- Add plugin support to webpack-dev-server for integrating with the compiler lifecycle
- Bump Express to v5
- Bump the webpack peer dependency range from ^5.0.0 to ^5.101.0
- Convert the source to native ES modules with both ESM and CommonJS builds via the exports field
- Update http-proxy-middleware to v4
- Update webpack-dev-middleware to v8 and make server.middleware.getFilenameFromUrl() asynchronous
- Enable the compression middleware for HTTP/2 connections
- Update chokidar to v5 and extend watchFiles.options.ignored to support glob string patterns via tinyglobby
- Use compiler.platform to determine the target environment instead of inspecting the resolved target string
- Use the WHATWG URL API instead of the deprecated url.parse
- Bump production dependencies notably open to v11 and p-retry to v8
- Treat loopback aliases as equivalent in isSameOrigin so the WebSocket client does not reject valid same-origin connections
- Drop support for Node.js < 22.15.0
- Remove CLI flags
- Remove the internalIP and internalIPSync static methods from Server
- Remove the bypass option from proxy configuration
- Remove SockJS support from the webSocketServer option
- Remove the spdy dependency
- Remove the colorette dependency in favor of native ANSI styling
- Reject cross-site requests to the internal open-editor and invalidate endpoints requiring same-origin validation
From webpack-dev-server
Major Changes
-
Bump Express to v5. See the Express 5 migration guide for the full list of breaking changes. (by @bjohansebas in #5674)
-
Bump the
webpackpeer dependency range from^5.0.0to^5.101.0. (by @bjohansebas in #5674) -
Drop support for Node.js < 22.15.0. (by @bjohansebas in #5674)
-
Convert the source to native ES modules. The package keeps
"type": "module"and now exposes both an ESM and a CommonJS build via theexportsfield: ESM consumers import the nativelib/, while CommonJS consumersrequire()a transpileddist/build, allowing the package to be consumed from both ESM and CommonJS without relying onrequire(ESM)for CommonJS consumers. (by @bjohansebas in #5674) -
Remove CLI flags. Use the
servecommand fromwebpack-clitogether with a configuration file or the programmatic API instead. (by @bjohansebas in #5674) -
Remove the
internalIPandinternalIPSyncstatic methods fromServer. Resolve the local IP yourself if you need it. (by @bjohansebas in #5674) -
Remove the
bypassoption from proxy configuration. Use therouterorcontextoptions provided byhttp-proxy-middlewareinstead. (by @bjohansebas in #5674) -
Remove SockJS support. The
webSocketServeroption no longer accepts"sockjs"; use the default"ws"transport instead. (by @bjohansebas in #5674) -
Remove the
spdydependency. Use the built-innode:http2module via theserveroption for HTTP/2 support. (by @bjohansebas in #5674) -
Update
http-proxy-middlewareto v4. See the http-proxy-middleware v3 release notes and v4 release notes for the full list of breaking changes. (by @bjohansebas in #5674) -
Update
webpack-dev-middlewareto v8 and syncoriginalUrlfor middleware compatibility.server.middleware.getFilenameFromUrl()is now asynchronous and resolves to{ filename, extra: { stats, outputFileSystem } }. See the webpack-dev-middleware v8 release notes for details. (by @bjohansebas in #5674)
Minor Changes
-
Add plugin support.
webpack-dev-servercan now be used as a webpack plugin, integrating with the compiler lifecycle without explicitly passing a compiler, preventing multiple server starts on recompilation, ensuring clean shutdown, and supportingMultiCompilersetups with multiple independent plugin servers. (by @bjohansebas in #5674) -
Enable the compression middleware for HTTP/2 connections. (by @bjohansebas in #5674)
-
Remove the
colorettedependency in favor of native ANSI styling. (by @bjohansebas in #5674) -
Update
chokidarto v5 and extendwatchFiles.options.ignoredto support glob string patterns viatinyglobby. (by @bjohansebas in #5674) -
Use
compiler.platformto determine the target environment instead of inspecting the resolvedtargetstring. Universal targets ("universal"or["web", "node"], wherecompiler.platform.universalistruesince webpack5.108.0) are treated as web targets so the client runtime is injected. (by @bjohansebas in #5674) -
Use the WHATWG
URLAPI instead of the deprecatedurl.parse. (by @bjohansebas in #5674)
Patch Changes
-
Bump production dependencies, notably
opento v11 andp-retryto v8. (by @bjohansebas in #5674) -
Reject cross-site requests to the internal
open-editorandinvalidateendpoints. They performed state-changing actions (opening a file in the editor, forcing a recompilation) on any GET request, so a page the developer visited could trigger them. They now require a same-origin request, validated viaSec-Fetch-Sitewith anOrigin/Hostfallback. (by @bjohansebas in #5691) -
Treat loopback aliases (
127.0.0.1,::1,localhost) as equivalent inisSameOriginso the WebSocket client does not reject valid same-origin connections. (by @bjohansebas in #5674) -
Migrate the test suite from Jest to
node:testand set up the jsdom environment. (by @bjohansebas in #5674) -
Update
webpack-clito v7.0.2. (by @bjohansebas in #5674)