fix: resolve webpack-dev-server security vulnerabilities #719
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Resolves the last 2 remaining security vulnerabilities by upgrading webpack-dev-server from 4.15.2 to 5.2.2 using npm overrides.
Vulnerabilities Fixed
Both moderate severity, dev-only:
Affected: webpack-dev-server <=5.2.0
Fixed in: webpack-dev-server 5.2.1+
The Solution
webpack-dev-server is a transitive dependency of @wordpress/scripts which specifies
^4.15.1. Using npm'soverridesfeature forces all packages to use the patched version:Testing
✅ Build: Completes successfully
✅ Tests: All pass
✅ npm audit: 0 vulnerabilities (production and dev)
Security Achievement
Complete vulnerability elimination:
Related PRs
🤖 Generated with Claude Code