dependabot[bot] opened a new pull request, #25879: URL: https://github.com/apache/datafusion/pull/25879
Bumps [webpack-dev-middleware](https://github.com/webpack/webpack-dev-middleware) from 8.0.4 to 8.3.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-middleware/releases">webpack-dev-middleware's releases</a>.</em></p> <blockquote> <h2>v8.3.0</h2> <h3>Minor Changes</h3> <ul> <li> <p>Added a <code>hot</code> option that enables hot module replacement, replacing the need for <code>webpack-hot-middleware</code>. Pass <code>hot: true</code> to enable with defaults, or <code>hot: { path, heartbeat, progress, statsOptions }</code> to customize. The client runtime is served by the middleware itself. (by <a href="https://github.com/bjohansebas"><code>@bjohansebas</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2370">#2370</a>)</p> </li> <li> <p>Take the diagnostics a hot payload carries from the <code>stats</code> option, so one setting governs what a build reports in the terminal and in the browser: <code>stats: "errors-only"</code> keeps warnings out of both, and <code>stats: false</code> keeps errors and warnings out of both, the client's error overlay included — reach for the client's <code>?logging=</code> or <code>?overlay=</code> to quiet the browser alone. <code>hot.statsOptions</code> is deprecated and will be removed in the next major release; its <code>hash</code>, <code>timings</code> and <code>children</code> keys are now ignored, because they could leave a payload without the hash the client compares, or carry a child compilation's hash instead, which stopped updates applying and forced a full page reload on every rebuild. (by <a href="https://github.com/alexander-akait"><code>@alexander-akait</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2392">#239 2</a>)</p> </li> </ul> <h3>Patch Changes</h3> <ul> <li> <p>Fixed a crash when calling <code>invalidate()</code> in plugin mode (<code>isPlugin = true</code>). Since the host (webpack-cli, webpack-dev-server, etc.) owns <code>compiler.watch()</code>, the middleware now invalidates the host's <code>watching</code> instead (each child compiler's one for a <code>MultiCompiler</code> on webpack < 5.109). When nothing is watching it logs a warning and completes the callback, as <code>close()</code> does, rather than leaving <code>invalidate(callback)</code> waiting on a build that never runs. (by <a href="https://github.com/bjohansebas"><code>@bjohansebas</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2378">#2378</a>)</p> </li> <li> <p>Reject with <code>403 Forbidden</code> the requests whose resolved filename falls outside <code>outputPath</code> (<a href="https://github.com/webpack/webpack-dev-middleware/security/advisories/GHSA-g84c-rxfj-3j2c">GHSA-g84c-rxfj-3j2c</a>). With a <code>publicPath</code> without a trailing slash, a sibling path sharing its prefix (<code>/assets../secret</code>) escaped the output root once the prefix was stripped and joined. (by <a href="https://github.com/bjohansebas"><code>@bjohansebas</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2404">#2404</a>)</p> </li> <li> <p>Update the changelog generator to the <code>@changesets/get-github-info</code> 1.0 API. (by <a href="https://github.com/alexander-akait"><code>@alexander-akait</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2396">#2396</a>)</p> </li> <li> <p>Update dependencies. (by <a href="https://github.com/alexander-akait"><code>@alexander-akait</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2394">#2394</a>)</p> </li> </ul> <h2>v8.2.0</h2> <h3>Minor Changes</h3> <ul> <li>Added a <code>hot</code> option that enables hot module replacement, replacing the need for <code>webpack-hot-middleware</code>. Pass <code>hot: true</code> to enable with defaults, or <code>hot: { path, heartbeat, progress, statsOptions }</code> to customize. The client runtime ships with the package and is added as a webpack entry. (by <a href="https://github.com/bjohansebas"><code>@bjohansebas</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2322">#2322</a>)</li> </ul> <h2>v8.1.1</h2> <h3>Patch Changes</h3> <ul> <li>Fixed a crash when calling <code>close()</code> in plugin mode (<code>isPlugin = true</code>). Since the host (webpack-cli, webpack-dev-server, etc.) owns <code>compiler.watch()</code>, the middleware has no <code>watching</code> of its own to close, so <code>close()</code> now just calls the callback instead of throwing. (by <a href="https://github.com/bjohansebas"><code>@bjohansebas</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2347">#2347</a>)</li> </ul> <h2>v8.1.0</h2> <h3>Minor Changes</h3> <ul> <li>Reuse an already active <code>MultiCompiler</code> watching session instead of starting a duplicate one (requires webpack >= 5.109). (by <a href="https://github.com/bjohansebas"><code>@bjohansebas</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2371">#2371</a>)</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/webpack/webpack-dev-middleware/blob/main/CHANGELOG.md">webpack-dev-middleware's changelog</a>.</em></p> <blockquote> <h2>8.3.0</h2> <h3>Minor Changes</h3> <ul> <li> <p>Added a <code>hot</code> option that enables hot module replacement, replacing the need for <code>webpack-hot-middleware</code>. Pass <code>hot: true</code> to enable with defaults, or <code>hot: { path, heartbeat, progress, statsOptions }</code> to customize. The client runtime is served by the middleware itself. (by <a href="https://github.com/bjohansebas"><code>@bjohansebas</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2370">#2370</a>)</p> </li> <li> <p>Take the diagnostics a hot payload carries from the <code>stats</code> option, so one setting governs what a build reports in the terminal and in the browser: <code>stats: "errors-only"</code> keeps warnings out of both, and <code>stats: false</code> keeps errors and warnings out of both, the client's error overlay included — reach for the client's <code>?logging=</code> or <code>?overlay=</code> to quiet the browser alone. <code>hot.statsOptions</code> is deprecated and will be removed in the next major release; its <code>hash</code>, <code>timings</code> and <code>children</code> keys are now ignored, because they could leave a payload without the hash the client compares, or carry a child compilation's hash instead, which stopped updates applying and forced a full page reload on every rebuild. (by <a href="https://github.com/alexander-akait"><code>@alexander-akait</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2392">#239 2</a>)</p> </li> </ul> <h3>Patch Changes</h3> <ul> <li> <p>Fixed a crash when calling <code>invalidate()</code> in plugin mode (<code>isPlugin = true</code>). Since the host (webpack-cli, webpack-dev-server, etc.) owns <code>compiler.watch()</code>, the middleware now invalidates the host's <code>watching</code> instead (each child compiler's one for a <code>MultiCompiler</code> on webpack < 5.109). When nothing is watching it logs a warning and completes the callback, as <code>close()</code> does, rather than leaving <code>invalidate(callback)</code> waiting on a build that never runs. (by <a href="https://github.com/bjohansebas"><code>@bjohansebas</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2378">#2378</a>)</p> </li> <li> <p>Reject with <code>403 Forbidden</code> the requests whose resolved filename falls outside <code>outputPath</code> (<a href="https://github.com/webpack/webpack-dev-middleware/security/advisories/GHSA-g84c-rxfj-3j2c">GHSA-g84c-rxfj-3j2c</a>). With a <code>publicPath</code> without a trailing slash, a sibling path sharing its prefix (<code>/assets../secret</code>) escaped the output root once the prefix was stripped and joined. (by <a href="https://github.com/bjohansebas"><code>@bjohansebas</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2404">#2404</a>)</p> </li> <li> <p>Update the changelog generator to the <code>@changesets/get-github-info</code> 1.0 API. (by <a href="https://github.com/alexander-akait"><code>@alexander-akait</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2396">#2396</a>)</p> </li> <li> <p>Update dependencies. (by <a href="https://github.com/alexander-akait"><code>@alexander-akait</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2394">#2394</a>)</p> </li> </ul> <h2>8.2.0</h2> <h3>Minor Changes</h3> <ul> <li>Added a <code>hot</code> option that enables hot module replacement, replacing the need for <code>webpack-hot-middleware</code>. Pass <code>hot: true</code> to enable with defaults, or <code>hot: { path, heartbeat, progress, statsOptions }</code> to customize. The client runtime ships with the package and is added as a webpack entry. (by <a href="https://github.com/bjohansebas"><code>@bjohansebas</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2322">#2322</a>)</li> </ul> <h2>8.1.1</h2> <h3>Patch Changes</h3> <ul> <li>Fixed a crash when calling <code>close()</code> in plugin mode (<code>isPlugin = true</code>). Since the host (webpack-cli, webpack-dev-server, etc.) owns <code>compiler.watch()</code>, the middleware has no <code>watching</code> of its own to close, so <code>close()</code> now just calls the callback instead of throwing. (by <a href="https://github.com/bjohansebas"><code>@bjohansebas</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2347">#2347</a>)</li> </ul> <h2>8.1.0</h2> <h3>Minor Changes</h3> <ul> <li>Reuse an already active <code>MultiCompiler</code> watching session instead of starting a duplicate one (requires webpack >= 5.109). (by <a href="https://github.com/bjohansebas"><code>@bjohansebas</code></a> in <a href="https://redirect.github.com/webpack/webpack-dev-middleware/pull/2371">#2371</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/webpack/webpack-dev-middleware/commit/1abbf0898f1ca6cb1f8cc42b7469c7c0c45a5787"><code>1abbf08</code></a> chore(release): new release (<a href="https://redirect.github.com/webpack/webpack-dev-middleware/issues/2393">#2393</a>)</li> <li><a href="https://github.com/webpack/webpack-dev-middleware/commit/ef479c9e4d35fa1fda3aff09b51bded65025e065"><code>ef479c9</code></a> feat: add missing changelog (<a href="https://redirect.github.com/webpack/webpack-dev-middleware/issues/2404">#2404</a>)</li> <li><a href="https://github.com/webpack/webpack-dev-middleware/commit/13344e78b26d88fe9b7c8381a3860e248a52359b"><code>13344e7</code></a> Merge commit from fork</li> <li><a href="https://github.com/webpack/webpack-dev-middleware/commit/e58a70ba9c36f6acc10617f338b73269f951de35"><code>e58a70b</code></a> test(hot): reach 100% of the client, off the deprecated statsOptions (<a href="https://redirect.github.com/webpack/webpack-dev-middleware/issues/2402">#2402</a>)</li> <li><a href="https://github.com/webpack/webpack-dev-middleware/commit/17e689e3290f6d0add35443ca049ea9b906d001b"><code>17e689e</code></a> chore(deps): bump the dependencies group across 1 directory with 2 updates (#...</li> <li><a href="https://github.com/webpack/webpack-dev-middleware/commit/d81681815b998fc4a13260c9462ec8ecdfdabf93"><code>d816818</code></a> fix(plugin): resolve crash on invalidate() in plugin mode (<a href="https://redirect.github.com/webpack/webpack-dev-middleware/issues/2378">#2378</a>)</li> <li><a href="https://github.com/webpack/webpack-dev-middleware/commit/09a9095d9e88cf727626423233659c366b984940"><code>09a9095</code></a> chore(deps): bump changesets/action (<a href="https://redirect.github.com/webpack/webpack-dev-middleware/issues/2384">#2384</a>)</li> <li><a href="https://github.com/webpack/webpack-dev-middleware/commit/4c1dcfcf02ca827d8802fda395e393fa154cbcd1"><code>4c1dcfc</code></a> test: rewrite to e2e (<a href="https://redirect.github.com/webpack/webpack-dev-middleware/issues/2370">#2370</a>)</li> <li><a href="https://github.com/webpack/webpack-dev-middleware/commit/9133f47afea2673d1e2097263ecfad11e4929c90"><code>9133f47</code></a> build: update changesets tooling (<a href="https://redirect.github.com/webpack/webpack-dev-middleware/issues/2396">#2396</a>)</li> <li><a href="https://github.com/webpack/webpack-dev-middleware/commit/a337174ccb37d33c2559d11c13929c445a29da80"><code>a337174</code></a> build: update dependencies (<a href="https://redirect.github.com/webpack/webpack-dev-middleware/issues/2394">#2394</a>)</li> <li>Additional commits viewable in <a href="https://github.com/webpack/webpack-dev-middleware/compare/v8.0.4...v8.3.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/apache/datafusion/network/alerts). </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
