NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1954 most downloaded on npm
Serves a webpack app. Updates the browser on changes.
Last release 3 months ago
03 Jul 2026
Release timing varies
gaps range from 8 days to 8 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
226 releases · first in 2012
fixes #1081, closes #1079. addDevServerEndpoints needs app stub for createDomain fixes #1080 - jQuery update caused live bundle iframe issue clean up
fixes #1081, closes #1079. addDevServerEndpoints needs app stub for createDomain fixes #1080 - jQuery update caused live bundle iframe issue clean up progress option typo and options def
Print webpack progress to browser console
--open option to specify the browser to use (#825)subjectAltName field in self-signed cert (#987)One column per quarter.
Nothing published for this version
Move loglevel from devDependencies to dependencies #1001
loglevel from devDependencies to dependencies #1001Browser console messages now respect clientLogLevel (#921).
clientLogLevel (#921).quiet is set to true (#970).--disable-host-check (#980).Fix peer dependencies to support webpack 3 ( #946 ) ( Fixes #932 )
Fix peer dependencies to support webpack 3 ( #946 ) ( Fixes #932 )
Don't provide a SSL cert, but generate one on demand. Unique for each developer.
Don't provide a SSL cert, but generate one on demand. Unique for each developer.
https://medium.com/@mikenorth/961572624c54 by Mike North
allowedHosts optionopenPage option to open a specific page--bonjourlan option, which listen on lan ip by defaultfix a bug preventing publicHost from working
# Bugfixes: * add disableHostCheck to schema
disableHostCheck to schemaThis version contains a security fix, which is also breaking change if you have an insecure configuration. We are releasing this breaking change as pa…
This version contains a security fix, which is also breaking change if you have an insecure configuration. We are releasing this breaking change as patch version to protect you from attacks. Sorry if this breaks your setup, but the fix is easy.
We added a check for the correct Host header to the webpack-dev-server.
This allowed evil websites to access your assets.
The Host header of the request have to match the listening adress or the host provided in the public option.
Make sure to provide correct values here.
The response will contain a note when using an incorrect Host header.
For usage behind a Proxy or similar setups we also added a disableHostCheck option to disable this check.
Only use it when you know what you do. Not recommended.
This version also includes this security fix for webpack-dev-middleware: https://github.com/webpack/webpack-dev-middleware/releases/tag/v1.10.2
Note: This only affect the development server and middleware. webpack and built bundles are not affected.
Credits to Ed Morley from Mozilla for reporting the issue.
Host doesn't match listening host or public option.localhost or 127.0.0.1 are not blocked.disableHostCheck option to disable the host checkProperly close CLI when SIGINT or SIGTERM is called. This should fix some Docker issues (#787).
entry not working when it was a function (#802).contentBase as an array did not work when used via CLI (#832).After fixing a warning/error, the overlay was not always cleared correctly (3cb79bd39489d12a2df9896ce204b8de15e636f4).
contentBase: false in combination with the historyApiFallback option threw an error (#791).
contentBase: false in combination with the historyApiFallback option threw an error (#791).--open fails to open the browser (#780).overlay option to also show compiler warnings (off by default) (#790):overlay: {
errors: true,
warnings: true
}
Add new fancy error overlay in-browser, which shows up when there are compilation errors. Disabled by default, add overlay: true to enable (#764)!
overlay: true to enable (#764)!--open and options.public, the browser will now open the same URL as you have defined in public (#749).options.port now allows strings to be passed in, previously only integers were accepted (#766).Nothing published for this version
Following the webpack 2 release. It's equal to the last RC.
Following the webpack 2 release. It's equal to the last RC.
If you're curious about the highlights, read this fancy Medium post.
Allow latest webpack 2.2.0-rc.0 as peer dependency (#714).
beta.11 prevented the page from reloading when there was an error or a warning. Now it will only prevent a reload when there are errors, since you can
clientLogLevel: "none" from working (#693).Breaking change: all options passed to the server get validated now, just like the webpack options already are. In most cases this shouldn't break any…
--version flag not working in CLI (#679).--open flag opening the wrong URL when using lazy mode (7cb0490bcaedd5ac32e6e1834b9da7a9de777303).Breaking change: only support Node.js 0.12 and higher.
0.12 and higher.--socket flag (#661).contentBase with a URL or port, since the proxy option does about the same and is more powerful (61b46ba).Add support for watching files provided by the contentBase option. Enable with watchContentBase: true or --watch-content-base in the CLI (#649).
contentBase option. Enable with watchContentBase: true or --watch-content-base in the CLI (#649).host option (#644).historyApiFallback taking preference of contentBase files instead of the in-memory files; this caused issues with html-webpack-plugin (#640).Add full Web Worker support (#632).
historyApiFallback not working when specifying an index that is not index.html (#627, cb1b32f).pfx and pfxPassphrase. Use with --pfx and --pfx-passphrase in the CLI (#631).Add support for http/2 when using the https option. Falls back on http/1.1.
https option. Falls back on http/1.1.Start with tests! There's still a lot more to test, but at least there are _some_ tests now (#623).
close API (1cf6549).historyApiFallback to fallback correctly to contentBase (#617).bypass feature in a proxy, it was not possible to use in-memory webpack assets (#613).Add proxy config hot reloading - needs some additional configuration (#605).
--progress not working (#609).[WDS] Hot Module Replacement enabled appearing even if the clientLogLevel was set to a non-info value (#607).--inline does in help section for the CLI (#596).Fix contentBase option in webpack config being ignored when using the CLI (#597).
contentBase option in webpack config being ignored when using the CLI (#597).--open parameter (#593).Breaking change: removed overriding output.path to "/" in the webpack config when using the CLI (#337). Note that output.path needs to be an absolute…
output.path to "/" in the webpack config when using the CLI (#337). Note that output.path needs to be an absolute path!contentBase as a proxy feature (deprecated since 1.x).clientLogLevel (--client-log-level for CLI) option. It controls the log messages shown in the browser. Available levels are error, warning, info or none (#579).--no-content-base flag (previously it always defaulted to the working directory).https modus, to prevent browsers from complaining about it (#572).Breaking change: Only compatible with webpack v2.
--inline is enabled by default now.yargs to handle command line options.Promise instead of a config object in the CLI (#419).--hot-only flag, a shortcut that adds webpack/hot/only-dev-server in entry in the webpack config (#439).Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This version contains a security fix, which is also breaking change if you have an insecure configuration. We are releasing this breaking change as pa…
This version contains a security fix, which is also breaking change if you have an insecure configuration. We are releasing this breaking change as patch version to protect you from attacks. Sorry if this breaks your setup, but the fix is easy.
We added a check for the correct Host header to the webpack-dev-server.
This allowed evil websites to access your assets.
The Host header of the request have to match the listening adress or the host provided in the public option.
Make sure to provide correct values here.
The response will contain a note when using an incorrect Host header.
For usage behind a Proxy or similar setups we also added a disableHostCheck option to disable this check.
Only use it when you know what you do. Not recommended.
This version also includes this security fix for webpack-dev-middleware: https://github.com/webpack/webpack-dev-middleware/releases/tag/v1.10.2
Note: This only affect the development server and middleware. webpack and built bundles are not affected.
Credits to Ed Morley from Mozilla for reporting the issue.
Host doesn't match listening host or public option.localhost or 127.0.0.1 are not blocked.disableHostCheck option to disable the host checkProbably the last release in the v1.x range:
Probably the last release in the v1.x range:
Promise.Support for PFX files as SSL connection options (#630).
bypass feature (#614).Nothing published for this version
Backport a few more fixes from v2:
clientLogLevel (--client-log-level for CLI) option. It controls the log messages shown in the browser. Available levels are error, warning, info or none (#579).Backport a few fixes from v2 (#604):
Fix the bypass config option for proxies (#563).
bypass config option for proxies (#563).* as a proxy wildcard.document when using inline modus (#577).Use http-proxy-middleware instead of http-proxy. This fixes compatibility with native web sockets (#359).
--stdin flag, to close the dev server on process exit (#352).--open flag to open a browser pointing to the server (#329).--public flag to override the url used for connecting to the web socket (#368).options.contentBase, so multiple sources are allowed (#374).options.staticOptions to allow passing through Express static options (#385).--cacert flag not doing anything (#532).Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →