Skip to content

Update webpack 5.108.4 → 5.109.2 (minor) - #434

Open
depfu[bot] wants to merge 1 commit into
masterfrom
depfu/update/yarn/webpack-5.109.2
Open

Update webpack 5.108.4 → 5.109.2 (minor)#434
depfu[bot] wants to merge 1 commit into
masterfrom
depfu/update/yarn/webpack-5.109.2

Conversation

@depfu

@depfu depfu Bot commented Aug 4, 2026

Copy link
Copy Markdown

Here is everything you need to know about this upgrade. Please take a good look at what changed and the test results before merging this pull request.

What changed?

✳️ webpack (5.108.4 → 5.109.2) · Repo · Changelog

Release Notes

5.109.2

Patch Changes

  • Resolve aliases pointing at a package directory whose name ends with .js again. (by @alexander-akait in #21542)

  • Name CSS sources in source maps by their resource path, without the css prefix. (by @bjohansebas in #21536)

  • Delete no longer referenced files from the filesystem cache directory after storing the cache, age them by recorded time so restored caches are cleaned too, and collect every fully expired pack in one store instead of one per build. (by @bjohansebas in #21528)

  • Report "universal" as the loader context target for the universal target. (by @alexander-akait in #21540)

  • Skip require().prop in dead branches gated by inlined imported constants. (by @hai-x in #21517)

  • Annotate configuration options and public hooks in the generated types with the @since JSDoc tag. (by @bjohansebas in #21473)

5.109.1

Patch Changes

  • Fix stray semicolon emitted before an imported call following a parenthesized sequence element. (by @alexander-akait in #21533)

  • Make require(esm) module.exports re-export analysis independent of module processing order. (by @alexander-akait in #21521)

  • Ignore ERR_SERVER_NOT_RUNNING on lazy-compilation backend dispose so compiler.close() succeeds on Bun. (by @alexander-akait in #21521)

  • Name the failing key when DefinePlugin fails to evaluate a typeof value. (by @alexander-akait in #21503)

  • Improve Deno compatibility: guard setNoDelay and force-close connections on lazy-compilation backend dispose, and return a real ArrayBuffer from the Node async/sync wasm loader so WebAssembly.instantiate accepts it. (by @alexander-akait in #21524)

  • Speed up the HTML parser and cut its peak memory: module-scope helpers/state and tokenizer callbacks, plus exact AST column pre-sizing. (by @alexander-akait in #21492)

  • Track CommonJS build dependencies by parsing sources when require.cache children are unavailable (e.g. Bun). (by @alexander-akait in #21531)

  • Cook common string-literal escapes on the JS parser fast path and own the tokenizer's cold-path readers. (by @alexander-akait in #21500)

  • Build the CSS parseA* AST on the SoA store instead of node classes, cutting parse memory and time. (by @alexander-akait in #21498)

  • Speed up and cut memory of the experimental CSS and HTML parsers: drop two derivable AST node columns, and scan long string, url, comment, and plaintext token bodies natively. (by @alexander-akait in #21504)

  • Speed up non-modules CSS parsing: skip redundant token re-reads, drop selector-prelude tokens without materializing nodes, allocate rule preludes lazily, and fast-path empty list seals. (by @alexander-akait in #21511)

  • Speed up stats generation and cut its peak memory: reuse cached sort comparators instead of thrashing the comparator caches on every sort, and drop redundant module-graph lookups and allocations in the extractors. (by @alexander-akait in #21506)

  • Speed up CSS parsing: byte-range function-name checks, indexed sibling lookahead. (by @bjohansebas in #21520)

  • Reduce allocations and redundant work across the code-generation, module-concatenation, exports/usage-analysis, hashing, and chunk-splitting hot paths. (by @alexander-akait in #21516)

  • Enable the Node.js compile cache in the webpack CLI entry point. (by @bjohansebas in #21523)

  • Encode the persistent cache with V8's value serializer. (by @avivkeller in #21514)

  • Speed up SplitChunksPlugin: reject non-subset chunk sets with 64-bit signatures, cache unnamed entry keys, and drop per-module closures. (by @avivkeller in #21529)

  • Initialize NormalModule._ast in the constructor so each instance keeps a single hidden-class shape. (by @alexander-akait in #21515)

  • Reduce allocations in the binary serialization hot paths. (by @alexander-akait in #21526)

  • Deduplicate and simplify several lib modules and speed up AggressiveMergingPlugin. (by @alexander-akait in #21525)

  • Rename nested const/let __webpack_require__ and __webpack_exports__ declarations in bundled webpack output. (by @hai-x in #21508)

5.109.0

Minor Changes

  • Default experiments.typescript to "auto", enabling built-in TypeScript support on Node.js >= 22.6 when no TypeScript loader is registered. (by @alexander-akait in #21477)

  • Default experiments.css, experiments.html and experiments.asyncWebAssembly to "auto", enabling built-in support unless a loader is registered for those files; modules with inline or hook-injected loaders (e.g. html-webpack-plugin templates) keep being parsed as JavaScript. (by @alexander-akait in #21477)

  • Add output.resourceHints to emit resource hints (preload/prefetch/modulepreload/preconnect), on by default for ESM output, plus module.parser.<type>.urlHints, css.fontPreload and javascript.dynamicImportCssPreload. (by @alexander-akait in #21477)

  • Add built-in build progress via infrastructureLogging.progress, plus estimatedTime, phaseTimings, progress bar width and progressBar: "auto" on ProgressPlugin. (by @alexander-akait in #21477)

  • Concatenate CommonJS modules with statically analyzable exports; opt out via optimization.concatenateModules: { commonjs: false }. (by @alexander-akait in #21477)

  • Wrap "weird" CommonJS modules into module concatenation instead of bailing out. (by @alexander-akait in #21477)

  • Add output.html.inline (true | "script" | "style") and the webpackInline magic comment to inline chunk content into HTML. (by @alexander-akait in #21477)

  • Add output.html.inject to control where chunk tags are injected. (by @alexander-akait in #21477)

  • Add output.html.title, output.html.meta and output.html.base options for head generation. (by @alexander-akait in #21477)

  • Support per-icon link attributes (sizes, media, color, type, crossorigin) and arrays in output.html.favicon. (by @alexander-akait in #21487)

  • Add output.html.manifest to generate and link a web app manifest with hashed icons. (by @alexander-akait in #21487)

  • Add output.html.csp to inject a Content-Security-Policy meta with inline-content hashes and an optional nonce. (by @alexander-akait in #21487)

  • Add the output.html injectTags compilation hook to inject tags (script/link/meta/…) with injectTo placement. (by @alexander-akait in #21487)

  • Add the output.html transformTags compilation hook to mutate, remove, or move (between <head> and <body>) a page's existing <script>/<link>/<style>/<meta> tags. (by @alexander-akait in #21487)

  • Extend the HTML pipeline with html link sources (bundled as their own emitted page) and rel="preload"/"prefetch" links bundled as chunks. (by @alexander-akait in #21477)

  • Recognize more asset-bearing HTML sources: the twitter:player:stream meta, legacy SVG references, and Web App Manifest icons/screenshots/shortcuts URLs. (by @alexander-akait in #21477)

  • Add module.parser.html.as to parse HTML as a document or an element fragment. (by @alexander-akait in #21477)

  • Allow disabling a built-in HTML parser source via type: false in sources. (by @alexander-akait in #21477)

  • Export webpack.html.HtmlModulesPlugin with transformHtml/htmlEmitted compilation hooks. (by @alexander-akait in #21477)

  • Resolve @custom-media (including media-type values) and @custom-selector in native CSS. (by @alexander-akait in #21477)

  • Scope view-transition-name/-group/-class names and ::view-transition-*() pseudo references in CSS modules under customIdents. (by @alexander-akait in #21486)

  • Add import.meta.glob support, with a caseSensitive option and consistent hidden/node_modules matching. (by @alexander-akait in #21477)

  • Resolve import.meta.resolve("./asset") to the emitted asset URL via the importMeta.resolve parser option. (by @alexander-akait in #21477)

  • Add import.meta.env defaults: MODE, DEV, PROD, SSR and BASE_URL. (by @alexander-akait in #21477)

  • Add fine-grained import.meta parser options. (by @alexander-akait in #21477)

  • Deprecate the importMetaContext parser option in favor of importMeta.webpackContext. (by @alexander-akait in #21477)

  • Emit analyzable new URL(…, import.meta.url), worker/worklet URL and import() references with literal specifiers for ESM module output. (by @alexander-akait in #21477)

  • Compile async modules to generators for targets without async/await. (by @alexander-akait in #21477)

  • Evaluate and validate the second argument of dynamic import(specifier, options). (by @alexander-akait in #21477)

  • Add module.parser.javascript.worklet to bundle Worklet addModule() entries. (by @alexander-akait in #21477)

  • Add ?raw, ?url, ?inline and ?no-inline asset query suffixes under experiments.futureDefaults. (by @alexander-akait in #21477)

  • Add an interop ("default" | "esModule") hint for object externals to control default-export interop. (by @alexander-akait in #21477)

  • Add an amd-async externals type that loads AMD externals without an AMD library wrapper. (by @alexander-akait in #21477)

  • Support cache.compression: "zstd" for the filesystem cache. (by @alexander-akait in #21477)

  • Warn on strict-mode-only syntax and semantic hazards in ES module output, configurable via the strictModeViolations parser option. (by @alexander-akait in #21477)

  • Support parsers without location APIs: locations derive from node offsets and AST nodes no longer carry loc. (by @alexander-akait in #21477)

  • Attach the original DOM event to ChunkLoadError and ScriptExternalLoadError as error.event. (by @alexander-akait in #21477)

  • Add output.wasmStreamingFallback for wasm fallback on a wrong MIME type. (by @alexander-akait in #21477)

  • Show why a module was marked as not cacheable in stats output. (by @alexander-akait in #21477)

  • Expose the active MultiWatching on MultiCompiler.watching. (by @alexander-akait in #21477)

  • Resolve git merge conflicts when parsing the build-http lockfile. (by @alexander-akait in #21477)

Patch Changes

  • Fix broken HMR with output.module and non-import chunk loading by emitting a plain-JSON hot-update manifest. (by @alexander-akait in #21477)

  • Fix unused CSS module exports leaking into the JS wrapper. (by @alexander-akait in #21477)

  • Fix deferred import evaluation: re-throw cached errors, guard forcing a still-evaluating module, keep re-exported deferred namespaces identical, and evaluate initial-chunk deferred context imports lazily. (by @alexander-akait in #21477)

  • Keep ESM live bindings for a module library's entry exports, including when the runtime is emitted as a separate chunk. (by @alexander-akait in #21477)

  • Fix SplitChunks merging undersized modules into the wrong result group. (by @alexander-akait in #21477)

  • Fix named id assignment reusing an already-used numbered suffix, which could produce duplicate module/chunk ids. (by @alexander-akait in #21477)

  • Fix inlined non-binary asset modules with encoding: false emitting "undefined" instead of their content. (by @alexander-akait in #21477)

  • Decode non-base64 data URIs as UTF-8 so multi-byte characters are preserved. (by @alexander-akait in #21477)

  • Keep required JSON data intact when a prototype method (e.g. arr.includes()) is called on it. (by @alexander-akait in #21477)

  • Recognize modern RegExp flags (d, s, u, v) when statically evaluating new RegExp(...). (by @alexander-akait in #21477)

  • Merge object-form and dotted DefinePlugin definitions so import.meta.env/process.env are consistent across direct, whole-object and destructured access. (by @alexander-akait in #21477)

  • Emit an error when an object external has no entry for the used externals type. (by @alexander-akait in #21477)

  • Fix a persistent cache restore crash when a content section starts exactly on a content-buffer boundary. (by @alexander-akait in #21477)

  • Restore missing internalSerializables entries (webpack/lib/Module and cold filesystem cache). (by @alexander-akait in #21477)

  • Fix watch rebuild crash when context symlink targets lack timestampHash. (by @alexander-akait in #21477)

  • Fix lazy compilation backend leaking idle module entries and hanging on exit. (by @alexander-akait in #21477)

  • Stop logging benign ECONNRESET client errors from the lazy compilation server. (by @alexander-akait in #21477)

  • Accept compilations from another webpack copy in getCompilationHooks again. (by @alexander-akait in #21477)

  • Fix output.html injection edge cases: escaping, head detection, duplicate meta tags, resource-hint/entry-tag retention with inject: false, and stylesheet placement. (by @alexander-akait in #21477)

  • Ignore a <base> inside an inert <template> when resolving HTML URLs. (by @alexander-akait in #21477)

  • Bust an HTML page's [contenthash] when its inlined chunk content changes. (by @alexander-akait in #21477)

  • Fix a dangling stylesheet <link> for a JS-only chunk in an HTML entry. (by @alexander-akait in #21477)

  • Fix a malformed HTML magic comment leaking a pending webpackInline directive onto the next element. (by @alexander-akait in #21477)

  • Fix off-by-one dropping the last character of an unterminated url(...) at end-of-input. (by @alexander-akait in #21477)

  • Consume the trailing whitespace of a CSS hex escape when unescaping identifiers. (by @alexander-akait in #21477)

  • Fix [fullhash] in output.webassemblyModuleFilename by dropping a stray brace and requesting the getFullHash runtime module. (by @alexander-akait in #21477)

  • Fix duplicated errors/warnings in stats output when detail-less entries exceed errorsSpace/warningsSpace. (by @alexander-akait in #21477)

  • Improve module parse errors with a babel-style code frame and the module type. (by @alexander-akait in #21485)

  • Fix formatSize rendering sizes of 1 TiB or larger as "undefined". (by @alexander-akait in #21477)

  • Skip the anonymous default export .name fix-up when name is non-configurable, instead of throwing on pre-ES2015 engines. (by @alexander-akait in #21477)

  • Escape ? and # in context module regexp identifiers so source map names are not truncated. (by @alexander-akait in #21477)

  • Resolve directory requests to their index module in scoped DllReferencePlugin. (by @alexander-akait in #21477)

  • Skip the hasSymbol check in the async module runtime when environment.symbol is set. (by @alexander-akait in #21477)

  • Use a shared __webpack_require__.cjs helper for wrapped CommonJS modules. (by @alexander-akait in #21477)

  • Derive ASI positions from source text instead of acorn's onInsertedSemicolon, so custom parsers need not collect semicolons. (by @alexander-akait in #21477)

  • Avoid a second full parse for auto source type by downgrading module to script in place on a top-level return. (by @alexander-akait in #21477)

  • Fix exponential-time side-effects analysis on cyclic module graphs by memoizing cycle-free results via Tarjan lowlink. (by @alexander-akait in #21477)

  • Speed up JavaScript parsing and AST walking and reduce parser memory usage. (by @alexander-akait in #21477)

  • Speed up CSS and HTML parsing and code generation and reduce parser memory usage. (by @alexander-akait in #21477)

  • Speed up snapshot creation and reduce its memory usage. (by @alexander-akait in #21477)

  • Reduce allocations in JS codegen, concatenation, queues and parser setup. (by @alexander-akait in #21477)

  • Speed up stats generation on large builds by reusing the item context across array items. (by @alexander-akait in #21477)

  • Memoize loader resolution per compilation to avoid re-resolving the same loader for every matching module. (by @alexander-akait in #21477)

  • Reuse and harden webpack's shared resource parser in the loader runner. (by @alexander-akait in #21477)

  • Update webpack-sources to 3.5.1 and enhanced-resolve to 5.24.2 to cut peak memory. (by @alexander-akait in #21477)

  • Inline the loader-runner package into core. (by @alexander-akait in #21477)

  • Fix context hash crash on unsupported directory entries like FIFOs and sockets. (by @hai-x in #21484)

  • Verify internalSerializables in lint:special and regenerate it in fix:special. (by @alexander-akait in #21476)

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by more commits than we can show here.


Depfu Status

Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with @depfu rebase.

All Depfu comment commands
@​depfu rebase
Rebases against your default branch and redoes this update
@​depfu recreate
Recreates this PR, overwriting any edits that you've made to it
@​depfu merge
Merges this PR once your tests are passing and conflicts are resolved
@​depfu cancel merge
Cancels automatic merging of this PR
@​depfu close
Closes this PR and deletes the branch
@​depfu reopen
Restores the branch and reopens this PR (if it's closed)
@​depfu pause
Ignores all future updates for this dependency and closes this PR
@​depfu pause [minor|major]
Ignores all future minor/major updates for this dependency and closes this PR
@​depfu resume
Future versions of this dependency will create PRs again (leaves this PR as is)

@depfu
depfu Bot requested a review from canova as a code owner August 4, 2026 18:25
@depfu depfu Bot added the dependencies Pull requests that update a dependency file label Aug 4, 2026
@depfu
depfu Bot requested a review from fatadel as a code owner August 4, 2026 18:25
@depfu depfu Bot added the dependencies Pull requests that update a dependency file label Aug 4, 2026
@netlify

netlify Bot commented Aug 4, 2026

Copy link
Copy Markdown

Deploy Preview for firefox-devtools-react-contextmenu ready!

Name Link
🔨 Latest commit d9e666a
🔍 Latest deploy log https://app.netlify.com/projects/firefox-devtools-react-contextmenu/deploys/6a722eafca36cd0008c026c0
😎 Deploy Preview https://deploy-preview-434--firefox-devtools-react-contextmenu.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants