NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1954 most downloaded on npm
Serves a webpack app. Updates the browser on changes.
Last release 3 months ago
03 Jul 2026
Release timing varies
gaps range from 8 days to 8 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
226 releases · first in 2012
Bump Express to v5. See the Express 5 migration guide for the full list of breaking changes. (by @bjohansebas in #5674 )
Bump Express to v5. See the Express 5 migration guide for the full list of breaking changes. (by @bjohansebas in #5674)
Bump the webpack peer dependency range from ^5.0.0 to ^5.101.0. (by @bjohansebas in #5674)
Drop support for Node.js < 22.15.0. (by @bjohansebas in #5674)
Convert the source to native ES modules. The package keeps "type": "module" and now exposes both an ESM and a CommonJS build via the exports field: ESM consumers import the native lib/, while CommonJS consumers require() a transpiled dist/ build, allowing the package to be consumed from both ESM and CommonJS without relying on require(ESM) for CommonJS consumers. (by @bjohansebas in #5674)
Remove CLI flags. Use the serve command from webpack-cli together with a configuration file or the programmatic API instead. (by @bjohansebas in #5674)
Remove the internalIP and internalIPSync static methods from Server. Resolve the local IP yourself if you need it. (by @bjohansebas in #5674)
Remove the bypass option from proxy configuration. Use the router or context options provided by http-proxy-middleware instead. (by @bjohansebas in #5674)
Remove SockJS support. The webSocketServer option no longer accepts "sockjs"; use the default "ws" transport instead. (by @bjohansebas in #5674)
Remove the spdy dependency. Use the built-in node:http2 module via the server option for HTTP/2 support. (by @bjohansebas in #5674)
Update http-proxy-middleware to v4. See the http-proxy-middleware v3 release notes and v4 release notes for the full list of breaking changes. (by @bjohansebas in #5674)
Update webpack-dev-middleware to v8 and sync originalUrl for middleware compatibility. server.middleware.getFilenameFromUrl() is now asynchronous and resolves to { filename, extra: { stats, outputFileSystem } }. See the webpack-dev-middleware v8 release notes for details. (by @bjohansebas in #5674)
Add plugin support. webpack-dev-server can now be used as a webpack plugin, integrating with the compiler lifecycle without explicitly passing a compiler, preventing multiple server starts on recompilation, ensuring clean shutdown, and supporting MultiCompiler setups with multiple independent plugin servers. (by @bjohansebas in #5674)
Enable the compression middleware for HTTP/2 connections. (by @bjohansebas in #5674)
Remove the colorette dependency in favor of native ANSI styling. (by @bjohansebas in #5674)
Update chokidar to v5 and extend watchFiles.options.ignored to support glob string patterns via tinyglobby. (by @bjohansebas in #5674)
Use compiler.platform to determine the target environment instead of inspecting the resolved target string. Universal targets ("universal" or ["web", "node"], where compiler.platform.universal is true since webpack 5.108.0) are treated as web targets so the client runtime is injected. (by @bjohansebas in #5674)
Use the WHATWG URL API instead of the deprecated url.parse. (by @bjohansebas in #5674)
Bump production dependencies, notably open to v11 and p-retry to v8. (by @bjohansebas in #5674)
Reject cross-site requests to the internal open-editor and invalidate endpoints. They performed state-changing actions (opening a file in the editor, forcing a recompilation) on any GET request, so a page the developer visited could trigger them. They now require a same-origin request, validated via Sec-Fetch-Site with an Origin/Host fallback. (by @bjohansebas in #5691)
Treat loopback aliases (127.0.0.1, ::1, localhost) as equivalent in isSameOrigin so the WebSocket client does not reject valid same-origin connections. (by @bjohansebas in #5674)
Migrate the test suite from Jest to node:test and set up the jsdom environment. (by @bjohansebas in #5674)
Update webpack-cli to v7.0.2. (by @bjohansebas in #5674)
One column per quarter.
fix: allow undefined as the Server constructor options argument again (by @bjohansebas in #5695 )
fix: allow undefined as the Server constructor options argument again (by @bjohansebas in #5695)
Restores accepting undefined (defaulting it to {}) for the options
argument, so passing a webpack config's optional devServer field type-checks and works as before.
Protect the built-in state-changing routes (/webpack-dev-server/invalidate and /webpack-dev-server/open-editor) against cross-site request forgery. Requests are now checked with Sec-Fetch-Site (falling back to an Origin/Host comparison when it is absent), so a cross-site page can no longer trigger a rebuild or open a file in the editor. Same-origin requests, user-initiated navigations, and non-browser clients (e.g. curl) are unaffected. (by @bjohansebas in #5698)
Handle malformed Host and Origin header values gracefully when validating requests. (by @bjohansebas in #5699)
Skip the HMR WebSocket path when forwarding upgrade requests to user-defined proxies, so custom proxy WebSocket upgrades are no longer intercepted by
All notable changes to this project will be documented in this file. See standard-version for commit guidelines.
cause for errorObject (#5518) (37b033d)set Cross-Origin-Resource-Policy header to prevent source code theft over HTTP
compatibility with event target and universal target and lazy compilation
"Overlay enabled" false positive
cross-origin requests are not allowed unless allowed by Access-Control-Allow-Origin header
Access-Control-Allow-Origin headerOrigin header are not allowed to connect to WebSocket server unless configured by allowedHosts or it different from the Host headerThe above changes may make the dev server not work if you relied on such behavior, but unfortunately they carry security risks, so they were considered as fixes.
added getClientEntry and getClientHotEntry methods to get clients entries
added the app option to be Function (by default only with connect compatibility frameworks)
app option to be Function (by default only with connect compatibility frameworks) (3096148)server option to be Function (#5275) (02a1c6d)connect and connect compatibility frameworks which support HTTP2 (#5267) (6509a3f)app option to be Function (by default only with connect compatibility frameworks) (3096148)server option to be Function (#5275) (02a1c6d)connect and connect compatibility frameworks which support HTTP2 (#5267) (6509a3f)platform property to determinate the target (#5269) (c3b532c)rimraf with rm (#5162) (1a1561f)devServer: false (#5272) (8b341cb)security: bump webpack-dev-middleware
### 5.0.3 (2024-03-12) ### Bug Fixes * types: proxy
### 5.0.2 (2024-02-16) ### Bug Fixes * types
## 5.0.0 (2024-02-12) Migration Guide and Changes.
security: bump webpack-dev-middleware
overlay displays unhandled promise rejection
allow filter overlay errors/warnings/runtimeErrors with function
perf: reduced initial start time
prevent open 0.0.0.0 in browser due windows problems
make webpack optional peer dependency
added client.overlay.runtimeErrors option to control runtime errors
allow to set the sockjs_url option (only sockjs) using the webSocketServer.options.sockjsUrl option
sockjs_url option (only sockjs) using the webSocketServer.options.sockjsUrl option (#4586) (69a2fba)sockjs_url option (only sockjs) using the webSocketServer.options.sockjsUrl option (#4586) (69a2fba)experiments.buildHttp (#4585) (5b846cb)NODE_PATH env variable (#4581) (b857e6f)respect client.logging option for all logs
make allowedHosts accept localhost subdomains by default
compatibility with old browsers
allow to configure more client options via resource URL
avoid creation unnecessary stream for static sockjs file
add @types/serve-static to dependencies
### 4.9.1 (2022-05-31) ### Bug Fixes * security problem with sockjs
support Trusted Types for client overlay
### 4.8.1 (2022-04-06) ### Bug Fixes * types
export initialized socket client
--no-client-reconnect (#4248) (317648d)--no-client (#4250) (c3b6690)--no-history-api-fallback (#4277) (d63a0a2)negatedDescription only for type boolean (#4280) (fcf8e8e)--no-client-reconnect (#4248) (317648d)--no-client (#4250) (c3b6690)--no-history-api-fallback (#4277) (d63a0a2)negatedDescription only for type boolean (#4280) (fcf8e8e)proxy option (#4173) (efec2f5)--open-app-name and --web-socket-server (#4215) (329679a)selfsigned to 2.0.0 versiononAfterSetupMiddleware after setupMiddlewares (as behavior earlier) (f6bc644)use CLI specific description for --open-app-name and --web-socket-server
update selfsigned to 2.0.0 version
apply onAfterSetupMiddleware after setupMiddlewares (as behavior earlier)
removed url package, fixed compatibility with future webpack defaults
added the setupMiddlewares option and deprecated onAfterSetupMiddleware and onBeforeSetupMiddleware options
setupMiddlewares option and deprecated onAfterSetupMiddleware and onBeforeSetupMiddleware options (#4068) (c13aa56)cacert option (#4115) (c73ddfb)watchFiles options (#4057) (75f3817)ClientLogging (#4084) (9b7ae7b)--open-app deprecated in favor of --open-app-name (#4091) (693c28a)https and http2 (#4069) (d8d5d71)--web-socket-server description (#4098) (65955e9)listen and close deprecation warning message (#4097) (b217a19)https and server options (#4094) (f97c9e2)show deprecation warning for https/http2 option, migration guide for `https` and migration guide for `http2` (because we use `spdy` for http2 due expr…
--web-socket-server-type option for CLI (#4001) (17c390a)https/http2 option, migration guide for https and migration guide for http2 (because we use spdy for http2 due express doesn't support http2) (#4003) (521cf85)added the server option, now you can pass server options, example { server: { type: 'http', options: { maxHeaderSize: 32768 } } }, available options f
server option, now you can pass server options, example { server: { type: 'http', options: { maxHeaderSize: 32768 } } }, available options for http and https, note - for http2 is used spdy, options specified in the server.options option take precedence over https/http2 options (#3940) (a70a7ef)client.reconnect option (#3912) (5edad76)startCallback and endCallback (#3969) (b0928ac)server option, now you can pass server options, example { server: { type: 'http', options: { maxHeaderSize: 32768 } } }, available options for http and https, note - for http2 is used spdy, options specified in the server.options option take precedence over https/http2 options (#3940) (a70a7ef)client.reconnect option (#3912) (5edad76)startCallback and endCallback (#3969) (b0928ac)### 4.3.1 (2021-10-04) ### Bug Fixes * perf
avoid web socket connection when web socket server is not running
port option property (ed67f66)http.ca option (CLI option added too) (should be used instead cacert, because we will remove it in the next major release in favor the https.ca option)https.crl option (CLI options added too), more informationhttps.ca/https.cacert/ https.cert/https.crl/https.key/https.pfx options are now accept Arrays of Buffer/string/Path to file, using --https-*-reset CLI options you can reset these optionshttps.pfx/https.key can be Object[], more informationhttps options can now accept custom options, you can use:module.exports = {
// Other options
devServer: {
https: {
// Allow to set additional TSL options https://nodejs.org/api/tls.html#tls_tls_createsecurecontext_options
minVersion: "TLSv1.1",
ca: path.join(httpsCertificateDirectory, "ca.pem"),
pfx: path.join(httpsCertificateDirectory, "server.pfx"),
key: path.join(httpsCertificateDirectory, "server.key"),
cert: path.join(httpsCertificateDirectory, "server.crt"),
passphrase: "webpack-dev-server",
},
},
};
file: and chrome-extensions: protocol by default (#3822) (138f064)https.cacert option (#3820) (0002ebf)added the http.ca option (CLI option added too) (should be used instead cacert, because we will remove it in the next major release in favor the https
http.ca option (CLI option added too) (should be used instead cacert, because we will remove it in the next major release in favor the https.ca option)https.crl option (CLI options added too), more informationhttps.ca/https.cacert/ https.cert/https.crl/https.key/https.pfx options are now accept Arrays of Buffer/string/Path to file, using --https-*-reset CLI options you can reset these optionshttps.pfx/https.key can be Object[], more informationhttps options can now accept custom options, you can use:module.exports = {
// Other options
devServer: {
https: {
// Allow to set additional TSL options https://nodejs.org/api/tls.html#tls_tls_createsecurecontext_options
minVersion: "TLSv1.1",
ca: path.join(httpsCertificateDirectory, "ca.pem"),
pfx: path.join(httpsCertificateDirectory, "server.pfx"),
key: path.join(httpsCertificateDirectory, "server.key"),
cert: path.join(httpsCertificateDirectory, "server.crt"),
passphrase: "webpack-dev-server",
},
}
};
allow to set hot and live-reload for client using search params
migration guide from v3 to v4 can be found here
show deprecation warning for incorrect usage of Node.js API
target option (#3651) (6e2cbde)infastructureLogging.level option by default for client.logging. (#3613) (c9ccc96)host option (#3549) (7200d31)migration guide from v3 to v4 can be found here
client.transport to client.webSocketTransportthis.webSocketServer.clientshotEntry and needClientEntry) in favor manual setup entries (#3494)reset option, please look them in webpack serve --helphost and port options can't be null or empty stringauto (#3297) (437c8d3)<url> pattern for open and allow to use multiple browsers (#3496) (7c7ccf9)client.webSocketURL.port (#3354) (f5e7f8f)webSocketServer: false (f62f20f)username and password in clientURL (#3452) (a7225d5)compress by default (#3303) (4d251b5)client.webSocketURL.protocol option (#3380) (8998d6b)ipc option was added for unix socket (#3479) (b559738)Function in headers option (#3267) (28f9597)80 port for dev server (#3487) (22f18eb)App updated. Recompiling... (#3488) (a2e3ead)port (#3372) (8c53102)allowedHosts option (#3451) (17aa345)host option can't be null or empty string (#3352) (216b0d3)firewall option to allowedHosts option (#3345) (81e4e55)port and bonjour (c2805fe)path to pathname for client.webSocketURL (#3466) (fd63e02)logLevel and logProvider option for proxy (#3257) (199baec)Don't worry about a lot of changes, before the stable release, we will list all the changes and what you should do to migrate
Don't worry about a lot of changes, before the stable release, we will list all the changes and what you should do to migrate
https.ca option was removed in favor the https.cacert optiondev option was renamed to devMiddlewareclient.overlay option is true by default and show warnings by defaultwebpack-dev-server, please update webpack-cli to v4.7.0 (#3185) (0c3f817)12.13.0https.cacert (#3240) (b212a2c)webpack server --help to look at them (#3238) (469e558)bonjour options (#3202) (5534583)open (#3191) (d473fd9)client.logging option for HMR logging (#3159) (6f3c6ba)client.needClientEntry and client.needHotEntry options (#3178) (a2b6db9)open optionthe openPage option and the --open-page CLI option were removed in favor { open: ['/my-page', '/my-other-page/'] } for Node.js API and --open-target [
openPage option and the --open-page CLI option were removed in favor { open: ['/my-page', '/my-other-page/'] } for Node.js API and --open-target [URL] (without [URL] dev server will open a browser using the host option value) and --open-app <browser> for CLIuseLocalIp option was removed in favor { host: 'local-ip' }, alternative you can provide values: local-ipv4 for IPv4 and local-ipv6 for IPv6stdin option was removed in favor --watch-options-stdininjectClient and injectHot was removed in favor client.needClientEntry and client.needHotEntrywatchFiles option, now you can reload server on file changes, for example { watchFiles: ['src/**/*.php', 'public/**/*'] } (#3136) (d73213a)webpack server --help (#3148) (03a2b27)open option, i.e. { open: { target: ['/my-page', '/my-other-page'], app: ['google-chrome', '--incognito'] } } (e3c2683)/webpack-dev-server url shows list of files (#3101) (b3374c3)
dev server client compatibility with IE11/IE10/IE9 (#3129) (1e3e656)
IE11/IE10 you need polyfill fetch() and Promise, example:module.exports = {
entry: {
entry: [
'whatwg-fetch',
'core-js/features/promise',
'./entry.js'
],
},
};
IE9 you need polyfill fetch() and Promise and use sockjs for communications (because WebSocket is not supported), example:module.exports = {
entry: {
entry: [
'whatwg-fetch',
'core-js/features/promise',
'./entry.js'
],
},
devServer: {
transportMode: 'sockjs',
},
};
IE8 is not supported
reduce number of dependencies
default value of the static option is path.resolve(process.cwd(), 'public'), previously path.resolve(process.cwd(), 'static')
--hot-only option was removedstatic option is path.resolve(process.cwd(), 'public'), previously path.resolve(process.cwd(), 'static')overlay option was moved into the client option--no-https, --no-http2, --no-compress and --no-history-api-fallback (#3070) (ebc966f)Boolean type for the --firewall option (#3041) (6711c1d)--open-page (#3032) (581ee07)file: and chrome-extension: protocols in client (#2954) (163bdce)drop support Node.js@6 and Node.js@8, minimum supported Node.js version is Node@10
Node.js@6 and Node.js@8, minimum supported Node.js version is Node@10hot option is true by defaulthotOnly option was removed, if you need hot only mode, use hot: 'only' valuetransportMode is switched from sockjs to ws (IE 11 and other old browsers doesn't support WebSocket, set sockjs value for transportMode if you need supports IE 11)before, after and setup were removed in favor onBeforeSetupMiddleware (previously before) and onAfterSetupMiddleware options (previously after)clientOptions was renamed to the client optionkey, cert, pfx, pfx-passphrase, cacert, ca and requestCert options were moved to https options, please use https.{key|cert|pfx|passphrase|requestCert|cacert|ca|requestCert}sockHost, sockPath and sockPort options were removed in client optioninline option (iframe live mode) was removedlazy and filename options were removedfeatures option was removedlog, logLevel, logTime, noInfo, quiet, reporter and warn options were removed in favor of built-in webpack logger, please read this to enable and setup logging outputfs, index, mimeTypes, publicPath, serverSideRender, and writeToDisk options were moved in the dev option (webpack-dev-middleware options)webpack-dev-middleware to v4, which includes many breaking options changes, please readstats option was removed, please use the stats option from webpack.config.jssocket option was removedcontentBase, contentBasePublicPath, serveIndex, staticOptions, watchContentBase, watchOptions were removed in favor of the static optiondisableHostCheck and allowedHosts options were removed in favor of the firewall optionserver.listen() will find free port if the port is not set and the port argument is not passed, also print a warning if the port option and the port argument passed to server.listen() are differentprogress option is moved to the client option, set client: {progress: true}profile option was removed, to print profile data, set client: { progress: 'profile' }location.port, equivalent to sockPort: 'location'), by default. To get previously behavior, set the client.port with the port you'd like to setlocation.hostname), by default. To get previously behavior, set the client.host with the hostname you'd like to setwebpack@5webpack-cli@4setupExitSignals option, it takes a boolean and if true (default on CLI), the server will close and exit the process on SIGINT and SIGTERMchokidar to v3Unfortunately, due to the huge amount of changes it is very difficult to display all changes in a convenient form. Therefore, we offer you a couple of popular examples (feel free to send a PR with more examples).
staticPreviously contentBase, contentBasePublicPath, serveIndex, staticOptions, watchContentBase and watchOptions
module.exports = {
// ...
devServer: {
// Can be:
// static: path.resolve(__dirname, 'static')
// static: false
static: [
// Simple example
path.resolve(__dirname, 'static'),
// Complex example
{
directory: path.resolve(__dirname, 'static'),
staticOptions: {},
// Don't be confused with `dev.publicPath`, it is `publicPath` for static directory
// Can be:
// publicPath: ['/static-public-path-one/', '/static-public-path-two/'],
publicPath: '/static-public-path/',
// Can be:
// serveIndex: {} (options for the `serveIndex` option you can find https://github.com/expressjs/serve-index)
serveIndex: true,
// Can be:
// watch: {} (options for the `watch` option you can find https://github.com/paulmillr/chokidar)
watch: true,
},
],
},
};
publicPathmodule.exports = {
// ...
devServer: {
dev: {
publicPath: '/publicPathForDevServe',
},
},
};
firewallPreviously disableHostCheck and allowedHosts
module.exports = {
// ...
devServer: {
// Can be
// firewall: ['192.168.0.1', 'domain.com']
firewall: false,
},
};
module.exports = {
// ...
infrastructureLogging: {
// Only warnings and errors
// level: 'none' disable logging
// Please read https://webpack.js.org/configuration/other-options/#infrastructurelogginglevel
level: 'warn',
},
};
replace ansi-html with ansi-html-community
cli arguments for serve command
security vulnerability in yargs-parser
contentBasePublicPath paths (#2489) (c6bdfe4)GET and HEAD request to routes (#2374) (ebe8eca)forward error requests to the proxy
Your coding agent can read these notes before it upgrades. Set up the MCP server →