Skip to content
This repository was archived by the owner on Feb 9, 2024. It is now read-only.

Update webpack-dev-server to version 2.4.3 🚀 - #444

Closed
greenkeeperio-bot wants to merge 1 commit into
masterfrom
greenkeeper-webpack-dev-server-2.4.3
Closed

Update webpack-dev-server to version 2.4.3 🚀#444
greenkeeperio-bot wants to merge 1 commit into
masterfrom
greenkeeper-webpack-dev-server-2.4.3

Conversation

@greenkeeperio-bot

Copy link
Copy Markdown
Contributor

Hello lovely humans,

webpack-dev-server just published its new version 2.4.3.

State Update 🚀
Dependency webpack-dev-server
New version 2.4.3
Type devDependency

This version is not covered by your current version range.

Without accepting this pull request your project will work just like it did before. There might be a bunch of new features, fixes and perf improvements that the maintainers worked on for you though.

I recommend you look into these changes and try to get onto the latest version of webpack-dev-server.
Given that you have a decent test suite, a passing build is a strong indicator that you can take advantage of these changes by merging the proposed change into your project. Otherwise this branch is a great starting point for you to work on the update.

Do you have any ideas how I could improve these pull requests? Did I report anything you think isn’t right?
Are you unsure about how things are supposed to work?

There is a collection of frequently asked questions and while I’m just a bot, there is a group of people who are happy to teach me new things. Let them know.

Good luck with your project ✨

You rock!

🌴


GitHub Release

Security fix:

This version contains a security fix, which is also breaking change if you have an insecure configuration.
We are releasing this breaking change as patch version to protect you from attacks.
Sorry if this breaks your setup, but the fix is easy.

We added a check for the correct Host header to the webpack-dev-server.
This allowed evil websites to access your assets.

The Host header of the request have to match the listening adress or the host provided in the public option.
Make sure to provide correct values here.

The response will contain a note when using an incorrect Host header.

For usage behind a Proxy or similar setups we also added a disableHostCheck option to disable this check.
Only use it when you know what you do. Not recommended.

This version also includes this security fix for webpack-dev-middleware: https://github.com/webpack/webpack-dev-middleware/releases/tag/v1.10.2

Bugfixes:

  • Requests are not blocked when Host doesn't match listening host or public option.
  • Requests to localhost or 127.0.0.1 are not blocked.

Features:

  • Added disableHostCheck option to disable the host check

The new version differs by 259 commits (ahead by 259, behind by 34).

  • ca932842.4.3
  • f3a4ac6Merge branch 'security/host-check'
  • 8db5fd5Require a secure webpack-dev-middleware version
  • 2957853enable Host header check for all requests and sockets
  • 60e47272.4.2
  • 32adae3Added beforeunload check to index.js (#544) (#841)
  • d69559aHandle external upgrade for all websocket proxies (#843)
  • 35a44d1Remove Node.js v7 warning
  • d2f579cSupport for array of contentBase (#832)
  • aabeeaaRemove unnecessary logging of closing the dev-server
  • 1dc9461Fix to share proxy option between proxy settings when the proxy option is a same object (#836)
  • 42cd23cExplicitely but gracefully handle SIGINT and SIGTERM signals. (#787)
  • 85de417Use arrow function if it possible and get rid of .bind in server part (#835)
  • 234294aAdd unit tests for proxy options (#834)
  • 8d4b826add codecov

There are 250 commits in total. See the full diff.


✨ Try the all new Greenkeeper GitHub Integration
With Integrationsfirst-class bot support landed on GitHub and we’ve rewritten Greenkeeper to take full advantage of it. Simpler setup, fewer pull-requests, faster than ever.

Screencast

Try it today. Free for private repositories during beta.

@coveralls

Copy link
Copy Markdown

Coverage Status

Coverage increased (+0.3%) to 89.298% when pulling ef3986c on greenkeeper-webpack-dev-server-2.4.3 into 020295b on master.

@instantlinux

Copy link
Copy Markdown

replaced by #447

@instantlinux
instantlinux deleted the greenkeeper-webpack-dev-server-2.4.3 branch January 31, 2020 01:21
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@greenkeeperio-bot@coveralls@instantlinux@sethyates
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Update webpack-dev-server to version 2.4.3 🚀 by greenkeeperio-bot · Pull Request #444 · krux/postscribe · GitHub
Skip to content
This repository was archived by the owner on Feb 9, 2024. It is now read-only.

Update webpack-dev-server to version 2.4.3 🚀 - #444

Closed
greenkeeperio-bot wants to merge 1 commit into
masterfrom
greenkeeper-webpack-dev-server-2.4.3
Closed

Update webpack-dev-server to version 2.4.3 🚀#444
greenkeeperio-bot wants to merge 1 commit into
masterfrom
greenkeeper-webpack-dev-server-2.4.3

Conversation

@greenkeeperio-bot

Copy link
Copy Markdown
Contributor

Hello lovely humans,

webpack-dev-server just published its new version 2.4.3.

State Update 🚀
Dependency webpack-dev-server
New version 2.4.3
Type devDependency

This version is not covered by your current version range.

Without accepting this pull request your project will work just like it did before. There might be a bunch of new features, fixes and perf improvements that the maintainers worked on for you though.

I recommend you look into these changes and try to get onto the latest version of webpack-dev-server.
Given that you have a decent test suite, a passing build is a strong indicator that you can take advantage of these changes by merging the proposed change into your project. Otherwise this branch is a great starting point for you to work on the update.

Do you have any ideas how I could improve these pull requests? Did I report anything you think isn’t right?
Are you unsure about how things are supposed to work?

There is a collection of frequently asked questions and while I’m just a bot, there is a group of people who are happy to teach me new things. Let them know.

Good luck with your project ✨

You rock!

🌴


GitHub Release

Security fix:

This version contains a security fix, which is also breaking change if you have an insecure configuration.
We are releasing this breaking change as patch version to protect you from attacks.
Sorry if this breaks your setup, but the fix is easy.

We added a check for the correct Host header to the webpack-dev-server.
This allowed evil websites to access your assets.

The Host header of the request have to match the listening adress or the host provided in the public option.
Make sure to provide correct values here.

The response will contain a note when using an incorrect Host header.

For usage behind a Proxy or similar setups we also added a disableHostCheck option to disable this check.
Only use it when you know what you do. Not recommended.

This version also includes this security fix for webpack-dev-middleware: https://github.com/webpack/webpack-dev-middleware/releases/tag/v1.10.2

Bugfixes:

  • Requests are not blocked when Host doesn't match listening host or public option.
  • Requests to localhost or 127.0.0.1 are not blocked.

Features:

  • Added disableHostCheck option to disable the host check

The new version differs by 259 commits (ahead by 259, behind by 34).

  • ca932842.4.3
  • f3a4ac6Merge branch 'security/host-check'
  • 8db5fd5Require a secure webpack-dev-middleware version
  • 2957853enable Host header check for all requests and sockets
  • 60e47272.4.2
  • 32adae3Added beforeunload check to index.js (#544) (#841)
  • d69559aHandle external upgrade for all websocket proxies (#843)
  • 35a44d1Remove Node.js v7 warning
  • d2f579cSupport for array of contentBase (#832)
  • aabeeaaRemove unnecessary logging of closing the dev-server
  • 1dc9461Fix to share proxy option between proxy settings when the proxy option is a same object (#836)
  • 42cd23cExplicitely but gracefully handle SIGINT and SIGTERM signals. (#787)
  • 85de417Use arrow function if it possible and get rid of .bind in server part (#835)
  • 234294aAdd unit tests for proxy options (#834)
  • 8d4b826add codecov

There are 250 commits in total. See the full diff.


✨ Try the all new Greenkeeper GitHub Integration
With Integrationsfirst-class bot support landed on GitHub and we’ve rewritten Greenkeeper to take full advantage of it. Simpler setup, fewer pull-requests, faster than ever.

Screencast

Try it today. Free for private repositories during beta.

@coveralls

Copy link
Copy Markdown

Coverage Status

Coverage increased (+0.3%) to 89.298% when pulling ef3986c on greenkeeper-webpack-dev-server-2.4.3 into 020295b on master.

@instantlinux

Copy link
Copy Markdown

replaced by #447

@instantlinux
instantlinux deleted the greenkeeper-webpack-dev-server-2.4.3 branch January 31, 2020 01:21
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@greenkeeperio-bot@coveralls@instantlinux@sethyates
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Update webpack-dev-server to version 2.4.3 🚀 by greenkeeperio-bot · Pull Request #444 · krux/postscribe · GitHub
Skip to content
This repository was archived by the owner on Feb 9, 2024. It is now read-only.

Update webpack-dev-server to version 2.4.3 🚀 - #444

Closed
greenkeeperio-bot wants to merge 1 commit into
masterfrom
greenkeeper-webpack-dev-server-2.4.3
Closed

Update webpack-dev-server to version 2.4.3 🚀#444
greenkeeperio-bot wants to merge 1 commit into
masterfrom
greenkeeper-webpack-dev-server-2.4.3

Conversation

@greenkeeperio-bot

Copy link
Copy Markdown
Contributor

Hello lovely humans,

webpack-dev-server just published its new version 2.4.3.

State Update 🚀
Dependency webpack-dev-server
New version 2.4.3
Type devDependency

This version is not covered by your current version range.

Without accepting this pull request your project will work just like it did before. There might be a bunch of new features, fixes and perf improvements that the maintainers worked on for you though.

I recommend you look into these changes and try to get onto the latest version of webpack-dev-server.
Given that you have a decent test suite, a passing build is a strong indicator that you can take advantage of these changes by merging the proposed change into your project. Otherwise this branch is a great starting point for you to work on the update.

Do you have any ideas how I could improve these pull requests? Did I report anything you think isn’t right?
Are you unsure about how things are supposed to work?

There is a collection of frequently asked questions and while I’m just a bot, there is a group of people who are happy to teach me new things. Let them know.

Good luck with your project ✨

You rock!

🌴


GitHub Release

Security fix:

This version contains a security fix, which is also breaking change if you have an insecure configuration.
We are releasing this breaking change as patch version to protect you from attacks.
Sorry if this breaks your setup, but the fix is easy.

We added a check for the correct Host header to the webpack-dev-server.
This allowed evil websites to access your assets.

The Host header of the request have to match the listening adress or the host provided in the public option.
Make sure to provide correct values here.

The response will contain a note when using an incorrect Host header.

For usage behind a Proxy or similar setups we also added a disableHostCheck option to disable this check.
Only use it when you know what you do. Not recommended.

This version also includes this security fix for webpack-dev-middleware: https://github.com/webpack/webpack-dev-middleware/releases/tag/v1.10.2

Bugfixes:

  • Requests are not blocked when Host doesn't match listening host or public option.
  • Requests to localhost or 127.0.0.1 are not blocked.

Features:

  • Added disableHostCheck option to disable the host check

The new version differs by 259 commits (ahead by 259, behind by 34).

  • ca932842.4.3
  • f3a4ac6Merge branch 'security/host-check'
  • 8db5fd5Require a secure webpack-dev-middleware version
  • 2957853enable Host header check for all requests and sockets
  • 60e47272.4.2
  • 32adae3Added beforeunload check to index.js (#544) (#841)
  • d69559aHandle external upgrade for all websocket proxies (#843)
  • 35a44d1Remove Node.js v7 warning
  • d2f579cSupport for array of contentBase (#832)
  • aabeeaaRemove unnecessary logging of closing the dev-server
  • 1dc9461Fix to share proxy option between proxy settings when the proxy option is a same object (#836)
  • 42cd23cExplicitely but gracefully handle SIGINT and SIGTERM signals. (#787)
  • 85de417Use arrow function if it possible and get rid of .bind in server part (#835)
  • 234294aAdd unit tests for proxy options (#834)
  • 8d4b826add codecov

There are 250 commits in total. See the full diff.


✨ Try the all new Greenkeeper GitHub Integration
With Integrationsfirst-class bot support landed on GitHub and we’ve rewritten Greenkeeper to take full advantage of it. Simpler setup, fewer pull-requests, faster than ever.

Screencast

Try it today. Free for private repositories during beta.

@coveralls

Copy link
Copy Markdown

Coverage Status

Coverage increased (+0.3%) to 89.298% when pulling ef3986c on greenkeeper-webpack-dev-server-2.4.3 into 020295b on master.

@instantlinux

Copy link
Copy Markdown

replaced by #447

@instantlinux
instantlinux deleted the greenkeeper-webpack-dev-server-2.4.3 branch January 31, 2020 01:21
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@greenkeeperio-bot@coveralls@instantlinux@sethyates
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Update webpack-dev-server to version 2.4.3 🚀 by greenkeeperio-bot · Pull Request #444 · krux/postscribe · GitHub
Skip to content
This repository was archived by the owner on Feb 9, 2024. It is now read-only.

Update webpack-dev-server to version 2.4.3 🚀 - #444

Closed
greenkeeperio-bot wants to merge 1 commit into
masterfrom
greenkeeper-webpack-dev-server-2.4.3
Closed

Update webpack-dev-server to version 2.4.3 🚀#444
greenkeeperio-bot wants to merge 1 commit into
masterfrom
greenkeeper-webpack-dev-server-2.4.3

Conversation

@greenkeeperio-bot

Copy link
Copy Markdown
Contributor

Hello lovely humans,

webpack-dev-server just published its new version 2.4.3.

State Update 🚀
Dependency webpack-dev-server
New version 2.4.3
Type devDependency

This version is not covered by your current version range.

Without accepting this pull request your project will work just like it did before. There might be a bunch of new features, fixes and perf improvements that the maintainers worked on for you though.

I recommend you look into these changes and try to get onto the latest version of webpack-dev-server.
Given that you have a decent test suite, a passing build is a strong indicator that you can take advantage of these changes by merging the proposed change into your project. Otherwise this branch is a great starting point for you to work on the update.

Do you have any ideas how I could improve these pull requests? Did I report anything you think isn’t right?
Are you unsure about how things are supposed to work?

There is a collection of frequently asked questions and while I’m just a bot, there is a group of people who are happy to teach me new things. Let them know.

Good luck with your project ✨

You rock!

🌴


GitHub Release

Security fix:

This version contains a security fix, which is also breaking change if you have an insecure configuration.
We are releasing this breaking change as patch version to protect you from attacks.
Sorry if this breaks your setup, but the fix is easy.

We added a check for the correct Host header to the webpack-dev-server.
This allowed evil websites to access your assets.

The Host header of the request have to match the listening adress or the host provided in the public option.
Make sure to provide correct values here.

The response will contain a note when using an incorrect Host header.

For usage behind a Proxy or similar setups we also added a disableHostCheck option to disable this check.
Only use it when you know what you do. Not recommended.

This version also includes this security fix for webpack-dev-middleware: https://github.com/webpack/webpack-dev-middleware/releases/tag/v1.10.2

Bugfixes:

  • Requests are not blocked when Host doesn't match listening host or public option.
  • Requests to localhost or 127.0.0.1 are not blocked.

Features:

  • Added disableHostCheck option to disable the host check

The new version differs by 259 commits (ahead by 259, behind by 34).

  • ca932842.4.3
  • f3a4ac6Merge branch 'security/host-check'
  • 8db5fd5Require a secure webpack-dev-middleware version
  • 2957853enable Host header check for all requests and sockets
  • 60e47272.4.2
  • 32adae3Added beforeunload check to index.js (#544) (#841)
  • d69559aHandle external upgrade for all websocket proxies (#843)
  • 35a44d1Remove Node.js v7 warning
  • d2f579cSupport for array of contentBase (#832)
  • aabeeaaRemove unnecessary logging of closing the dev-server
  • 1dc9461Fix to share proxy option between proxy settings when the proxy option is a same object (#836)
  • 42cd23cExplicitely but gracefully handle SIGINT and SIGTERM signals. (#787)
  • 85de417Use arrow function if it possible and get rid of .bind in server part (#835)
  • 234294aAdd unit tests for proxy options (#834)
  • 8d4b826add codecov

There are 250 commits in total. See the full diff.


✨ Try the all new Greenkeeper GitHub Integration
With Integrationsfirst-class bot support landed on GitHub and we’ve rewritten Greenkeeper to take full advantage of it. Simpler setup, fewer pull-requests, faster than ever.

Screencast

Try it today. Free for private repositories during beta.

@coveralls

Copy link
Copy Markdown

Coverage Status

Coverage increased (+0.3%) to 89.298% when pulling ef3986c on greenkeeper-webpack-dev-server-2.4.3 into 020295b on master.

@instantlinux

Copy link
Copy Markdown

replaced by #447

@instantlinux
instantlinux deleted the greenkeeper-webpack-dev-server-2.4.3 branch January 31, 2020 01:21
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@greenkeeperio-bot@coveralls@instantlinux@sethyates
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Update webpack-dev-server to version 2.4.3 🚀 by greenkeeperio-bot · Pull Request #444 · krux/postscribe · GitHub
Skip to content
This repository was archived by the owner on Feb 9, 2024. It is now read-only.

Update webpack-dev-server to version 2.4.3 🚀 - #444

Closed
greenkeeperio-bot wants to merge 1 commit into
masterfrom
greenkeeper-webpack-dev-server-2.4.3
Closed

Update webpack-dev-server to version 2.4.3 🚀#444
greenkeeperio-bot wants to merge 1 commit into
masterfrom
greenkeeper-webpack-dev-server-2.4.3

Conversation

@greenkeeperio-bot

Copy link
Copy Markdown
Contributor

Hello lovely humans,

webpack-dev-server just published its new version 2.4.3.

State Update 🚀
Dependency webpack-dev-server
New version 2.4.3
Type devDependency

This version is not covered by your current version range.

Without accepting this pull request your project will work just like it did before. There might be a bunch of new features, fixes and perf improvements that the maintainers worked on for you though.

I recommend you look into these changes and try to get onto the latest version of webpack-dev-server.
Given that you have a decent test suite, a passing build is a strong indicator that you can take advantage of these changes by merging the proposed change into your project. Otherwise this branch is a great starting point for you to work on the update.

Do you have any ideas how I could improve these pull requests? Did I report anything you think isn’t right?
Are you unsure about how things are supposed to work?

There is a collection of frequently asked questions and while I’m just a bot, there is a group of people who are happy to teach me new things. Let them know.

Good luck with your project ✨

You rock!

🌴


GitHub Release

Security fix:

This version contains a security fix, which is also breaking change if you have an insecure configuration.
We are releasing this breaking change as patch version to protect you from attacks.
Sorry if this breaks your setup, but the fix is easy.

We added a check for the correct Host header to the webpack-dev-server.
This allowed evil websites to access your assets.

The Host header of the request have to match the listening adress or the host provided in the public option.
Make sure to provide correct values here.

The response will contain a note when using an incorrect Host header.

For usage behind a Proxy or similar setups we also added a disableHostCheck option to disable this check.
Only use it when you know what you do. Not recommended.

This version also includes this security fix for webpack-dev-middleware: https://github.com/webpack/webpack-dev-middleware/releases/tag/v1.10.2

Bugfixes:

  • Requests are not blocked when Host doesn't match listening host or public option.
  • Requests to localhost or 127.0.0.1 are not blocked.

Features:

  • Added disableHostCheck option to disable the host check

The new version differs by 259 commits (ahead by 259, behind by 34).

  • ca932842.4.3
  • f3a4ac6Merge branch 'security/host-check'
  • 8db5fd5Require a secure webpack-dev-middleware version
  • 2957853enable Host header check for all requests and sockets
  • 60e47272.4.2
  • 32adae3Added beforeunload check to index.js (#544) (#841)
  • d69559aHandle external upgrade for all websocket proxies (#843)
  • 35a44d1Remove Node.js v7 warning
  • d2f579cSupport for array of contentBase (#832)
  • aabeeaaRemove unnecessary logging of closing the dev-server
  • 1dc9461Fix to share proxy option between proxy settings when the proxy option is a same object (#836)
  • 42cd23cExplicitely but gracefully handle SIGINT and SIGTERM signals. (#787)
  • 85de417Use arrow function if it possible and get rid of .bind in server part (#835)
  • 234294aAdd unit tests for proxy options (#834)
  • 8d4b826add codecov

There are 250 commits in total. See the full diff.


✨ Try the all new Greenkeeper GitHub Integration
With Integrationsfirst-class bot support landed on GitHub and we’ve rewritten Greenkeeper to take full advantage of it. Simpler setup, fewer pull-requests, faster than ever.

Screencast

Try it today. Free for private repositories during beta.

@coveralls

Copy link
Copy Markdown

Coverage Status

Coverage increased (+0.3%) to 89.298% when pulling ef3986c on greenkeeper-webpack-dev-server-2.4.3 into 020295b on master.

@instantlinux

Copy link
Copy Markdown

replaced by #447

@instantlinux
instantlinux deleted the greenkeeper-webpack-dev-server-2.4.3 branch January 31, 2020 01:21
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@greenkeeperio-bot@coveralls@instantlinux@sethyates
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Update webpack-dev-server to version 2.4.3 🚀 by greenkeeperio-bot · Pull Request #444 · krux/postscribe · GitHub
Skip to content
This repository was archived by the owner on Feb 9, 2024. It is now read-only.

Update webpack-dev-server to version 2.4.3 🚀 - #444

Closed
greenkeeperio-bot wants to merge 1 commit into
masterfrom
greenkeeper-webpack-dev-server-2.4.3
Closed

Update webpack-dev-server to version 2.4.3 🚀#444
greenkeeperio-bot wants to merge 1 commit into
masterfrom
greenkeeper-webpack-dev-server-2.4.3

Conversation

@greenkeeperio-bot

Copy link
Copy Markdown
Contributor

Hello lovely humans,

webpack-dev-server just published its new version 2.4.3.

State Update 🚀
Dependency webpack-dev-server
New version 2.4.3
Type devDependency

This version is not covered by your current version range.

Without accepting this pull request your project will work just like it did before. There might be a bunch of new features, fixes and perf improvements that the maintainers worked on for you though.

I recommend you look into these changes and try to get onto the latest version of webpack-dev-server.
Given that you have a decent test suite, a passing build is a strong indicator that you can take advantage of these changes by merging the proposed change into your project. Otherwise this branch is a great starting point for you to work on the update.

Do you have any ideas how I could improve these pull requests? Did I report anything you think isn’t right?
Are you unsure about how things are supposed to work?

There is a collection of frequently asked questions and while I’m just a bot, there is a group of people who are happy to teach me new things. Let them know.

Good luck with your project ✨

You rock!

🌴


GitHub Release

Security fix:

This version contains a security fix, which is also breaking change if you have an insecure configuration.
We are releasing this breaking change as patch version to protect you from attacks.
Sorry if this breaks your setup, but the fix is easy.

We added a check for the correct Host header to the webpack-dev-server.
This allowed evil websites to access your assets.

The Host header of the request have to match the listening adress or the host provided in the public option.
Make sure to provide correct values here.

The response will contain a note when using an incorrect Host header.

For usage behind a Proxy or similar setups we also added a disableHostCheck option to disable this check.
Only use it when you know what you do. Not recommended.

This version also includes this security fix for webpack-dev-middleware: https://github.com/webpack/webpack-dev-middleware/releases/tag/v1.10.2

Bugfixes:

  • Requests are not blocked when Host doesn't match listening host or public option.
  • Requests to localhost or 127.0.0.1 are not blocked.

Features:

  • Added disableHostCheck option to disable the host check

The new version differs by 259 commits (ahead by 259, behind by 34).

  • ca932842.4.3
  • f3a4ac6Merge branch 'security/host-check'
  • 8db5fd5Require a secure webpack-dev-middleware version
  • 2957853enable Host header check for all requests and sockets
  • 60e47272.4.2
  • 32adae3Added beforeunload check to index.js (#544) (#841)
  • d69559aHandle external upgrade for all websocket proxies (#843)
  • 35a44d1Remove Node.js v7 warning
  • d2f579cSupport for array of contentBase (#832)
  • aabeeaaRemove unnecessary logging of closing the dev-server
  • 1dc9461Fix to share proxy option between proxy settings when the proxy option is a same object (#836)
  • 42cd23cExplicitely but gracefully handle SIGINT and SIGTERM signals. (#787)
  • 85de417Use arrow function if it possible and get rid of .bind in server part (#835)
  • 234294aAdd unit tests for proxy options (#834)
  • 8d4b826add codecov

There are 250 commits in total. See the full diff.


✨ Try the all new Greenkeeper GitHub Integration
With Integrationsfirst-class bot support landed on GitHub and we’ve rewritten Greenkeeper to take full advantage of it. Simpler setup, fewer pull-requests, faster than ever.

Screencast

Try it today. Free for private repositories during beta.

@coveralls

Copy link
Copy Markdown

Coverage Status

Coverage increased (+0.3%) to 89.298% when pulling ef3986c on greenkeeper-webpack-dev-server-2.4.3 into 020295b on master.

@instantlinux

Copy link
Copy Markdown

replaced by #447

@instantlinux
instantlinux deleted the greenkeeper-webpack-dev-server-2.4.3 branch January 31, 2020 01:21
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@greenkeeperio-bot@coveralls@instantlinux@sethyates
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Update webpack-dev-server to version 2.4.3 🚀 by greenkeeperio-bot · Pull Request #444 · krux/postscribe · GitHub
Skip to content
This repository was archived by the owner on Feb 9, 2024. It is now read-only.

Update webpack-dev-server to version 2.4.3 🚀 - #444

Closed
greenkeeperio-bot wants to merge 1 commit into
masterfrom
greenkeeper-webpack-dev-server-2.4.3
Closed

Update webpack-dev-server to version 2.4.3 🚀#444
greenkeeperio-bot wants to merge 1 commit into
masterfrom
greenkeeper-webpack-dev-server-2.4.3

Conversation

@greenkeeperio-bot

Copy link
Copy Markdown
Contributor

Hello lovely humans,

webpack-dev-server just published its new version 2.4.3.

State Update 🚀
Dependency webpack-dev-server
New version 2.4.3
Type devDependency

This version is not covered by your current version range.

Without accepting this pull request your project will work just like it did before. There might be a bunch of new features, fixes and perf improvements that the maintainers worked on for you though.

I recommend you look into these changes and try to get onto the latest version of webpack-dev-server.
Given that you have a decent test suite, a passing build is a strong indicator that you can take advantage of these changes by merging the proposed change into your project. Otherwise this branch is a great starting point for you to work on the update.

Do you have any ideas how I could improve these pull requests? Did I report anything you think isn’t right?
Are you unsure about how things are supposed to work?

There is a collection of frequently asked questions and while I’m just a bot, there is a group of people who are happy to teach me new things. Let them know.

Good luck with your project ✨

You rock!

🌴


GitHub Release

Security fix:

This version contains a security fix, which is also breaking change if you have an insecure configuration.
We are releasing this breaking change as patch version to protect you from attacks.
Sorry if this breaks your setup, but the fix is easy.

We added a check for the correct Host header to the webpack-dev-server.
This allowed evil websites to access your assets.

The Host header of the request have to match the listening adress or the host provided in the public option.
Make sure to provide correct values here.

The response will contain a note when using an incorrect Host header.

For usage behind a Proxy or similar setups we also added a disableHostCheck option to disable this check.
Only use it when you know what you do. Not recommended.

This version also includes this security fix for webpack-dev-middleware: https://github.com/webpack/webpack-dev-middleware/releases/tag/v1.10.2

Bugfixes:

  • Requests are not blocked when Host doesn't match listening host or public option.
  • Requests to localhost or 127.0.0.1 are not blocked.

Features:

  • Added disableHostCheck option to disable the host check

The new version differs by 259 commits (ahead by 259, behind by 34).

  • ca932842.4.3
  • f3a4ac6Merge branch 'security/host-check'
  • 8db5fd5Require a secure webpack-dev-middleware version
  • 2957853enable Host header check for all requests and sockets
  • 60e47272.4.2
  • 32adae3Added beforeunload check to index.js (#544) (#841)
  • d69559aHandle external upgrade for all websocket proxies (#843)
  • 35a44d1Remove Node.js v7 warning
  • d2f579cSupport for array of contentBase (#832)
  • aabeeaaRemove unnecessary logging of closing the dev-server
  • 1dc9461Fix to share proxy option between proxy settings when the proxy option is a same object (#836)
  • 42cd23cExplicitely but gracefully handle SIGINT and SIGTERM signals. (#787)
  • 85de417Use arrow function if it possible and get rid of .bind in server part (#835)
  • 234294aAdd unit tests for proxy options (#834)
  • 8d4b826add codecov

There are 250 commits in total. See the full diff.


✨ Try the all new Greenkeeper GitHub Integration
With Integrationsfirst-class bot support landed on GitHub and we’ve rewritten Greenkeeper to take full advantage of it. Simpler setup, fewer pull-requests, faster than ever.

Screencast

Try it today. Free for private repositories during beta.

@coveralls

Copy link
Copy Markdown

Coverage Status

Coverage increased (+0.3%) to 89.298% when pulling ef3986c on greenkeeper-webpack-dev-server-2.4.3 into 020295b on master.

@instantlinux

Copy link
Copy Markdown

replaced by #447

@instantlinux
instantlinux deleted the greenkeeper-webpack-dev-server-2.4.3 branch January 31, 2020 01:21
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@greenkeeperio-bot@coveralls@instantlinux@sethyates
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Update webpack-dev-server to version 2.4.3 🚀 by greenkeeperio-bot · Pull Request #444 · krux/postscribe · GitHub
Skip to content
This repository was archived by the owner on Feb 9, 2024. It is now read-only.

Update webpack-dev-server to version 2.4.3 🚀 - #444

Closed
greenkeeperio-bot wants to merge 1 commit into
masterfrom
greenkeeper-webpack-dev-server-2.4.3
Closed

Update webpack-dev-server to version 2.4.3 🚀#444
greenkeeperio-bot wants to merge 1 commit into
masterfrom
greenkeeper-webpack-dev-server-2.4.3

Conversation

@greenkeeperio-bot

Copy link
Copy Markdown
Contributor

Hello lovely humans,

webpack-dev-server just published its new version 2.4.3.

State Update 🚀
Dependency webpack-dev-server
New version 2.4.3
Type devDependency

This version is not covered by your current version range.

Without accepting this pull request your project will work just like it did before. There might be a bunch of new features, fixes and perf improvements that the maintainers worked on for you though.

I recommend you look into these changes and try to get onto the latest version of webpack-dev-server.
Given that you have a decent test suite, a passing build is a strong indicator that you can take advantage of these changes by merging the proposed change into your project. Otherwise this branch is a great starting point for you to work on the update.

Do you have any ideas how I could improve these pull requests? Did I report anything you think isn’t right?
Are you unsure about how things are supposed to work?

There is a collection of frequently asked questions and while I’m just a bot, there is a group of people who are happy to teach me new things. Let them know.

Good luck with your project ✨

You rock!

🌴


GitHub Release

Security fix:

This version contains a security fix, which is also breaking change if you have an insecure configuration.
We are releasing this breaking change as patch version to protect you from attacks.
Sorry if this breaks your setup, but the fix is easy.

We added a check for the correct Host header to the webpack-dev-server.
This allowed evil websites to access your assets.

The Host header of the request have to match the listening adress or the host provided in the public option.
Make sure to provide correct values here.

The response will contain a note when using an incorrect Host header.

For usage behind a Proxy or similar setups we also added a disableHostCheck option to disable this check.
Only use it when you know what you do. Not recommended.

This version also includes this security fix for webpack-dev-middleware: https://github.com/webpack/webpack-dev-middleware/releases/tag/v1.10.2

Bugfixes:

  • Requests are not blocked when Host doesn't match listening host or public option.
  • Requests to localhost or 127.0.0.1 are not blocked.

Features:

  • Added disableHostCheck option to disable the host check

The new version differs by 259 commits (ahead by 259, behind by 34).

  • ca932842.4.3
  • f3a4ac6Merge branch 'security/host-check'
  • 8db5fd5Require a secure webpack-dev-middleware version
  • 2957853enable Host header check for all requests and sockets
  • 60e47272.4.2
  • 32adae3Added beforeunload check to index.js (#544) (#841)
  • d69559aHandle external upgrade for all websocket proxies (#843)
  • 35a44d1Remove Node.js v7 warning
  • d2f579cSupport for array of contentBase (#832)
  • aabeeaaRemove unnecessary logging of closing the dev-server
  • 1dc9461Fix to share proxy option between proxy settings when the proxy option is a same object (#836)
  • 42cd23cExplicitely but gracefully handle SIGINT and SIGTERM signals. (#787)
  • 85de417Use arrow function if it possible and get rid of .bind in server part (#835)
  • 234294aAdd unit tests for proxy options (#834)
  • 8d4b826add codecov

There are 250 commits in total. See the full diff.


✨ Try the all new Greenkeeper GitHub Integration
With Integrationsfirst-class bot support landed on GitHub and we’ve rewritten Greenkeeper to take full advantage of it. Simpler setup, fewer pull-requests, faster than ever.

Screencast

Try it today. Free for private repositories during beta.

@coveralls

Copy link
Copy Markdown

Coverage Status

Coverage increased (+0.3%) to 89.298% when pulling ef3986c on greenkeeper-webpack-dev-server-2.4.3 into 020295b on master.

@instantlinux

Copy link
Copy Markdown

replaced by #447

@instantlinux
instantlinux deleted the greenkeeper-webpack-dev-server-2.4.3 branch January 31, 2020 01:21
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@greenkeeperio-bot@coveralls@instantlinux@sethyates