Skip to content

Bump webpack-dev-server from 5.2.4 to 5.2.6 in /components/dash-table in the npm-dependencies-security group across 1 directory - #3868

Closed
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/components/dash-table/npm-dependencies-security-b2fd70aae3
Closed

dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/components/dash-table/npm-dependencies-security-b2fd70aae3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-dependencies-security group with 1 update in the /components/dash-table directory: webpack-dev-server.

Updates webpack-dev-server from 5.2.4 to 5.2.6

Release notes

Sourced from webpack-dev-server's releases.

v5.2.6

Patch Changes

  • fix: allow undefined as the Server constructor options argument again (by @​bjohansebas in #5695)

    Restores accepting undefined (defaulting it to {}) for the options argument, so passing a webpack config's optional devServer field type-checks and works as before.

  • Protect the built-in state-changing routes (/webpack-dev-server/invalidate and /webpack-dev-server/open-editor) against cross-site request forgery. Requests are now checked with Sec-Fetch-Site (falling back to an Origin/Host comparison when it is absent), so a cross-site page can no longer trigger a rebuild or open a file in the editor. Same-origin requests, user-initiated navigations, and non-browser clients (e.g. curl) are unaffected. (by @​bjohansebas in #5698)

  • Handle malformed Host and Origin header values gracefully when validating requests. (by @​bjohansebas in #5699)

v5.2.5

Patch Changes

  • Skip the HMR WebSocket path when forwarding upgrade requests to user-defined proxies, so custom proxy WebSocket upgrades are no longer intercepted by the dev server. (by @​bjohansebas in #5680)
Changelog

Sourced from webpack-dev-server's changelog.

5.2.6

Patch Changes

  • fix: allow undefined as the Server constructor options argument again (by @​bjohansebas in #5695)

    Restores accepting undefined (defaulting it to {}) for the options argument, so passing a webpack config's optional devServer field type-checks and works as before.

  • Protect the built-in state-changing routes (/webpack-dev-server/invalidate and /webpack-dev-server/open-editor) against cross-site request forgery. Requests are now checked with Sec-Fetch-Site (falling back to an Origin/Host comparison when it is absent), so a cross-site page can no longer trigger a rebuild or open a file in the editor. Same-origin requests, user-initiated navigations, and non-browser clients (e.g. curl) are unaffected. (by @​bjohansebas in #5698)

  • Handle malformed Host and Origin header values gracefully when validating requests. (by @​bjohansebas in #5699)

5.2.5

Patch Changes

  • Skip the HMR WebSocket path when forwarding upgrade requests to user-defined proxies, so custom proxy WebSocket upgrades are no longer intercepted by the dev server. (by @​bjohansebas in #5680)

All notable changes to this project will be documented in this file. See standard-version for commit guidelines.

Commits
  • 8a37b0e chore(release): new release (#5697)
  • f21ed0f fix: handle malformed Host and Origin headers (#5699)
  • 80cd9ee fix: reject cross-site requests to open-editor and invalidate endpoints (#5698)
  • 308e853 fix: handle undefined options in Server constructor (#5695)
  • 8b2b915 chore: update branch references from v4 to v5 in workflow configuration
  • 870ed22 chore: add v5 branch to release workflow triggers
  • c3ee325 chore(release): new release (#5682)
  • 60173be feat: add changeset validation and release workflow (#5680)
  • 948d5e6 fix(proxy): match the HMR upgrade path exactly like the ws server (#5678)
  • 93e8996 fix: skip HMR websocket path when forwarding upgrades to user-defined proxies...
  • See full diff in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for webpack-dev-server since your current version.


Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 3, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/components/dash-table/npm-dependencies-security-b2fd70aae3 branch 2 times, most recently from c4738b0 to 55f98fa Compare July 13, 2026 16:42
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/components/dash-table/npm-dependencies-security-b2fd70aae3 branch from 55f98fa to 0360094 Compare July 20, 2026 16:42
Bumps the npm-dependencies-security group with 1 update in the /components/dash-table directory: [webpack-dev-server](https://github.com/webpack/webpack-dev-server).


Updates `webpack-dev-server` from 5.2.4 to 5.2.6
- [Release notes](https://github.com/webpack/webpack-dev-server/releases)
- [Changelog](https://github.com/webpack/webpack-dev-server/blob/v5.2.6/CHANGELOG.md)
- [Commits](webpack/webpack-dev-server@v5.2.4...v5.2.6)

---
updated-dependencies:
- dependency-name: webpack-dev-server
  dependency-version: 5.2.6
  dependency-type: direct:development
  dependency-group: npm-dependencies-security
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/components/dash-table/npm-dependencies-security-b2fd70aae3 branch from 0360094 to fa08526 Compare July 21, 2026 15:30
@sonarqubecloud

Copy link
Copy Markdown

@dependabot @github

dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/components/dash-table/npm-dependencies-security-b2fd70aae3 branch September 21, 2026 19:20
pull Bot pushed a commit to stungkit/dash that referenced this pull request Sep 21, 2026
Regenerate all npm lockfiles to the latest versions within the existing
semver ranges (node 24 / npm 11, lockfileVersion 2) across the root,
dash-renderer, the three component packages, and dash-component-plugins.
No direct dependency crosses a major boundary. This supersedes the stale,
failing dependabot PRs, which had bundled breaking majors (eslint 9,
typescript 6, webpack-cli 7, react-window 2, Babel 8).

- renderer: pin transitive types-ramda to 0.29.2 via a scoped override.
  @types/ramda 0.29.1 pulls types-ramda, which within its range jumped to
  0.29.10 and tightened keys() to `extends object`, breaking the type
  check with 37 tsc errors. Also bump webpack-cli to ^7 to match the
  component packages (verified building).
- dash-table: webpack-dev-server 5.2.4 -> 5.2.6 (security, closes plotly#3868).
- dependabot.yml: ignore the majors that break the build so stale red PRs
  stop reopening: typescript >=6, @babel/* >=8, babel-loader >=10,
  react-window >=2 (dcc), @types/ramda >=0.30 (renderer).

Verified on node 24: renderer build/eslint/prettier/karma (85),
dash-core-components build/es-check/eslint/jest (85), dash-table and
dash-html-components build/es-check/eslint, dash-component-plugins build.

Supersedes plotly#3868, plotly#3869, plotly#3890, plotly#3904, plotly#3905, plotly#3906, plotly#3910, plotly#3917-plotly#3920.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants