Skip to content

chore(deps): Bump webpack from 5.97.0 to 5.104.0 in ember-classic e2e test#19239

Merged
chargome merged 1 commit intodevelopfrom
fix/bump-webpack-ember-classic
Feb 10, 2026
Merged

chore(deps): Bump webpack from 5.97.0 to 5.104.0 in ember-classic e2e test#19239
chargome merged 1 commit intodevelopfrom
fix/bump-webpack-ember-classic

Conversation

@chargome
Copy link
Member

@chargome chargome commented Feb 9, 2026

Addresses CVE-2025-68157 (GHSA-38r7-794h-5758), an allowedUris bypass via HTTP redirects in webpack's HttpUriPlugin that could enable SSRF at build time.

https://github.com/getsentry/sentry-javascript/security/dependabot/1047

Addresses CVE-2025-68157 (GHSA-38r7-794h-5758), an allowedUris bypass
via HTTP redirects in webpack's HttpUriPlugin that could enable SSRF
at build time.

Co-Authored-By: Claude <noreply@anthropic.com>
@chargome chargome self-assigned this Feb 10, 2026
@github-actions
Copy link
Contributor

github-actions bot commented Feb 10, 2026

Codecov Results 📊


Generated by Codecov Action

@chargome chargome merged commit 9d612f6 into develop Feb 10, 2026
58 of 61 checks passed
@chargome chargome deleted the fix/bump-webpack-ember-classic branch February 10, 2026 10:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants