Skip to content

build(deps): bump undici and miniflare - #44

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-b4ec3d8270
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-b4ec3d8270

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown

Bumps undici to 8.11.2 and updates ancestor dependency miniflare. These dependencies need to be updated together.

Updates undici from 8.8.0 to 8.11.2

Release notes

Sourced from undici's releases.

v8.11.2

What's Changed

New Contributors

Full Changelog: nodejs/undici@v8.11.1...v8.11.2

v8.11.1

What's Changed

Full Changelog: nodejs/undici@v8.11.0...v8.11.1

v8.11.0

What's Changed

... (truncated)

Commits

Updates miniflare from 4.20260714.0 to 5.20261001.0-alpha

Release notes

Sourced from miniflare's releases.

miniflare@5.20261001.0-alpha

Minor Changes

  • #15970 b00ef4f Thanks @​wperron! - Keep local development responsive while capturing observability data

    Local observability now records high volumes of spans and logs with less impact on the main Worker, making local requests faster and more responsive. If observability data arrives faster than it can be stored, completed entries are dropped rather than slowing the Worker; the buffer size can be tuned with X_LOCAL_OBSERVABILITY_BATCH_SIZE.

  • #15777 464a582 Thanks @​Naapperas! - Support the new Workflows createBatch() API in local development

    Local Workflows bindings now accept object-form batches that create instances from a count or a list of instance options. The result includes handles for created instances and indexed per-instance errors, matching the runtime API while preserving the deprecated array form.

Patch Changes

  • #15984 9d7b08e Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20260930.2 ^5.20261001.1
    workerd 1.20260930.2 1.20261001.1

miniflare@5.20260930.0-alpha

Minor Changes

  • #15685 b9f1cdc Thanks @​Ankcorn! - Add native support for the Analytics SQL binding

    Declare the zero-configuration binding in wrangler.json with "analytics": { "binding": "ANALYTICS" }. Wrangler uploads the analytics binding type and proxies it to the remote service during local development, so wrangler dev can call the binding without unsafe.bindings.

  • #15948 a0712e5 Thanks @​akoval-cf! - Add beta K2 producer bindings for existing streams

    Configure a stream created through Wrangler, the Dashboard, or the API in wrangler.json:

    {
      "k2": [
        {
          "binding": "ORDERS",
          "stream": "0123456789abcdef0123456789abcdef"
        }
      ]
    }

    The binding supports env.ORDERS.send([{ content: new TextEncoder().encode("order"), headers: { event: "order.created" } }]). Batches use either all ArrayBuffer or all Uint8Array content. Check the returned success value, handle rejected RPC promises, and retry only when the returned error explicitly allows it. Generated environment types describe this producer contract without requiring a separate application dependency.

    K2 requires an enabled account. Deployment credentials need Worker deployment and K2 configuration-read access. Default Wrangler logins now request the K2 OAuth scopes; existing OAuth users should run wrangler login again to grant the new permissions. Development always uses a real K2 stream and may incur usage charges; no local simulator is provided. The remote setting can be omitted, remote: true suppresses the usage warning, and remote: false is rejected. Consumption is not part of this Worker binding.

Patch Changes

... (truncated)

Changelog

Sourced from miniflare's changelog.

5.20261001.0-alpha

Minor Changes

  • #15970 b00ef4f Thanks @​wperron! - Keep local development responsive while capturing observability data

    Local observability now records high volumes of spans and logs with less impact on the main Worker, making local requests faster and more responsive. If observability data arrives faster than it can be stored, completed entries are dropped rather than slowing the Worker; the buffer size can be tuned with X_LOCAL_OBSERVABILITY_BATCH_SIZE.

  • #15777 464a582 Thanks @​Naapperas! - Support the new Workflows createBatch() API in local development

    Local Workflows bindings now accept object-form batches that create instances from a count or a list of instance options. The result includes handles for created instances and indexed per-instance errors, matching the runtime API while preserving the deprecated array form.

Patch Changes

  • #15984 9d7b08e Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20260930.2 ^5.20261001.1
    workerd 1.20260930.2 1.20261001.1

5.20260930.0-alpha

Minor Changes

  • #15685 b9f1cdc Thanks @​Ankcorn! - Add native support for the Analytics SQL binding

    Declare the zero-configuration binding in wrangler.json with "analytics": { "binding": "ANALYTICS" }. Wrangler uploads the analytics binding type and proxies it to the remote service during local development, so wrangler dev can call the binding without unsafe.bindings.

  • #15948 a0712e5 Thanks @​akoval-cf! - Add beta K2 producer bindings for existing streams

    Configure a stream created through Wrangler, the Dashboard, or the API in wrangler.json:

    {
      "k2": [
        {
          "binding": "ORDERS",
          "stream": "0123456789abcdef0123456789abcdef"
        }
      ]
    }

    The binding supports env.ORDERS.send([{ content: new TextEncoder().encode("order"), headers: { event: "order.created" } }]). Batches use either all ArrayBuffer or all Uint8Array content. Check the returned success value, handle rejected RPC promises, and retry only when the returned error explicitly allows it. Generated environment types describe this producer contract without requiring a separate application dependency.

    K2 requires an enabled account. Deployment credentials need Worker deployment and K2 configuration-read access. Default Wrangler logins now request the K2 OAuth scopes; existing OAuth users should run wrangler login again to grant the new permissions. Development always uses a real K2 stream and may incur usage charges; no local simulator is provided. The remote setting can be omitted, remote: true suppresses the usage warning, and remote: false is rejected. Consumption is not part of this Worker binding.

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [undici](https://github.com/nodejs/undici) to 8.11.2 and updates ancestor dependency [miniflare](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/miniflare). These dependencies need to be updated together.


Updates `undici` from 8.8.0 to 8.11.2
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v8.8.0...v8.11.2)

Updates `miniflare` from 4.20260714.0 to 5.20261001.0-alpha
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Changelog](https://github.com/cloudflare/workers-sdk/blob/main/packages/miniflare/CHANGELOG.md)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/miniflare@5.20261001.0-alpha/packages/miniflare)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 8.11.2
  dependency-type: indirect
- dependency-name: miniflare
  dependency-version: 5.20261001.0-alpha
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 3, 2026
@dependabot
dependabot Bot requested a review from kcsfelty as a code owner October 3, 2026 05:25

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants