NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1572 most downloaded on npm
A development middleware for webpack
Last release 15 days ago
03 Sep 2026
Release timing varies
gaps range from 9 days to 13 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
130 releases · first in 2012
index: don't modify the default behavior for unhandledRejection
Bug FixesOne column per quarter.
middleware: expose the memory filesystem (response.locals.fs)
package: 18 security vulnerabilities
Excluded outputPath from URI escaping to fix #297.
refactor: use chalk from webpack-log
fix(package): add chalk to peerDeps
On windows path spaces should resolve to %20
Nothing published for this version
remove watchOffset option in favor of time-fix-plugin
watchOffset option has been removed and the README has been updated with alternative means of accomplishing the same result for this module and webpack v4.middleware.webpack now returns a Promise that should be handled with .then when needing to perform other actions, like adding additional middleware.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Implemented `webpack-log`, removed dependencies related to the previous logging implementation.
webpack-log, removed dependencies related to the previous logging implementation.Publish to correct package.json.
Publish to correct package.json.
It also introduced a number of breaking changes, as outlined below.
This major release introduces a comprehensive refactor of the codebase and move to leverage more ES6 as supported by Node 6+. It also introduced a number of breaking changes, as outlined below.
webpack-dev-middleware version 2 and higher will only support Node 6.x and higher. Active LTS for Node 4.x ended October 31st, 2017 and entered maintenance on that date. Likewise, the version 1.x branch of webpack-dev-middleware will enter maintenance on that date.
log-level and follows the same patterns as
webpack-dev-server.watchDelay option was previous deprecated and has now been removed.reportTime option renamed to logTimenoInfo option removed in favor of setting a logLevel higher than 'info'quiet option removed in favor of logLevel: 'silent'reporter signature changed to reporter(middlewareOptions, reporterOptions)serve .wasm files as application/wasm (without charset)
update mime package to avoid security vulnerability
mime package to avoid security vulnerability (#231)Test updates for Node 8 and Sinon
Use options.log, warn and error for messages
mimeTypes optionThis version contains a security fix, which is also breaking change if you have an insecure configuration. We are releasing this breaking change as pa…
This version contains a security fix, which is also breaking change if you have an insecure configuration. We are releasing this breaking change as patch version to protect you from attacks. Sorry if this breaks your setup, but the fix is easy.
We removed setting Access-Control-Allow-Origin to * be default. This allowed evil websites to access your assets.
Instead we ask you to set Access-Control-Allow-Origin manually to your host if required in your setup.
Use the headers option to do so.
middleware(compiler, {
headers: {
"Access-Control-Allow-Origin": "your-host"
}
})
Read more about CORS here: https://developer.mozilla.org/en-US/docs/Web/HTTP/Access_control_CORS
Access-Control-Allow-Origin = * defaultFiles with non-ascii names were not getting served (#171).
You probably have seen the infamous message webpack: bundle is now (IN)VALID. a lot of times. This has now been changed to more clear messages, clearl
webpack: bundle is now (IN)VALID. a lot of times. This has now been changed to more clear messages, clearly indicating when compiling and when done compiling, it will tell you if it was successful or with errors (#164).Allow latest webpack 2.2.0-rc.0 as peer dependency (#160).
memory-fs dependency to 0.4.1.Enforce UTF-8 in requests. This fixes a lot of issues with special characters (#136).
Fix exception when using the deprecated watchDelay option (#131).
The last few releases had a few bugs in them that shouldn't have reached stable. We're working hard on adding enough tests to prevent these kind of failures.
output.path check with node < 0.12 (38ff513).output.path check on Windows with node < 5.0 (38ff513).watchDelay option (#131).Add a nice error message when output.path in the webpack config is relative.
output.path in the webpack config is relative.publicPath (#129).Fix exception thrown when using webpack array config (#125).
Add tests for everything (#121)!
Range header, the status code would not always be correct (cedc09f).index option (default: index.html) to customize the file used as index for a directory (#123).Add reporter option for custom logs (#91).
reporter option for custom logs (#91).serverSideRender option to help support server-side rendering (#118).statusCode to 200 for served files (#94).waitUntilValid callback always being called immediately when using MultiCompiler (#100).Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →