You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Treat top-level await and import.meta as ES module markers, matching Node.js syntax detection so no explicit module type is needed. (by @alexander-akait in #21218)
Add a bun target that emits ESM and externalizes bun:* and node.js built-in modules. (by @alexander-akait in #21248)
Support CommonJS reexports via Object.defineProperty value and getter descriptors. (by @alexander-akait in #21129)
Support JSON Schema const when generating CLI flags from a schema. (by @alexander-akait in #21087)
Support JSON Schema if/then/else when generating CLI flags from a schema. (by @alexander-akait in #21087)
Skip import specifiers, require() and import() calls in dead conditional branches gated by inlined imported constants (isDEV ? A : B), evaluated via getCondition. (by @hai-x in #21136)
CSS localIdentName[hash] now resolves to the local ident hash (matching css-loader); use [modulehash] for the module hash. (by @alexander-akait in #21259)
Add CSS parser as option and resolve url() inside HTML style attributes. (by @alexander-akait in #21157)
Add a deno target (with versions, e.g. deno, deno2, deno1.40) that emits ESM, resolves node.js built-ins via the required node: specifier, and keeps Deno's own import protocols (npm:, jsr:, node:, http(s)://) external. (by @alexander-akait in #21247)
Use module-import for electron externals when the target supports ESM. (by @alexander-akait in #21184)
Add output.environment.logicalAssignment to emit ||= in runtime code when the target supports logical assignment operators. (by @bjohansebas in #21219)
Resolve and rewrite asset URLs inside <iframe srcdoc> in HTML modules. (by @bjohansebas in #21226)
Add HMR support for HTML modules with body/title DOM patching on update. (by @alexander-akait in #21011)
Add css-url html source type extracting url() references from CSS-valued attributes. (by @alexander-akait in #21250)
Add module.parser.html.sources option to disable or customize URL-attribute extraction for HTML modules, with script / script-module / stylesheet / stylesheet-inline types for custom attributes (by @alexander-akait in #21022)
Add module.parser.html.template option to transform HTML module source before parsing. (by @alexander-akait in #21055)
Extract more source URLs in HTML modules (SVG, legacy and obsolete attributes). (by @alexander-akait in #21241)
Inline export default <const> when the default-exported value is a primitive constant. (by @hai-x in #21189)
Support optimization.inlineExports for better tree-shaking. (by @hai-x in #20973)
Re-encode inline hash digests ([contenthash]/[chunkhash]/[fullhash]/[modulehash]) from the full content hash, so they carry full entropy and work under optimization.realContentHash and in dynamically-loaded chunk filenames; also preserve leading zero bytes in base-N digests. (by @alexander-akait in #21267)
Allow tree-shaking unused calls to /*#__NO_SIDE_EFFECTS__*/-annotated (pure) exports across module boundaries. (by @hai-x in #20907)
Defer building unused re-export targets of side-effect-free barrel modules. (by @hai-x in #21165)
Keep export mangling enabled for modules whose namespace object is used as a whole value, by materializing a decoupled namespace object that keeps the original export names. (by @alexander-akait in #21234)
Add output.environment.let option (paired with target's let capability) and emit let/const instead of var in generated runtime code wherever it is safe. Bindings that may be wrapped in runtime-condition if blocks (harmony imports, ConcatenatedModule external imports) continue to use var to preserve function scoping. (by @alexander-akait in #21010)
Add output.html to emit an HTML file per entrypoint, injecting its JS/CSS chunks (including dependOn shared chunks). (by @alexander-akait in #21215)
Add module.parser.javascript.pureFunctions to mark top-level names as side-effect-free for tree shaking. (by @hai-x in #21063)
Add universal to compiler.platform, true for universal targets ("universal" or ["web", "node"]). (by @bjohansebas in #21252)
Add output.strictModuleResolution to gate the runtime MODULE_NOT_FOUND guard. (by @hai-x in #21067)
Support an inline digest in hash path placeholders, e.g. [contenthash:base64:8]. (by @alexander-akait in #21259)
Support [uniqueName] and its [uniquename] alias in template paths. (by @alexander-akait in #21155)
Support CSS in Node for universal targets, collecting styles for SSR. (by @alexander-akait in #21208)
Improve commonjs, node-commonjs and global externals for universal targets. (by @alexander-akait in #21187)
Add a universal target preset (browser + web worker + Node.js + Electron + NW.js) that always outputs ECMAScript modules. (by @alexander-akait in #21214)
Support new Worker(new URL(...)) in universal (node + web) targets by resolving the Worker constructor from worker_threads when no global Worker exists. (by @alexander-akait in #21195)
Add output.workerChunkFilename and entry.worker for worker chunk filenames. (by @alexander-akait in #21128)
Patch Changes
Skip re-parsing the inlined entry module when no renaming is needed. (by @alexander-akait in #21167)
Extend the avoidEntryIife no-parse fast path to multi-entry chunks. (by @alexander-akait in #21173)
Reuse the binary deserialize dispatch table to speed up cache restore. (by @alexander-akait in #21175)
Type buildInfo and buildMeta per module type with shared common properties. (by @alexander-akait in #21172)
Avoid copying module runtime requirements when ownership is not transferred. (by @alexander-akait in #21140)
Keep all CommonJS exports when an exported function accesses them via this. (by @alexander-akait in #21179)
Include the schema origin path in conflicting-schema CLI argument errors. (by @alexander-akait in #21087)
Reject __proto__, constructor and prototype path segments in cli.processArguments to prevent prototype pollution. (by @alexander-akait in #21057)
Speed up Compilation.deleteAsset and Compilation.renameAsset via a lazy reverse index from asset file name to containing chunks. (by @alexander-akait in #21035)
Fix merging of inner modules' top-level declarations in concatenated modules. (by @alexander-akait in #21170)
Reduce allocations in export hashing and concatenation name lookups. (by @alexander-akait in #21167)
Support inline hash digest and length in CSS module localIdentName placeholders. (by @alexander-akait in #21259)
Resolve full CSS escapes (including hex) in CSS-Modules names, so e.g. \75 rl() matches url(). (by @alexander-akait in #21196)
Reduce CSS parser CPU (hoisted per-call regexes, byte-compared @container pure-mode keywords) and stop retaining parsed comments on the reused parser instance between modules. (by @alexander-akait in #21202)
Reduce CSS build time and memory usage. Per-export CSS dependencies are consolidated into one dependency per module, and hot-path allocations and lookups in CSS code generation and the module-graph cache are trimmed. (by @alexander-akait in #21114)
Cache CSS public-path placeholder offsets per module source to avoid re-materializing and re-scanning the source on every render. (by @alexander-akait in #21054)
Fix CSS tokenizer infinite loops and dropped tokens on malformed input. (by @alexander-akait in #21102)
Skip already-visited symlink targets when resolving context hashes so cyclic symlink graphs no longer overflow the queue. (by @alexander-akait in #21088)
Resolve DefinePlugin access to an undefined object member as undefined. (by @alexander-akait in #21040)
Avoid materializing dependency source locations when sorting, keeping them lazy to reduce build time and memory. (by @alexander-akait in #21228)
Speed up serialization deserialize by replacing a Buffer.isBuffer call with a typeof check. (by @hai-x in #21203)
Emit assets with absolute target paths as-is to avoid invalid Windows paths. (by @alexander-akait in #21223)
Add output.environment.spread, output.environment.hasOwn, and output.environment.symbol, and use method shorthand, spread, Object.hasOwn, and an unguarded Symbol in generated runtime code where the environment supports it. (by @alexander-akait in #21188)
Drop the unused loadScript runtime from ESM hot-update bundles. (by @alexander-akait in #21208)
Extend value binding optimization to export default expressions. (by @xiaoxiaojx in #21117)
Reduce ExportInfo memory and cache size for inline-exports metadata. (by @alexander-akait in #21171)
Resolve nested exports info paths iteratively to cut per-level array allocations. (by @alexander-akait in #21137)
Fix stale incremental cache for css, html and asset/source/inline modules. (by @alexander-akait in #21108)
CommonJS tree-shaking no longer drops exports accessed before a deferred require binding. (by @xiaoxiaojx in #21123)
Make CSS-referenced asset available in lazy JS chunk during incremental rebuilds. (by @alexander-akait in #21100)
Correct string/template import specifier parsing for filesystem cache build dependencies and fix module-sharing hostname validation. (by @alexander-akait in #21232)
perf: guard isDeferred() behind experiments.deferImport in ConcatenatedModule (by @shashank-u03 in #21096)
Speed up deterministicGrouping and cached comparators on large builds. (by @alexander-akait in #21197)
Force-load a module's new owning chunk during HMR when its only loaded chunk is removed from a runtime, so it keeps receiving updates. (by @alexander-akait in #21131)
Fix HTML parser adoption agency to handle a nobr shielded by a marker. (by @alexander-akait in #21274)
Expand HTML parser tag/attribute coverage and decode character references. (by @alexander-akait in #21159)
Speed up and reduce allocations in the experimental HTML parser's tokenizer, tree builder, and entity decoder. (by @alexander-akait in #21152)
Speed up the experimental HTML parser and reduce its memory usage. (by @alexander-akait in #21130)
Avoid redundant HTML module work: reuse the dependency-template render across the JS and HTML code-generation passes, and memoize sentinel resolution/content hashing per source. (by @alexander-akait in #21054)
Release inner-graph state after use and speed up inlined-export checks. (by @alexander-akait in #21167)
Reduce JavascriptParser allocations on the walk hot path to speed up parsing and lower memory usage. (by @alexander-akait in #21139)
Reduce CPU and memory overhead of the lazy barrel optimization. (by @alexander-akait in #21213)
Keep the error message in module build errors on engines whose Error.stack omits it. (by @alexander-akait in #21239)
Speed up module concatenation by caching repeated per-module computations. (by @alexander-akait in #21115)
Move the hot flag from Module to NormalModule, where it's actually read and written. (by @alexander-akait in #21028)
Move the weak flag from Dependency to ModuleDependency, where it's actually set. (by @alexander-akait in #21111)
Avoid the entry IIFE for multiple inlined entry modules by renaming collisions. (by @alexander-akait in #21151)
Reject new import.defer(...)/new import.source(...) with member access as a SyntaxError. (by @alexander-akait in #21211)
Avoid ProvidePlugin injection for local CommonJS require bindings that use the same variable name. (by @fireairforce in #21041)
Resolve the global new Worker(new URL(...)) to worker_threads on the node target. (by @alexander-akait in #21217)
Use optional chaining in generated runtime code where the environment supports it. (by @alexander-akait in #21186)
Allow output.path to be the filesystem root by treating EISDIR like EEXIST in mkdirp. (by @alexander-akait in #21223)
Reduce memory by not retaining the source location object on every dependency. (by @alexander-akait in #21183)
Keep the full exports object when a require() binding is re-exported. (by @alexander-akait in #21144)
Replace glob-to-regexp dependency with watchpack's globToRegExp utility. (by @hai-x in #21176)
Shrink the persistent cache: add a NULL_AND_I16 binary tier and inline tiny strings instead of larger far back-references. (by @hai-x in #21210)
Type serializer read/write contexts with positional tuples and fix a ProvideSharedDependency version/request swap. (by @alexander-akait in #21201)
Speed up buildChunkGraph by deriving block modules from the first runtime. (by @alexander-akait in #21166)
Cache re-export target resolution in SideEffectsFlagPlugin for faster builds. (by @alexander-akait in #21085)
Skip pure single-star passthrough modules for export * re-exports. (by @alexander-akait in #21085)
Skip dependency error/warning reporting for unchanged modules on rebuilds. (by @alexander-akait in #21154)
Use value descriptors instead of getters for const export bindings. (by @xiaoxiaojx in #21021)
Medium Risk
Webpack 5.108.x includes minor behavioral changes (ESM markers, bundling) that could affect Docusaurus builds; Docusaurus 3.10.2 is a broad patch across core, MDX, and dev server. Risk is limited to docs build/serve and release automation, not runtime product code.
Overview
Bumps the docs site toolchain via package-lock.json and pins webpack from 5.107.2 to 5.108.4 in package.json overrides.
Docusaurus resolves to 3.10.2 across the @docusaurus/* packages (patch release), including dev-server changes such as detect-port v2 and front matter handling via @11ty/gray-matter instead of gray-matter. semantic-release moves to 25.0.8 (transitive npm/Octokit bumps in the lockfile). No application source under src/ is changed—only dependency versions.
Reviewed by Cursor Bugbot for commit 5051a2a. Bugbot is set up for automated code reviews on this repo. Configure here.
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/npm@11.18.0. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
Warn
Obfuscated code: npm npm is 90.0% likely obfuscated
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/npm@11.18.0. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
Warn
Obfuscated code: npm webpack is 90.0% likely obfuscated
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/webpack@5.108.4. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.10.1→3.10.23.10.1→3.10.23.10.1→3.10.23.10.1→3.10.23.10.1→3.10.23.10.1→3.10.23.10.1→3.10.23.10.1→3.10.23.10.1→3.10.225.0.5→25.0.85.107.2→5.108.4Warning
Some dependencies could not be looked up. Check the warning logs for more information.
Release Notes
facebook/docusaurus (@docusaurus/core)
v3.10.2Compare Source
Backport and cherry-pick commits from main for v3.10.2 patch release:
@swc/html, fix StackBlitz playground #12055extractLeadingEmoji()edge cases #12100@types/gtag.js, upgrade@swc/html#12080docusaurus serveshould pass--hosttoserver.listen()#12127trustPolicydowngrade issue #12012@11ty/gray-matter#12181semantic-release/semantic-release (semantic-release)
v25.0.8Compare Source
Bug Fixes
v25.0.7Compare Source
Bug Fixes
v25.0.6Compare Source
Bug Fixes
webpack/webpack (webpack)
v5.108.4Compare Source
Patch Changes
Speed up non-CSS-Modules parsing by not building unused selector AST nodes. (by @alexander-akait in #21324)
Speed up non-CSS-Modules CSS parsing by dropping value tokens nothing reads. (by @alexander-akait in #21324)
Resolve HTML asset URLs against the document
<base href>. (by @alexander-akait in #21329)Add HTML integration tests: generateError output, ignored src, null-char parse. (by @aryanraj45 in #21328)
Reduce CPU and memory overhead of HTML and CSS parsing and code generation. (by @alexander-akait in #21332)
Reduce HTML parser memory and CPU by skipping unused AST nodes. (by @alexander-akait in #21323)
Reduce HTML parser memory by storing the AST in struct-of-arrays form. (by @alexander-akait in #21331)
Key the provided-exports cache on a lazy barrel's still-lazy re-export targets. (by @hai-x in #21326)
Default
output.globalObjecttoglobalThisfor universal targets. (by @alexander-akait in #21314)Pass through
new URL(...)directory references instead of resolving them. (by @alexander-akait in #21312)v5.108.3Compare Source
Patch Changes
Speed up CSS parsing and reduce CSS AST node memory. (by @alexander-akait in #21285)
Fix HMR codegen crash for harmony accept with unresolved imports. (by @xiaoxiaojx in #21302)
Match harmony accept dependencies by module reference so HMR codegen handles imports without a module or chunk id. (by @alexander-akait in #21303)
v5.108.2Compare Source
Patch Changes
Fix lazy barrel deferral of ungrouped side-effect imports. (by @hai-x in #21291)
Respect the
node:prefix for node.js core modules used as externals. (by @alexander-akait in #21286)v5.108.1Compare Source
Patch Changes
Fix invalid property access for escaped namespace imports with multi-character mangled export names. (by @xiaoxiaojx in #21280)
Add frames to ProfilingPlugin TracingStartedInBrowser event so the trace loads in Chrome DevTools. (by @alexander-akait in #21269)
v5.108.0Compare Source
Minor Changes
Treat top-level await and
import.metaas ES module markers, matching Node.js syntax detection so no explicit module type is needed. (by @alexander-akait in #21218)Add a
buntarget that emits ESM and externalizesbun:*and node.js built-in modules. (by @alexander-akait in #21248)Support CommonJS reexports via
Object.definePropertyvalue and getter descriptors. (by @alexander-akait in #21129)Support JSON Schema
constwhen generating CLI flags from a schema. (by @alexander-akait in #21087)Support JSON Schema
if/then/elsewhen generating CLI flags from a schema. (by @alexander-akait in #21087)Skip import specifiers,
require()andimport()calls in dead conditional branches gated by inlined imported constants (isDEV ? A : B), evaluated viagetCondition. (by @hai-x in #21136)CSS
localIdentName[hash]now resolves to the local ident hash (matching css-loader); use[modulehash]for the module hash. (by @alexander-akait in #21259)Add CSS parser
asoption and resolveurl()inside HTMLstyleattributes. (by @alexander-akait in #21157)Add dedicated module classes for all built-in module types. (by @alexander-akait in #21164)
Support
.html/.cssfor the default./srcentry under the html/css experiments. (by @alexander-akait in #21039)Add
defineConfighelper for typed configuration files. (by @alexander-akait in #21169)Add a
denotarget (with versions, e.g.deno,deno2,deno1.40) that emits ESM, resolves node.js built-ins via the requirednode:specifier, and keeps Deno's own import protocols (npm:,jsr:,node:,http(s)://) external. (by @alexander-akait in #21247)Use
module-importfor electron externals when the target supports ESM. (by @alexander-akait in #21184)Add
output.environment.logicalAssignmentto emit||=in runtime code when the target supports logical assignment operators. (by @bjohansebas in #21219)Resolve and rewrite asset URLs inside
<iframe srcdoc>in HTML modules. (by @bjohansebas in #21226)Add HMR support for HTML modules with body/title DOM patching on update. (by @alexander-akait in #21011)
Add
css-urlhtml source type extractingurl()references from CSS-valued attributes. (by @alexander-akait in #21250)Add
module.parser.html.sourcesoption to disable or customize URL-attribute extraction for HTML modules, withscript/script-module/stylesheet/stylesheet-inlinetypes for custom attributes (by @alexander-akait in #21022)Add
module.parser.html.templateoption to transform HTML module source before parsing. (by @alexander-akait in #21055)Extract more source URLs in HTML modules (SVG, legacy and obsolete attributes). (by @alexander-akait in #21241)
Inline
export default <const>when the default-exported value is a primitive constant. (by @hai-x in #21189)Support
optimization.inlineExportsfor better tree-shaking. (by @hai-x in #20973)Re-encode inline hash digests (
[contenthash]/[chunkhash]/[fullhash]/[modulehash]) from the full content hash, so they carry full entropy and work underoptimization.realContentHashand in dynamically-loaded chunk filenames; also preserve leading zero bytes in base-N digests. (by @alexander-akait in #21267)Allow tree-shaking unused calls to
/*#__NO_SIDE_EFFECTS__*/-annotated (pure) exports across module boundaries. (by @hai-x in #20907)Defer building unused re-export targets of side-effect-free barrel modules. (by @hai-x in #21165)
Keep export mangling enabled for modules whose namespace object is used as a whole value, by materializing a decoupled namespace object that keeps the original export names. (by @alexander-akait in #21234)
Add
output.environment.letoption (paired with target'sletcapability) and emitlet/constinstead ofvarin generated runtime code wherever it is safe. Bindings that may be wrapped in runtime-conditionifblocks (harmony imports, ConcatenatedModule external imports) continue to usevarto preserve function scoping. (by @alexander-akait in #21010)Add
output.htmlto emit an HTML file per entrypoint, injecting its JS/CSS chunks (includingdependOnshared chunks). (by @alexander-akait in #21215)Add
module.parser.javascript.pureFunctionsto mark top-level names as side-effect-free for tree shaking. (by @hai-x in #21063)Add
universaltocompiler.platform, true for universal targets ("universal"or["web", "node"]). (by @bjohansebas in #21252)Add
output.strictModuleResolutionto gate the runtimeMODULE_NOT_FOUNDguard. (by @hai-x in #21067)Support an inline digest in hash path placeholders, e.g.
[contenthash:base64:8]. (by @alexander-akait in #21259)Support
[uniqueName]and its[uniquename]alias in template paths. (by @alexander-akait in #21155)Support CSS in Node for universal targets, collecting styles for SSR. (by @alexander-akait in #21208)
Improve commonjs, node-commonjs and global externals for universal targets. (by @alexander-akait in #21187)
Add a
universaltarget preset (browser + web worker + Node.js + Electron + NW.js) that always outputs ECMAScript modules. (by @alexander-akait in #21214)Support
new Worker(new URL(...))in universal (node + web) targets by resolving the Worker constructor fromworker_threadswhen no globalWorkerexists. (by @alexander-akait in #21195)Add
output.workerChunkFilenameandentry.workerfor worker chunk filenames. (by @alexander-akait in #21128)Patch Changes
Skip re-parsing the inlined entry module when no renaming is needed. (by @alexander-akait in #21167)
Extend the avoidEntryIife no-parse fast path to multi-entry chunks. (by @alexander-akait in #21173)
Reuse the binary deserialize dispatch table to speed up cache restore. (by @alexander-akait in #21175)
Type
buildInfoandbuildMetaper module type with shared common properties. (by @alexander-akait in #21172)Avoid copying module runtime requirements when ownership is not transferred. (by @alexander-akait in #21140)
Keep all CommonJS exports when an exported function accesses them via
this. (by @alexander-akait in #21179)Align CLI color-support detection across Node, Deno and Bun. (by @alexander-akait in #21257)
Include the schema origin path in conflicting-schema CLI argument errors. (by @alexander-akait in #21087)
Reject
__proto__,constructorandprototypepath segments incli.processArgumentsto prevent prototype pollution. (by @alexander-akait in #21057)Speed up
Compilation.deleteAssetandCompilation.renameAssetvia a lazy reverse index from asset file name to containing chunks. (by @alexander-akait in #21035)Fix merging of inner modules' top-level declarations in concatenated modules. (by @alexander-akait in #21170)
Reduce allocations in export hashing and concatenation name lookups. (by @alexander-akait in #21167)
Avoid toLowerCase allocations in CSS keyword comparisons. (by @alexander-akait in #21109)
Speed up CSS identifier escaping with a char-class lookup table. (by @alexander-akait in #21109)
Resolve
[fullhash]inurl()public paths for inlined CSS export types (style/text/css-style-sheet) at runtime. (by @alexander-akait in #21054)Avoid quadratic line scan when building CSS module exports source maps. (by @alexander-akait in #21109)
Compute CSS comment source locations lazily. (by @alexander-akait in #21109)
Support inline hash digest and length in CSS module
localIdentNameplaceholders. (by @alexander-akait in #21259)Resolve full CSS escapes (including hex) in CSS-Modules names, so e.g.
\75 rl()matchesurl(). (by @alexander-akait in #21196)Reduce CSS parser CPU (hoisted per-call regexes, byte-compared
@containerpure-mode keywords) and stop retaining parsed comments on the reused parser instance between modules. (by @alexander-akait in #21202)Reduce CSS build time and memory usage. Per-export CSS dependencies are consolidated into one dependency per module, and hot-path allocations and lookups in CSS code generation and the module-graph cache are trimmed. (by @alexander-akait in #21114)
Cache CSS public-path placeholder offsets per module source to avoid re-materializing and re-scanning the source on every render. (by @alexander-akait in #21054)
Fix CSS tokenizer infinite loops and dropped tokens on malformed input. (by @alexander-akait in #21102)
Speed up CSS identifier unescaping with bulk run flushing. (by @alexander-akait in #21109)
Skip already-visited symlink targets when resolving context hashes so cyclic symlink graphs no longer overflow the queue. (by @alexander-akait in #21088)
Resolve
DefinePluginaccess to an undefined object member asundefined. (by @alexander-akait in #21040)Avoid materializing dependency source locations when sorting, keeping them lazy to reduce build time and memory. (by @alexander-akait in #21228)
Speed up serialization deserialize by replacing a Buffer.isBuffer call with a typeof check. (by @hai-x in #21203)
Emit assets with absolute target paths as-is to avoid invalid Windows paths. (by @alexander-akait in #21223)
Add
output.environment.spread,output.environment.hasOwn, andoutput.environment.symbol, and use method shorthand, spread,Object.hasOwn, and an unguardedSymbolin generated runtime code where the environment supports it. (by @alexander-akait in #21188)Drop the unused loadScript runtime from ESM hot-update bundles. (by @alexander-akait in #21208)
Extend value binding optimization to export default expressions. (by @xiaoxiaojx in #21117)
Reduce ExportInfo memory and cache size for inline-exports metadata. (by @alexander-akait in #21171)
Resolve nested exports info paths iteratively to cut per-level array allocations. (by @alexander-akait in #21137)
Fix stale incremental cache for css, html and asset/source/inline modules. (by @alexander-akait in #21108)
CommonJS tree-shaking no longer drops exports accessed before a deferred require binding. (by @xiaoxiaojx in #21123)
Make CSS-referenced asset available in lazy JS chunk during incremental rebuilds. (by @alexander-akait in #21100)
Correct string/template import specifier parsing for filesystem cache build dependencies and fix module-sharing hostname validation. (by @alexander-akait in #21232)
perf: guard isDeferred() behind experiments.deferImport in ConcatenatedModule (by @shashank-u03 in #21096)
Speed up deterministicGrouping and cached comparators on large builds. (by @alexander-akait in #21197)
Reduce allocations on harmony/commonjs dependency hot paths. (by @alexander-akait in #21180)
Force-load a module's new owning chunk during HMR when its only loaded chunk is removed from a runtime, so it keeps receiving updates. (by @alexander-akait in #21131)
Fix HTML parser adoption agency to handle a
nobrshielded by a marker. (by @alexander-akait in #21274)Expand HTML parser tag/attribute coverage and decode character references. (by @alexander-akait in #21159)
Speed up and reduce allocations in the experimental HTML parser's tokenizer, tree builder, and entity decoder. (by @alexander-akait in #21152)
Speed up the experimental HTML parser and reduce its memory usage. (by @alexander-akait in #21130)
Avoid redundant HTML module work: reuse the dependency-template render across the JS and HTML code-generation passes, and memoize sentinel resolution/content hashing per source. (by @alexander-akait in #21054)
Release inner-graph state after use and speed up inlined-export checks. (by @alexander-akait in #21167)
Reduce JavascriptParser allocations on the walk hot path to speed up parsing and lower memory usage. (by @alexander-akait in #21139)
Reduce CPU and memory overhead of the lazy barrel optimization. (by @alexander-akait in #21213)
Keep the error message in module build errors on engines whose
Error.stackomits it. (by @alexander-akait in #21239)Speed up module concatenation by caching repeated per-module computations. (by @alexander-akait in #21115)
Move the
hotflag fromModuletoNormalModule, where it's actually read and written. (by @alexander-akait in #21028)Move the
weakflag fromDependencytoModuleDependency, where it's actually set. (by @alexander-akait in #21111)Avoid the entry IIFE for multiple inlined entry modules by renaming collisions. (by @alexander-akait in #21151)
Reject
new import.defer(...)/new import.source(...)with member access as a SyntaxError. (by @alexander-akait in #21211)Avoid
ProvidePlugininjection for local CommonJS require bindings that use the same variable name. (by @fireairforce in #21041)Resolve the global
new Worker(new URL(...))toworker_threadson thenodetarget. (by @alexander-akait in #21217)Use optional chaining in generated runtime code where the environment supports it. (by @alexander-akait in #21186)
Allow output.path to be the filesystem root by treating EISDIR like EEXIST in mkdirp. (by @alexander-akait in #21223)
Reduce memory by not retaining the source location object on every dependency. (by @alexander-akait in #21183)
Keep the full exports object when a
require()binding is re-exported. (by @alexander-akait in #21144)Replace glob-to-regexp dependency with watchpack's globToRegExp utility. (by @hai-x in #21176)
Shrink the persistent cache: add a NULL_AND_I16 binary tier and inline tiny strings instead of larger far back-references. (by @hai-x in #21210)
Type serializer read/write contexts with positional tuples and fix a ProvideSharedDependency version/request swap. (by @alexander-akait in #21201)
Speed up buildChunkGraph by deriving block modules from the first runtime. (by @alexander-akait in #21166)
Cache re-export target resolution in SideEffectsFlagPlugin for faster builds. (by @alexander-akait in #21085)
Skip pure single-star passthrough modules for
export *re-exports. (by @alexander-akait in #21085)Skip dependency error/warning reporting for unchanged modules on rebuilds. (by @alexander-akait in #21154)
Use value descriptors instead of getters for const export bindings. (by @xiaoxiaojx in #21021)
Apply CSS hot updates on the Node side of a universal target. (by @alexander-akait in #21217)
Guard CSS
styleexport-type injection so it no-ops when there is nodocument. (by @alexander-akait in #21193)Avoid building warning stats objects when counting warnings without a filter. (by @alexander-akait in #21198)
Recognize forward-slash Windows absolute paths (e.g. C:/dir) consistently. (by @alexander-akait in #21223)
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.
Note
Medium Risk
Webpack 5.108.x includes minor behavioral changes (ESM markers, bundling) that could affect Docusaurus builds; Docusaurus 3.10.2 is a broad patch across core, MDX, and dev server. Risk is limited to docs build/serve and release automation, not runtime product code.
Overview
Bumps the docs site toolchain via
package-lock.jsonand pinswebpackfrom5.107.2to5.108.4inpackage.jsonoverrides.Docusaurus resolves to 3.10.2 across the
@docusaurus/*packages (patch release), including dev-server changes such asdetect-portv2 and front matter handling via@11ty/gray-matterinstead ofgray-matter. semantic-release moves to 25.0.8 (transitive npm/Octokit bumps in the lockfile). No application source undersrc/is changed—only dependency versions.Reviewed by Cursor Bugbot for commit 5051a2a. Bugbot is set up for automated code reviews on this repo. Configure here.