmeio/markdown/security/dependabot/302)
[#358](https://github.com/readmeio/markdown/security/dependabot/358)
[#361](https://github.com/readmeio/markdown/security/dependabot/361)
- **handlebars** `4.7.8` → `4.7.9` —
[#236](https://github.com/readmeio/markdown/security/dependabot/236)
[#239](https://github.com/readmeio/markdown/security/dependabot/239)
[#240](https://github.com/readmeio/markdown/security/dependabot/240)
[#242](https://github.com/readmeio/markdown/security/dependabot/242)
[#243](https://github.com/readmeio/markdown/security/dependabot/243)
[#245](https://github.com/readmeio/markdown/security/dependabot/245)
[#246](https://github.com/readmeio/markdown/security/dependabot/246)
- **js-yaml** `3.14.2` → `3.15.2`, `4.1.0` → `4.3.2` —
[#156](https://github.com/readmeio/markdown/security/dependabot/156)
[#340](https://github.com/readmeio/markdown/security/dependabot/340)
[#341](https://github.com/readmeio/markdown/security/dependabot/341)
[#347](https://github.com/readmeio/markdown/security/dependabot/347)
[#351](https://github.com/readmeio/markdown/security/dependabot/351)
[#392](https://github.com/readmeio/markdown/security/dependabot/392)
[#393](https://github.com/readmeio/markdown/security/dependabot/393)
- **lodash** `4.17.21` → `4.18.1` —
[#176](https://github.com/readmeio/markdown/security/dependabot/176)
[#251](https://github.com/readmeio/markdown/security/dependabot/251)
[#252](https://github.com/readmeio/markdown/security/dependabot/252)
- **lodash-es** `4.17.21` → `4.18.1` —
[#175](https://github.com/readmeio/markdown/security/dependabot/175)
[#249](https://github.com/readmeio/markdown/security/dependabot/249)
[#250](https://github.com/readmeio/markdown/security/dependabot/250)
- **undici** `7.16.0` → `7.29.0`; `5.29.0` → `6.28.0` (via
semantic-release / `@actions/http-client@4`) —
[#216](https://github.com/readmeio/markdown/security/dependabot/216)
[#218](https://github.com/readmeio/markdown/security/dependabot/218)
[#222](https://github.com/readmeio/markdown/security/dependabot/222)
[#223](https://github.com/readmeio/markdown/security/dependabot/223)
[#326](https://github.com/readmeio/markdown/security/dependabot/326)
[#330](https://github.com/readmeio/markdown/security/dependabot/330)
[#331](https://github.com/readmeio/markdown/security/dependabot/331)
[#334](https://github.com/readmeio/markdown/security/dependabot/334)
[#335](https://github.com/readmeio/markdown/security/dependabot/335)
[#336](https://github.com/readmeio/markdown/security/dependabot/336)
[#337](https://github.com/readmeio/markdown/security/dependabot/337)
[#375](https://github.com/readmeio/markdown/security/dependabot/375)
[#376](https://github.com/readmeio/markdown/security/dependabot/376)
[#377](https://github.com/readmeio/markdown/security/dependabot/377)
[#378](https://github.com/readmeio/markdown/security/dependabot/378)
[#379](https://github.com/readmeio/markdown/security/dependabot/379)
[#381](https://github.com/readmeio/markdown/security/dependabot/381)
[#382](https://github.com/readmeio/markdown/security/dependabot/382)
[#383](https://github.com/readmeio/markdown/security/dependabot/383)
- **minimatch** `3.1.2` → `3.1.5` —
[#202](https://github.com/readmeio/markdown/security/dependabot/202)
- **uuid** mermaid `11.1.0` → `14.0.2`; sockjs `8.3.2` removed with
webpack-dev-server 6 —
[#291](https://github.com/readmeio/markdown/security/dependabot/291)
- **mdast-util-to-hast** `13.1.0` → `13.2.1` —
[#165](https://github.com/readmeio/markdown/security/dependabot/165)
- **follow-redirects** `1.15.11` → `1.16.0` —
[#259](https://github.com/readmeio/markdown/security/dependabot/259)
- **websocket-driver** removed with webpack-dev-server 6 (SockJS
dropped) —
[#344](https://github.com/readmeio/markdown/security/dependabot/344)
- **http-proxy-middleware** `2.0.9` → `4.2.0` (webpack-dev-server 6) —
[#338](https://github.com/readmeio/markdown/security/dependabot/338)
- **picomatch** `2.3.1` → `2.3.2` —
[#230](https://github.com/readmeio/markdown/security/dependabot/230)
- **@babel/plugin-transform-modules-systemjs** `7.24.1` → `7.29.8` —
[#283](https://github.com/readmeio/markdown/security/dependabot/283)
- **immutable** `4.3.6` → `4.3.9` —
[#213](https://github.com/readmeio/markdown/security/dependabot/213)
[#363](https://github.com/readmeio/markdown/security/dependabot/363)
[#364](https://github.com/readmeio/markdown/security/dependabot/364)
- **brace-expansion** `1.1.11` → `1.1.18` —
[#350](https://github.com/readmeio/markdown/security/dependabot/350)
- **form-data** `4.0.5` → `4.0.6` —
[#318](https://github.com/readmeio/markdown/security/dependabot/318)
- **rollup** `4.40.2` → `4.63.0` —
[#197](https://github.com/readmeio/markdown/security/dependabot/197)

### Also resolved because those parents now pull patched copies

- **@remix-run/router** `1.15.3` → `1.23.4` (react-router-dom) —
[#168](https://github.com/readmeio/markdown/security/dependabot/168)
[#386](https://github.com/readmeio/markdown/security/dependabot/386)
- **dompurify** `3.2.5` → `3.4.14` (mermaid) —
[#208](https://github.com/readmeio/markdown/security/dependabot/208)
[#209](https://github.com/readmeio/markdown/security/dependabot/209)
[#244](https://github.com/readmeio/markdown/security/dependabot/244)
[#253](https://github.com/readmeio/markdown/security/dependabot/253)
[#254](https://github.com/readmeio/markdown/security/dependabot/254)
[#262](https://github.com/readmeio/markdown/security/dependabot/262)
[#263](https://github.com/readmeio/markdown/security/dependabot/263)
[#264](https://github.com/readmeio/markdown/security/dependabot/264)
[#265](https://github.com/readmeio/markdown/security/dependabot/265)
[#311](https://github.com/readmeio/markdown/security/dependabot/311)
[#319](https://github.com/readmeio/markdown/security/dependabot/319)
[#320](https://github.com/readmeio/markdown/security/dependabot/320)
[#321](https://github.com/readmeio/markdown/security/dependabot/321)
[#322](https://github.com/readmeio/markdown/security/dependabot/322)
[#323](https://github.com/readmeio/markdown/security/dependabot/323)
[#324](https://github.com/readmeio/markdown/security/dependabot/324)
[#327](https://github.com/readmeio/markdown/security/dependabot/327)
[#365](https://github.com/readmeio/markdown/security/dependabot/365)
[#394](https://github.com/readmeio/markdown/security/dependabot/394)
- **launch-editor** `2.6.1` → `2.14.1` (webpack-dev-server) —
[#299](https://github.com/readmeio/markdown/security/dependabot/299)
[#310](https://github.com/readmeio/markdown/security/dependabot/310)
- **shell-quote** `1.8.1` → `1.10.0` (launch-editor) —
[#306](https://github.com/readmeio/markdown/security/dependabot/306)
[#346](https://github.com/readmeio/markdown/security/dependabot/346)
- **on-headers** `1.0.2` → `1.1.0` (compression via webpack-dev-server)
— [#143](https://github.com/readmeio/markdown/security/dependabot/143)
- **qs** `6.13.0` → `6.15.3` (express / body-parser via
webpack-dev-server) —
[#166](https://github.com/readmeio/markdown/security/dependabot/166)
[#186](https://github.com/readmeio/markdown/security/dependabot/186)
[#293](https://github.com/readmeio/markdown/security/dependabot/293)
- **node-forge** removed (webpack-dev-server 5 dropped it) —
[#161](https://github.com/readmeio/markdown/security/dependabot/161)
[#162](https://github.com/readmeio/markdown/security/dependabot/162)
[#233](https://github.com/readmeio/markdown/security/dependabot/233)
[#234](https://github.com/readmeio/markdown/security/dependabot/234)
[#235](https://github.com/readmeio/markdown/security/dependabot/235)
- **serialize-javascript** removed (terser-webpack-plugin 5.6) —
[#206](https://github.com/readmeio/markdown/security/dependabot/206)
[#292](https://github.com/readmeio/markdown/security/dependabot/292)
- **nanoid** already at patched `3.3.18` —
[#396](https://github.com/readmeio/markdown/security/dependabot/396)
[#398](https://github.com/readmeio/markdown/security/dependabot/398)

### Still cannot update (parent pins the old range, or the copy is
bundled)

- **[email protected]** (`levelup` `~0.8.1`) —
[#83](https://github.com/readmeio/markdown/security/dependabot/83)
[#84](https://github.com/readmeio/markdown/security/dependabot/84)
- **ip-address** / **tar** / **[email protected]** /
**[email protected]** / **[email protected]** / **[email protected]**
(bundled inside `[email protected]`) —
[#172](https://github.com/readmeio/markdown/security/dependabot/172)
[#174](https://github.com/readmeio/markdown/security/dependabot/174)
[#177](https://github.com/readmeio/markdown/security/dependabot/177)
[#188](https://github.com/readmeio/markdown/security/dependabot/188)
[#201](https://github.com/readmeio/markdown/security/dependabot/201)
[#205](https://github.com/readmeio/markdown/security/dependabot/205)
[#212](https://github.com/readmeio/markdown/security/dependabot/212)
[#214](https://github.com/readmeio/markdown/security/dependabot/214)
[#228](https://github.com/readmeio/markdown/security/dependabot/228)
[#269](https://github.com/readmeio/markdown/security/dependabot/269)
[#317](https://github.com/readmeio/markdown/security/dependabot/317)
[#345](https://github.com/readmeio/markdown/security/dependabot/345)
[#355](https://github.com/readmeio/markdown/security/dependabot/355)
[#380](https://github.com/readmeio/markdown/security/dependabot/380)
- **[email protected]** (graphql-config pins it exactly) —
[#200](https://github.com/readmeio/markdown/security/dependabot/200)
- **[email protected]** / **[email protected]** / **[email protected]** (puppeteer
exact pins) —
[#122](https://github.com/readmeio/markdown/security/dependabot/122)
[#135](https://github.com/readmeio/markdown/security/dependabot/135)
[#152](https://github.com/readmeio/markdown/security/dependabot/152)
[#81](https://github.com/readmeio/markdown/security/dependabot/81)
[#312](https://github.com/readmeio/markdown/security/dependabot/312)
[#397](https://github.com/readmeio/markdown/security/dependabot/397)
- **[email protected]** (`@readme/markdown-legacy`)
- **[email protected]** remaining alerts need 7.18.0 —
[#367](https://github.com/readmeio/markdown/security/dependabot/367)
[#368](https://github.com/readmeio/markdown/security/dependabot/368)
- **@babel/[email protected]** —
[#313](https://github.com/readmeio/markdown/security/dependabot/313)
- **[email protected]** / **@sigstore/[email protected]** (inside bundled `npm`) —
[#339](https://github.com/readmeio/markdown/security/dependabot/339)
[#342](https://github.com/readmeio/markdown/security/dependabot/342)

## 🧪 QA tips

- [ ] `npx vitest run` (3253 passed locally after the nested updates and
webpack-dev-server 6)
- [x] `npm start` / `webpack serve` still serves the example app on
webpack-cli 7 + webpack-dev-server 6 (`HTTP 200` on `:9966`)
- [x] BundleWatch CI uses Node 22.x (dropped Node 20 + `npm i -g npm@7`)
- [ ] Watch visual tests — mermaid `11.16.1` previously passed them
here; `11.17.2` has not been screenshot-tested locally
- [ ] After merge, confirm the linked “resolved” Dependabot alerts close

## 📸 Screenshot or Loom

n/a — dependency / lockfile only

---------

Co-authored-by: Cursor <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants