Skip to content

Commit 1e6cfc7

Browse files
authored
chore(deps): Bump vulnerable webpack version (#909)
Bump webpack from vulnerable versions (5.0.0, 5.74.0) to 5.76.0 across 4 packages to fix CVE-2023-28154 (cross-realm object access in Webpack 5)
1 parent 3bf270c commit 1e6cfc7

File tree

5 files changed

+16
-550
lines changed

5 files changed

+16
-550
lines changed

packages/e2e-tests/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@
3434
"rollup": "3.2.0",
3535
"ts-node": "^10.9.1",
3636
"vite": "3.0.0",
37-
"webpack": "5.74.0"
37+
"webpack": "5.76.0"
3838
},
3939
"volta": {
4040
"extends": "../../package.json"

packages/integration-tests/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@
3838
"rollup": "3.2.0",
3939
"ts-node": "^10.9.1",
4040
"vite": "3.0.0",
41-
"webpack": "5.74.0"
41+
"webpack": "5.76.0"
4242
},
4343
"devDependencies": {
4444
"premove": "^4.0.0"

packages/playground/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@
2727
"http-proxy": "^1.18.1",
2828
"rollup": "3.2.0",
2929
"vite": "3.0.0",
30-
"webpack": "5.74.0"
30+
"webpack": "5.76.0"
3131
},
3232
"devDependencies": {
3333
"premove": "^4.0.0"

packages/webpack-plugin/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -66,7 +66,7 @@
6666
"rolldown": "1.0.0-rc.10",
6767
"ts-node": "^10.9.1",
6868
"typescript": "^4.7.4",
69-
"webpack": "5.0.0"
69+
"webpack": "5.76.0"
7070
},
7171
"peerDependencies": {
7272
"webpack": ">=5.0.0"

0 commit comments

Comments
 (0)