Skip to content

Bump enhanced-resolve from 5.25.1 to 5.26.0 in the npm-dependencies group - #650

Merged
BaseMax merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-dependencies-86ba490182
Oct 7, 2026
Merged

BaseMax merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-dependencies-86ba490182

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-dependencies group with 1 update: enhanced-resolve.

Updates enhanced-resolve from 5.25.1 to 5.26.0

Release notes

Sourced from enhanced-resolve's releases.

v5.26.0

Minor Changes

  • Add experimental support for Node.js package maps through a new packageMap option, which takes the path of the configuration file (or a file: URL) or an already-parsed packages object. When it is set, a bare specifier is resolved through the importing package's dependencies table and the target package's location is handed to the regular pipeline, instead of walking node_modules; relative and absolute requests and node: builtins are unaffected. Because several package entries may share one url, the package a request resolved into is exposed as packageId on the result and can be passed back in as context.packageId to resolve from that package unambiguously. Package maps are stability 1 (experimental) in Node.js, and this option tracks that specification and may change with it. (by @​alexander-akait in #667)

  • Explain an exports/imports field whose conditions wrap subpaths, instead of failing with a message that points at the request. A field shaped like { "import": { ".": "./esm/index.js", "./*": "./esm/*.js" }, "require": "./build/bundle.js" } is not supported by Node.js: the subpaths inside a condition are read as condition names, so they match nothing, and every request into the package failed as "./foo" is not exported under the conditions [...] — which reads as though the package forgot to export ./foo. Such a failure now names the offending keys and shows the arrangement that works, with the subpaths at the top level and the conditions nested inside them. Resolution itself is unchanged: the diagnosis runs only on a request that has already failed, so nothing that resolves today starts failing, and a successful resolve does no extra work. Errors raised while processing either field also name the package.json they came from, which previously only appeared in the resolver log. (by @​alexander-akait in #676)

  • Generate the published type declarations with TypeScript instead of webpack/tooling, which is no longer a dependency. Every name the package exported before is still exported, and types.d.ts is still the entry point, but the declarations themselves now live in types/ and are emitted by tsc from the JSDoc in lib/. Two shapes follow the sources more closely than the previous generator did: the object form of Plugin no longer declares this: Resolver on apply (it is called as plugin.apply(resolver), so this is the plugin), and the entries of ResolveContext.stack declare name: string | undefined rather than an optional name. Class fields that the old generator dropped, such as the cache backends on CachedInputFileSystem, are now part of the declarations. (by @​alexander-akait in #675)

Patch Changes

  • Size the ancestor path and segment arrays that getPathsCached keeps to what they actually hold: a push-built store keeps room for 17 entries while a path has a handful, and the cache holds these for the filesystem's lifetime. (by @​alexander-akait in #681)
Changelog

Sourced from enhanced-resolve's changelog.

5.26.0

Minor Changes

  • Add experimental support for Node.js package maps through a new packageMap option, which takes the path of the configuration file (or a file: URL) or an already-parsed packages object. When it is set, a bare specifier is resolved through the importing package's dependencies table and the target package's location is handed to the regular pipeline, instead of walking node_modules; relative and absolute requests and node: builtins are unaffected. Because several package entries may share one url, the package a request resolved into is exposed as packageId on the result and can be passed back in as context.packageId to resolve from that package unambiguously. Package maps are stability 1 (experimental) in Node.js, and this option tracks that specification and may change with it. (by @​alexander-akait in #667)

  • Explain an exports/imports field whose conditions wrap subpaths, instead of failing with a message that points at the request. A field shaped like { "import": { ".": "./esm/index.js", "./*": "./esm/*.js" }, "require": "./build/bundle.js" } is not supported by Node.js: the subpaths inside a condition are read as condition names, so they match nothing, and every request into the package failed as "./foo" is not exported under the conditions [...] — which reads as though the package forgot to export ./foo. Such a failure now names the offending keys and shows the arrangement that works, with the subpaths at the top level and the conditions nested inside them. Resolution itself is unchanged: the diagnosis runs only on a request that has already failed, so nothing that resolves today starts failing, and a successful resolve does no extra work. Errors raised while processing either field also name the package.json they came from, which previously only appeared in the resolver log. (by @​alexander-akait in #676)

  • Generate the published type declarations with TypeScript instead of webpack/tooling, which is no longer a dependency. Every name the package exported before is still exported, and types.d.ts is still the entry point, but the declarations themselves now live in types/ and are emitted by tsc from the JSDoc in lib/. Two shapes follow the sources more closely than the previous generator did: the object form of Plugin no longer declares this: Resolver on apply (it is called as plugin.apply(resolver), so this is the plugin), and the entries of ResolveContext.stack declare name: string | undefined rather than an optional name. Class fields that the old generator dropped, such as the cache backends on CachedInputFileSystem, are now part of the declarations. (by @​alexander-akait in #675)

Patch Changes

  • Size the ancestor path and segment arrays that getPathsCached keeps to what they actually hold: a push-built store keeps room for 17 entries while a path has a handful, and the cache holds these for the filesystem's lifetime. (by @​alexander-akait in #681)
Commits
  • c65e40a chore(release): new release (#674)
  • 7ed8697 perf: size the paths a request walks from its split (#681)
  • 7e37289 chore(deps-dev): bump the dependencies group with 4 updates (#680)
  • cba4ba4 test(alias): cover compileAliasOptions bucketing and the onlyModule flag (#679)
  • f07a030 feat: explain exports/imports conditions that wrap subpaths (#676)
  • d9a13d7 chore(deps): bump codecov/codecov-action from 7.0.0 to 7.1.1 in the dependenc...
  • f8d395e chore(deps-dev): bump the dependencies group with 6 updates (#677)
  • e1bdb75 refactor: generate types with typescript instead of webpack/tooling (#675)
  • 332d999 ci: cancel superseded pull request runs (#673)
  • e638bc9 feat: experimental support for Node.js package maps (#667)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the npm-dependencies group with 1 update: [enhanced-resolve](https://github.com/webpack/enhanced-resolve).


Updates `enhanced-resolve` from 5.25.1 to 5.26.0
- [Release notes](https://github.com/webpack/enhanced-resolve/releases)
- [Changelog](https://github.com/webpack/enhanced-resolve/blob/main/CHANGELOG.md)
- [Commits](webpack/enhanced-resolve@v5.25.1...v5.26.0)

---
updated-dependencies:
- dependency-name: enhanced-resolve
  dependency-version: 5.26.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript labels Oct 7, 2026
@dependabot
dependabot Bot requested review from BaseMax and jbampton as code owners October 7, 2026 10:23
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript labels Oct 7, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​enhanced-resolve@​5.25.1 ⏵ 5.26.0100 +110010097100

View full report

@deepsource-io

deepsource-io Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in f0c6704...b3b63b7 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
JavaScript Oct 7, 2026 10:24a.m. Review ↗
Secrets Oct 7, 2026 10:24a.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

@BaseMax
BaseMax merged commit ff0b7b8 into main Oct 7, 2026
16 of 17 checks passed
@BaseMax
BaseMax deleted the dependabot/npm_and_yarn/npm-dependencies-86ba490182 branch October 7, 2026 11:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant