Skip to content

chore(deps): bump postcss-selector-parser, @symfony/webpack-encore, postcss-preset-env and vue-loader - #3822

Open
dependabot[bot] wants to merge 1 commit into
6.1from
dependabot/npm_and_yarn/multi-ea31481295
Open

dependabot[bot] wants to merge 1 commit into
6.1from
dependabot/npm_and_yarn/multi-ea31481295

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps postcss-selector-parser to 7.1.6 and updates ancestor dependencies postcss-selector-parser, @symfony/webpack-encore, postcss-preset-env and vue-loader. These dependencies need to be updated together.

Updates postcss-selector-parser from 7.1.5 to 7.1.6

Release notes

Sourced from postcss-selector-parser's releases.

7.1.6

  • fix: parse flat selectors in linear time, closing a CPU exhaustion vulnerability (GHSA-rj75-hqrm-r3gf, reported by Wayde Shi)
Changelog

Sourced from postcss-selector-parser's changelog.

7.1.6 - 2026-09-03

  • fix: parse flat selectors in linear time, closing a CPU exhaustion vulnerability (GHSA-rj75-hqrm-r3gf, reported by Wayde Shi)
Commits
  • 4eb3468 7.1.6
  • 62b1917 fix: parse flat selectors in linear time, closing a CPU exhaustion vulnerability
  • See full diff in compare view

Updates @symfony/webpack-encore from 1.8.2 to 7.2.0

Release notes

Sourced from @​symfony/webpack-encore's releases.

7.2.0 - The Now-With-Types Release

[!NOTE] The entire codebase is now TypeScript, and the package ships type definitions out of the box, so methods like enableSassLoader() and configureDevServerOptions() give you real autocompletion and validation for every option you pass in webpack.config.js.

[!IMPORTANT] Reprise v0.6.0 reaches near feature-parity with Encore on both Vite and Rsbuild, including a migration guide that maps every Encore.* call to its equivalent. Active maintenance on Webpack Encore slows from here (mostly dependency updates and bug fixes), but Encore stays supported, and Reprise is the recommended path if you want to move to a modern setup.

What's Changed

New Contributors

Full Changelog: symfony/webpack-encore@v7.1.0...v7.2.0


Thanks to everyone who contributed to this release! 🙌

Update Encore in your project:

npm install @symfony/webpack-encore@latest --save-dev
pnpm add --save-dev @symfony/webpack-encore@latest
yarn add --dev @symfony/webpack-encore@latest

7.1.0 - The "Wait, We Forgot Some Things" Release

[!NOTE] A small follow-up to 7.0.0: a few dependency updates didn't make it into that release, so 7.1.0 ships them now. You get support for sass-loader v17 (v16 still works), @vue/babel-plugin-jsx bumped to v3, webpack-manifest-plugin requiring at least v6.0.1, and JS/CSS minifier peer dependencies relaxed to optional with no version constraint. No upgrade steps needed for most projects, just bump and go.

What's Changed

Full Changelog: symfony/webpack-encore@v7.0.0...v7.1.0


Thanks to everyone who contributed to this release! 🙌

Update Encore in your project:

... (truncated)

Changelog

Sourced from @​symfony/webpack-encore's changelog.

7.2.0

  • Migrate internal code to TypeScript, ship package with type definitions (better DX and IDE support!)
  • Improve the typing of the configuration methods (enableSassLoader(), configureDevServerOptions(), enableVueLoader(), configureBabelPresetEnv(), etc.): options now resolve to the real loader/plugin types, giving full autocompletion and validation in your webpack.config
  • Add support for webpack-dev-server ^6.0.0 (requires webpack ^5.102.0 and webpack-cli ^7.0.2)

7.1.0

  • Add support for sass-loader ^17.0.0
  • Add support for @vue/babel-plugin-jsx to ^3.0.0, remove support for @vue/babel-plugin-jsx to ^1.0.0
  • Update the minimum version of webpack-manifest-plugin to ^6.0.1
  • Declare the JS/CSS minifiers as optional peer dependencies without a version constraint, matching minimizer-webpack-plugin behavior

7.0.0

This is a new major version that contains several backwards-compatibility breaks.

BC Breaks

  • Migrate from CJS (CommonJS) to ESM (ES Modules)
  • Migrate synchronous API to asynchronous API
  • Drop support of Babel 7 in favor of Babel 8
  • Remove Encore.configureTerserPlugin() in favor of Encore.configureJsMinimizerPlugin()

Features

  • Add support for webpack-cli ^7.0.0
  • Add support for typescript ^6.0.0
  • Add support for Node.js` ^26.0.0
  • Add support of Babel 8
  • Use ESM exports in Encore.copyFiles() for better webpack optimizations
  • Use peerDependencies instead of devDependencies for optional dependencies checking
  • Replace css-minimizer-webpack-plugin and terser-webpack-plugin by minimizer-webpack-plugin to unify the minification process

See the upgrade guide for the full list of breaking changes and upgrade steps.

6.0.0

This is a new major version that contains several backwards-compatibility breaks, but for the best!

BC Breaks

  • Remove support of Node.js <22.13.0
  • Remove support of babel-loader@^9.1.3, see possible BC breaks in 10.0.0 release notes
  • Remove support of style-loader@^3.3.0, see possible BC breaks in 4.0.0 release notes
  • Remove support of less-loader@^11.0.0, see possible BC breaks in 12.0.0 release notes
  • Remove support of postcss-loader@^7.0.0, see possible BC breaks in 8.0.0 release notes
  • Remove support of stylus-loader@^7.0.0, see possible BC breaks in 8.0.0 release notes
  • Remove support of webpack-cli@^5.0.0, see possible BC breaks in 6.0.0 release notes
  • Remove unmaintained file-loader dependency

... (truncated)

Upgrade guide

Sourced from @​symfony/webpack-encore's upgrade guide.

Upgrading

7.0.0

[!IMPORTANT] v7.0.0 is ESM-only, Encore.getWebpackConfig() is now async, Babel 8 is required, and CSS minification is no longer enabled by default. These are real breaking changes, so please follow the steps below.

The Node.js ecosystem has largely moved to ESM as the standard module format. Most actively maintained packages now ship ESM-only, and since Encore already requires Node.js ^22.13.0 || >=24.0 (which has full ESM support), continuing to publish as CJS would mean fighting the ecosystem: pinning to older dependencies, adding workarounds, and missing out on tree-shaking and static analysis.

Moving to ESM also unlocks async/await in Encore's internals. Now that getWebpackConfig() is natively async, Encore can adopt modern async APIs from the ecosystem without hacks.

  • Migrate from CommonJS to ESM: the package now requires "type": "module" in your project or the use of .mjs file extensions. Update your webpack.config.js:

    // Before (CJS)
    const Encore = require('@symfony/webpack-encore');
    // ...
    module.exports = Encore.getWebpackConfig();
    // After (ESM)
    import Encore from '@​symfony/webpack-encore';
    // ...
    export default await Encore.getWebpackConfig();

    Note: Encore.getWebpackConfig() is now async and returns a Promise. Use await at the top level of your webpack config (webpack supports async config files natively).

  • If you prefer not to add "type": "module", rename your webpack config to webpack.config.mjs instead; webpack detects the .mjs extension and treats it as ESM automatically.

  • Replace __dirname and __filename with their ESM equivalents in your webpack config:

    // Before (CJS)
    path.resolve(__dirname, 'src/utilities/');
    config: [__filename];
    // After (ESM)
    path.resolve(import.meta.dirname, 'src/utilities/');
    config: [import.meta.filename];

... (truncated)

Commits
  • a995eff Tagging 7.2.0
  • da6a33b bug #1520 Recommend the project's package manager for missing dependency erro...
  • 0f0389e Recommend the project's package manager for missing dependency errors
  • 09800d2 feature #1523 Add support for webpack-dev-server ^6.0.0 (Kocal)
  • eb48ad3 Add support for webpack-dev-server ^6.0.0
  • 5198083 feature #1503 Migrate project to TypeScript ✨ (Kocal)
  • 53a691a [TypeScript] Improve public API configuration option types (#1521)
  • bbebcee Minor improvements
  • c1e0ecc [TypeScript] Use .js import specifiers and drop TS-extension tsconfig options...
  • 283f574 [TypeScript] Migrate index.js (#1511)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by kocal, a new releaser for @​symfony/webpack-encore since your current version.

Install script changes

This version adds prepare script that runs during installation. Review the package contents before updating.


Updates postcss-preset-env from 7.8.3 to 11.6.1

Changelog

Sourced from postcss-preset-env's changelog.

11.6.1

October 5, 2026

11.6.0

October 2, 2026

11.5.5

October 1, 2026

Notable changes:

  • postcss-mixins now implements more of the current spec
  • many plugins now have bounds to prevent CPU starvation or OOM

All updates plugins:

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by romainmenke, a new releaser for postcss-preset-env since your current version.


Updates vue-loader from 15.11.1 to 17.4.2

Release notes

Sourced from vue-loader's releases.

v17.3.1

Bug Fixes

  • do not skip style post loader for v-bind() in non-scoped CSS (d7071bb), closes #2061

v17.3.0

Bug Fixes

Features

  • skip normal css files without scoped flag in stylePostLoader (#2053) (98782e7)

v17.2.2

Bug Fixes

v17.2.1

Features

  • A new experimentalInlineMatchResource option (webpack 5 only), which leverages webpack 5's inline matchResource feature in the underlying implementation, and works well with the experiments.css feature This also makes vue-loader compatible with Rspack (#2046) (3149f6d).

Note: v17.2.0 was released by accident; it has the same content as v17.1.2, therefore not included in the Releases page.

v17.1.2

Bug Fixes

  • keep build stable when run in a different path (#2040) (a81dc0f)
  • properly close the watcher after webpack 4 tests (40b93b9)

v17.1.1

Bug Fixes

  • support experimental propsDestructure and defineModel options (6269698)

v17.1.0

Bug Fixes

Features

  • support 3.3 imported types hmr (bbd98fc)

Full Changelog: vuejs/vue-loader@v17.0.1...v17.1.0

... (truncated)

Changelog

Sourced from vue-loader's changelog.

17.4.2 (2023-12-30)

Bug Fixes

  • pass compilerOptions to sfc parse & re-enable AST reuse (d2a2e05)

17.4.1 (2023-12-30)

Bug Fixes

  • (temporarily) disable template ast reuse (31b03af)

17.4.0 (2023-12-25)

Features

  • leverage ast reuse in 3.4 (479835f)

17.3.1 (2023-10-31)

Bug Fixes

  • do not skip style post loader for v-bind() in CSS (d7071bb), closes #2061

17.3.0 (2023-10-07)

Bug Fixes

Features

  • skip normal css files without scoped flag in stylePostLoader (#2053) (98782e7)

17.2.2 (2023-06-02)

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file 🧹 Chore labels Oct 6, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-ea31481295 branch 4 times, most recently from 0b3d5f7 to 24e91e3 Compare October 6, 2026 14:29
…ostcss-preset-env and vue-loader

Bumps [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) to 7.1.6 and updates ancestor dependencies [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser), [@symfony/webpack-encore](https://github.com/symfony/webpack-encore), [postcss-preset-env](https://github.com/csstools/postcss-plugins/tree/HEAD/plugin-packs/postcss-preset-env) and [vue-loader](https://github.com/vuejs/vue-loader). These dependencies need to be updated together.


Updates `postcss-selector-parser` from 7.1.5 to 7.1.6
- [Release notes](https://github.com/postcss/postcss-selector-parser/releases)
- [Changelog](https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss-selector-parser@7.1.5...7.1.6)

Updates `@symfony/webpack-encore` from 1.8.2 to 7.2.0
- [Release notes](https://github.com/symfony/webpack-encore/releases)
- [Changelog](https://github.com/symfony/webpack-encore/blob/main/CHANGELOG.md)
- [Upgrade guide](https://github.com/symfony/webpack-encore/blob/main/UPGRADE.md)
- [Commits](symfony/webpack-encore@v1.8.2...v7.2.0)

Updates `postcss-preset-env` from 7.8.3 to 11.6.1
- [Changelog](https://github.com/csstools/postcss-plugins/blob/main/plugin-packs/postcss-preset-env/CHANGELOG.md)
- [Commits](https://github.com/csstools/postcss-plugins/commits/HEAD/plugin-packs/postcss-preset-env)

Updates `vue-loader` from 15.11.1 to 17.4.2
- [Release notes](https://github.com/vuejs/vue-loader/releases)
- [Changelog](https://github.com/vuejs/vue-loader/blob/main/CHANGELOG.md)
- [Commits](vuejs/vue-loader@v15.11.1...v17.4.2)

---
updated-dependencies:
- dependency-name: "@symfony/webpack-encore"
  dependency-version: 7.2.0
  dependency-type: direct:development
- dependency-name: postcss-preset-env
  dependency-version: 11.6.1
  dependency-type: direct:development
- dependency-name: postcss-selector-parser
  dependency-version: 7.1.6
  dependency-type: indirect
- dependency-name: vue-loader
  dependency-version: 17.4.2
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-ea31481295 branch from 24e91e3 to e1773d6 Compare October 6, 2026 14:43

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🧹 Chore dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants