Skip to content

Update workers-sdk - #219

Merged
petebacondarwin merged 1 commit into
mainfrom
renovate/workers-sdk
Oct 6, 2026
Merged

petebacondarwin merged 1 commit into
mainfrom
renovate/workers-sdk

Conversation

@ant-release-bot

Copy link
Copy Markdown
Collaborator

This PR contains the following updates:

Package Change Age Confidence
@cloudflare/autoconfig (source) 0.7.5 → 0.7.6 age confidence
@cloudflare/build-output-utils (source) 0.8.5 → 0.8.6 age confidence
@cloudflare/cli-shared-helpers (source) 0.2.3 → 0.2.4 age confidence
@cloudflare/codemods (source) 0.4.0 → 0.4.1 age confidence
@cloudflare/config (source) 0.23.0 → 0.24.0 age confidence
@cloudflare/containers-shared (source) 0.21.3 → 0.21.4 age confidence
@cloudflare/deploy-helpers (source) 0.19.2 → 0.20.0 age confidence
@cloudflare/runtime-types (source) 0.1.7 → 0.1.8 age confidence
@cloudflare/workers-auth (source) 0.12.0 → 0.13.0 age confidence
@cloudflare/workers-utils (source) 0.46.0 → 0.47.0 age confidence
miniflare (source) 5.20261001.0-alpha → 5.20261006.0-alpha age confidence
wrangler (source) 4.147.0 → 4.148.0 age confidence

Release Notes

cloudflare/workers-sdk (@​cloudflare/autoconfig)

v0.7.6

Compare Source

Patch Changes
cloudflare/workers-sdk (@​cloudflare/build-output-utils)

v0.8.6

Compare Source

Patch Changes
cloudflare/workers-sdk (@​cloudflare/cli-shared-helpers)

v0.2.4

Compare Source

Patch Changes
cloudflare/workers-sdk (@​cloudflare/codemods)

v0.4.1

Compare Source

Patch Changes
  • #​16016 f025bbf Thanks @​Ankcorn! - Add bindings.analytics() as the preferred name for Analytics SQL bindings and deprecate bindings.analyticsSQL().

  • #​15991 b4f6054 Thanks @​NuroDev! - Use the default type generation behavior in projects migrated by cf migrate.

    Wrangler projects without dev.generate_types: false no longer get a wrangler.config.ts solely for a redundant type setting. An explicit opt-out still emits types.generate: false, and other Wrangler tooling still produces a config when needed.

  • #​15946 1d38b36 Thanks @​NuroDev! - Upgrade Wrangler dependencies to a version supported by cf dev when Wrangler-to-cf migration generates wrangler.config.ts.

    Affected projects receive the latest Wrangler release and an updated lockfile through their existing package manager. Compatible workspace links and existing dependency sections are preserved, and --no-install and --dry-run avoid package installation.

  • #​15947 969f760 Thanks @​NuroDev! - Upgrade the Vite plugin when migrating a Wrangler project to cf with Vite

    Vite migrations now install @cloudflare/vite-plugin@beta, keep the beta dist tag in package.json, and update the project's lockfile when the existing version is unsupported. Compatible installations remain unchanged, and Wrangler migrations do not update the plugin.

  • #​15990 22dbde6 Thanks @​NuroDev! - Avoid a manual migration TODO when an R2 binding uses the same production and preview bucket name.

    cf migrate now requests manual review only when the preview bucket name differs from the production bucket name.

cloudflare/workers-sdk (@​cloudflare/config)

v0.24.0

Compare Source

Minor Changes
  • #​16016 f025bbf Thanks @​Ankcorn! - Add bindings.analytics() as the preferred name for Analytics SQL bindings and deprecate bindings.analyticsSQL().

  • #​15998 b75421f Thanks @​dario-piotrowicz! - Add assets.base_path support to Workers Assets

    Serve an asset directory from a public URL prefix without changing its on-disk layout:

    {
      "assets": {
        "directory": "./public",
        "base_path": "/docs"
      }
    }

    Wrangler, preview, Miniflare, and generated build configuration preserve the explicitly selected value, while the Asset Worker normalizes it and strips the prefix only for asset lookup. Requests passed to a user Worker, request-facing headers, and redirects retain the public path. Relative pathname inputs are interpreted as root-relative prefixes, URL-shaped values are rejected, and omitting the option preserves existing root-path behavior.

    Authored _headers and _redirects rules continue to match full public paths. In particular, both the source and destination of an authored 200 asset rewrite must include the configured public prefix; Asset Worker-generated redirects are prefixed automatically.

cloudflare/workers-sdk (@​cloudflare/containers-shared)

v0.21.4

Compare Source

Patch Changes
cloudflare/workers-sdk (@​cloudflare/deploy-helpers)

v0.20.0

Compare Source

Minor Changes
  • #​15998 b75421f Thanks @​dario-piotrowicz! - Add assets.base_path support to Workers Assets

    Serve an asset directory from a public URL prefix without changing its on-disk layout:

    {
      "assets": {
        "directory": "./public",
        "base_path": "/docs"
      }
    }

    Wrangler, preview, Miniflare, and generated build configuration preserve the explicitly selected value, while the Asset Worker normalizes it and strips the prefix only for asset lookup. Requests passed to a user Worker, request-facing headers, and redirects retain the public path. Relative pathname inputs are interpreted as root-relative prefixes, URL-shaped values are rejected, and omitting the option preserves existing root-path behavior.

    Authored _headers and _redirects rules continue to match full public paths. In particular, both the source and destination of an authored 200 asset rewrite must include the configured public prefix; Asset Worker-generated redirects are prefixed automatically.

Patch Changes
cloudflare/workers-sdk (@​cloudflare/runtime-types)

v0.1.8

Compare Source

Patch Changes
cloudflare/workers-sdk (@​cloudflare/workers-auth)

v0.13.0

Compare Source

Minor Changes
  • #​16068 26e03e2 Thanks @​edevil! - Add a temporaryAccountLogger option for temporary-account notices

    AuthContext.temporaryAccountLogger receives the terms notice, the proof-of-work message, and the "Temporary account ready" claim details. A CLI whose commands write parseable output to stdout can route these messages to stderr. When it is not set, the messages go to logger as before.

Patch Changes
cloudflare/workers-sdk (@​cloudflare/workers-utils)

v0.47.0

Compare Source

Minor Changes
  • #​15998 b75421f Thanks @​dario-piotrowicz! - Add assets.base_path support to Workers Assets

    Serve an asset directory from a public URL prefix without changing its on-disk layout:

    {
      "assets": {
        "directory": "./public",
        "base_path": "/docs"
      }
    }

    Wrangler, preview, Miniflare, and generated build configuration preserve the explicitly selected value, while the Asset Worker normalizes it and strips the prefix only for asset lookup. Requests passed to a user Worker, request-facing headers, and redirects retain the public path. Relative pathname inputs are interpreted as root-relative prefixes, URL-shaped values are rejected, and omitting the option preserves existing root-path behavior.

    Authored _headers and _redirects rules continue to match full public paths. In particular, both the source and destination of an authored 200 asset rewrite must include the configured public prefix; Asset Worker-generated redirects are prefixed automatically.

Patch Changes
  • #​15534 2b1a0ca Thanks @​vahidshaik1901! - Improve guidance for conflicting Wrangler configuration files

    When user and generated deploy configurations are found under different base paths, Wrangler now identifies the expected deploy configuration location, suggests how to resolve the conflict, and links to the relevant documentation.

  • #​16030 aa2f9b7 Thanks @​edmundhung! - Extend startTunnel() to support email-protected Quick Tunnels

    Pass a list of email addresses or domain patterns through TunnelOptions.allowedMail to restrict access to a Quick Tunnel.

cloudflare/workers-sdk (miniflare)

v5.20261006.0-alpha

Compare Source

Minor Changes
  • #​15998 b75421f Thanks @​dario-piotrowicz! - Add assets.base_path support to Workers Assets

    Serve an asset directory from a public URL prefix without changing its on-disk layout:

    {
      "assets": {
        "directory": "./public",
        "base_path": "/docs"
      }
    }

    Wrangler, preview, Miniflare, and generated build configuration preserve the explicitly selected value, while the Asset Worker normalizes it and strips the prefix only for asset lookup. Requests passed to a user Worker, request-facing headers, and redirects retain the public path. Relative pathname inputs are interpreted as root-relative prefixes, URL-shaped values are rejected, and omitting the option preserves existing root-path behavior.

    Authored _headers and _redirects rules continue to match full public paths. In particular, both the source and destination of an authored 200 asset rewrite must include the configured public prefix; Asset Worker-generated redirects are prefixed automatically.

  • #​15330 f8cdcb9 Thanks @​akshitsinha! - Manage local Flagship flags in Local Explorer

    Bound Flagship apps now appear in Local Explorer. You can create, edit, toggle, delete, and evaluate flags against the same local store used by your Worker, including targeting conditions and percentage rollouts.

    Explorer requests are routed to the development process that owns each app, so Flagship management also works across multiple local Workers.

Patch Changes
  • #​16081 0ec13b7 Thanks @​petebacondarwin! - Authenticate dev registry updates and internal loopback requests

    Require per-instance credentials for dev registry updates and internal loopback requests, including WebSocket upgrades. Authenticate callers before parsing registry updates or dispatching privileged loopback operations, while preserving legitimate shared-storage peers.

  • #​16014 c492d63 Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20261001.1 ^5.20261005.1
    workerd 1.20261001.1 1.20261005.1
  • #​16079 ba52118 Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20261005.1 ^5.20261006.1
    workerd 1.20261005.1 1.20261006.1
  • #​14921 946aaa7 Thanks @​Mohith26! - Prevent local D1 session bookmark errors from crashing the development server

    Session bookmark lookup failures, including SQLite errors when another connection holds the database write lock, now reach the Worker as catchable D1_ERRORs. SQL execution and bookmark retrieval share a transaction, so a failed lookup rolls back the queries and retrying cannot duplicate their writes. This applies to local D1 through Miniflare, Wrangler, the Vite plugin, and the Vitest plugin.

    Fixes #​14916

  • #​15781 48f3c04 Thanks @​Wichtowski! - Reduce dispatchFetch() connection exhaustion under sustained local and CI workloads

    Repeated dispatches now reuse runtime connections for all HTTP methods, including POST, PUT, DELETE, and PATCH, instead of creating a new connection for every request. This prevents read-heavy and write-heavy Miniflare test suites from exhausting the host's available ephemeral ports. Transport failures are surfaced without automatically replaying requests, since Worker handlers can have side effects even for GET and HEAD. Idle runtime connections now close after one second, before workerd's five-second idle timeout can race with reuse.

  • #​16033 5606a74 Thanks @​Pduhard! - Remove a 40 ms delay from Hyperdrive queries in local dev

    Miniflare's local Hyperdrive proxy left Nagle's algorithm on for its sockets. A Postgres driver that sends one query in several small writes, such as pg for every query with parameters, had the later writes held back until the database acknowledged the first, which took about 40 ms per query. Large results were held back the same way on the way back to the Worker.

    The proxy now turns on noDelay for the connection from the Worker and for the connection to the database. Connection strings using sslmode=disable are unaffected, since that mode connects directly and skips the proxy.

  • #​16050 e44cf6b Thanks @​acchou! - Serve each Worker's own static assets when several Workers with assets run together

    When several Workers with static assets ran in one Miniflare instance, such as wrangler dev with multiple -c configs or the test harness, every Worker read its assets from the same Worker's directory. Other Workers got 404s or that Worker's file at the same path. Each Worker now reads its own assets directory.

  • #​16063 0b51fec Thanks @​Cherry! - Start the synchronous proxy worker before returning proxies

    getBindings(), getDurableObjectNamespace() and the other proxy getters now wait for the worker that serves synchronous proxy calls to start, instead of the first synchronous call blocking Node's main thread while it boots. That block also stalled every other Miniflare instance served from the same process, such as Vitest pool workers running test files in parallel.

cloudflare/workers-sdk (wrangler)

v4.148.0

Compare Source

Minor Changes
  • #​16051 b4e1299 Thanks @​devteamaegis! - Add --source-namespace and --source-repo-name to wrangler queues subscription create for the artifacts.repo source

    The Event Subscriptions API requires source.namespace and source.repo_name for artifacts.repo subscriptions, but Wrangler had no way to pass them, so --source artifacts.repo always failed with a validation error. Both flags are now required for this source, and wrangler queues subscription get shows the subscription's resource as <namespace>/<repo-name>.

  • #​15998 b75421f Thanks @​dario-piotrowicz! - Add assets.base_path support to Workers Assets

    Serve an asset directory from a public URL prefix without changing its on-disk layout:

    {
      "assets": {
        "directory": "./public",
        "base_path": "/docs"
      }
    }

    Wrangler, preview, Miniflare, and generated build configuration preserve the explicitly selected value, while the Asset Worker normalizes it and strips the prefix only for asset lookup. Requests passed to a user Worker, request-facing headers, and redirects retain the public path. Relative pathname inputs are interpreted as root-relative prefixes, URL-shaped values are rejected, and omitting the option preserves existing root-path behavior.

    Authored _headers and _redirects rules continue to match full public paths. In particular, both the source and destination of an authored 200 asset rewrite must include the configured public prefix; Asset Worker-generated redirects are prefixed automatically.

  • #​16005 4d308f6 Thanks @​oOPa! - Add a --experimental-mode instant option to wrangler kv namespace create

    This lets entitled accounts create Workers KV Instant namespaces while the feature is in private beta.

  • #​16030 aa2f9b7 Thanks @​edmundhung! - Add email-protected Quick Tunnels to wrangler dev

    Pass one or more --tunnel-allowed-mail flags to require email authentication when exposing a local development server through a Quick Tunnel. Each value can be an exact email address or a domain pattern.

  • #​15283 2dde890 Thanks @​shubhxho! - Support deleting secrets with wrangler versions secret bulk

    Set a secret's value to null in JSON input to remove it from the new Worker version. Bulk output now distinguishes between created and deleted secrets, so retrying wrangler secret bulk with wrangler versions secret bulk preserves requested deletions. Deploy the new version with wrangler versions deploy to apply the changes to production traffic.

Patch Changes
  • #​15534 2b1a0ca Thanks @​vahidshaik1901! - Improve guidance for conflicting Wrangler configuration files

    When user and generated deploy configurations are found under different base paths, Wrangler now identifies the expected deploy configuration location, suggests how to resolve the conflict, and links to the relevant documentation.

  • #​16014 c492d63 Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20261001.1 ^5.20261005.1
    workerd 1.20261001.1 1.20261005.1
  • #​16079 ba52118 Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20261005.1 ^5.20261006.1
    workerd 1.20261005.1 1.20261006.1
  • #​15573 14f0339 Thanks @​xgame92! - Include default module rules in generated Worker types

    wrangler types now declares the built-in Text, Data, and WebAssembly module patterns even when they are not repeated in the Wrangler configuration, keeping generated types aligned with deployment behavior.

    Service-worker declaration files are emitted as global scripts so that the generated wildcard module types are visible to imports.

    Directory-specific rules retain their scope when TypeScript can represent it; ambiguous relative imports use a union of the possible deployed module types.

    When generating combined types for named environments, each environment's effective rules are resolved independently and differing import types are represented as unions.

  • #​15261 42c7219 Thanks @​ondraulehla! - Fix r2 object put and r2 bulk put storing a different key in local mode

    Keys that are not URL-safe were mangled on the way into local storage.

    • A key with a space or a non-ASCII character was stored under its percent-encoded name, so a later r2 object get for that key reported that the key does not exist.
    • Two keys that differ only after a # collapsed into a single object, and the second upload replaced the first.
    • A key with a % that is not a valid escape failed outright with "Invalid URL string.", and one with a valid escape, such as %41.txt, was stored as A.txt.

    Spaces, non-ASCII characters, # and % now survive the trip into local storage. Objects already in local state are left where they are.

  • #​15283 2dde890 Thanks @​shubhxho! - Show a useful error when wrangler secret bulk hits an undeployed latest version

    wrangler secret put already explained this case (API error 10215). secret bulk just dumped the raw API response, which for 10214 talks about logpush and tail_consumers even though you were only uploading secrets.

    Both commands now point at wrangler versions secret … instead.

  • #​16068 26e03e2 Thanks @​edevil! - Print temporary account notices to stderr

    The terms notice, the proof-of-work message, and the "Temporary account ready" claim details printed by --temporary now go to stderr instead of stdout. Previously they corrupted command output on stdout, such as the JSON from wrangler kv namespace list --temporary or the raw value from wrangler kv key get --temporary. Commands that lower the log level for --json, such as wrangler d1 execute --json --temporary, also hid the claim URL; it is now shown unless logging is disabled with WRANGLER_LOG=none.

    Scripts that read the claim URL from stdout should read stderr instead.

  • Updated dependencies [b75421f, 0ec13b7, c492d63, ba52118, 946aaa7, 48f3c04, 5606a74, f8cdcb9, e44cf6b, 0b51fec]:


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@ant-release-bot
ant-release-bot requested a review from a team as a code owner October 6, 2026 19:04
@ant-release-bot ant-release-bot added the dependencies Pull requests that update a dependency file label Oct 6, 2026
@pkg-pr-new

pkg-pr-new Bot commented Oct 6, 2026

Copy link
Copy Markdown
npm i https://pkg.pr.new/cf@219

commit: 1a05f4c

@ask-bonk

ask-bonk Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🤖 I've done a thorough review of your PR.

Updates the Workers SDK, Wrangler, and Miniflare dependency batch.

  1. Warning: wrangler@4.148.0 declares @cloudflare/workers-types@^5.20261006.1, but both Vite fixtures retain 5.20261003.1. This leaves the fixtures with an unmet peer and type definitions that do not match their Wrangler runtime. Update both fixture package manifests to 5.20261006.1 and regenerate pnpm-lock.yaml.
"@cloudflare/workers-types": "5.20261006.1"

@ask-bonk

ask-bonk Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🤖 I've done a thorough review of your PR.

Updates the Workers SDK, Wrangler, and Miniflare dependency batch.

  1. Warning: Posted a comment: both Vite fixtures retain incompatible @cloudflare/workers-types versions for wrangler@4.148.0.

github run

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

cf --help startup

mean stddev min max
PR 257.9 ms 7.9 ms 250.5 ms 283.0 ms
base 256.2 ms 7.0 ms 249.6 ms 279.1 ms

Δ (PR vs base): ↑ +1.7 ms (+0.7%)

Measured with hyperfine on ubuntu-latest (3 warmup runs, 20 timed runs). CI numbers carry ±a few ms of runner jitter; treat small deltas as noise.

@petebacondarwin
petebacondarwin added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit 24d188a Oct 6, 2026
11 checks passed
@petebacondarwin
petebacondarwin deleted the renovate/workers-sdk branch October 6, 2026 20:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants