NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1572 most downloaded on npm
A development middleware for webpack
Last release 1 months ago
03 Sep 2026
Release timing varies
gaps range from 9 days to 13 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
130 releases · first in 2012
…to quiet the browser alone. hot.statsOptions is deprecated and will be removed in the next major release; its hash , timings and children keys are now…
Added a hot option that enables hot module replacement, replacing the need for webpack-hot-middleware. Pass hot: true to enable with defaults, or hot: { path, heartbeat, progress, statsOptions } to customize. The client runtime is served by the middleware itself. (by @bjohansebas in #2370)
Take the diagnostics a hot payload carries from the stats option, so one setting governs what a build reports in the terminal and in the browser: stats: "errors-only" keeps warnings out of both, and stats: false keeps errors and warnings out of both, the client's error overlay included — reach for the client's ?logging= or ?overlay= to quiet the browser alone. hot.statsOptions is deprecated and will be removed in the next major release; its hash, timings and children keys are now ignored, because they could leave a payload without the hash the client compares, or carry a child compilation's hash instead, which stopped updates applying and forced a full page reload on every rebuild. (by @alexander-akait in #2392)
Fixed a crash when calling invalidate() in plugin mode (isPlugin = true). Since the host (webpack-cli, webpack-dev-server, etc.) owns compiler.watch(), the middleware now invalidates the host's watching instead (each child compiler's one for a MultiCompiler on webpack < 5.109). When nothing is watching it logs a warning and completes the callback, as close() does, rather than leaving invalidate(callback) waiting on a build that never runs. (by @bjohansebas in #2378)
Reject with 403 Forbidden the requests whose resolved filename falls outside outputPath (GHSA-g84c-rxfj-3j2c). With a publicPath without a trailing slash, a sibling path sharing its prefix (/assets../secret) escaped the output root once the prefix was stripped and joined. (by @bjohansebas in #2404)
Update the changelog generator to the @changesets/get-github-info 1.0 API. (by @alexander-akait in #2396)
Update dependencies. (by @alexander-akait in #2394)
One column per quarter.
Added a hot option that enables hot module replacement, replacing the need for webpack-hot-middleware . Pass hot: true to enable with defaults, or hot
hot option that enables hot module replacement, replacing the need for webpack-hot-middleware. Pass hot: true to enable with defaults, or hot: { path, heartbeat, progress, statsOptions } to customize. The client runtime ships with the package and is added as a webpack entry. (by @bjohansebas in #2322)Fixed a crash when calling close() in plugin mode ( isPlugin = true ). Since the host (webpack-cli, webpack-dev-server, etc.) owns compiler.watch() ,
close() in plugin mode (isPlugin = true). Since the host (webpack-cli, webpack-dev-server, etc.) owns compiler.watch(), the middleware has no watching of its own to close, so close() now just calls the callback instead of throwing. (by @bjohansebas in #2347)Reuse an already active MultiCompiler watching session instead of starting a duplicate one (requires webpack >= 5.109). (by @bjohansebas in #2371 )
MultiCompiler watching session instead of starting a duplicate one (requires webpack >= 5.109). (by @bjohansebas in #2371)Replace the on-finished dependency with Node.js built-in stream.finished . (by @bjohansebas in #2346 )
on-finished dependency with Node.js built-in stream.finished. (by @bjohansebas in #2346)Respect req.url when modified by middleware such as connect-history-api-fallback . (by @bjohansebas in #2304 )
req.url when modified by middleware such as connect-history-api-fallback. (by @bjohansebas in #2304)Fixed compatibility with rspack. (by @alexander-akait in #2295 )
Fixed compatibility with rspack. (by @alexander-akait in 0b40cfd )
0b40cfd)The getFilenameFromUrl function is now asynchronous, returning a Promise that resolves to the object with the found filename (or undefined if the file
The getFilenameFromUrl function is now asynchronous, returning a Promise that resolves to the object with the found filename (or undefined if the file was not found) or throws an error if the URL cannot be processed. Additionally, the object contains the extra property with stats (file system stats) and outputFileSystem (output file system where file was found) properties. (by @alexander-akait in #2284)
Minimum supported Node.js version is 20.9.0. (by @alexander-akait in #2284)
Minimum supported webpack version is 5.101.0. (by @alexander-akait in #2284)
Added support for plugin usage, useful when the middleware will be used as a webpack plugin (no stats output, no extra actions). (by @alexander-akait in #2284)
Added the forwardError option to enable error forwarding to next middleware. (by @alexander-akait in #2284)
Enable cacheImmutable by default for immutable assets. (by @alexander-akait in #2284)
Improved initial loading module time. (by @alexander-akait in #2284)
Removed outdated code and improved performance by avoiding extra loops. (by @alexander-akait in #2284)
All notable changes to this project will be documented in this file. See standard-version for commit guidelines.
reject requests that resolve outside the output directory
7.4.5 (2025-09-24) Bug Fixes unpin memfs
7.4.4 (2025-09-23) Bug Fixes pin memfs version
no crash when headers are already sent
assetsInfo may be undefined (rspack)
added the cacheImmutable option to cache immutable assets (assets with a hash in file name like image.e12ab567.jpg)
## 7.3.0 (2024-07-18) ### Features * support hono
### 7.2.1 (2024-04-02) ### Bug Fixes * avoid extra log
support Last-Modified header generation
prefer to use fs.createReadStream over fs.readFileSync to read files
minimum supported Node.js version is 18.12.0
### 6.1.3 (2024-03-29) ### Bug Fixes * security problem
security: do not allow to read files above
types: methods should be string array
added modifyResponseData option
### 6.0.2 (2023-03-19) ### Bug Fixes * make webpack optional peerDep
update schema for index and methods properties
minimum supported webpack version is 5.0.0
security: do not allow to read files above
### 5.3.3 (2022-05-18) ### Bug Fixes * types for Request and Response
### 5.3.2 (2022-05-17) ### Bug Fixes * node types (#1195) (d68ab36) * compatibility with Node.js 18
### 5.3.1 (2022-02-01) ### Bug Fixes * types
## 5.3.0 (2021-12-16) ### Features * added types (a2fa77f) * removed cjs wrapper
update schema-utils package to 4.0.0 version
internal release, no visible changes and features
## 5.2.0 (2021-09-24) ### Features * allow array for headers option
don't read full file if Range header is present
minimum supported Node.js version is 12.13.0
## 4.3.0 (2021-05-19) ### Features * add getFilenameFromUrl to API
allow the headers option to accept function
## 4.1.0 (2021-01-15) ### Features * added the stats option
stats option (376cdba)stats to stdout instead stderr, how does webpack-cli, if you need hide stats from output please use { stats: false } or { stats: 'none' } (4de0f97)stats (4de0f97)Content-type header on unknown types (#809) (5c9eee5)connect (b83a1db)### 4.0.4 (2021-01-13) ### Bug Fixes * compatibility with webpack@4
output stats to stdout instead stderr, how does webpack-cli, if you need hide stats from output please use { stats: false } or { stats: 'none' }
compatibility with the headers option
### 4.0.1 (2020-11-09) ### Bug Fixes * compatibility with connect
compatibility with new webpack@5 API
## 4.0.0-rc.3 (2020-07-14) * internal improvements
prefer mime type option over built-in
## 4.0.0-rc.1 (2020-02-20) ### Bug Fixes * missing options.json file
output.path and output.publicPath options from the configurationstats option from the configurationwatchOptions option from the configurationwriteToDisk option now correctly works in multi-compiler modeoutputFileSystem option now correctly works in multi-compiler mode[hash]/[fullhash] in output.path and output.publicPathContent-Type header doesn't have charset=utf-8 value for custom MIME types and MIME types which can be non utf-8webpack loggermemfs package10.13.0publicPath is taken from the value of the output.publicPath option from the configuration (webpack.config.js)stats option was removed, the default value of the stats option is taken from the value of the stats option from the configuration (webpack.config.js)watchOptions was removed, the default value of the watchOptions option is taken from the value of the watchOptions option from the configuration (webpack.config.js)Content-Type header doesn't have charset=utf-8 value for custom MIME types and MIME types which can be non utf-8fs option was renamed to the outputFileSystem optionlazy option was removed without replacementlogger, logLevel and logTime options were removed without replacement. You can setup the level value using { infrastructureLogging: { level: 'warn' } }, please read https://webpack.js.org/configuration/other-options/#infrastructurelogging. You can use the infrastructurelog (infrastructureLog in webpack@5) hook to customize logs. The log property in the middleware context was renamed to loggermimeTypes option first requires you to specify an extension and then a content-type - { mimeTypes: { phtml: 'text/html' } }force option from the mimeTypes option was removed without replacementreporter option was removed without replacementgetFilenameFromUrl method was removed from the APIlocals now under res.locals.webpack - use res.locals.webpack.stats for access stats and res.locals.webpack.outputFileSystem to access outputFileSystemrespect output.path and output.publicPath options from the configuration
output.path and output.publicPath options from the configurationstats option from the configurationwatchOptions option from the configurationwriteToDisk option now correctly works in multi-compiler modeoutputFileSystem option now correctly works in multi-compiler mode[hash]/[fullhash] in output.path and output.publicPathContent-Type header doesn't have charset=utf-8 value for custom MIME types and MIME types which can be non utf-8webpack loggermemfs package10.13.0publicPath is taken from the value of the output.publicPath option from the configuration (webpack.config.js)stats option was removed, the default value of the stats option is taken from the value of the stats option from the configuration (webpack.config.js)watchOptions was removed, the default value of the watchOptions option is taken from the value of the watchOptions option from the configuration (webpack.config.js)Content-Type header doesn't have charset=utf-8 value for custom MIME types and MIME types which can be non utf-8fs option was renamed to the outputFileSystem optionlazy option was removed without replacementlogger, logLevel and logTime options were removed without replacement. You can setup the level value using { infrastructureLogging: { level: 'warn' } }, please read https://webpack.js.org/configuration/other-options/#infrastructurelogging. You can use the infrastructurelog (infrastructureLog in webpack@5) hook to customize logs. The log property in the middleware context was renamed to loggermimeTypes option first requires you to specify an extension and then a content-type - { mimeTypes: { phtml: 'text/html' } }force option from the mimeTypes option was removed without replacementreporter option was removed without replacementgetFilenameFromUrl method was removed from the APIlocals now under res.locals.webpack - use res.locals.webpack.stats for access stats and res.locals.webpack.outputFileSystem to access outputFileSystempeer dependencies with webpack@5
## 3.7.0 (2019-05-15) ### Features * support HEAD method by default
check existence of res.getHeader and set the correct Content-Type
do not overwrite Content-Type if header already exists
configurable file system via options.fs
don't add charset to usdz file type
remove querystring from filenames when writing to disk
<a name="3.5.0"></a>
<a name="3.3.0"></a>
<a name="3.2.0"></a>
Your coding agent can read these notes before it upgrades. Set up the MCP server →