Repository navigation
chore(deps): update dependency wrangler to v4 - #555
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
size-limit report 📦
|
renovate
Bot
force-pushed
the
renovate/wrangler-4.x
branch
8 times, most recently
from
March 21, 2025 02:10
c81b62f to
61d49a9
Compare
renovate
Bot
force-pushed
the
renovate/wrangler-4.x
branch
9 times, most recently
from
March 28, 2025 02:41
c370a91 to
6d156e7
Compare
renovate
Bot
force-pushed
the
renovate/wrangler-4.x
branch
9 times, most recently
from
April 4, 2025 10:06
ebeecb1 to
69188a7
Compare
renovate
Bot
force-pushed
the
renovate/wrangler-4.x
branch
3 times, most recently
from
April 5, 2025 05:47
b2a5082 to
5afdbd1
Compare
renovate
Bot
force-pushed
the
renovate/wrangler-4.x
branch
10 times, most recently
from
April 20, 2025 05:13
dedb561 to
622eab4
Compare
renovate
Bot
force-pushed
the
renovate/wrangler-4.x
branch
13 times, most recently
from
April 27, 2025 05:54
f5d2e28 to
1347ae5
Compare
renovate
Bot
force-pushed
the
renovate/wrangler-4.x
branch
6 times, most recently
from
May 2, 2025 02:09
4004eb2 to
21d7980
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.114.17→4.148.0Release Notes
cloudflare/workers-sdk (wrangler)
v4.148.0Compare Source
Minor Changes
#16051
b4e1299Thanks @devteamaegis! - Add--source-namespaceand--source-repo-nametowrangler queues subscription createfor theartifacts.reposourceThe Event Subscriptions API requires
source.namespaceandsource.repo_nameforartifacts.reposubscriptions, but Wrangler had no way to pass them, so--source artifacts.repoalways failed with a validation error. Both flags are now required for this source, andwrangler queues subscription getshows the subscription's resource as<namespace>/<repo-name>.#15998
b75421fThanks @dario-piotrowicz! - Addassets.base_pathsupport to Workers AssetsServe an asset directory from a public URL prefix without changing its on-disk layout:
{ "assets": { "directory": "./public", "base_path": "/docs" } }Wrangler, preview, Miniflare, and generated build configuration preserve the explicitly selected value, while the Asset Worker normalizes it and strips the prefix only for asset lookup. Requests passed to a user Worker, request-facing headers, and redirects retain the public path. Relative pathname inputs are interpreted as root-relative prefixes, URL-shaped values are rejected, and omitting the option preserves existing root-path behavior.
Authored
_headersand_redirectsrules continue to match full public paths. In particular, both the source and destination of an authored200asset rewrite must include the configured public prefix; Asset Worker-generated redirects are prefixed automatically.#16005
4d308f6Thanks @oOPa! - Add a--experimental-mode instantoption towrangler kv namespace createThis lets entitled accounts create Workers KV Instant namespaces while the feature is in private beta.
#16030
aa2f9b7Thanks @edmundhung! - Add email-protected Quick Tunnels towrangler devPass one or more
--tunnel-allowed-mailflags to require email authentication when exposing a local development server through a Quick Tunnel. Each value can be an exact email address or a domain pattern.#15283
2dde890Thanks @shubhxho! - Support deleting secrets withwrangler versions secret bulkSet a secret's value to
nullin JSON input to remove it from the new Worker version. Bulk output now distinguishes between created and deleted secrets, so retryingwrangler secret bulkwithwrangler versions secret bulkpreserves requested deletions. Deploy the new version withwrangler versions deployto apply the changes to production traffic.Patch Changes
#15534
2b1a0caThanks @vahidshaik1901! - Improve guidance for conflicting Wrangler configuration filesWhen user and generated deploy configurations are found under different base paths, Wrangler now identifies the expected deploy configuration location, suggests how to resolve the conflict, and links to the relevant documentation.
#16014
c492d63Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#16079
ba52118Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15573
14f0339Thanks @xgame92! - Include default module rules in generated Worker typeswrangler typesnow declares the built-in Text, Data, and WebAssembly module patterns even when they are not repeated in the Wrangler configuration, keeping generated types aligned with deployment behavior.Service-worker declaration files are emitted as global scripts so that the generated wildcard module types are visible to imports.
Directory-specific rules retain their scope when TypeScript can represent it; ambiguous relative imports use a union of the possible deployed module types.
When generating combined types for named environments, each environment's effective rules are resolved independently and differing import types are represented as unions.
#15261
42c7219Thanks @ondraulehla! - Fixr2 object putandr2 bulk putstoring a different key in local modeKeys that are not URL-safe were mangled on the way into local storage.
r2 object getfor that key reported that the key does not exist.#collapsed into a single object, and the second upload replaced the first.%that is not a valid escape failed outright with "Invalid URL string.", and one with a valid escape, such as%41.txt, was stored asA.txt.Spaces, non-ASCII characters,
#and%now survive the trip into local storage. Objects already in local state are left where they are.#15283
2dde890Thanks @shubhxho! - Show a useful error whenwrangler secret bulkhits an undeployed latest versionwrangler secret putalready explained this case (API error 10215).secret bulkjust dumped the raw API response, which for 10214 talks about logpush and tail_consumers even though you were only uploading secrets.Both commands now point at
wrangler versions secret …instead.#16068
26e03e2Thanks @edevil! - Print temporary account notices to stderrThe terms notice, the proof-of-work message, and the "Temporary account ready" claim details printed by
--temporarynow go to stderr instead of stdout. Previously they corrupted command output on stdout, such as the JSON fromwrangler kv namespace list --temporaryor the raw value fromwrangler kv key get --temporary. Commands that lower the log level for--json, such aswrangler d1 execute --json --temporary, also hid the claim URL; it is now shown unless logging is disabled withWRANGLER_LOG=none.Scripts that read the claim URL from stdout should read stderr instead.
Updated dependencies [
b75421f,0ec13b7,c492d63,ba52118,946aaa7,48f3c04,5606a74,f8cdcb9,e44cf6b,0b51fec]:v4.147.0Compare Source
Minor Changes
#15928
7f57b1cThanks @ichernetsky-cf! - Allow"us"as a jurisdiction for Container applicationsContainer placement constraints now accept
constraints.jurisdiction: "us"in Wrangler and typed Cloudflare configuration. This makes the US jurisdiction available alongside"eu"and"fedramp".Patch Changes
#15974
7f700efThanks @martinezjandrew! - Fixwrangler containers listto report live instancesThe
LIVE INSTANCEScolumn now reports each application's active runtime instances instead of its configured instance count, matching the Cloudflare dashboard. JSON output continues to expose the configured count through the existinginstancesfield.#15980
90e6a1bThanks @martinezjandrew! - Accept Durable Object application IDs in Containers commandswrangler containers instancesandwrangler containers deletenow accept the 32-character hexadecimal application IDs returned for Durable Object-backed applications, in addition to legacy dashed UUIDs.#15871
6a4b0feThanks @tw4! - Retry transient API failures inwrangler workflows instances listandwrangler workflows instances describePreviously, a single temporary 5xx response or dropped connection made these read-only commands exit with an error, even though the next request would have succeeded. They now use Wrangler's existing bounded API retry handling. The read that resolves
--id latestis retried too, which also benefits the otherwrangler workflows instancescommands that acceptlatest; the mutating requests they make afterwards are not retried. Persistent failures are still reported after the retries are exhausted, and under--jsonany retry notices are written to stderr so stdout stays valid JSON.Updated dependencies []:
v4.146.0Compare Source
Minor Changes
#15777
464a582Thanks @Naapperas! - Support the new WorkflowscreateBatch()API in local developmentLocal Workflows bindings now accept object-form batches that create instances from a count or a list of instance options. The result includes handles for created instances and indexed per-instance errors, matching the runtime API while preserving the deprecated array form.
#15639
aee2842Thanks @hugo-vicente11! - Add--allowed-mailto the experimentalwrangler tunnel quick-startcommandThe option forwards exact email addresses, comma-separated lists, and wildcard domains to
cloudflared. It can be specified more than once to combine multiple recipient rules.Email-protected tunnels require
cloudflared2026.9.2 or later. Wrangler checks the selected binary before starting the tunnel and reports an upgrade error when it is incompatible.Patch Changes
#15992
b8e7cc3Thanks @zebp! - Markwrangler artifactscommands as open betaArtifacts has entered open beta, so the
wrangler artifactscommands no longer display a "private beta" label in help output and warnings.#15984
9d7b08eThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15959
efd67e6Thanks @breken-ai! - Keep colons inwrangler tail --headerfilter valueswrangler tail --headersplits its argument into a header name and an optional value at the colon. It split at every colon and kept only the first two parts, so a value containing a colon was cut short:--header "Origin:https://app.example.com"filtered onhttps. The value now includes everything after the first colon, so URLs, ports and IPv6 addresses are sent to the tail filter intact.Updated dependencies [
b00ef4f,9d7b08e,464a582]:v4.145.0Compare Source
Minor Changes
#15685
b9f1cdcThanks @Ankcorn! - Add native support for the Analytics SQL bindingDeclare the zero-configuration binding in
wrangler.jsonwith"analytics": { "binding": "ANALYTICS" }. Wrangler uploads theanalyticsbinding type and proxies it to the remote service during local development, sowrangler devcan call the binding withoutunsafe.bindings.#15943
8468487Thanks @sejoker! - Graduate SQL, Catalog, and Pipelines underwrangler basinout of beta to stableBasin SQL is now available under
wrangler basin sql, Basin Catalog operations are available underwrangler basin catalog, and Pipelines operations are available underwrangler basin pipelines. These commands are now stable, while the previouswrangler r2 sql,wrangler r2 bucket catalog, andwrangler pipelinescommand paths remain available as hidden compatibility aliases.The Basin SQL authentication environment variable is now
WRANGLER_BASIN_SQL_AUTH_TOKEN. Update any existingWRANGLER_R2_SQL_AUTH_TOKENconfiguration to use the new name. The fallback toCLOUDFLARE_API_TOKENremains available.#15948
a0712e5Thanks @akoval-cf! - Add beta K2 producer bindings for existing streamsConfigure a stream created through Wrangler, the Dashboard, or the API in
wrangler.json:{ "k2": [ { "binding": "ORDERS", "stream": "0123456789abcdef0123456789abcdef" } ] }The binding supports
env.ORDERS.send([{ content: new TextEncoder().encode("order"), headers: { event: "order.created" } }]). Batches use either allArrayBufferor allUint8Arraycontent. Check the returnedsuccessvalue, handle rejected RPC promises, and retry only when the returned error explicitly allows it. Generated environment types describe this producer contract without requiring a separate application dependency.K2 requires an enabled account. Deployment credentials need Worker deployment and K2 configuration-read access. Default Wrangler logins now request the K2 OAuth scopes; existing OAuth users should run
wrangler loginagain to grant the new permissions. Development always uses a real K2 stream and may incur usage charges; no local simulator is provided. Theremotesetting can be omitted,remote: truesuppresses the usage warning, andremote: falseis rejected. Consumption is not part of this Worker binding.#15948
a0712e5Thanks @akoval-cf! - Add beta K2 stream management commandsUse
wrangler k2 streams create order_events,wrangler k2 streams list,wrangler k2 streams get <stream-id>, andwrangler k2 streams delete <stream-id>to manage K2 streams. Creation enables Worker bindings but not HTTP ingestion by default, matching the dashboard. Pass--http-enabledto enable authenticated HTTP ingestion and print its endpoint. Creation prints the stream ID and a binding configuration with aYOUR_BINDING_NAMEplaceholder for the Worker's variable name, but does not edit the configuration file automatically.All four commands support
--json. Deletion requires confirmation, or--force/-yto skip it; use--force --jsonfor JSON deletion output. Creation also accepts retention, HTTP authentication, Worker-input, and CORS options; listing supports pagination and a name filter. Default Wrangler logins now requestk2.readandk2.write; existing OAuth users should runwrangler loginagain, or use a custom API token granting K2 Config Write. The account must be enabled for K2.Patch Changes
#15908
ddaa558Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
Updated dependencies [
b9f1cdc,ddaa558,a0712e5]:v4.144.0Compare Source
Minor Changes
#15919
91a3606Thanks @flakey5! - Add--tty(-t) flag towrangler containers sshto force pseudo-terminal allocationOpenSSH only allocates a pseudo-terminal when no remote command is given, so interactive commands such as
wrangler containers ssh <ID> -- bashpreviously ran without a prompt or line editing. Pass--ttyto force one:wrangler containers ssh <ID> --tty -- bash#15951
2a15ae2Thanks @flakey5! - Support SSH settings for Durable Object-managed Containers in the configuration APIdefineContainernow acceptssshandauthorizedKeyswithschedulingPolicy: "durable-object", matching thesshandauthorized_keysfields that Wrangler already supports for these Containers. Previously the schema rejected them, so they could not be set fromcloudflare.config.ts.Patch Changes
v4.143.1Compare Source
Patch Changes
#15159
7bb6eaeThanks @veggiedefender! - Fixwrangler devremote bindings forworkers.devsubdomains protected by AccessRunning
wrangler devwith remote bindings on an unpublished worker protected by Access (e.g. using a wildcard on your workers.dev domain) previously failed with a redirect loop. Wrangler now correctly authenticates remote bindings with Access in this situation.#15923
60ccdbdThanks @petebacondarwin! - Upgrade the bundled capnweb implementation to 0.12.0This updates the RPC implementation shipped in Miniflare and remote-binding proxy workers to the latest capnweb release.
#15938
62fd03aThanks @dieub! - Resolve the affected Undici dependency in new Wrangler and Vite plugin installsUndici 7.29.1 fixes GHSA-3wwx-pv8p-q78v. Update the shared dependency catalog and matching types used by Miniflare and Wrangler so downstream installs can resolve the patched runtime without an application-level override. A published release is still required for consumers; this changeset does not alter already published package metadata.
#15903
06ed9c8Thanks @itsmunzir! - Fix custom-domain-only deploys failing for API tokens without Zone Workers Routes read permissionWhen
workers_devwas disabled androutescontained only entries withcustom_domain: true, every deploy after the first one fetched/zones/:zoneId/workers/routesto check for route conflicts, even though custom domains are not zone Workers Routes. Tokens scoped to Workers Scripts edit plus custom domains - withoutZone > Workers Routes > Read- failed with "No access to the specified resource" after the Worker version had already been uploaded. The conflict check now only covers non-custom-domain routes; custom domain conflicts continue to be reported by the custom domains changeset API.#15887
86211feThanks @alepacheco! - Report an unreachable auth server instead of an expired login when refreshing an OAuth tokenWhen the OAuth token endpoint could not be reached (for example a DNS failure or a connection timeout), the refresh failure was reported as "Your auth token has expired and could not be refreshed", with advice to run
wrangler login; in an interactive terminal Wrangler also started a new browser login. A network failure says nothing about the stored refresh token, and a new login would need the same unreachable server. Wrangler now reports that the Cloudflare auth server could not be reached, leaves the stored credentials unchanged, and does not start a login, so the next run can refresh with the same token once the network is back.Updated dependencies [
60ccdbd,62fd03a,c2bb4c8,eb1efe0,485cfb3]:v4.143.0Compare Source
Minor Changes
#15914
7f0734cThanks @jamesopstad! - Usecf/configforcloudflare.config.tsauthoringExperimental
cloudflare.config.tsprojects must now importdefineConfig, bindings, triggers, and related helpers fromcf/config. Generated declarations from Wrangler and the Vite plugin also reference this package, so projects using the experimental configuration flow must addcfas a dependency.The Vite plugin no longer exports
@cloudflare/vite-plugin/experimental-config.wrangler/experimental-configremains available fordefineWranglerConfig, but no longer re-exports Cloudflare configuration helpers.v4.142.0Compare Source
Minor Changes
#15856
4c2993bThanks @Naapperas! - Support Workflows declared inexportsonctx.exportsin local developmentA Workflow declared in a Worker's
exportsis now available onctx.exportsinwrangler dev, the Vite plugin and the Vitest plugin, with the same API as a Workflow binding:ctx.exportsandworkflowsbindings with the same Workflownameshare their instances, including instances created before the Workflow was declared inexports. Two Workers can't export the same Workflow name, and a binding to an exported Workflow must refer to the Worker and class that export it.getPlatformProxy()ignores Workflows declared inexports, since it doesn't run the Worker's code.wrangler workflowscommands run with--localalso work with Workflows declared only inexports, without aworkflowsbinding.In the Vitest plugin,
introspectWorkflow()andintrospectWorkflowInstance()still need a Workflow binding, and now explain how to add one when passed a Workflow fromctx.exports. Instances created throughctx.exportsare introspected too. Aworkflowsbinding whosescript_nameis the Worker's own name now resolves to the Worker itself again.Patch Changes
#15891
8dc53aeThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
Updated dependencies [
8dc53ae,4c2993b]:v4.141.0Compare Source
Minor Changes
#15658
8280086Thanks @jqmmes! - Add Durable Objects code update strategies to Worker deploymentsUse
--durable-objects-code-update-mode immediatewithwrangler deploy,wrangler versions deploy, andwrangler rollbackto update code without waiting for active instances to hibernate. Use--durable-objects-code-update-mode deferred 30sto set a maximum delay, or configuredurable_objects.code_update_strategywithmodeandmax_delay. When unset, the strategy defaults to deferred with a 5-minute maximum delay; delays cannot exceed 24 hours and must use millisecond precision.#15800
bd56b98Thanks @Refaerds! - Add Browser Run as an event source for Queue subscriptionsYou can now create Queue subscriptions with
--source browserRun.Patch Changes
#15864
ee2b200Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15207
805af2fThanks @exKAZUu! - Show the stack and cause of failed proxied requests inwrangler devdebug logsWhen a request proxied to the local Worker fails, running with
--log-level debugnow shows the underlying error's stack and cause chain.Updated dependencies [
ee2b200,c91279b]:v4.140.0Compare Source
Minor Changes
8f7916cThanks @GregBrimble! - Support Containers in Worker Preview deployments with the Build Output.Patch Changes
v4.139.0Compare Source
Minor Changes
#15792
479e1e8Thanks @flakey5! - Configure SSH for experimental Durable Object-managed ContainersSet
containers[].sshandcontainers[].authorized_keyswhen usingscheduling_policy: "durable_object". These are application-wide settings that follow the same rules as the existing Durable Object-managed Container settings: normal deployments create missing applications and update explicitly configured values, while omitted settings preserve the existing application configuration.#15648
52c0e9fThanks @tpmmorris! - Expose configured Cron Triggers to local development consumersWrangler now passes the active environment's exact Cron Trigger expressions to Miniflare so Local Explorer can display them. Headless agent sessions also advertise the Local Explorer scheduled invocation API.
#15786
bdda4c3Thanks @ThomasRubini! - Support UDP connect handlers in local developmentThe experimental
connectconfiguration now acceptsprotocol: "udp", with optionalidle_timeout_msandmax_pending_bytessettings. UDP datagrams are delivered to the Worker'sconnect()handler using workerd's value-mode socket streams, and can be tested withMiniflare#dispatchConnect({ protocol: "udp" }).#15779
fc3cbaaThanks @Naapperas! - Supportworkflowentries in theexportsconfiguration mapA Worker can now declare the Workflows it defines in
exports, keyed by theWorkflowEntrypointclass name:{ "exports": { "MyWorkflow": { "type": "workflow", "name": "my-workflow", "limits": { "steps": 100 }, "schedules": "0 * * * *" } } }A
workflowexport accepts the same settings as aworkflowsbinding:limits,concurrency,schedules, anddefault_retention.wrangler deployandwrangler versions uploadsend these entries to the upload API by name, andwrangler deployandwrangler triggers deployprovision the Workflow with its settings, just as they do forworkflowsbindings owned by the Worker. A Workflow may be declared both as a binding and as an export, as long as both declarations use the same class and do not set the same setting to different values. A binding to another Worker's Workflow cannot share a name with an export.@cloudflare/configadds the matchingexports.workflow()helper. Local development does not yet act on these entries.Patch Changes
#15796
be72815Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#14847
940c692Thanks @TheSaiEaranti! - Emulate the deterministic-ID uniqueness contract in the local Workflows bindingThe local Workflows binding now matches the documented production behavior for deterministic instance IDs:
create({ id })with an ID that already exists throws(instance.already_exists)and retains the existing instance, andcreateBatch()skips IDs that already exist or repeat within the batch, excluding them from the result instead of creating duplicate executions. Previously both paths silently created duplicates, so code relying on deterministic IDs for idempotency (for example a Queue consumer creating one workflow per message) appeared to work locally while double-executing workflow bodies.#15803
cd60c9cThanks @pmiguel! - Show--jurisdictionin help forwrangler kv namespace createThe option was supported but omitted from the command's help output. Users can now discover how to create KV namespaces in a specific jurisdiction.
#15838
15799d4Thanks @oddharsh! - Updatesmol-tomlto 1.9.0 to fix slow parsing of very large TOML filesParse time for TOML config files now grows linearly with their size, instead of with its square: a 40,000-line file that took 259 ms to parse now takes 17 ms, while typical
wrangler.tomlfiles parse in the same time as before. This addresses theGHSA-r4xh-jqrq-34v2advisory against earlier versions of the parser.Some TOML syntax errors now point at the character that caused them. For example, a
wrangler.tomlcontainingINVALID "FILEis now reported asillegal character in keyat the", rather thanincomplete key-valueat the start of the line.Updated dependencies [
52c0e9f,44f5295,be72815,940c692,bdda4c3,fc3cbaa]:v4.138.0Compare Source
Minor Changes
#15776
b03f960Thanks @edevil! - Add event-code support to temporary Worker deploymentsUse
wrangler deploy --temporary --event-code <code>to provision an account for an event. Wrangler requires explicit server acknowledgement before caching the account and keeps the event code out of its cache and telemetry.#15817
6e77c53Thanks @jamesopstad! - Allow framework commands to produce Preview Build Output with the experimental configWhen
cf previews deployinvokes a framework build command, Preview intent is now preserved. Function-basedcloudflare.config.tsfiles receiveisPreview: true, and generated Build Output is marked as a Preview build.Patch Changes
#15806
8fade73Thanks @NuroDev! - Standardize Zod validation error outputFormat validation errors with Zod's built-in
prettifyError()helper so Miniflare, Wrangler, the Vite plugin, and the Vitest plugin show consistent messages and property paths.Updated dependencies [
a71237a,8fade73]:v4.137.0Compare Source
Minor Changes
#15778
cd7508cThanks @jamesopstad! - Generate types during development and supported builds with Vite'sexperimental.newConfigoption or Wrangler's--experimental-new-configflag (and--experimental-cf-build-outputfor builds)When Wrangler's
--experimental-new-configflag or Vite'sexperimental.newConfigoption is enabled, inferred configuration and runtime declarations are now kept in.cloudflare/types/index.d.ts. Vite refreshes them during development and production builds. Wrangler refreshes them during development and when building with both--experimental-new-configand--experimental-cf-build-output. In the experimentalwrangler.config.tsformat, thetypesoption is now top-level because it applies to both commands.Patch Changes
#15765
1bdb96dThanks @th0m! - Prepare the required egress sidecar for local Containers without configured imagesWrangler dev and Vite dev/preview now pull the required sidecar for Durable Object-managed Containers that select their application image at start time. Previously, these Containers failed to start unless the sidecar image was already cached in Docker.
#15712
f5605f5Thanks @alsuren! - Match D1 SQL statement splitting to the local SQLite runtimeWrangler now uses SQLite's statement-completion state machine when splitting D1 SQL files. This keeps trigger, quoted identifier, comment, and keyword handling consistent with local execution.
v4.136.3Compare Source
Patch Changes
#15662
59267fcThanks @oddharsh! - Updatesmol-tomlto 1.8.0This updates the bundled TOML parser that reads
wrangler.tomlto a version that addresses two advisories against 1.5.2:GHSA-7w5x-hrqm-74c2(a value followed by a comment with no trailing newline, such asa=[1 #, put the parser in an infinite loop) andGHSA-v3rj-xjv7-4jmq(thousands of consecutive comment lines overflowed the stack). On the old version,wrangler deployagainst awrangler.tomlending ina=[1 #never returned; it now fails withInvalid TOML document: cannot find end of structure.#15760
6906bf0Thanks @yomna-shousha! - Warn whenwrangler previewreturns only non-custom-domain URLs even though custom-domain Preview URLs are configured.#15761
354ebdbThanks @podonnell-dev! - Fix Preview output artifacts to always include the resolved parent Worker namePreview artifacts now use Wrangler's resolved Worker name instead of relying on the Preview API response to include it.
Updated dependencies []:
v4.136.2Compare Source
Patch Changes
#15762
ad20547Thanks @podonnell-dev! - Fixwrangler typesgenerating runtime headers with trailing whitespaceRuntime type headers without compatibility flags now end at the compatibility date, keeping generated types reproducible when tools remove trailing whitespace.
#15703
02c1d83Thanks @KianNH! - Improve Container image listing and deletionList all image pages using read-only credentials, validate tags before deletion, and report successful deletion when the garbage-collection request fails.
#15700
275184dThanks @KianNH! - Fix Container SSH connection setup and shutdownPrevent SSH connections from stalling during setup and ensure proxy processes exit when sessions close.
#15759
bd59ecaThanks @petebacondarwin! - Show validsha256-prefixed tags in Container image listingsContainer image listings now distinguish valid OCI tags such as
sha256-releasefrom synthetic digest entries such assha256:<digest>.Updated dependencies []:
v4.136.1Compare Source
Patch Changes
#15744
0ed4c54Thanks @podonnell-dev! - Improvewrangler previewonboarding guidanceWrangler now displays placeholder replacement guidance directly beneath the suggested Preview configuration instead of as a separate warning. JSON output continues to include the guidance in its structured onboarding messages.
#15678
703922dThanks @christhorwarth! - Read workers.dev URLs from the Worker resource during deploymentWrangler no longer requires account-level subdomain permission to display Worker and version-preview URLs. It now uses the Worker-scoped URL fields while preserving account-level registration for accounts without a workers.dev subdomain.
Updated dependencies [
14d946d]:v4.136.0Compare Source
Minor Changes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.