You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Treat top-level await and import.meta as ES module markers, matching Node.js syntax detection so no explicit module type is needed. (by @alexander-akait in #21218)
Add a bun target that emits ESM and externalizes bun:* and node.js built-in modules. (by @alexander-akait in #21248)
Support CommonJS reexports via Object.defineProperty value and getter descriptors. (by @alexander-akait in #21129)
Support JSON Schema const when generating CLI flags from a schema. (by @alexander-akait in #21087)
Support JSON Schema if/then/else when generating CLI flags from a schema. (by @alexander-akait in #21087)
Skip import specifiers, require() and import() calls in dead conditional branches gated by inlined imported constants (isDEV ? A : B), evaluated via getCondition. (by @hai-x in #21136)
CSS localIdentName[hash] now resolves to the local ident hash (matching css-loader); use [modulehash] for the module hash. (by @alexander-akait in #21259)
Add CSS parser as option and resolve url() inside HTML style attributes. (by @alexander-akait in #21157)
Add a deno target (with versions, e.g. deno, deno2, deno1.40) that emits ESM, resolves node.js built-ins via the required node: specifier, and keeps Deno's own import protocols (npm:, jsr:, node:, http(s)://) external. (by @alexander-akait in #21247)
Use module-import for electron externals when the target supports ESM. (by @alexander-akait in #21184)
Add output.environment.logicalAssignment to emit ||= in runtime code when the target supports logical assignment operators. (by @bjohansebas in #21219)
Resolve and rewrite asset URLs inside <iframe srcdoc> in HTML modules. (by @bjohansebas in #21226)
Add HMR support for HTML modules with body/title DOM patching on update. (by @alexander-akait in #21011)
Add css-url html source type extracting url() references from CSS-valued attributes. (by @alexander-akait in #21250)
Add module.parser.html.sources option to disable or customize URL-attribute extraction for HTML modules, with script / script-module / stylesheet / stylesheet-inline types for custom attributes (by @alexander-akait in #21022)
Add module.parser.html.template option to transform HTML module source before parsing. (by @alexander-akait in #21055)
Extract more source URLs in HTML modules (SVG, legacy and obsolete attributes). (by @alexander-akait in #21241)
Inline export default <const> when the default-exported value is a primitive constant. (by @hai-x in #21189)
Support optimization.inlineExports for better tree-shaking. (by @hai-x in #20973)
Re-encode inline hash digests ([contenthash]/[chunkhash]/[fullhash]/[modulehash]) from the full content hash, so they carry full entropy and work under optimization.realContentHash and in dynamically-loaded chunk filenames; also preserve leading zero bytes in base-N digests. (by @alexander-akait in #21267)
Allow tree-shaking unused calls to /*#__NO_SIDE_EFFECTS__*/-annotated (pure) exports across module boundaries. (by @hai-x in #20907)
Defer building unused re-export targets of side-effect-free barrel modules. (by @hai-x in #21165)
Keep export mangling enabled for modules whose namespace object is used as a whole value, by materializing a decoupled namespace object that keeps the original export names. (by @alexander-akait in #21234)
Add output.environment.let option (paired with target's let capability) and emit let/const instead of var in generated runtime code wherever it is safe. Bindings that may be wrapped in runtime-condition if blocks (harmony imports, ConcatenatedModule external imports) continue to use var to preserve function scoping. (by @alexander-akait in #21010)
Add output.html to emit an HTML file per entrypoint, injecting its JS/CSS chunks (including dependOn shared chunks). (by @alexander-akait in #21215)
Add module.parser.javascript.pureFunctions to mark top-level names as side-effect-free for tree shaking. (by @hai-x in #21063)
Add universal to compiler.platform, true for universal targets ("universal" or ["web", "node"]). (by @bjohansebas in #21252)
Add output.strictModuleResolution to gate the runtime MODULE_NOT_FOUND guard. (by @hai-x in #21067)
Support an inline digest in hash path placeholders, e.g. [contenthash:base64:8]. (by @alexander-akait in #21259)
Support [uniqueName] and its [uniquename] alias in template paths. (by @alexander-akait in #21155)
Support CSS in Node for universal targets, collecting styles for SSR. (by @alexander-akait in #21208)
Improve commonjs, node-commonjs and global externals for universal targets. (by @alexander-akait in #21187)
Add a universal target preset (browser + web worker + Node.js + Electron + NW.js) that always outputs ECMAScript modules. (by @alexander-akait in #21214)
Support new Worker(new URL(...)) in universal (node + web) targets by resolving the Worker constructor from worker_threads when no global Worker exists. (by @alexander-akait in #21195)
Add output.workerChunkFilename and entry.worker for worker chunk filenames. (by @alexander-akait in #21128)
Patch Changes
Skip re-parsing the inlined entry module when no renaming is needed. (by @alexander-akait in #21167)
Extend the avoidEntryIife no-parse fast path to multi-entry chunks. (by @alexander-akait in #21173)
Reuse the binary deserialize dispatch table to speed up cache restore. (by @alexander-akait in #21175)
Type buildInfo and buildMeta per module type with shared common properties. (by @alexander-akait in #21172)
Avoid copying module runtime requirements when ownership is not transferred. (by @alexander-akait in #21140)
Keep all CommonJS exports when an exported function accesses them via this. (by @alexander-akait in #21179)
Include the schema origin path in conflicting-schema CLI argument errors. (by @alexander-akait in #21087)
Reject __proto__, constructor and prototype path segments in cli.processArguments to prevent prototype pollution. (by @alexander-akait in #21057)
Speed up Compilation.deleteAsset and Compilation.renameAsset via a lazy reverse index from asset file name to containing chunks. (by @alexander-akait in #21035)
Fix merging of inner modules' top-level declarations in concatenated modules. (by @alexander-akait in #21170)
Reduce allocations in export hashing and concatenation name lookups. (by @alexander-akait in #21167)
Support inline hash digest and length in CSS module localIdentName placeholders. (by @alexander-akait in #21259)
Resolve full CSS escapes (including hex) in CSS-Modules names, so e.g. \75 rl() matches url(). (by @alexander-akait in #21196)
Reduce CSS parser CPU (hoisted per-call regexes, byte-compared @container pure-mode keywords) and stop retaining parsed comments on the reused parser instance between modules. (by @alexander-akait in #21202)
Reduce CSS build time and memory usage. Per-export CSS dependencies are consolidated into one dependency per module, and hot-path allocations and lookups in CSS code generation and the module-graph cache are trimmed. (by @alexander-akait in #21114)
Cache CSS public-path placeholder offsets per module source to avoid re-materializing and re-scanning the source on every render. (by @alexander-akait in #21054)
Fix CSS tokenizer infinite loops and dropped tokens on malformed input. (by @alexander-akait in #21102)
Skip already-visited symlink targets when resolving context hashes so cyclic symlink graphs no longer overflow the queue. (by @alexander-akait in #21088)
Resolve DefinePlugin access to an undefined object member as undefined. (by @alexander-akait in #21040)
Avoid materializing dependency source locations when sorting, keeping them lazy to reduce build time and memory. (by @alexander-akait in #21228)
Speed up serialization deserialize by replacing a Buffer.isBuffer call with a typeof check. (by @hai-x in #21203)
Emit assets with absolute target paths as-is to avoid invalid Windows paths. (by @alexander-akait in #21223)
Add output.environment.spread, output.environment.hasOwn, and output.environment.symbol, and use method shorthand, spread, Object.hasOwn, and an unguarded Symbol in generated runtime code where the environment supports it. (by @alexander-akait in #21188)
Drop the unused loadScript runtime from ESM hot-update bundles. (by @alexander-akait in #21208)
Extend value binding optimization to export default expressions. (by @xiaoxiaojx in #21117)
Reduce ExportInfo memory and cache size for inline-exports metadata. (by @alexander-akait in #21171)
Resolve nested exports info paths iteratively to cut per-level array allocations. (by @alexander-akait in #21137)
Fix stale incremental cache for css, html and asset/source/inline modules. (by @alexander-akait in #21108)
CommonJS tree-shaking no longer drops exports accessed before a deferred require binding. (by @xiaoxiaojx in #21123)
Make CSS-referenced asset available in lazy JS chunk during incremental rebuilds. (by @alexander-akait in #21100)
Correct string/template import specifier parsing for filesystem cache build dependencies and fix module-sharing hostname validation. (by @alexander-akait in #21232)
perf: guard isDeferred() behind experiments.deferImport in ConcatenatedModule (by @shashank-u03 in #21096)
Speed up deterministicGrouping and cached comparators on large builds. (by @alexander-akait in #21197)
Force-load a module's new owning chunk during HMR when its only loaded chunk is removed from a runtime, so it keeps receiving updates. (by @alexander-akait in #21131)
Fix HTML parser adoption agency to handle a nobr shielded by a marker. (by @alexander-akait in #21274)
Expand HTML parser tag/attribute coverage and decode character references. (by @alexander-akait in #21159)
Speed up and reduce allocations in the experimental HTML parser's tokenizer, tree builder, and entity decoder. (by @alexander-akait in #21152)
Speed up the experimental HTML parser and reduce its memory usage. (by @alexander-akait in #21130)
Avoid redundant HTML module work: reuse the dependency-template render across the JS and HTML code-generation passes, and memoize sentinel resolution/content hashing per source. (by @alexander-akait in #21054)
Release inner-graph state after use and speed up inlined-export checks. (by @alexander-akait in #21167)
Reduce JavascriptParser allocations on the walk hot path to speed up parsing and lower memory usage. (by @alexander-akait in #21139)
Reduce CPU and memory overhead of the lazy barrel optimization. (by @alexander-akait in #21213)
Keep the error message in module build errors on engines whose Error.stack omits it. (by @alexander-akait in #21239)
Speed up module concatenation by caching repeated per-module computations. (by @alexander-akait in #21115)
Move the hot flag from Module to NormalModule, where it's actually read and written. (by @alexander-akait in #21028)
Move the weak flag from Dependency to ModuleDependency, where it's actually set. (by @alexander-akait in #21111)
Avoid the entry IIFE for multiple inlined entry modules by renaming collisions. (by @alexander-akait in #21151)
Reject new import.defer(...)/new import.source(...) with member access as a SyntaxError. (by @alexander-akait in #21211)
Avoid ProvidePlugin injection for local CommonJS require bindings that use the same variable name. (by @fireairforce in #21041)
Resolve the global new Worker(new URL(...)) to worker_threads on the node target. (by @alexander-akait in #21217)
Use optional chaining in generated runtime code where the environment supports it. (by @alexander-akait in #21186)
Allow output.path to be the filesystem root by treating EISDIR like EEXIST in mkdirp. (by @alexander-akait in #21223)
Reduce memory by not retaining the source location object on every dependency. (by @alexander-akait in #21183)
Keep the full exports object when a require() binding is re-exported. (by @alexander-akait in #21144)
Replace glob-to-regexp dependency with watchpack's globToRegExp utility. (by @hai-x in #21176)
Shrink the persistent cache: add a NULL_AND_I16 binary tier and inline tiny strings instead of larger far back-references. (by @hai-x in #21210)
Type serializer read/write contexts with positional tuples and fix a ProvideSharedDependency version/request swap. (by @alexander-akait in #21201)
Speed up buildChunkGraph by deriving block modules from the first runtime. (by @alexander-akait in #21166)
Cache re-export target resolution in SideEffectsFlagPlugin for faster builds. (by @alexander-akait in #21085)
Skip pure single-star passthrough modules for export * re-exports. (by @alexander-akait in #21085)
Skip dependency error/warning reporting for unchanged modules on rebuilds. (by @alexander-akait in #21154)
Use value descriptors instead of getters for const export bindings. (by @xiaoxiaojx in #21021)
Reduce per-file overhead in ContextModuleFactory.resolveDependencies by batching alternativeRequests hook calls. Previously the hook was invoked once per file in the context (with a single-item array), paying per-call overhead (closure allocation, resolverFactory.get, intermediate arrays in RequireContextPlugin) for every file. The hook is now invoked once per directory with all matched files in one batch — RequireContextPlugin's tap already iterates the items array, so the output is unchanged. Steady-state rebuild on a 4000-file require.context drops a further ~15 ms (after the watch-mode purge fix in the same release). (by @alexander-akait in #21020)
Include each external info's runtimeCondition in ConcatenatedModule#updateHash so changes to a concatenated external's runtime condition invalidate persistent caches instead of slipping through with the module id alone. (by @alexander-akait in #21023)
Fix HTML [contenthash] for referenced asset and inline-style URL changes. (by @alexander-akait in #21018)
Resolve chunk-hash placeholders in chunk URLs embedded into extracted HTML. (by @alexander-akait in #21018)
Remove unnecessary __webpack_require__ runtime helpers in ESM library output with multi-module chunks. (by @xiaoxiaojx in #21032)
Rewrite NormalModule#getSideEffectsConnectionState walk as an allocation-light iterative loop instead of a generator trampoline, restoring rebuild performance lost in #20993 while keeping deep import chains stack-safe. (by @alexander-akait in #21014)
Fix runtime ReferenceError on the first activation of a lazy-compiled module when output.library.type produces a closure-wrapped bundle (umd, umd2, amd, amd-require, system). (by @alexander-akait in #21013)
External modules of these types reference closure-bound identifiers like __WEBPACK_EXTERNAL_MODULE_react__, supplied by the library wrapper that is generated once per chunk. When lazyCompilation activates an entry or import for the first time, any external dependency the lazily-built module pulls in arrives in a hot-update chunk that lives outside the original wrapper closure, so its factory body cannot resolve the closure identifier and only a manual page refresh recovers.
The inactive LazyCompilationProxyModule now declares statically-enumerable externals (string and object forms of externals) as its own dependencies, so the initial entry chunk's library wrapper already exposes their closure identifiers. When activation later pulls in those externals through the lazily-compiled module, they resolve to the already-installed factories instead of throwing. Function and RegExp externals are not pre-populated because their effective request set isn't knowable up front.
Fill in missing entryOptions when an async block joins an existing entrypoint. (by @alexander-akait in #21026)
Release per-child codeGenerationResults in MultiCompiler and at Compiler.close to reduce memory retention. (by @alexander-akait in #21015)
Fix slow require.context() / dynamic import() rebuilds in watch mode (#13636). When a file inside a watched context directory changed, NodeWatchFileSystem would call inputFileSystem.purge(contextDir). The enhanced-resolve purge implementation matches cache keys with key.startsWith(contextDir), so the stat cache of every file under the directory was discarded on every rebuild — ContextModuleFactory.resolveDependencies then re-stat-ed the whole tree on each rebuild. Single-file rebuilds on a 4000-file context now reuse the warm stat cache, dropping median rebuild from ~1260 ms to ~650 ms in a local reproduction (≈49%). For directory items that are explicitly watched contexts, purge is now called with { exact: true } (added in enhanced-resolve@5.22.0) so only the directory's own entry is invalidated; file-level changes in the same aggregated event continue to purge file stats and the parent readdir as before. (by @alexander-akait in #21020)
Align the experimental HTML tokenizer with the WHATWG spec: fix offset-range bugs in the script-data, content-mode end-tag, attribute-value, and EOF states; surface tokenizer parse errors to consumers via a new parseError callback ("warning" when the tokenizer recovers and the emitted token is still well-formed, "error" when the offset range is incomplete — e.g. eof-in-tag); and add the full WHATWG named character references table so decodeHtmlEntities handles all named entities (including legacy bare forms like & and multi-code-point entities like ≂̸) with proper longest-prefix backtracking. (by @alexander-akait in #21000)
Tree-shake CommonJS modules imported through a const NAME = require(LITERAL) binding when only static members of NAME are read. Previously webpack treated every export of such modules as referenced (because the bare require() dependency reports EXPORTS_OBJECT_REFERENCED), so unused exports.x = ... assignments remained in the bundle even with usedExports enabled. The parser now forwards NAME.x / NAME.x() / NAME["x"] accesses to the underlying CommonJsRequireDependency as referenced exports, falling back to the full exports object the moment NAME is read in any other context (passed by value, destructured later, accessed with a dynamic key, …). This brings the binding form to parity with the existing destructuring form (const { x } = require(...)). (by @alexander-akait in #21003)
Fix RangeError: Maximum call stack size exceeded thrown from HarmonyImportSideEffectDependency.getModuleEvaluationSideEffectsState on long linear chains of side-effect-free imports. NormalModule.getSideEffectsConnectionState previously descended through HarmonyImportSideEffectDependency.getModuleEvaluationSideEffectsState recursively, adding two stack frames per module, which overflowed V8's stack at a few thousand modules deep. The traversal is now iterative. (by @alexander-akait in #20993)
module.generator.html now uses HtmlGeneratorOptions instead of EmptyGeneratorOptions (the extract option was hidden from the createGenerator / generator hook types).
WebAssembly (webassembly/async, webassembly/sync) generator hooks now use EmptyGeneratorOptions instead of EmptyParserOptions.
NormalModuleFactory#getParser / createParser / getGenerator / createGenerator are now generic over the module-type string, returning the specific parser/generator class for known types (e.g. JavascriptParser for "javascript/auto", CssGenerator for "css", etc.) instead of always returning the base Parser / Generator.
NormalModuleCreateData is now generic over the module type so parser, parserOptions, generator, and generatorOptions are narrowed to the specific class / options for the given type.
Link import bindings used inside define(...) callbacks in ES modules. Previously, HarmonyDetectionParserPlugin skipped walking the arguments of define calls in harmony modules, so references to imported bindings inside an inline AMD define factory (e.g. define(function () { console.log(foo); })) were not rewritten to their imported references and could cause ReferenceError at runtime. Inner graph usage analysis is also fixed for the related pattern const fn = function () { foo; }; define(fn);. (by @alexander-akait in #20990)
HTML-entry pipeline (experiments.html + experiments.css): emit <link rel="stylesheet"> tags for CSS chunks reachable from a <script src> entry. Previously when the bundled JS imported CSS, the resulting .css file was emitted to disk but never referenced from the extracted HTML (no <link> tag), and when splitChunks extracted CSS into sibling chunks the HTML cloned the originating <script> for each one — producing <script src="style.js"> pointing at non-existent JS filenames instead of <link rel="stylesheet" href="style.css">. CSS chunks are now sorted by the entrypoint's module post-order index so the <link> tags also appear in source import order, fixing the cascade ordering issue documented in html-webpack-plugin#1838 and webpack/mini-css-extract-plugin#959 for HTML-entry builds. nonce/crossorigin/referrerpolicy are copied from the originating tag onto the emitted <link>. (by @alexander-akait in #21002)
Allow devtool and SourceMapDevToolPlugin (or multiple SourceMapDevToolPlugin instances) to coexist on the same asset. Previously the second instance would silently skip any asset whose info.related.sourceMap had already been set by an earlier instance, and even when it ran the asset had been rewrapped as a RawSource so no source map could be recovered — producing an empty .map file. The plugin now keeps a per-compilation stash of pristine source maps, namespaces its persistent cache entries by the options that affect output, and appends additional related.sourceMap entries instead of overwriting them. The classic workaround of pairing devtool: 'hidden-source-map' with a new webpack.SourceMapDevToolPlugin({ filename: '[file].secondary.map', noSources: true }) now produces both maps in a single build. (by @alexander-akait in #21001)
Narrow TemplatePathFn callback types by context. pathData.chunk is now non-optional for chunk filename callbacks (output.filename, chunkFilename, cssFilename, cssChunkFilename, htmlFilename, htmlChunkFilename, optimization.splitChunks.cacheGroups[*].filename), and pathData.module is non-optional for module filename callbacks (output.assetModuleFilename, per-module generator.filename / generator.outputPath, module.parser.css.localIdentName). (by @alexander-akait in #20987)
Tighten the CreateData typedef in NormalModuleFactory. CreateData now represents the fully-populated value passed to the createModule, module, and createModuleClass hooks (NormalModuleCreateData & { settings: ModuleSettings }), while ResolveData.createData is typed as Partial<CreateData> to reflect the empty initial state. Plugins tapping those hooks no longer need to cast individual fields away from optional. (by @alexander-akait in #20992)
Stop webpackPrefetch / webpackPreload magic comments from leaking across import() call sites that share a webpackChunkName. When two imports targeted the same named chunk and only one of them set webpackPrefetch: true, the prefetch directive was applied from every parent chunk that referenced the named chunk. Prefetch and preload orders are now resolved per import() call site instead of from the shared chunk group's accumulated options. (by @alexander-akait in #20994)
Fix [fullhash:N] and [hash:N] (with length suffix) in output.publicPath not being interpolated at runtime. The detection regex in RuntimePlugin only matched [fullhash] / [hash] without a length suffix, so the PublicPathRuntimeModule was not flagged as a full-hash module and __webpack_require__.p was emitted with the placeholder XXXX left in place (e.g. out/XXXX/) instead of the real hash truncated to the requested length. (by @alexander-akait in #21004)
Re-export ModuleNotFoundError from webpack/lib/ModuleNotFoundError for backward compatibility with old plugins that import it from that path. This re-export will be removed in webpack 6. (by @alexander-akait in #20988)
Add module.generator.javascript.anonymousDefaultExportName option to control whether webpack sets .name to "default" for anonymous default export functions and classes per ES spec. Defaults to true for applications and false for libraries (when output.library is set) to avoid unnecessary bundle size overhead. Also extract anonymous default export .name fix-up into a shared runtime helper (__webpack_require__.dn), replacing repeated inline Object.defineProperty / Object.getOwnPropertyDescriptor calls with a single short call per module to reduce output size. (by @xiaoxiaojx in #20894)
Support module concatenation (scope hoisting) for CSS modules with text, css-style-sheet, style, and link export types (by @xiaoxiaojx in #20851)
The generator.exportsConvention function form for CSS modules now accepts string[] in addition to string. (by @alexander-akait in #20914)
Add linkInsert hook to CssLoadingRuntimeModule.getCompilationHooks(compilation) so plugin developers can control where stylesheet <link> elements are inserted into the document. (by @alexander-akait in #20947)
Add CssModulesPlugin.getCompilationHooks(compilation).orderModules hook. (by @alexander-akait in #20978)
Add a pure parser option for css/module and css/auto types matching postcss-modules-local-by-default's pure mode: every selector must contain at least one local class or id, otherwise webpack emits a build error. (by @alexander-akait in #20946)
Support CSS Modules @value identifiers as @import URLs and inside url() functions, e.g. @value path: "./other.css"; @​import path; and @value bg: "./image.png"; .a { background: url(bg); } (by @alexander-akait in #20925)
Add experimental TypeScript support via experiments.typescript: true (auto-enabled by experiments.futureDefaults). Uses Node.js's built-in module.stripTypeScriptTypes (Node.js >= 22.6 with the stable mode: "strip" API, including Node.js 26) to transform .ts, .cts, .mts, data:text/typescript, and data:application/typescript modules — no type checking, only erasable TypeScript (types, generics, import type, casts). .tsx/JSX and non-erasable syntax (enum, namespace, parameter-property constructors, decorator metadata) are NOT supported; use a TSX-capable loader (e.g. ts-loader, swc-loader) for those. (by @alexander-akait in #20964)
Added an experiments.html flag that reserves the html module type for the first-class HTML entry-point support. (by @aryanraj45 in #20902)
Preserve defer / source import phase keywords on external dependencies in ESM output, the same way import attributes are preserved. (by @alexander-akait in #20934)
Support the #__NO_SIDE_EFFECTS__ annotation to mark functions as pure for better tree-shaking. (by @hai-x in #20775)
Add module.generator.html.extract for HTML modules and the matching output.htmlFilename / output.htmlChunkFilename filename templates (defaults derived from output.filename / output.chunkFilename with .js swapped for .html, mirroring the CSS pipeline). When extraction is on, the parsed and URL-rewritten HTML is emitted as a standalone .html output file alongside the module's JavaScript export. (by @alexander-akait in #20979)
Add "module-sync" to default conditionNames for resolver defaults to align with Node.js, which exposes the module-sync community condition for synchronously-loadable ESM. (by @alexander-akait in #20933)
Patch Changes
Fix CSS modules composes so composes: foo from "./self.module.css" from inside self.module.css no longer creates a duplicate module instance. Fix CSS modules composes parsing so local() and global() function wrappers are tracked per class name. Fix CSS modules composes: ... from "<file>" so the composed files load in an order consistent with every rule's local composes order, instead of source first-appearance order. (by @alexander-akait in #20929)
Avoid emitting the __webpack_require__ runtime in CSS bundles when all imported CSS modules were concatenated into the same scope. (by @alexander-akait in #20936)
Recompute the CSS chunk's [contenthash] and the rendered CSS bytes when an asset referenced by url()/src()/string in CSS changes its hashed filename. (by @alexander-akait in #20938)
Embed an inline sourceMappingURL data URI inside the CSS when the parser.exportType option are text, style, or css-style-sheet. Also merge @imported CSS at build time for text and css-style-sheet exportTypes so the bundle ships a single accurate inline source map covering every contributing file. Map each generated CSS-module class export line in the JS bundle back to its selector position in the original CSS file (e.g. btn: "..." → .btn { ... }). (by @alexander-akait in #20886)
Fix CSS modules deduplication so a .module.<ext> file imported both directly (JS) and via icss (composes from / :import) becomes a single module instance. (by @alexander-akait in #20929)
Preserve @charset at-rule when CSS modules use exportType: "text". (by @alexander-akait in #20912)
Resolve [hash]/[fullhash] placeholders in output.publicPath when generating url() references for experiments.css. (by @alexander-akait in #20879)
Fix HMR for concatenated CSS modules with style exportType by using stable per-module identifiers for injected style elements and tracking inner module IDs of concatenated modules in HMR records (by @xiaoxiaojx in #20911)
Fix CSS Modules @value resolution when the same local name is imported from multiple modules. (by @alexander-akait in #20940)
Fix typeof ns.default / ns.default instanceof X on a static import defer * as ns from "./mod" for default-only and default-with-named external modules under optimization.concatenateModules. The concatenated-module rewrite was
✂ Note
PR body was truncated to here.
Configuration
📅 Schedule: (UTC)
Branch creation
At any time (no schedule defined)
Automerge
At any time (no schedule defined)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
If you want to rebase/retry this PR, check this box
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/baseline-browser-mapping@2.10.43. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
Block
Recently published: npm browserslist published 34 minutes ago
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/browserslist@4.28.6. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
Block
Recently published: npm caniuse-lite published 33 minutes ago
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/caniuse-lite@1.0.30001805. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
renovateBot
changed the title
chore(deps): update dependency webpack to v5.108.3
chore(deps): update dependency webpack to v5.108.4
Jul 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.104.1→5.108.4Release Notes
webpack/webpack (webpack)
v5.108.4Compare Source
Patch Changes
Speed up non-CSS-Modules parsing by not building unused selector AST nodes. (by @alexander-akait in #21324)
Speed up non-CSS-Modules CSS parsing by dropping value tokens nothing reads. (by @alexander-akait in #21324)
Resolve HTML asset URLs against the document
<base href>. (by @alexander-akait in #21329)Add HTML integration tests: generateError output, ignored src, null-char parse. (by @aryanraj45 in #21328)
Reduce CPU and memory overhead of HTML and CSS parsing and code generation. (by @alexander-akait in #21332)
Reduce HTML parser memory and CPU by skipping unused AST nodes. (by @alexander-akait in #21323)
Reduce HTML parser memory by storing the AST in struct-of-arrays form. (by @alexander-akait in #21331)
Key the provided-exports cache on a lazy barrel's still-lazy re-export targets. (by @hai-x in #21326)
Default
output.globalObjecttoglobalThisfor universal targets. (by @alexander-akait in #21314)Pass through
new URL(...)directory references instead of resolving them. (by @alexander-akait in #21312)v5.108.3Compare Source
Patch Changes
Speed up CSS parsing and reduce CSS AST node memory. (by @alexander-akait in #21285)
Fix HMR codegen crash for harmony accept with unresolved imports. (by @xiaoxiaojx in #21302)
Match harmony accept dependencies by module reference so HMR codegen handles imports without a module or chunk id. (by @alexander-akait in #21303)
v5.108.2Compare Source
Patch Changes
Fix lazy barrel deferral of ungrouped side-effect imports. (by @hai-x in #21291)
Respect the
node:prefix for node.js core modules used as externals. (by @alexander-akait in #21286)v5.108.1Compare Source
Patch Changes
Fix invalid property access for escaped namespace imports with multi-character mangled export names. (by @xiaoxiaojx in #21280)
Add frames to ProfilingPlugin TracingStartedInBrowser event so the trace loads in Chrome DevTools. (by @alexander-akait in #21269)
v5.108.0Compare Source
Minor Changes
Treat top-level await and
import.metaas ES module markers, matching Node.js syntax detection so no explicit module type is needed. (by @alexander-akait in #21218)Add a
buntarget that emits ESM and externalizesbun:*and node.js built-in modules. (by @alexander-akait in #21248)Support CommonJS reexports via
Object.definePropertyvalue and getter descriptors. (by @alexander-akait in #21129)Support JSON Schema
constwhen generating CLI flags from a schema. (by @alexander-akait in #21087)Support JSON Schema
if/then/elsewhen generating CLI flags from a schema. (by @alexander-akait in #21087)Skip import specifiers,
require()andimport()calls in dead conditional branches gated by inlined imported constants (isDEV ? A : B), evaluated viagetCondition. (by @hai-x in #21136)CSS
localIdentName[hash]now resolves to the local ident hash (matching css-loader); use[modulehash]for the module hash. (by @alexander-akait in #21259)Add CSS parser
asoption and resolveurl()inside HTMLstyleattributes. (by @alexander-akait in #21157)Add dedicated module classes for all built-in module types. (by @alexander-akait in #21164)
Support
.html/.cssfor the default./srcentry under the html/css experiments. (by @alexander-akait in #21039)Add
defineConfighelper for typed configuration files. (by @alexander-akait in #21169)Add a
denotarget (with versions, e.g.deno,deno2,deno1.40) that emits ESM, resolves node.js built-ins via the requirednode:specifier, and keeps Deno's own import protocols (npm:,jsr:,node:,http(s)://) external. (by @alexander-akait in #21247)Use
module-importfor electron externals when the target supports ESM. (by @alexander-akait in #21184)Add
output.environment.logicalAssignmentto emit||=in runtime code when the target supports logical assignment operators. (by @bjohansebas in #21219)Resolve and rewrite asset URLs inside
<iframe srcdoc>in HTML modules. (by @bjohansebas in #21226)Add HMR support for HTML modules with body/title DOM patching on update. (by @alexander-akait in #21011)
Add
css-urlhtml source type extractingurl()references from CSS-valued attributes. (by @alexander-akait in #21250)Add
module.parser.html.sourcesoption to disable or customize URL-attribute extraction for HTML modules, withscript/script-module/stylesheet/stylesheet-inlinetypes for custom attributes (by @alexander-akait in #21022)Add
module.parser.html.templateoption to transform HTML module source before parsing. (by @alexander-akait in #21055)Extract more source URLs in HTML modules (SVG, legacy and obsolete attributes). (by @alexander-akait in #21241)
Inline
export default <const>when the default-exported value is a primitive constant. (by @hai-x in #21189)Support
optimization.inlineExportsfor better tree-shaking. (by @hai-x in #20973)Re-encode inline hash digests (
[contenthash]/[chunkhash]/[fullhash]/[modulehash]) from the full content hash, so they carry full entropy and work underoptimization.realContentHashand in dynamically-loaded chunk filenames; also preserve leading zero bytes in base-N digests. (by @alexander-akait in #21267)Allow tree-shaking unused calls to
/*#__NO_SIDE_EFFECTS__*/-annotated (pure) exports across module boundaries. (by @hai-x in #20907)Defer building unused re-export targets of side-effect-free barrel modules. (by @hai-x in #21165)
Keep export mangling enabled for modules whose namespace object is used as a whole value, by materializing a decoupled namespace object that keeps the original export names. (by @alexander-akait in #21234)
Add
output.environment.letoption (paired with target'sletcapability) and emitlet/constinstead ofvarin generated runtime code wherever it is safe. Bindings that may be wrapped in runtime-conditionifblocks (harmony imports, ConcatenatedModule external imports) continue to usevarto preserve function scoping. (by @alexander-akait in #21010)Add
output.htmlto emit an HTML file per entrypoint, injecting its JS/CSS chunks (includingdependOnshared chunks). (by @alexander-akait in #21215)Add
module.parser.javascript.pureFunctionsto mark top-level names as side-effect-free for tree shaking. (by @hai-x in #21063)Add
universaltocompiler.platform, true for universal targets ("universal"or["web", "node"]). (by @bjohansebas in #21252)Add
output.strictModuleResolutionto gate the runtimeMODULE_NOT_FOUNDguard. (by @hai-x in #21067)Support an inline digest in hash path placeholders, e.g.
[contenthash:base64:8]. (by @alexander-akait in #21259)Support
[uniqueName]and its[uniquename]alias in template paths. (by @alexander-akait in #21155)Support CSS in Node for universal targets, collecting styles for SSR. (by @alexander-akait in #21208)
Improve commonjs, node-commonjs and global externals for universal targets. (by @alexander-akait in #21187)
Add a
universaltarget preset (browser + web worker + Node.js + Electron + NW.js) that always outputs ECMAScript modules. (by @alexander-akait in #21214)Support
new Worker(new URL(...))in universal (node + web) targets by resolving the Worker constructor fromworker_threadswhen no globalWorkerexists. (by @alexander-akait in #21195)Add
output.workerChunkFilenameandentry.workerfor worker chunk filenames. (by @alexander-akait in #21128)Patch Changes
Skip re-parsing the inlined entry module when no renaming is needed. (by @alexander-akait in #21167)
Extend the avoidEntryIife no-parse fast path to multi-entry chunks. (by @alexander-akait in #21173)
Reuse the binary deserialize dispatch table to speed up cache restore. (by @alexander-akait in #21175)
Type
buildInfoandbuildMetaper module type with shared common properties. (by @alexander-akait in #21172)Avoid copying module runtime requirements when ownership is not transferred. (by @alexander-akait in #21140)
Keep all CommonJS exports when an exported function accesses them via
this. (by @alexander-akait in #21179)Align CLI color-support detection across Node, Deno and Bun. (by @alexander-akait in #21257)
Include the schema origin path in conflicting-schema CLI argument errors. (by @alexander-akait in #21087)
Reject
__proto__,constructorandprototypepath segments incli.processArgumentsto prevent prototype pollution. (by @alexander-akait in #21057)Speed up
Compilation.deleteAssetandCompilation.renameAssetvia a lazy reverse index from asset file name to containing chunks. (by @alexander-akait in #21035)Fix merging of inner modules' top-level declarations in concatenated modules. (by @alexander-akait in #21170)
Reduce allocations in export hashing and concatenation name lookups. (by @alexander-akait in #21167)
Avoid toLowerCase allocations in CSS keyword comparisons. (by @alexander-akait in #21109)
Speed up CSS identifier escaping with a char-class lookup table. (by @alexander-akait in #21109)
Resolve
[fullhash]inurl()public paths for inlined CSS export types (style/text/css-style-sheet) at runtime. (by @alexander-akait in #21054)Avoid quadratic line scan when building CSS module exports source maps. (by @alexander-akait in #21109)
Compute CSS comment source locations lazily. (by @alexander-akait in #21109)
Support inline hash digest and length in CSS module
localIdentNameplaceholders. (by @alexander-akait in #21259)Resolve full CSS escapes (including hex) in CSS-Modules names, so e.g.
\75 rl()matchesurl(). (by @alexander-akait in #21196)Reduce CSS parser CPU (hoisted per-call regexes, byte-compared
@containerpure-mode keywords) and stop retaining parsed comments on the reused parser instance between modules. (by @alexander-akait in #21202)Reduce CSS build time and memory usage. Per-export CSS dependencies are consolidated into one dependency per module, and hot-path allocations and lookups in CSS code generation and the module-graph cache are trimmed. (by @alexander-akait in #21114)
Cache CSS public-path placeholder offsets per module source to avoid re-materializing and re-scanning the source on every render. (by @alexander-akait in #21054)
Fix CSS tokenizer infinite loops and dropped tokens on malformed input. (by @alexander-akait in #21102)
Speed up CSS identifier unescaping with bulk run flushing. (by @alexander-akait in #21109)
Skip already-visited symlink targets when resolving context hashes so cyclic symlink graphs no longer overflow the queue. (by @alexander-akait in #21088)
Resolve
DefinePluginaccess to an undefined object member asundefined. (by @alexander-akait in #21040)Avoid materializing dependency source locations when sorting, keeping them lazy to reduce build time and memory. (by @alexander-akait in #21228)
Speed up serialization deserialize by replacing a Buffer.isBuffer call with a typeof check. (by @hai-x in #21203)
Emit assets with absolute target paths as-is to avoid invalid Windows paths. (by @alexander-akait in #21223)
Add
output.environment.spread,output.environment.hasOwn, andoutput.environment.symbol, and use method shorthand, spread,Object.hasOwn, and an unguardedSymbolin generated runtime code where the environment supports it. (by @alexander-akait in #21188)Drop the unused loadScript runtime from ESM hot-update bundles. (by @alexander-akait in #21208)
Extend value binding optimization to export default expressions. (by @xiaoxiaojx in #21117)
Reduce ExportInfo memory and cache size for inline-exports metadata. (by @alexander-akait in #21171)
Resolve nested exports info paths iteratively to cut per-level array allocations. (by @alexander-akait in #21137)
Fix stale incremental cache for css, html and asset/source/inline modules. (by @alexander-akait in #21108)
CommonJS tree-shaking no longer drops exports accessed before a deferred require binding. (by @xiaoxiaojx in #21123)
Make CSS-referenced asset available in lazy JS chunk during incremental rebuilds. (by @alexander-akait in #21100)
Correct string/template import specifier parsing for filesystem cache build dependencies and fix module-sharing hostname validation. (by @alexander-akait in #21232)
perf: guard isDeferred() behind experiments.deferImport in ConcatenatedModule (by @shashank-u03 in #21096)
Speed up deterministicGrouping and cached comparators on large builds. (by @alexander-akait in #21197)
Reduce allocations on harmony/commonjs dependency hot paths. (by @alexander-akait in #21180)
Force-load a module's new owning chunk during HMR when its only loaded chunk is removed from a runtime, so it keeps receiving updates. (by @alexander-akait in #21131)
Fix HTML parser adoption agency to handle a
nobrshielded by a marker. (by @alexander-akait in #21274)Expand HTML parser tag/attribute coverage and decode character references. (by @alexander-akait in #21159)
Speed up and reduce allocations in the experimental HTML parser's tokenizer, tree builder, and entity decoder. (by @alexander-akait in #21152)
Speed up the experimental HTML parser and reduce its memory usage. (by @alexander-akait in #21130)
Avoid redundant HTML module work: reuse the dependency-template render across the JS and HTML code-generation passes, and memoize sentinel resolution/content hashing per source. (by @alexander-akait in #21054)
Release inner-graph state after use and speed up inlined-export checks. (by @alexander-akait in #21167)
Reduce JavascriptParser allocations on the walk hot path to speed up parsing and lower memory usage. (by @alexander-akait in #21139)
Reduce CPU and memory overhead of the lazy barrel optimization. (by @alexander-akait in #21213)
Keep the error message in module build errors on engines whose
Error.stackomits it. (by @alexander-akait in #21239)Speed up module concatenation by caching repeated per-module computations. (by @alexander-akait in #21115)
Move the
hotflag fromModuletoNormalModule, where it's actually read and written. (by @alexander-akait in #21028)Move the
weakflag fromDependencytoModuleDependency, where it's actually set. (by @alexander-akait in #21111)Avoid the entry IIFE for multiple inlined entry modules by renaming collisions. (by @alexander-akait in #21151)
Reject
new import.defer(...)/new import.source(...)with member access as a SyntaxError. (by @alexander-akait in #21211)Avoid
ProvidePlugininjection for local CommonJS require bindings that use the same variable name. (by @fireairforce in #21041)Resolve the global
new Worker(new URL(...))toworker_threadson thenodetarget. (by @alexander-akait in #21217)Use optional chaining in generated runtime code where the environment supports it. (by @alexander-akait in #21186)
Allow output.path to be the filesystem root by treating EISDIR like EEXIST in mkdirp. (by @alexander-akait in #21223)
Reduce memory by not retaining the source location object on every dependency. (by @alexander-akait in #21183)
Keep the full exports object when a
require()binding is re-exported. (by @alexander-akait in #21144)Replace glob-to-regexp dependency with watchpack's globToRegExp utility. (by @hai-x in #21176)
Shrink the persistent cache: add a NULL_AND_I16 binary tier and inline tiny strings instead of larger far back-references. (by @hai-x in #21210)
Type serializer read/write contexts with positional tuples and fix a ProvideSharedDependency version/request swap. (by @alexander-akait in #21201)
Speed up buildChunkGraph by deriving block modules from the first runtime. (by @alexander-akait in #21166)
Cache re-export target resolution in SideEffectsFlagPlugin for faster builds. (by @alexander-akait in #21085)
Skip pure single-star passthrough modules for
export *re-exports. (by @alexander-akait in #21085)Skip dependency error/warning reporting for unchanged modules on rebuilds. (by @alexander-akait in #21154)
Use value descriptors instead of getters for const export bindings. (by @xiaoxiaojx in #21021)
Apply CSS hot updates on the Node side of a universal target. (by @alexander-akait in #21217)
Guard CSS
styleexport-type injection so it no-ops when there is nodocument. (by @alexander-akait in #21193)Avoid building warning stats objects when counting warnings without a filter. (by @alexander-akait in #21198)
Recognize forward-slash Windows absolute paths (e.g. C:/dir) consistently. (by @alexander-akait in #21223)
v5.107.2Compare Source
Patch Changes
Reduce per-file overhead in
ContextModuleFactory.resolveDependenciesby batchingalternativeRequestshook calls. Previously the hook was invoked once per file in the context (with a single-item array), paying per-call overhead (closure allocation,resolverFactory.get, intermediate arrays inRequireContextPlugin) for every file. The hook is now invoked once per directory with all matched files in one batch —RequireContextPlugin's tap already iterates the items array, so the output is unchanged. Steady-state rebuild on a 4000-filerequire.contextdrops a further ~15 ms (after the watch-mode purge fix in the same release). (by @alexander-akait in #21020)Include each external info's
runtimeConditioninConcatenatedModule#updateHashso changes to a concatenated external's runtime condition invalidate persistent caches instead of slipping through with the module id alone. (by @alexander-akait in #21023)Fix HTML
[contenthash]for referenced asset and inline-style URL changes. (by @alexander-akait in #21018)Resolve chunk-hash placeholders in chunk URLs embedded into extracted HTML. (by @alexander-akait in #21018)
Remove unnecessary
__webpack_require__runtime helpers in ESM library output with multi-module chunks. (by @xiaoxiaojx in #21032)Rewrite
NormalModule#getSideEffectsConnectionStatewalk as an allocation-light iterative loop instead of a generator trampoline, restoring rebuild performance lost in #20993 while keeping deep import chains stack-safe. (by @alexander-akait in #21014)Fix runtime
ReferenceErroron the first activation of a lazy-compiled module whenoutput.library.typeproduces a closure-wrapped bundle (umd,umd2,amd,amd-require,system). (by @alexander-akait in #21013)External modules of these types reference closure-bound identifiers like
__WEBPACK_EXTERNAL_MODULE_react__, supplied by the library wrapper that is generated once per chunk. WhenlazyCompilationactivates an entry or import for the first time, any external dependency the lazily-built module pulls in arrives in a hot-update chunk that lives outside the original wrapper closure, so its factory body cannot resolve the closure identifier and only a manual page refresh recovers.The inactive
LazyCompilationProxyModulenow declares statically-enumerable externals (string and object forms ofexternals) as its own dependencies, so the initial entry chunk's library wrapper already exposes their closure identifiers. When activation later pulls in those externals through the lazily-compiled module, they resolve to the already-installed factories instead of throwing. Function and RegExp externals are not pre-populated because their effective request set isn't knowable up front.Fill in missing
entryOptionswhen an async block joins an existing entrypoint. (by @alexander-akait in #21026)Release per-child
codeGenerationResultsinMultiCompilerand atCompiler.closeto reduce memory retention. (by @alexander-akait in #21015)Reduce peak memory of
SourceMapDevToolPluginon large builds (closes #20961). (by @alexander-akait in #20963)Fix slow
require.context()/ dynamicimport()rebuilds in watch mode (#13636). When a file inside a watched context directory changed,NodeWatchFileSystemwould callinputFileSystem.purge(contextDir). The enhanced-resolvepurgeimplementation matches cache keys withkey.startsWith(contextDir), so the stat cache of every file under the directory was discarded on every rebuild —ContextModuleFactory.resolveDependenciesthen re-stat-ed the whole tree on each rebuild. Single-file rebuilds on a 4000-file context now reuse the warm stat cache, dropping median rebuild from ~1260 ms to ~650 ms in a local reproduction (≈49%). For directory items that are explicitly watched contexts,purgeis now called with{ exact: true }(added inenhanced-resolve@5.22.0) so only the directory's own entry is invalidated; file-level changes in the same aggregated event continue to purge file stats and the parentreaddiras before. (by @alexander-akait in #21020)v5.107.1Compare Source
Patch Changes
Align the experimental HTML tokenizer with the WHATWG spec: fix offset-range bugs in the script-data, content-mode end-tag, attribute-value, and EOF states; surface tokenizer parse errors to consumers via a new
parseErrorcallback ("warning"when the tokenizer recovers and the emitted token is still well-formed,"error"when the offset range is incomplete — e.g.eof-in-tag); and add the full WHATWG named character references table sodecodeHtmlEntitieshandles all named entities (including legacy bare forms like&and multi-code-point entities like≂̸) with proper longest-prefix backtracking. (by @alexander-akait in #21000)Tree-shake CommonJS modules imported through a
const NAME = require(LITERAL)binding when only static members ofNAMEare read. Previously webpack treated every export of such modules as referenced (because the barerequire()dependency reportsEXPORTS_OBJECT_REFERENCED), so unusedexports.x = ...assignments remained in the bundle even withusedExportsenabled. The parser now forwardsNAME.x/NAME.x()/NAME["x"]accesses to the underlyingCommonJsRequireDependencyas referenced exports, falling back to the full exports object the momentNAMEis read in any other context (passed by value, destructured later, accessed with a dynamic key, …). This brings the binding form to parity with the existing destructuring form (const { x } = require(...)). (by @alexander-akait in #21003)Fix
RangeError: Maximum call stack size exceededthrown fromHarmonyImportSideEffectDependency.getModuleEvaluationSideEffectsStateon long linear chains of side-effect-free imports.NormalModule.getSideEffectsConnectionStatepreviously descended throughHarmonyImportSideEffectDependency.getModuleEvaluationSideEffectsStaterecursively, adding two stack frames per module, which overflowed V8's stack at a few thousand modules deep. The traversal is now iterative. (by @alexander-akait in #20993)Fix
NormalModuleFactoryparser/generator types: (by @alexander-akait in #20999)module.generator.htmlnow usesHtmlGeneratorOptionsinstead ofEmptyGeneratorOptions(theextractoption was hidden from thecreateGenerator/generatorhook types).webassembly/async,webassembly/sync) generator hooks now useEmptyGeneratorOptionsinstead ofEmptyParserOptions.NormalModuleFactory#getParser/createParser/getGenerator/createGeneratorare now generic over the module-type string, returning the specific parser/generator class for known types (e.g.JavascriptParserfor"javascript/auto",CssGeneratorfor"css", etc.) instead of always returning the baseParser/Generator.NormalModuleCreateDatais now generic over the module type soparser,parserOptions,generator, andgeneratorOptionsare narrowed to the specific class / options for the giventype.Link import bindings used inside
define(...)callbacks in ES modules. Previously,HarmonyDetectionParserPluginskipped walking the arguments ofdefinecalls in harmony modules, so references to imported bindings inside an inline AMDdefinefactory (e.g.define(function () { console.log(foo); })) were not rewritten to their imported references and could causeReferenceErrorat runtime. Inner graph usage analysis is also fixed for the related patternconst fn = function () { foo; }; define(fn);. (by @alexander-akait in #20990)HTML-entry pipeline (
experiments.html+experiments.css): emit<link rel="stylesheet">tags for CSS chunks reachable from a<script src>entry. Previously when the bundled JS imported CSS, the resulting.cssfile was emitted to disk but never referenced from the extracted HTML (no<link>tag), and whensplitChunksextracted CSS into sibling chunks the HTML cloned the originating<script>for each one — producing<script src="style.js">pointing at non-existent JS filenames instead of<link rel="stylesheet" href="style.css">. CSS chunks are now sorted by the entrypoint's module post-order index so the<link>tags also appear in source import order, fixing the cascade ordering issue documented inhtml-webpack-plugin#1838andwebpack/mini-css-extract-plugin#959for HTML-entry builds.nonce/crossorigin/referrerpolicyare copied from the originating tag onto the emitted<link>. (by @alexander-akait in #21002)Allow
devtoolandSourceMapDevToolPlugin(or multipleSourceMapDevToolPlugininstances) to coexist on the same asset. Previously the second instance would silently skip any asset whoseinfo.related.sourceMaphad already been set by an earlier instance, and even when it ran the asset had been rewrapped as aRawSourceso no source map could be recovered — producing an empty.mapfile. The plugin now keeps a per-compilation stash of pristine source maps, namespaces its persistent cache entries by the options that affect output, and appends additionalrelated.sourceMapentries instead of overwriting them. The classic workaround of pairingdevtool: 'hidden-source-map'with anew webpack.SourceMapDevToolPlugin({ filename: '[file].secondary.map', noSources: true })now produces both maps in a single build. (by @alexander-akait in #21001)Narrow
TemplatePathFncallback types by context.pathData.chunkis now non-optional for chunk filename callbacks (output.filename,chunkFilename,cssFilename,cssChunkFilename,htmlFilename,htmlChunkFilename,optimization.splitChunks.cacheGroups[*].filename), andpathData.moduleis non-optional for module filename callbacks (output.assetModuleFilename, per-modulegenerator.filename/generator.outputPath,module.parser.css.localIdentName). (by @alexander-akait in #20987)Tighten the
CreateDatatypedef inNormalModuleFactory.CreateDatanow represents the fully-populated value passed to thecreateModule,module, andcreateModuleClasshooks (NormalModuleCreateData & { settings: ModuleSettings }), whileResolveData.createDatais typed asPartial<CreateData>to reflect the empty initial state. Plugins tapping those hooks no longer need to cast individual fields away from optional. (by @alexander-akait in #20992)Stop
webpackPrefetch/webpackPreloadmagic comments from leaking acrossimport()call sites that share awebpackChunkName. When two imports targeted the same named chunk and only one of them setwebpackPrefetch: true, the prefetch directive was applied from every parent chunk that referenced the named chunk. Prefetch and preload orders are now resolved perimport()call site instead of from the shared chunk group's accumulated options. (by @alexander-akait in #20994)Fix
[fullhash:N]and[hash:N](with length suffix) inoutput.publicPathnot being interpolated at runtime. The detection regex inRuntimePluginonly matched[fullhash]/[hash]without a length suffix, so thePublicPathRuntimeModulewas not flagged as a full-hash module and__webpack_require__.pwas emitted with the placeholderXXXXleft in place (e.g.out/XXXX/) instead of the real hash truncated to the requested length. (by @alexander-akait in #21004)Re-export
ModuleNotFoundErrorfromwebpack/lib/ModuleNotFoundErrorfor backward compatibility with old plugins that import it from that path. This re-export will be removed in webpack 6. (by @alexander-akait in #20988)v5.107.0Compare Source
Minor Changes
Add
module.generator.javascript.anonymousDefaultExportNameoption to control whether webpack sets.nameto"default"for anonymous default export functions and classes per ES spec. Defaults totruefor applications andfalsefor libraries (whenoutput.libraryis set) to avoid unnecessary bundle size overhead. Also extract anonymous default export.namefix-up into a shared runtime helper (__webpack_require__.dn), replacing repeated inlineObject.defineProperty/Object.getOwnPropertyDescriptorcalls with a single short call per module to reduce output size. (by @xiaoxiaojx in #20894)Support module concatenation (scope hoisting) for CSS modules with
text,css-style-sheet,style, andlinkexport types (by @xiaoxiaojx in #20851)The
generator.exportsConventionfunction form for CSS modules now acceptsstring[]in addition tostring. (by @alexander-akait in #20914)Add
linkInserthook toCssLoadingRuntimeModule.getCompilationHooks(compilation)so plugin developers can control where stylesheet<link>elements are inserted into the document. (by @alexander-akait in #20947)Add
CssModulesPlugin.getCompilationHooks(compilation).orderModuleshook. (by @alexander-akait in #20978)Add a
pureparser option forcss/moduleandcss/autotypes matchingpostcss-modules-local-by-default's pure mode: every selector must contain at least one local class or id, otherwise webpack emits a build error. (by @alexander-akait in #20946)Support CSS Modules
@valueidentifiers as@importURLs and insideurl()functions, e.g.@value path: "./other.css"; @​import path;and@value bg: "./image.png"; .a { background: url(bg); }(by @alexander-akait in #20925)Add experimental TypeScript support via
experiments.typescript: true(auto-enabled byexperiments.futureDefaults). Uses Node.js's built-inmodule.stripTypeScriptTypes(Node.js >= 22.6 with the stablemode: "strip"API, including Node.js 26) to transform.ts,.cts,.mts,data:text/typescript, anddata:application/typescriptmodules — no type checking, only erasable TypeScript (types, generics,import type, casts)..tsx/JSX and non-erasable syntax (enum,namespace, parameter-property constructors, decorator metadata) are NOT supported; use a TSX-capable loader (e.g.ts-loader,swc-loader) for those. (by @alexander-akait in #20964)Added an
experiments.htmlflag that reserves thehtmlmodule type for the first-class HTML entry-point support. (by @aryanraj45 in #20902)Preserve
defer/sourceimport phase keywords on external dependencies in ESM output, the same way import attributes are preserved. (by @alexander-akait in #20934)Support the
#__NO_SIDE_EFFECTS__annotation to mark functions as pure for better tree-shaking. (by @hai-x in #20775)Add
module.generator.html.extractfor HTML modules and the matchingoutput.htmlFilename/output.htmlChunkFilenamefilename templates (defaults derived fromoutput.filename/output.chunkFilenamewith.jsswapped for.html, mirroring the CSS pipeline). When extraction is on, the parsed and URL-rewritten HTML is emitted as a standalone.htmloutput file alongside the module's JavaScript export. (by @alexander-akait in #20979)Add
"module-sync"to defaultconditionNamesfor resolver defaults to align with Node.js, which exposes themodule-synccommunity condition for synchronously-loadable ESM. (by @alexander-akait in #20933)Patch Changes
Fix CSS modules
composessocomposes: foo from "./self.module.css"from insideself.module.cssno longer creates a duplicate module instance. Fix CSS modulescomposesparsing solocal()andglobal()function wrappers are tracked per class name. Fix CSS modulescomposes: ... from "<file>"so the composed files load in an order consistent with every rule's local composes order, instead of source first-appearance order. (by @alexander-akait in #20929)Avoid emitting the
__webpack_require__runtime in CSS bundles when all imported CSS modules were concatenated into the same scope. (by @alexander-akait in #20936)Recompute the CSS chunk's
[contenthash]and the rendered CSS bytes when an asset referenced byurl()/src()/string in CSS changes its hashed filename. (by @alexander-akait in #20938)Embed an inline
sourceMappingURLdata URI inside the CSS when theparser.exportTypeoption aretext,style, orcss-style-sheet. Also merge@imported CSS at build time fortextandcss-style-sheetexportTypes so the bundle ships a single accurate inline source map covering every contributing file. Map each generated CSS-module class export line in the JS bundle back to its selector position in the original CSS file (e.g.btn: "..."→.btn { ... }). (by @alexander-akait in #20886)Fix CSS modules deduplication so a
.module.<ext>file imported both directly (JS) and via icss (composes from/:import) becomes a single module instance. (by @alexander-akait in #20929)Preserve
@charsetat-rule when CSS modules useexportType: "text". (by @alexander-akait in #20912)Resolve
[hash]/[fullhash]placeholders inoutput.publicPathwhen generatingurl()references forexperiments.css. (by @alexander-akait in #20879)Fix HMR for concatenated CSS modules with
styleexportType by using stable per-module identifiers for injected style elements and tracking inner module IDs of concatenated modules in HMR records (by @xiaoxiaojx in #20911)Fix CSS Modules
@valueresolution when the same local name is imported from multiple modules. (by @alexander-akait in #20940)Fix
typeof ns.default/ns.default instanceof Xon a staticimport defer * as ns from "./mod"fordefault-onlyanddefault-with-namedexternal modules underoptimization.concatenateModules. The concatenated-module rewrite wasConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.