Skip to content

build(deps): bump undici and miniflare - #61

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-089cbea947
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-089cbea947

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown

Bumps undici to 8.11.2 and updates ancestor dependency miniflare. These dependencies need to be updated together.

Updates undici from 8.8.0 to 8.11.2

Release notes

Sourced from undici's releases.

v8.11.2

What's Changed

New Contributors

Full Changelog: nodejs/undici@v8.11.1...v8.11.2

v8.11.1

What's Changed

Full Changelog: nodejs/undici@v8.11.0...v8.11.1

v8.11.0

What's Changed

... (truncated)

Commits

Updates miniflare from 4.20260714.0 to 5.20260926.1-alpha

Release notes

Sourced from miniflare's releases.

miniflare@5.20260926.1-alpha

Patch Changes

  • #15923 60ccdbd Thanks @​petebacondarwin! - Upgrade the bundled capnweb implementation to 0.12.0

    This updates the RPC implementation shipped in Miniflare and remote-binding proxy workers to the latest capnweb release.

  • #15938 62fd03a Thanks @​dieub! - Resolve the affected Undici dependency in new Wrangler and Vite plugin installs

    Undici 7.29.1 fixes GHSA-3wwx-pv8p-q78v. Update the shared dependency catalog and matching types used by Miniflare and Wrangler so downstream installs can resolve the patched runtime without an application-level override. A published release is still required for consumers; this changeset does not alter already published package metadata.

  • #15902 c2bb4c8 Thanks @​michealroberts! - Fix passing an R2ObjectBody#body back to R2Bucket#put() via Miniflare#getR2Bucket()

    Previously, a body returned by get() lost its length on the way back through the binding proxy, so put() rejected it with "Provided readable stream must have a known length", even though the same call works in a Worker. The proxy now forwards the stream's length and the body streams straight through without buffering.

  • #15906 eb1efe0 Thanks @​michealroberts! - Preserve the request body length in Miniflare#dispatchFetch()

    Previously, a request with a known-length body (e.g. a string) was sent to the Worker chunked, without a Content-Length. Passing its request.body to R2Bucket#put() then failed with "Provided readable stream must have a known length", even though the same request works in production. The body's length is now preserved.

  • #15910 485cfb3 Thanks @​james-elicx! - Raise the local R2 custom metadata limit to 8 KiB

    R2 put() now accepts up to 8,192 bytes of custom metadata, matching the documented R2 limit. Previously, Miniflare rejected metadata larger than 2 KiB.

    Multipart upload creation now enforces the same limit through both R2 bindings and the local S3 API. Oversized metadata is rejected with error 10012 through R2 bindings, or HTTP 400 MetadataTooLarge for S3 uploads, copies, and multipart initiation.

miniflare@5.20260926.0-alpha

Minor Changes

  • #15856 4c2993b Thanks @​Naapperas! - Support Workflows declared in exports on ctx.exports in local development

    A Workflow declared in a Worker's exports is now available on ctx.exports in wrangler dev, the Vite plugin and the Vitest plugin, with the same API as a Workflow binding:

    const instance = await ctx.exports.MyWorkflow.create({
      params: { name: "World" },
    });

    ctx.exports and workflows bindings with the same Workflow name share their instances, including instances created before the Workflow was declared in exports. Two Workers can't export the same Workflow name, and a binding to an exported Workflow must refer to the Worker and class that export it. getPlatformProxy() ignores Workflows declared in exports, since it doesn't run the Worker's code.

    wrangler workflows commands run with --local also work with Workflows declared only in exports, without a workflows binding.

    In the Vitest plugin, introspectWorkflow() and introspectWorkflowInstance() still need a Workflow binding, and now explain how to add one when passed a Workflow from ctx.exports. Instances created through ctx.exports are introspected too. A workflows binding whose script_name is the Worker's own name now resolves to the Worker itself again.

Patch Changes

  • #15891 8dc53ae Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

... (truncated)

Changelog

Sourced from miniflare's changelog.

5.20260926.1-alpha

Patch Changes

  • #15923 60ccdbd Thanks @​petebacondarwin! - Upgrade the bundled capnweb implementation to 0.12.0

    This updates the RPC implementation shipped in Miniflare and remote-binding proxy workers to the latest capnweb release.

  • #15938 62fd03a Thanks @​dieub! - Resolve the affected Undici dependency in new Wrangler and Vite plugin installs

    Undici 7.29.1 fixes GHSA-3wwx-pv8p-q78v. Update the shared dependency catalog and matching types used by Miniflare and Wrangler so downstream installs can resolve the patched runtime without an application-level override. A published release is still required for consumers; this changeset does not alter already published package metadata.

  • #15902 c2bb4c8 Thanks @​michealroberts! - Fix passing an R2ObjectBody#body back to R2Bucket#put() via Miniflare#getR2Bucket()

    Previously, a body returned by get() lost its length on the way back through the binding proxy, so put() rejected it with "Provided readable stream must have a known length", even though the same call works in a Worker. The proxy now forwards the stream's length and the body streams straight through without buffering.

  • #15906 eb1efe0 Thanks @​michealroberts! - Preserve the request body length in Miniflare#dispatchFetch()

    Previously, a request with a known-length body (e.g. a string) was sent to the Worker chunked, without a Content-Length. Passing its request.body to R2Bucket#put() then failed with "Provided readable stream must have a known length", even though the same request works in production. The body's length is now preserved.

  • #15910 485cfb3 Thanks @​james-elicx! - Raise the local R2 custom metadata limit to 8 KiB

    R2 put() now accepts up to 8,192 bytes of custom metadata, matching the documented R2 limit. Previously, Miniflare rejected metadata larger than 2 KiB.

    Multipart upload creation now enforces the same limit through both R2 bindings and the local S3 API. Oversized metadata is rejected with error 10012 through R2 bindings, or HTTP 400 MetadataTooLarge for S3 uploads, copies, and multipart initiation.

5.20260926.0-alpha

Minor Changes

  • #15856 4c2993b Thanks @​Naapperas! - Support Workflows declared in exports on ctx.exports in local development

    A Workflow declared in a Worker's exports is now available on ctx.exports in wrangler dev, the Vite plugin and the Vitest plugin, with the same API as a Workflow binding:

    const instance = await ctx.exports.MyWorkflow.create({
      params: { name: "World" },
    });

    ctx.exports and workflows bindings with the same Workflow name share their instances, including instances created before the Workflow was declared in exports. Two Workers can't export the same Workflow name, and a binding to an exported Workflow must refer to the Worker and class that export it. getPlatformProxy() ignores Workflows declared in exports, since it doesn't run the Worker's code.

    wrangler workflows commands run with --local also work with Workflows declared only in exports, without a workflows binding.

    In the Vitest plugin, introspectWorkflow() and introspectWorkflowInstance() still need a Workflow binding, and now explain how to add one when passed a Workflow from ctx.exports. Instances created through ctx.exports are introspected too. A workflows binding whose script_name is the Worker's own name now resolves to the Worker itself again.

Patch Changes

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [undici](https://github.com/nodejs/undici) to 8.11.2 and updates ancestor dependency [miniflare](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/miniflare). These dependencies need to be updated together.


Updates `undici` from 8.8.0 to 8.11.2
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v8.8.0...v8.11.2)

Updates `miniflare` from 4.20260714.0 to 5.20260926.1-alpha
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Changelog](https://github.com/cloudflare/workers-sdk/blob/main/packages/miniflare/CHANGELOG.md)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/miniflare@5.20260926.1-alpha/packages/miniflare)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 8.11.2
  dependency-type: indirect
- dependency-name: miniflare
  dependency-version: 5.20260926.1-alpha
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 29, 2026
@dependabot
dependabot Bot requested a review from kcsfelty as a code owner September 29, 2026 21:06
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 29, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants