Plate 29
Webpack 5.111: ESM output stable, output.copy, CSS targets (14 Sep 2026)
On 14 September 2026 webpack published the 5.111 blog: ES module output is stable (drop experiments.outputModule; keep/set output.module), output.copy copies public/static files into the build, browserslist-aware CSS lowering/color fallbacks expand, performance hint options rename, acorn/neo-async removed as deps, plus hot-update/cache fixes. npm latest as of 5 Oct 2026 research is 5.111.1 (5.111.0 shipped 14 Sep). ShopperCove docs checklist only; no affiliate.
Aditya Challa5 min read
Webpack 5.111: ESM output stable, output.copy, CSS targets (14 Sep 2026)
On 14 September 2026, the webpack project published Webpack 5.111. The release makes ES module output stable (you can drop experiments.outputModule and keep output.module), adds built-in output.copy for static/public files, expands browserslist-aware CSS lowering and color fallbacks, renames several performance hint options, ships a smaller chunk-loading runtime, drops acorn and neo-async as dependencies, and fixes hot updates and caching. ShopperCove did not upgrade a production webpack pipeline for this note and did not run build benchmarks. On 5 October 2026, npm dist-tag latest resolved to webpack@5.111.1 (published 18 Sep 2026); the feature blog and GitHub tag cover the 5.111.0 line that shipped 14 Sep 2026. This is a docs-based upgrade checklist—not performance advice and not a security advisory (no CVEs are claimed here).
There is no affiliate link in this article. This post has no affiliate links.
ESM output without an experiment
If you ship an app or library as ES modules, remove experiments.outputModule and keep output.module: true. ESM output is stable; module / modern-module library types and externalsType: "module" no longer need the experiment flag.
Upgrade gotcha: if you only had experiments.outputModule: true, add output.module: true. Webpack ignores the old flag alone, so keeping it without output.module will not enable ESM output.
A module or modern-module library type now turns output.module on by itself. experiments.futureDefaults now includes output.module where the target can read modules (classic script output still wins for targets that cannot, for script-style library types such as var/umd, or when you set output.module yourself).
Async startup: if an entry uses top-level await, importers wait until that setup finishes (and receive errors on failure) when the target supports TLA; override with output.environment.topLevelAwait if needed.
ES module libraries and externals also improve: live bindings on re-exports from externals, respect for your externals mapping on star re-exports, import attributes kept, cycle stack overflows fixed, and a build error when export * targets an external declared as an array (specifier + property path).
File URLs and copying static files
ESM webpack configs can pass file: URL strings to path options such as context and output.path (and to rule test/include) without wrapping fileURLToPath()—pass the URL .href string, not a URL object.
output.copy copies folders that nothing imports (for example robots.txt, public images, licenses) into the output directory as part of the build:
Patterns support from/to, contenthash filenames, filters, transforms, and permission/timestamp preservation. Watch mode recopies edits; files appear in stats and survive output.clean. Overwriting a generated asset is an error; empty patterns warn. For more control, use built-in CopyPlugin.
CSS for browser targets + HTML
With a browserslist target, the built-in CSS minimizer’s lowerUnsupported and colorFallbacks (on by default) cover more syntax—including inset, media ranges, and CSS nesting—and improve math/color simplification. Tune via optimization.minimize.css. Optional knobs include unusedSymbols, pseudoClasses, resolveCustomAtRules, rewriteDirSelector, and mergeDistantRules (off by default).
HTML native support: trim whitespace around URL attributes; optional mergeScripts and broader collapseBooleanAttributes; attribute minification no longer depends on quote spelling; plugins can reuse webpack.css.syntax.cssMinify / webpack.html.syntax.htmlMinify; NormalModule processResult can be async (for example image format conversion with module.buildInfo.assetResource).
Performance hints rename (breaking config names)
If you enabled checks in 5.110, update renamed options or webpack reports a configuration error:
| Previous | Use in 5.111 |
|---|---|
unusedAliases, unusedDefines, unusedExternals, unusedRules | unusedConfig |
unusedReexports | unusedModules |
embeddedSourceMaps | sourceMaps |
entrypointOverlap | duplicateModules |
New/clarified checks also include unusedAssets and analyzableBailouts. Use performance.hints: "stats" to explore findings without warning-level build noise. Note: hints: false silences bundle checks but enabled configuration checks still warn—turn those options off individually.
Smaller output, own parser, cache, namespaces
- Chunk-loading runtime shrinks (
__webpack_require__.e/ priority queue emission). - With ESM output, chunk imports move into the chunk loader; rebuilds invalidate less when lazy routes change.
- Idle/watch memory lower (blog cites ~6.3 MB off an 85.6 MB idle heap on a 1700-module project).
- Webpack parses JavaScript with its own parser;
acornandneo-asyncare no longer dependencies. - Filesystem cache
buildDependenciesmay mark entriesoptional: trueso a missing shared config file does not block saving the cache. - Optional
module.parser.javascript.specNamespaceObjectfor more native-likeimport *namespace objects (Proxy cost / less merging)—most apps leave this off.
Also: resolve.fileSystem is honored; module.exprContextCritical deprecation points at module.parser.javascript.exprContextCritical; DefinePlugin undefined property reads throw like native.
Bug fixes (blog summary)
More reliable CSS hot updates and cache invalidation; async init / optimized JS / CSS in server and loader workflows; clearer errors for missing assets and runtime codegen; scope-hoisting and HTML </ escaping fixes; DelegatedModule / cached resolveOptions / inlined-value consumer regeneration. Prefer the 5.111.0 release notes for the full contributor list.
Hands-on upgrade checklist
- Inventory:
npm ls webpack/ lockfile. Note whether you are on 5.110.x or earlier. - Pin in staging: install
webpack@5.111.1(or at least 5.111.0). Confirm withnpm view webpack version(expect 5.111.1 as latest as of sources read 5 Oct 2026). - ESM migration: replace lone
experiments.outputModulewithoutput.module: true; verify library/externalsTypemodule setups. - Static assets: try
output.copyforpublic/instead of a separate copy step; confirm watch +output.cleanbehavior. - Performance config: rename options per the table above before CI fails on unknown keys.
- CSS/HTML: if you rely on browserslist CSS minify, spot-check
inset/nesting/color output; re-test HMR for CSS. - Do not invent security urgency: the official blog frames features, size/memory, and bugfixes—ShopperCove is not attaching CVE IDs.
ShopperCove did not change production webpack versions for this article. Prefer the official 5.111 blog over third-party roundups.
Bottom line
Webpack 5.111 (blog 14 Sep 2026) stabilizes ESM output, adds output.copy, expands target-aware CSS lowering, renames performance checks, and lightens runtime/deps. Pin webpack@5.111.1 (or 5.111.0+) when ready. No affiliate.
Sources
- https://webpack.js.org/blog/2026-09-14-webpack-5-111/
- https://github.com/webpack/webpack/releases/tag/v5.111.0
- https://registry.npmjs.org/webpack/5.111.0
- https://registry.npmjs.org/webpack/5.111.1
- https://www.npmjs.com/package/webpack
Related
- https://www.shoppercove.com/blog/vite-plus-1-0-unified-toolchain-october-2026
- https://www.shoppercove.com/blog/playwright-1-63-test-locks-october-2026
- https://www.shoppercove.com/blog/astro-7-3-preview-ignore-lock-october-2026
- https://www.shoppercove.com/blog/angular-router-ssr-queryparams-dos-october-2026
- https://www.shoppercove.com/blog/nodejs-26-lts-october-2026-schedule-change
- https://www.shoppercove.com/blog/nextjs-15-lts-end-of-support-october-2026
- https://www.shoppercove.com/blog/nextjs-16-3-8-security-release-2026
- https://www.shoppercove.com/blog/firefox-157-security-fixes-css-changes-october-2026
Lab evidence
What I found running this
Sources read 5 Oct 2026 (Asia/Calcutta): official blog https://webpack.js.org/blog/2026-09-14-webpack-5-111/ (2026-09-14); GitHub tag v5.111.0; npm webpack@5.111.0 (time 2026-09-14T06:18:27.582Z) and dist-tag latest=5.111.1 (time 2026-09-18T11:27:13.638Z). Concrete checklist: if only experiments.outputModule:true, add output.module:true (old flag ignored); library type module|modern-module enables output.module; consider output.copy for public/; update performance unusedAliases/unusedReexports/embeddedSourceMaps/entrypointOverlap to unusedConfig/unusedModules/sourceMaps/duplicateModules; re-test HMR/CSS. No production webpack upgrade on ShopperCove; no invented CVEs.
Related links
Plate 96
FTC + 22 states sue Amazon over alleged secret Sponsored Ads surcharge (31 Aug 2026)
On 31 August 2026 the FTC and 22 states filed suit against Amazon.com, Inc. in the Western District of Washington (2:26-cv-03097), alleging that since about 2019 Amazon secretly inflated Sponsored Products, Sponsored Brands, and Sponsored Display auction prices with undisclosed “soft reserve” surcharges while telling advertisers it ran generalized second-price auctions—allegedly extracting tens of billions from ~1.2M advertisers. These are complaint allegations; Amazon’s About Amazon response calls the suit misguided and disputes advertiser and consumer harm. Distinct from the separate Amazon Prime FTC refund / subscription post. No affiliate; not legal advice.
5 Oct 2026
Plate 16
ESLint v10.12.0: SourceCode tokens/comments types + rule fixes (2 Oct 2026)
ESLint published v10.12.0 on 2 October 2026 as a minor release: documentation and TypeScript types for SourceCode#getText(), getLoc(), and getRange() now accept tokens and comments (matching runtime behavior), plus multiple rule fixes including astral/Unicode letter handling and autofix edge cases. npm latest confirmed 10.12.0; ShopperCove docs checklist only; no affiliate.
5 Oct 2026
Plate 81
FTC Impersonation Rule ANPR: platforms’ ad-optimization role (24 Sep / 1 Oct 2026)
On 24 September 2026 the FTC announced an Advance Notice of Proposed Rulemaking on whether to update its Rule on Impersonation of Government and Businesses—or take other action—to address social media, search, and digital marketplace platforms’ ad-optimization practices that may further impersonation scams. The ANPRM published in the Federal Register on 1 October 2026 (91 FR 62347; Doc. 2026-20143; Matter R207000; RIN 3084-AB90); Commission vote 2-0; comments due on or before 30 November 2026. This is a comment request, not a final rule; no affiliate.
5 Oct 2026