Skip to content

fix(deps): Bump enhanced-resolve from 5.24.5 to 5.26.0 - #843

Open
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/dev/enhanced-resolve-5.26.0
Open

dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/dev/enhanced-resolve-5.26.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps enhanced-resolve from 5.24.5 to 5.26.0.

Release notes

Sourced from enhanced-resolve's releases.

v5.26.0

Minor Changes

  • Add experimental support for Node.js package maps through a new packageMap option, which takes the path of the configuration file (or a file: URL) or an already-parsed packages object. When it is set, a bare specifier is resolved through the importing package's dependencies table and the target package's location is handed to the regular pipeline, instead of walking node_modules; relative and absolute requests and node: builtins are unaffected. Because several package entries may share one url, the package a request resolved into is exposed as packageId on the result and can be passed back in as context.packageId to resolve from that package unambiguously. Package maps are stability 1 (experimental) in Node.js, and this option tracks that specification and may change with it. (by @​alexander-akait in #667)

  • Explain an exports/imports field whose conditions wrap subpaths, instead of failing with a message that points at the request. A field shaped like { "import": { ".": "./esm/index.js", "./*": "./esm/*.js" }, "require": "./build/bundle.js" } is not supported by Node.js: the subpaths inside a condition are read as condition names, so they match nothing, and every request into the package failed as "./foo" is not exported under the conditions [...] — which reads as though the package forgot to export ./foo. Such a failure now names the offending keys and shows the arrangement that works, with the subpaths at the top level and the conditions nested inside them. Resolution itself is unchanged: the diagnosis runs only on a request that has already failed, so nothing that resolves today starts failing, and a successful resolve does no extra work. Errors raised while processing either field also name the package.json they came from, which previously only appeared in the resolver log. (by @​alexander-akait in #676)

  • Generate the published type declarations with TypeScript instead of webpack/tooling, which is no longer a dependency. Every name the package exported before is still exported, and types.d.ts is still the entry point, but the declarations themselves now live in types/ and are emitted by tsc from the JSDoc in lib/. Two shapes follow the sources more closely than the previous generator did: the object form of Plugin no longer declares this: Resolver on apply (it is called as plugin.apply(resolver), so this is the plugin), and the entries of ResolveContext.stack declare name: string | undefined rather than an optional name. Class fields that the old generator dropped, such as the cache backends on CachedInputFileSystem, are now part of the declarations. (by @​alexander-akait in #675)

Patch Changes

  • Size the ancestor path and segment arrays that getPathsCached keeps to what they actually hold: a push-built store keeps room for 17 entries while a path has a handful, and the cache holds these for the filesystem's lifetime. (by @​alexander-akait in #681)

v5.25.1

Patch Changes

v5.25.0

Minor Changes

Changelog

Sourced from enhanced-resolve's changelog.

5.26.0

Minor Changes

  • Add experimental support for Node.js package maps through a new packageMap option, which takes the path of the configuration file (or a file: URL) or an already-parsed packages object. When it is set, a bare specifier is resolved through the importing package's dependencies table and the target package's location is handed to the regular pipeline, instead of walking node_modules; relative and absolute requests and node: builtins are unaffected. Because several package entries may share one url, the package a request resolved into is exposed as packageId on the result and can be passed back in as context.packageId to resolve from that package unambiguously. Package maps are stability 1 (experimental) in Node.js, and this option tracks that specification and may change with it. (by @​alexander-akait in #667)

  • Explain an exports/imports field whose conditions wrap subpaths, instead of failing with a message that points at the request. A field shaped like { "import": { ".": "./esm/index.js", "./*": "./esm/*.js" }, "require": "./build/bundle.js" } is not supported by Node.js: the subpaths inside a condition are read as condition names, so they match nothing, and every request into the package failed as "./foo" is not exported under the conditions [...] — which reads as though the package forgot to export ./foo. Such a failure now names the offending keys and shows the arrangement that works, with the subpaths at the top level and the conditions nested inside them. Resolution itself is unchanged: the diagnosis runs only on a request that has already failed, so nothing that resolves today starts failing, and a successful resolve does no extra work. Errors raised while processing either field also name the package.json they came from, which previously only appeared in the resolver log. (by @​alexander-akait in #676)

  • Generate the published type declarations with TypeScript instead of webpack/tooling, which is no longer a dependency. Every name the package exported before is still exported, and types.d.ts is still the entry point, but the declarations themselves now live in types/ and are emitted by tsc from the JSDoc in lib/. Two shapes follow the sources more closely than the previous generator did: the object form of Plugin no longer declares this: Resolver on apply (it is called as plugin.apply(resolver), so this is the plugin), and the entries of ResolveContext.stack declare name: string | undefined rather than an optional name. Class fields that the old generator dropped, such as the cache backends on CachedInputFileSystem, are now part of the declarations. (by @​alexander-akait in #675)

Patch Changes

  • Size the ancestor path and segment arrays that getPathsCached keeps to what they actually hold: a push-built store keeps room for 17 entries while a path has a handful, and the cache holds these for the filesystem's lifetime. (by @​alexander-akait in #681)

5.25.1

Patch Changes

5.25.0

Minor Changes

Commits
  • c65e40a chore(release): new release (#674)
  • 7ed8697 perf: size the paths a request walks from its split (#681)
  • 7e37289 chore(deps-dev): bump the dependencies group with 4 updates (#680)
  • cba4ba4 test(alias): cover compileAliasOptions bucketing and the onlyModule flag (#679)
  • f07a030 feat: explain exports/imports conditions that wrap subpaths (#676)
  • d9a13d7 chore(deps): bump codecov/codecov-action from 7.0.0 to 7.1.1 in the dependenc...
  • f8d395e chore(deps-dev): bump the dependencies group with 6 updates (#677)
  • e1bdb75 refactor: generate types with typescript instead of webpack/tooling (#675)
  • 332d999 ci: cancel superseded pull request runs (#673)
  • e638bc9 feat: experimental support for Node.js package maps (#667)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [enhanced-resolve](https://github.com/webpack/enhanced-resolve) from 5.24.5 to 5.26.0.
- [Release notes](https://github.com/webpack/enhanced-resolve/releases)
- [Changelog](https://github.com/webpack/enhanced-resolve/blob/main/CHANGELOG.md)
- [Commits](webpack/enhanced-resolve@v5.24.5...v5.26.0)

---
updated-dependencies:
- dependency-name: enhanced-resolve
  dependency-version: 5.26.0
  dependency-type: indirect
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the security Security vulnerability or hardening label Oct 5, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Assignees

The following users could not be added as assignees: kellymusk. Either the username does not exist or it does not have the correct permissions to be added as an assignee.

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@vercel

vercel Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
aframp Error Error Oct 5, 2026 8:25am UTC

This branch had an error being deployed

1 failed deployment
Preview — 47a44362 Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Security vulnerability or hardening

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants