Snyk has created this PR to upgrade webpack from 4.26.0 to 4.46.0.
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 53 versions ahead of your current version.
The recommended version was released a month ago, on 2021-01-11.
Snyk has created this PR to upgrade webpack from 4.26.0 to 4.46.0.
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-SERIALIZEJAVASCRIPT-570062
Why? Proof of Concept exploit, CVSS 7.7
SNYK-JS-SERIALIZEJAVASCRIPT-536840
Why? Proof of Concept exploit, CVSS 7.7
SNYK-JS-INI-1048974
Why? Proof of Concept exploit, CVSS 7.7
SNYK-JS-ELLIPTIC-571484
Why? Proof of Concept exploit, CVSS 7.7
SNYK-JS-ACORN-559469
Why? Proof of Concept exploit, CVSS 7.7
npm:chownr:20180731
Why? Proof of Concept exploit, CVSS 7.7
SNYK-JS-ELLIPTIC-511941
Why? Proof of Concept exploit, CVSS 7.7
SNYK-JS-ELLIPTIC-1064899
Why? Proof of Concept exploit, CVSS 7.7
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: webpack
Bugfixes
resolve.roots
to be backward-compatibleFeatures
Bugfixes
splitChunk
minSize
is not handled correctlysplitChunk
cacheGroups
is not handled correctlyCommit messages
Package name: webpack
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs