Repository navigation
chore(deps-dev): Bump webpack-dev-server from 4.15.2 to 5.2.1 - #2622
Conversation
d79b697 to
d95ad00
Compare
|
@dependabot rebase |
d95ad00 to
f189106
Compare
|
@dependabot rebase |
f189106 to
f35a27f
Compare
|
Claude finished @ankita10119's task —— View job Overall Assessment❌ This PR introduces breaking changes that require configuration updates before it can be safely merged. Critical Issues Found1. Breaking Configuration Change in Example CodeFile: Required Fix: // BEFORE (v4)
devServer: {
contentBase: './',
https: true,
port: 3000
}
// AFTER (v5)
devServer: {
static: './', // Changed from contentBase
https: true,
port: 3000
}2. Security Changes May Affect Development WorkflowThe v5.2.1 release includes important security fixes that may impact the development server:
Impact: If developers rely on cross-origin requests during development, the dev server may reject these requests after this upgrade. Recommended Action: Add explicit CORS configuration if needed: devServer: {
headers: {
'Access-Control-Allow-Origin': '*',
'Access-Control-Allow-Methods': 'GET, POST, PUT, DELETE, PATCH, OPTIONS',
'Access-Control-Allow-Headers': 'X-Requested-With, content-type, Authorization'
}
}Additional Breaking Changes to VerifyThe main
Required Actions Before Merge
RecommendationDo not merge until the breaking configuration change is fixed. The example webpack configuration must be updated to use webpack-dev-server v5 syntax, otherwise the example will be broken for users. |
|
@dependabot rebase |
f35a27f to
30b4cbf
Compare
|
@dependabot recreate |
30b4cbf to
ecc1f4e
Compare
|
@dependabot recreate |
Bumps [webpack-dev-server](https://github.com/webpack/webpack-dev-server) from 4.15.2 to 5.2.1. - [Release notes](https://github.com/webpack/webpack-dev-server/releases) - [Changelog](https://github.com/webpack/webpack-dev-server/blob/master/CHANGELOG.md) - [Commits](webpack/webpack-dev-server@v4.15.2...v5.2.1) --- updated-dependencies: - dependency-name: webpack-dev-server dependency-version: 5.2.1 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <[email protected]>
ecc1f4e to
18a0a9a
Compare
…s to 3.1.0, and fix dev setup (#2771) ### Changes This PR consolidates three related dependency upgrades and fixes the local development setup that had been broken since PR #2622 . It supersedes #2769 (which will be closed). 1. **webpack-dev-server** `v4 `→ `v5` (`package.json`, `webpack.config.js`) PR #2622 bumped **webpack-dev-server** from `4.15.2` to `5.2.1`. This was a breaking change that went unnoticed because CI only runs tests, it never starts the dev server. Running npm start after that bump resulted in: _ValidationError: Invalid options object. Dev Server has been initialized using an options object that does not match the API schema. - options has an unknown property 'https'._ **Root cause**: webpack-dev-server v5 removed the https shorthand option that existed in v4. The replacement is the server object API. Fix in `webpack.config.js`: // Before (v4 API — broken in v5) `https: getDevCerts() || true` // After (v5 API) ``` server: { type: 'https', options: getDevCerts() || {} } ``` `package.json`: Version constraint updated from ^4.15.2 back to ^5.2.1 (resolves to 5.2.3, also covering PR #2767's bump). 2. Fix 403 Forbidden when loading bundle from Auth0 hosted pages (webpack.config.js) After fixing the startup crash, a second issue surfaced when testing against a custom hosted login page on manage.auth0.com: the browser reported Auth0Lock is not defined.Inspecting the Network tab showed the bundle request returning 403 Forbidden. **Root cause**: webpack-dev-server v5 introduced a security middleware (cross-origin-header-check) that blocks any request where both of these are true: - `sec-fetch-mode: no-cors` — always set by <script> tags - `sec-fetch-site: cross-site` — always set when an external origin (e.g. manage.auth0.com) loads a resource from localhost:3000 The combination of these two headers causes webpack-dev-server to return 403 before the bundle is served. **Fix**: ` allowedHosts: 'all'` This disables the cross-origin host check. It is safe for a local dev server — it has no effect on production builds and only applies when npm start is running. The original v4 server had no such restriction. 3. **auth0-password-policies** `1.0.2` → `3.1.0` and password-sheriff `1.1.1` → `2.0.0` (`package.json`, `webpack.config.js`) `[email protected]` was published in November 2018. After 7 years of inactivity, versions 1.1.0 through 3.1.0 were released between August 2025 and February 2026.Dependabot opened PR #2705 targeting 1.1.1 (the first post-gap release), but that PR failed CI and was superseded by two further major versions before it could be merged. This PR jumps directly to the current latest (3.1.0). **Why password-sheriff is also bumped**: `[email protected]` declares `password-sheriff@^2.0.0` as a peer/dependency. Lock also uses password-sheriff directly in src/field/password.js and `src/ui/input/password/password_strength.jsx `via `password-sheriff/lib/policy`. The `lib/policy.js` API is identical between `v1` and `v2` , the only additions are two new built-in rule types (sequentialChars, maxLength) which Lock does not use. Bumping Lock's direct constraint to ^2.0.0 avoids having two copies of password-sheriff in the install tree. **Why webpack.config.js needed a new babel-loader rule**: `[email protected]` ships its source with ES2020 syntax (optional chaining ?.). The project runs es-check es2017 against the built bundle as a CI gate. The existing webpack babel rule has `exclude: node_modules`, so third-party packages are bundled as-is. For most packages this is fine since they ship pre-built ES5, but auth0-password-policies does not. A dedicated babel-loader rule for `auth0-password-policies` is added before the main rule. There is one non-obvious subtlety: Babel 7's `.babelrc` is file-relative, it only applies to files within the same package root and is silently ignored when Babel processes files in a different package under node_modules. This means Babel would run but apply no transforms, leaving ?. in the output. The fix is to pass presets explicitly in the rule's options alongside configFile: false and `babelrc: false`, so Babel uses exactly those presets regardless of config file boundaries: ``` { test: /\.js$/, include: path.join(__dirname, 'node_modules', 'auth0-password-policies'), loader: 'babel-loader', options: { presets: [['@babel/preset-env', { useBuiltIns: 'entry', corejs: '3.26.1' }]], configFile: false, babelrc: false } } ``` 4. Fix webpack 5 compilation warning for CordovaAuth0Plugin (`src/core/web_api/p2_api.js`) After the auth0-js bump in PR #2766 (9.30.1 → 9.32.0), webpack emitted two warnings on every build: ``` WARNING in ./src/core/web_api/p2_api.js export 'default' (imported as 'CordovaAuth0Plugin') was not found in 'auth0-js/dist/cordova-auth0-plugin.min.js' (module has no exports) ``` **Root cause**: `cordova-auth0-plugin.min.js` uses a UMD format (module.exports = factory()). Webpack 5's static analysis cannot resolve a default export from a module.exports assignment inside a UMD IIFE, so it warns when the file is imported with ES module import default syntax. **Fix**: Replace the ES module import with require(), which webpack handles correctly for CommonJS/UMD modules: // Before `import CordovaAuth0Plugin from 'auth0-js/dist/cordova-auth0-plugin.min.js';` // After `const CordovaAuth0Plugin = require('auth0-js/dist/cordova-auth0-plugin.min.js');` Runtime behaviour is unchanged, the `typeof CordovaAuth0Plugin === 'function'` guard already in place handles the case where the plugin is unavailable. ### References - Supersedes #2769 - Supersedes #2705 - Fixes dev setup broken by #2622 - Related to #2767 (webpack-dev-server 5.2.1 → 5.2.3, covered by ^5.2.1 range) - Related to #2766 (auth0-js 9.30.1 → 9.32.0, source of the CordovaAuth0Plugin warning) ### Testing Tested with local development setup. * [ ] This change adds unit test coverage * [ ] This change adds integration test coverage * [ ] This change has been tested on the latest version of the platform/language ### Checklist * [ ] I have read the [Auth0 general contribution guidelines](https://github.com/auth0/open-source-template/blob/master/GENERAL-CONTRIBUTING.md) * [ ] I have read the [Auth0 Code of Conduct](https://github.com/auth0/open-source-template/blob/master/CODE-OF-CONDUCT.md) * [ ] All code quality tools/guidelines have been run/followed * [ ] All relevant assets have been compiled
Bumps webpack-dev-server from 4.15.2 to 5.2.1.
Release notes
Sourced from webpack-dev-server's releases.
... (truncated)
Changelog
Sourced from webpack-dev-server's changelog.
... (truncated)
Commits
0d22a08chore(release): 5.2.16045b1echore(deps): update (#5444)ffd0b86fix: take the first network found instead of the last one, this restores the ...9ea7b08ci: update dependency-review-action (#5442)5c9378bMerge commit from forkd2575adMerge commit from fork8c1abc9fix: prevent overlay for errors caught by React error boundaries (#5431)5a39c70ci: update codecov/codecov-action to v5 (#5406)55220a8chore(deps-dev): bump the dependencies group across 1 directory with 4 update...09f6f8echore(deps): bump the dependencies group across 1 directory with 2 updates (#...Install script changes
This version modifies
preparescript that runs during installation. Review the package contents before updating.