Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Roadmap: Dependency - update webpack #2163

Closed
4 tasks done
Aetherinox opened this issue Apr 12, 2024 · 0 comments
Closed
4 tasks done

Roadmap: Dependency - update webpack #2163

Aetherinox opened this issue Apr 12, 2024 · 0 comments
Assignees
Labels
𐄂 Release Ready This task is ready for release but not pushed yet. Type ◦ Dependency Item is associated to dependency
Milestone

Comments

@Aetherinox
Copy link
Contributor

Aetherinox commented Apr 12, 2024

Summary

Update https://www.npmjs.com/package/webpack from v5.36.2 to a later version.

The current version contains numerous critical vulnerabilities which need to be patched. Versions < 5.76.0 contain critical vulnerability CVE-2023-28154. This vulnerability only affects the builder system, not the end-user.

Reference:


Tested Versions

  • 5.37.1
  • 5.65.0
  • 5.76.0
  • 5.91.0

About Dependency

Webpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capable of transforming, bundling, or packaging just about any resource or asset.

@Aetherinox Aetherinox added the Type ◦ Dependency Item is associated to dependency label Apr 12, 2024
@Aetherinox Aetherinox added this to the v1.19 milestone Apr 12, 2024
@Aetherinox Aetherinox self-assigned this Apr 12, 2024
@Aetherinox Aetherinox added the 𐄂 Release Ready This task is ready for release but not pushed yet. label Apr 15, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
𐄂 Release Ready This task is ready for release but not pushed yet. Type ◦ Dependency Item is associated to dependency
Projects
Status: Done
Development

No branches or pull requests

1 participant