Skip to content

Update dependency webpack-bundle-analyzer to v4#136

Open
dev-mend-for-github-com[bot] wants to merge 1 commit intotrunkfrom
whitesource-remediate/webpack-bundle-analyzer-4.x
Open

Update dependency webpack-bundle-analyzer to v4#136
dev-mend-for-github-com[bot] wants to merge 1 commit intotrunkfrom
whitesource-remediate/webpack-bundle-analyzer-4.x

Conversation

@dev-mend-for-github-com
Copy link

This PR contains the following updates:

Package Type Update Change
webpack-bundle-analyzer dependencies major 3.9.04.0.0

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability Reachability
High High 8.8 CVE-2024-33883

Release Notes

webpack/webpack-bundle-analyzer (webpack-bundle-analyzer)

v4.0.0

Compare Source

  • Breaking change

    • Dropped support for Node.js 6 and 8. Minimal required version now is v10.13.0
  • Improvement

    • Support for Webpack 5
  • Bug Fix

    • Prevent crashes when openAnalyzer was set to true in environments where there's no program to handle opening. (#​382 by @​wbobeirne)
  • Internal

    • Updated dependencies
    • Added support for multiple Webpack versions in tests

  • If you want to rebase/retry this PR, check this box

@dev-mend-for-github-com dev-mend-for-github-com bot added the security fix Security fix generated by Mend label Feb 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants