Repository navigation
Update workers-sdk - #219
Merged
Merged
Conversation
commit: |
Contributor
|
🤖 I've done a thorough review of your PR. Updates the Workers SDK, Wrangler, and Miniflare dependency batch.
|
Contributor
|
🤖 I've done a thorough review of your PR. Updates the Workers SDK, Wrangler, and Miniflare dependency batch.
|
Contributor
|
| mean | stddev | min | max | |
|---|---|---|---|---|
| PR | 257.9 ms | 7.9 ms | 250.5 ms | 283.0 ms |
| base | 256.2 ms | 7.0 ms | 249.6 ms | 279.1 ms |
Δ (PR vs base): ↑ +1.7 ms (+0.7%)
Measured with hyperfine on ubuntu-latest (3 warmup runs, 20 timed runs). CI numbers carry ±a few ms of runner jitter; treat small deltas as noise.
petebacondarwin
approved these changes
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.7.5→0.7.60.8.5→0.8.60.2.3→0.2.40.4.0→0.4.10.23.0→0.24.00.21.3→0.21.40.19.2→0.20.00.1.7→0.1.80.12.0→0.13.00.46.0→0.47.05.20261001.0-alpha→5.20261006.0-alpha4.147.0→4.148.0Release Notes
cloudflare/workers-sdk (@cloudflare/autoconfig)
v0.7.6Compare Source
Patch Changes
f025bbf,b75421f,2b1a0ca,aa2f9b7]:cloudflare/workers-sdk (@cloudflare/build-output-utils)
v0.8.6Compare Source
Patch Changes
f025bbf,b75421f]:cloudflare/workers-sdk (@cloudflare/cli-shared-helpers)
v0.2.4Compare Source
Patch Changes
b75421f,2b1a0ca,aa2f9b7]:cloudflare/workers-sdk (@cloudflare/codemods)
v0.4.1Compare Source
Patch Changes
#16016
f025bbfThanks @Ankcorn! - Addbindings.analytics()as the preferred name for Analytics SQL bindings and deprecatebindings.analyticsSQL().#15991
b4f6054Thanks @NuroDev! - Use the default type generation behavior in projects migrated bycf migrate.Wrangler projects without
dev.generate_types: falseno longer get awrangler.config.tssolely for a redundant type setting. An explicit opt-out still emitstypes.generate: false, and other Wrangler tooling still produces a config when needed.#15946
1d38b36Thanks @NuroDev! - Upgrade Wrangler dependencies to a version supported bycf devwhen Wrangler-to-cf migration generateswrangler.config.ts.Affected projects receive the latest Wrangler release and an updated lockfile through their existing package manager. Compatible workspace links and existing dependency sections are preserved, and
--no-installand--dry-runavoid package installation.#15947
969f760Thanks @NuroDev! - Upgrade the Vite plugin when migrating a Wrangler project to cf with ViteVite migrations now install
@cloudflare/vite-plugin@beta, keep thebetadist tag inpackage.json, and update the project's lockfile when the existing version is unsupported. Compatible installations remain unchanged, and Wrangler migrations do not update the plugin.#15990
22dbde6Thanks @NuroDev! - Avoid a manual migration TODO when an R2 binding uses the same production and preview bucket name.cf migratenow requests manual review only when the preview bucket name differs from the production bucket name.cloudflare/workers-sdk (@cloudflare/config)
v0.24.0Compare Source
Minor Changes
#16016
f025bbfThanks @Ankcorn! - Addbindings.analytics()as the preferred name for Analytics SQL bindings and deprecatebindings.analyticsSQL().#15998
b75421fThanks @dario-piotrowicz! - Addassets.base_pathsupport to Workers AssetsServe an asset directory from a public URL prefix without changing its on-disk layout:
{ "assets": { "directory": "./public", "base_path": "/docs" } }Wrangler, preview, Miniflare, and generated build configuration preserve the explicitly selected value, while the Asset Worker normalizes it and strips the prefix only for asset lookup. Requests passed to a user Worker, request-facing headers, and redirects retain the public path. Relative pathname inputs are interpreted as root-relative prefixes, URL-shaped values are rejected, and omitting the option preserves existing root-path behavior.
Authored
_headersand_redirectsrules continue to match full public paths. In particular, both the source and destination of an authored200asset rewrite must include the configured public prefix; Asset Worker-generated redirects are prefixed automatically.cloudflare/workers-sdk (@cloudflare/containers-shared)
v0.21.4Compare Source
Patch Changes
f025bbf,b75421f,2b1a0ca,aa2f9b7]:cloudflare/workers-sdk (@cloudflare/deploy-helpers)
v0.20.0Compare Source
Minor Changes
#15998
b75421fThanks @dario-piotrowicz! - Addassets.base_pathsupport to Workers AssetsServe an asset directory from a public URL prefix without changing its on-disk layout:
{ "assets": { "directory": "./public", "base_path": "/docs" } }Wrangler, preview, Miniflare, and generated build configuration preserve the explicitly selected value, while the Asset Worker normalizes it and strips the prefix only for asset lookup. Requests passed to a user Worker, request-facing headers, and redirects retain the public path. Relative pathname inputs are interpreted as root-relative prefixes, URL-shaped values are rejected, and omitting the option preserves existing root-path behavior.
Authored
_headersand_redirectsrules continue to match full public paths. In particular, both the source and destination of an authored200asset rewrite must include the configured public prefix; Asset Worker-generated redirects are prefixed automatically.Patch Changes
#16069
425662bThanks @Pitchfork-and-Torch! - fix: infer Preview/git branch names from unborn repositoriesgetBranchName()previously usedgit rev-parse --abbrev-ref HEAD, which fails (and can leak stderr) before the first commit, and returns the literalHEADon detached checkouts. It now usesgit branch --show-currentwith stderr suppressed so unborn branches resolve and detached checkouts return no inferred name.Preview commit ref, commit message, and the CI repository URL git fallback swallow stderr the same way, so an unborn repository does not print Git fatal errors.
Refs: cloudflare/cf#24
Updated dependencies [
f025bbf,b75421f,0ec13b7,2b1a0ca,c492d63,ba52118,946aaa7,48f3c04,5606a74,f8cdcb9,e44cf6b,aa2f9b7,0b51fec]:cloudflare/workers-sdk (@cloudflare/runtime-types)
v0.1.8Compare Source
Patch Changes
b75421f,0ec13b7,c492d63,ba52118,946aaa7,48f3c04,5606a74,f8cdcb9,e44cf6b,0b51fec]:cloudflare/workers-sdk (@cloudflare/workers-auth)
v0.13.0Compare Source
Minor Changes
#16068
26e03e2Thanks @edevil! - Add atemporaryAccountLoggeroption for temporary-account noticesAuthContext.temporaryAccountLoggerreceives the terms notice, the proof-of-work message, and the "Temporary account ready" claim details. A CLI whose commands write parseable output to stdout can route these messages to stderr. When it is not set, the messages go tologgeras before.Patch Changes
b75421f,2b1a0ca,aa2f9b7]:cloudflare/workers-sdk (@cloudflare/workers-utils)
v0.47.0Compare Source
Minor Changes
#15998
b75421fThanks @dario-piotrowicz! - Addassets.base_pathsupport to Workers AssetsServe an asset directory from a public URL prefix without changing its on-disk layout:
{ "assets": { "directory": "./public", "base_path": "/docs" } }Wrangler, preview, Miniflare, and generated build configuration preserve the explicitly selected value, while the Asset Worker normalizes it and strips the prefix only for asset lookup. Requests passed to a user Worker, request-facing headers, and redirects retain the public path. Relative pathname inputs are interpreted as root-relative prefixes, URL-shaped values are rejected, and omitting the option preserves existing root-path behavior.
Authored
_headersand_redirectsrules continue to match full public paths. In particular, both the source and destination of an authored200asset rewrite must include the configured public prefix; Asset Worker-generated redirects are prefixed automatically.Patch Changes
#15534
2b1a0caThanks @vahidshaik1901! - Improve guidance for conflicting Wrangler configuration filesWhen user and generated deploy configurations are found under different base paths, Wrangler now identifies the expected deploy configuration location, suggests how to resolve the conflict, and links to the relevant documentation.
#16030
aa2f9b7Thanks @edmundhung! - ExtendstartTunnel()to support email-protected Quick TunnelsPass a list of email addresses or domain patterns through
TunnelOptions.allowedMailto restrict access to a Quick Tunnel.cloudflare/workers-sdk (miniflare)
v5.20261006.0-alphaCompare Source
Minor Changes
#15998
b75421fThanks @dario-piotrowicz! - Addassets.base_pathsupport to Workers AssetsServe an asset directory from a public URL prefix without changing its on-disk layout:
{ "assets": { "directory": "./public", "base_path": "/docs" } }Wrangler, preview, Miniflare, and generated build configuration preserve the explicitly selected value, while the Asset Worker normalizes it and strips the prefix only for asset lookup. Requests passed to a user Worker, request-facing headers, and redirects retain the public path. Relative pathname inputs are interpreted as root-relative prefixes, URL-shaped values are rejected, and omitting the option preserves existing root-path behavior.
Authored
_headersand_redirectsrules continue to match full public paths. In particular, both the source and destination of an authored200asset rewrite must include the configured public prefix; Asset Worker-generated redirects are prefixed automatically.#15330
f8cdcb9Thanks @akshitsinha! - Manage local Flagship flags in Local ExplorerBound Flagship apps now appear in Local Explorer. You can create, edit, toggle, delete, and evaluate flags against the same local store used by your Worker, including targeting conditions and percentage rollouts.
Explorer requests are routed to the development process that owns each app, so Flagship management also works across multiple local Workers.
Patch Changes
#16081
0ec13b7Thanks @petebacondarwin! - Authenticate dev registry updates and internal loopback requestsRequire per-instance credentials for dev registry updates and internal loopback requests, including WebSocket upgrades. Authenticate callers before parsing registry updates or dispatching privileged loopback operations, while preserving legitimate shared-storage peers.
#16014
c492d63Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#16079
ba52118Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#14921
946aaa7Thanks @Mohith26! - Prevent local D1 session bookmark errors from crashing the development serverSession bookmark lookup failures, including SQLite errors when another connection holds the database write lock, now reach the Worker as catchable
D1_ERRORs. SQL execution and bookmark retrieval share a transaction, so a failed lookup rolls back the queries and retrying cannot duplicate their writes. This applies to local D1 through Miniflare, Wrangler, the Vite plugin, and the Vitest plugin.Fixes #14916
#15781
48f3c04Thanks @Wichtowski! - ReducedispatchFetch()connection exhaustion under sustained local and CI workloadsRepeated dispatches now reuse runtime connections for all HTTP methods, including
POST,PUT,DELETE, andPATCH, instead of creating a new connection for every request. This prevents read-heavy and write-heavy Miniflare test suites from exhausting the host's available ephemeral ports. Transport failures are surfaced without automatically replaying requests, since Worker handlers can have side effects even forGETandHEAD. Idle runtime connections now close after one second, before workerd's five-second idle timeout can race with reuse.#16033
5606a74Thanks @Pduhard! - Remove a 40 ms delay from Hyperdrive queries in local devMiniflare's local Hyperdrive proxy left Nagle's algorithm on for its sockets. A Postgres driver that sends one query in several small writes, such as
pgfor every query with parameters, had the later writes held back until the database acknowledged the first, which took about 40 ms per query. Large results were held back the same way on the way back to the Worker.The proxy now turns on
noDelayfor the connection from the Worker and for the connection to the database. Connection strings usingsslmode=disableare unaffected, since that mode connects directly and skips the proxy.#16050
e44cf6bThanks @acchou! - Serve each Worker's own static assets when several Workers with assets run togetherWhen several Workers with static assets ran in one Miniflare instance, such as
wrangler devwith multiple-cconfigs or the test harness, every Worker read its assets from the same Worker's directory. Other Workers got 404s or that Worker's file at the same path. Each Worker now reads its own assets directory.#16063
0b51fecThanks @Cherry! - Start the synchronous proxy worker before returning proxiesgetBindings(),getDurableObjectNamespace()and the other proxy getters now wait for the worker that serves synchronous proxy calls to start, instead of the first synchronous call blocking Node's main thread while it boots. That block also stalled every other Miniflare instance served from the same process, such as Vitest pool workers running test files in parallel.cloudflare/workers-sdk (wrangler)
v4.148.0Compare Source
Minor Changes
#16051
b4e1299Thanks @devteamaegis! - Add--source-namespaceand--source-repo-nametowrangler queues subscription createfor theartifacts.reposourceThe Event Subscriptions API requires
source.namespaceandsource.repo_nameforartifacts.reposubscriptions, but Wrangler had no way to pass them, so--source artifacts.repoalways failed with a validation error. Both flags are now required for this source, andwrangler queues subscription getshows the subscription's resource as<namespace>/<repo-name>.#15998
b75421fThanks @dario-piotrowicz! - Addassets.base_pathsupport to Workers AssetsServe an asset directory from a public URL prefix without changing its on-disk layout:
{ "assets": { "directory": "./public", "base_path": "/docs" } }Wrangler, preview, Miniflare, and generated build configuration preserve the explicitly selected value, while the Asset Worker normalizes it and strips the prefix only for asset lookup. Requests passed to a user Worker, request-facing headers, and redirects retain the public path. Relative pathname inputs are interpreted as root-relative prefixes, URL-shaped values are rejected, and omitting the option preserves existing root-path behavior.
Authored
_headersand_redirectsrules continue to match full public paths. In particular, both the source and destination of an authored200asset rewrite must include the configured public prefix; Asset Worker-generated redirects are prefixed automatically.#16005
4d308f6Thanks @oOPa! - Add a--experimental-mode instantoption towrangler kv namespace createThis lets entitled accounts create Workers KV Instant namespaces while the feature is in private beta.
#16030
aa2f9b7Thanks @edmundhung! - Add email-protected Quick Tunnels towrangler devPass one or more
--tunnel-allowed-mailflags to require email authentication when exposing a local development server through a Quick Tunnel. Each value can be an exact email address or a domain pattern.#15283
2dde890Thanks @shubhxho! - Support deleting secrets withwrangler versions secret bulkSet a secret's value to
nullin JSON input to remove it from the new Worker version. Bulk output now distinguishes between created and deleted secrets, so retryingwrangler secret bulkwithwrangler versions secret bulkpreserves requested deletions. Deploy the new version withwrangler versions deployto apply the changes to production traffic.Patch Changes
#15534
2b1a0caThanks @vahidshaik1901! - Improve guidance for conflicting Wrangler configuration filesWhen user and generated deploy configurations are found under different base paths, Wrangler now identifies the expected deploy configuration location, suggests how to resolve the conflict, and links to the relevant documentation.
#16014
c492d63Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#16079
ba52118Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15573
14f0339Thanks @xgame92! - Include default module rules in generated Worker typeswrangler typesnow declares the built-in Text, Data, and WebAssembly module patterns even when they are not repeated in the Wrangler configuration, keeping generated types aligned with deployment behavior.Service-worker declaration files are emitted as global scripts so that the generated wildcard module types are visible to imports.
Directory-specific rules retain their scope when TypeScript can represent it; ambiguous relative imports use a union of the possible deployed module types.
When generating combined types for named environments, each environment's effective rules are resolved independently and differing import types are represented as unions.
#15261
42c7219Thanks @ondraulehla! - Fixr2 object putandr2 bulk putstoring a different key in local modeKeys that are not URL-safe were mangled on the way into local storage.
r2 object getfor that key reported that the key does not exist.#collapsed into a single object, and the second upload replaced the first.%that is not a valid escape failed outright with "Invalid URL string.", and one with a valid escape, such as%41.txt, was stored asA.txt.Spaces, non-ASCII characters,
#and%now survive the trip into local storage. Objects already in local state are left where they are.#15283
2dde890Thanks @shubhxho! - Show a useful error whenwrangler secret bulkhits an undeployed latest versionwrangler secret putalready explained this case (API error 10215).secret bulkjust dumped the raw API response, which for 10214 talks about logpush and tail_consumers even though you were only uploading secrets.Both commands now point at
wrangler versions secret …instead.#16068
26e03e2Thanks @edevil! - Print temporary account notices to stderrThe terms notice, the proof-of-work message, and the "Temporary account ready" claim details printed by
--temporarynow go to stderr instead of stdout. Previously they corrupted command output on stdout, such as the JSON fromwrangler kv namespace list --temporaryor the raw value fromwrangler kv key get --temporary. Commands that lower the log level for--json, such aswrangler d1 execute --json --temporary, also hid the claim URL; it is now shown unless logging is disabled withWRANGLER_LOG=none.Scripts that read the claim URL from stdout should read stderr instead.
Updated dependencies [
b75421f,0ec13b7,c492d63,ba52118,946aaa7,48f3c04,5606a74,f8cdcb9,e44cf6b,0b51fec]:Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.