Skip to content

chore(deps): update dependency wrangler to v4.144.0 - #68

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/wrangler-4.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/wrangler-4.x

Conversation

@renovate

@renovate renovate Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
wrangler (source) 4.136.3 → 4.144.0 age confidence

Release Notes

cloudflare/workers-sdk (wrangler)

v4.144.0

Compare Source

Minor Changes
  • #​15919 91a3606 Thanks @​flakey5! - Add --tty (-t) flag to wrangler containers ssh to force pseudo-terminal allocation

    OpenSSH only allocates a pseudo-terminal when no remote command is given, so interactive commands such as wrangler containers ssh <ID> -- bash previously ran without a prompt or line editing. Pass --tty to force one:

    wrangler containers ssh <ID> --tty -- bash

  • #​15951 2a15ae2 Thanks @​flakey5! - Support SSH settings for Durable Object-managed Containers in the configuration API

    defineContainer now accepts ssh and authorizedKeys with schedulingPolicy: "durable-object", matching the ssh and authorized_keys fields that Wrangler already supports for these Containers. Previously the schema rejected them, so they could not be set from cloudflare.config.ts.

    defineContainer({
      name: "sandbox",
      schedulingPolicy: "durable-object",
      ssh: { enabled: true },
      authorizedKeys: [{ name: "laptop", publicKey: "ssh-ed25519 AAAA..." }],
    });
Patch Changes

v4.143.1

Compare Source

Patch Changes
  • #​15159 7bb6eae Thanks @​veggiedefender! - Fix wrangler dev remote bindings for workers.dev subdomains protected by Access

    Running wrangler dev with remote bindings on an unpublished worker protected by Access (e.g. using a wildcard on your workers.dev domain) previously failed with a redirect loop. Wrangler now correctly authenticates remote bindings with Access in this situation.

  • #​15923 60ccdbd Thanks @​petebacondarwin! - Upgrade the bundled capnweb implementation to 0.12.0

    This updates the RPC implementation shipped in Miniflare and remote-binding proxy workers to the latest capnweb release.

  • #​15938 62fd03a Thanks @​dieub! - Resolve the affected Undici dependency in new Wrangler and Vite plugin installs

    Undici 7.29.1 fixes GHSA-3wwx-pv8p-q78v. Update the shared dependency catalog and matching types used by Miniflare and Wrangler so downstream installs can resolve the patched runtime without an application-level override. A published release is still required for consumers; this changeset does not alter already published package metadata.

  • #​15903 06ed9c8 Thanks @​itsmunzir! - Fix custom-domain-only deploys failing for API tokens without Zone Workers Routes read permission

    When workers_dev was disabled and routes contained only entries with custom_domain: true, every deploy after the first one fetched /zones/:zoneId/workers/routes to check for route conflicts, even though custom domains are not zone Workers Routes. Tokens scoped to Workers Scripts edit plus custom domains - without Zone > Workers Routes > Read - failed with "No access to the specified resource" after the Worker version had already been uploaded. The conflict check now only covers non-custom-domain routes; custom domain conflicts continue to be reported by the custom domains changeset API.

  • #​15887 86211fe Thanks @​alepacheco! - Report an unreachable auth server instead of an expired login when refreshing an OAuth token

    When the OAuth token endpoint could not be reached (for example a DNS failure or a connection timeout), the refresh failure was reported as "Your auth token has expired and could not be refreshed", with advice to run wrangler login; in an interactive terminal Wrangler also started a new browser login. A network failure says nothing about the stored refresh token, and a new login would need the same unreachable server. Wrangler now reports that the Cloudflare auth server could not be reached, leaves the stored credentials unchanged, and does not start a login, so the next run can refresh with the same token once the network is back.

  • Updated dependencies [60ccdbd, 62fd03a, c2bb4c8, eb1efe0, 485cfb3]:

v4.143.0

Compare Source

Minor Changes
  • #​15914 7f0734c Thanks @​jamesopstad! - Use cf/config for cloudflare.config.ts authoring

    Experimental cloudflare.config.ts projects must now import defineConfig, bindings, triggers, and related helpers from cf/config. Generated declarations from Wrangler and the Vite plugin also reference this package, so projects using the experimental configuration flow must add cf as a dependency.

    The Vite plugin no longer exports @cloudflare/vite-plugin/experimental-config. wrangler/experimental-config remains available for defineWranglerConfig, but no longer re-exports Cloudflare configuration helpers.

v4.142.0

Compare Source

Minor Changes
  • #​15856 4c2993b Thanks @​Naapperas! - Support Workflows declared in exports on ctx.exports in local development

    A Workflow declared in a Worker's exports is now available on ctx.exports in wrangler dev, the Vite plugin and the Vitest plugin, with the same API as a Workflow binding:

    const instance = await ctx.exports.MyWorkflow.create({
      params: { name: "World" },
    });

    ctx.exports and workflows bindings with the same Workflow name share their instances, including instances created before the Workflow was declared in exports. Two Workers can't export the same Workflow name, and a binding to an exported Workflow must refer to the Worker and class that export it. getPlatformProxy() ignores Workflows declared in exports, since it doesn't run the Worker's code.

    wrangler workflows commands run with --local also work with Workflows declared only in exports, without a workflows binding.

    In the Vitest plugin, introspectWorkflow() and introspectWorkflowInstance() still need a Workflow binding, and now explain how to add one when passed a Workflow from ctx.exports. Instances created through ctx.exports are introspected too. A workflows binding whose script_name is the Worker's own name now resolves to the Worker itself again.

Patch Changes

v4.141.0

Compare Source

Minor Changes
  • #​15658 8280086 Thanks @​jqmmes! - Add Durable Objects code update strategies to Worker deployments

    Use --durable-objects-code-update-mode immediate with wrangler deploy, wrangler versions deploy, and wrangler rollback to update code without waiting for active instances to hibernate. Use --durable-objects-code-update-mode deferred 30s to set a maximum delay, or configure durable_objects.code_update_strategy with mode and max_delay. When unset, the strategy defaults to deferred with a 5-minute maximum delay; delays cannot exceed 24 hours and must use millisecond precision.

  • #​15800 bd56b98 Thanks @​Refaerds! - Add Browser Run as an event source for Queue subscriptions

    You can now create Queue subscriptions with --source browserRun.

Patch Changes

v4.140.0

Compare Source

Minor Changes
Patch Changes

v4.139.0

Compare Source

Minor Changes
  • #​15792 479e1e8 Thanks @​flakey5! - Configure SSH for experimental Durable Object-managed Containers

    Set containers[].ssh and containers[].authorized_keys when using scheduling_policy: "durable_object". These are application-wide settings that follow the same rules as the existing Durable Object-managed Container settings: normal deployments create missing applications and update explicitly configured values, while omitted settings preserve the existing application configuration.

    // wrangler.jsonc
    {
      "containers": [
        {
          "name": "sandbox",
          "class_name": "Sandbox",
          "scheduling_policy": "durable_object",
          "ssh": { "enabled": true },
          "authorized_keys": [
            { "name": "laptop", "public_key": "ssh-ed25519 AAAA..." }
          ]
        }
      ]
    }
  • #​15648 52c0e9f Thanks @​tpmmorris! - Expose configured Cron Triggers to local development consumers

    Wrangler now passes the active environment's exact Cron Trigger expressions to Miniflare so Local Explorer can display them. Headless agent sessions also advertise the Local Explorer scheduled invocation API.

  • #​15786 bdda4c3 Thanks @​ThomasRubini! - Support UDP connect handlers in local development

    The experimental connect configuration now accepts protocol: "udp", with optional idle_timeout_ms and max_pending_bytes settings. UDP datagrams are delivered to the Worker's connect() handler using workerd's value-mode socket streams, and can be tested with Miniflare#dispatchConnect({ protocol: "udp" }).

  • #​15779 fc3cbaa Thanks @​Naapperas! - Support workflow entries in the exports configuration map

    A Worker can now declare the Workflows it defines in exports, keyed by the WorkflowEntrypoint class name:

    {
      "exports": {
        "MyWorkflow": {
          "type": "workflow",
          "name": "my-workflow",
          "limits": { "steps": 100 },
          "schedules": "0 * * * *"
        }
      }
    }

    A workflow export accepts the same settings as a workflows binding: limits, concurrency, schedules, and default_retention. wrangler deploy and wrangler versions upload send these entries to the upload API by name, and wrangler deploy and wrangler triggers deploy provision the Workflow with its settings, just as they do for workflows bindings owned by the Worker. A Workflow may be declared both as a binding and as an export, as long as both declarations use the same class and do not set the same setting to different values. A binding to another Worker's Workflow cannot share a name with an export. @cloudflare/config adds the matching exports.workflow() helper. Local development does not yet act on these entries.

Patch Changes
  • #​15796 be72815 Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20260921.1 ^5.20260923.1
    workerd 1.20260921.1 1.20260923.1
  • #​14847 940c692 Thanks @​TheSaiEaranti! - Emulate the deterministic-ID uniqueness contract in the local Workflows binding

    The local Workflows binding now matches the documented production behavior for deterministic instance IDs: create({ id }) with an ID that already exists throws (instance.already_exists) and retains the existing instance, and createBatch() skips IDs that already exist or repeat within the batch, excluding them from the result instead of creating duplicate executions. Previously both paths silently created duplicates, so code relying on deterministic IDs for idempotency (for example a Queue consumer creating one workflow per message) appeared to work locally while double-executing workflow bodies.

  • #​15803 cd60c9c Thanks @​pmiguel! - Show --jurisdiction in help for wrangler kv namespace create

    The option was supported but omitted from the command's help output. Users can now discover how to create KV namespaces in a specific jurisdiction.

  • #​15838 15799d4 Thanks @​oddharsh! - Update smol-toml to 1.9.0 to fix slow parsing of very large TOML files

    Parse time for TOML config files now grows linearly with their size, instead of with its square: a 40,000-line file that took 259 ms to parse now takes 17 ms, while typical wrangler.toml files parse in the same time as before. This addresses the GHSA-r4xh-jqrq-34v2 advisory against earlier versions of the parser.

    Some TOML syntax errors now point at the character that caused them. For example, a wrangler.toml containing INVALID "FILE is now reported as illegal character in key at the ", rather than incomplete key-value at the start of the line.

  • Updated dependencies [52c0e9f, 44f5295, be72815, 940c692, bdda4c3, fc3cbaa]:

v4.138.0

Compare Source

Minor Changes
  • #​15776 b03f960 Thanks @​edevil! - Add event-code support to temporary Worker deployments

    Use wrangler deploy --temporary --event-code <code> to provision an account for an event. Wrangler requires explicit server acknowledgement before caching the account and keeps the event code out of its cache and telemetry.

  • #​15817 6e77c53 Thanks @​jamesopstad! - Allow framework commands to produce Preview Build Output with the experimental config

    When cf previews deploy invokes a framework build command, Preview intent is now preserved. Function-based cloudflare.config.ts files receive isPreview: true, and generated Build Output is marked as a Preview build.

Patch Changes

v4.137.0

Compare Source

Minor Changes
  • #​15778 cd7508c Thanks @​jamesopstad! - Generate types during development and supported builds with Vite's experimental.newConfig option or Wrangler's --experimental-new-config flag (and --experimental-cf-build-output for builds)

    When Wrangler's --experimental-new-config flag or Vite's experimental.newConfig option is enabled, inferred configuration and runtime declarations are now kept in .cloudflare/types/index.d.ts. Vite refreshes them during development and production builds. Wrangler refreshes them during development and when building with both --experimental-new-config and --experimental-cf-build-output. In the experimental wrangler.config.ts format, the types option is now top-level because it applies to both commands.

Patch Changes
  • #​15765 1bdb96d Thanks @​th0m! - Prepare the required egress sidecar for local Containers without configured images

    Wrangler dev and Vite dev/preview now pull the required sidecar for Durable Object-managed Containers that select their application image at start time. Previously, these Containers failed to start unless the sidecar image was already cached in Docker.

  • #​15712 f5605f5 Thanks @​alsuren! - Match D1 SQL statement splitting to the local SQLite runtime

    Wrangler now uses SQLite's statement-completion state machine when splitting D1 SQL files. This keeps trigger, quoted identifier, comment, and keyword handling consistent with local execution.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from b232596 to 93f212c Compare September 24, 2026 22:32
@renovate renovate Bot changed the title chore(deps): update dependency wrangler to v4.137.0 chore(deps): update dependency wrangler to v4.139.0 Sep 24, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from 93f212c to fdd76c6 Compare September 25, 2026 10:46
@renovate renovate Bot changed the title chore(deps): update dependency wrangler to v4.139.0 chore(deps): update dependency wrangler to v4.140.0 Sep 25, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from fdd76c6 to 40d9a18 Compare September 25, 2026 20:44
@renovate renovate Bot changed the title chore(deps): update dependency wrangler to v4.140.0 chore(deps): update dependency wrangler to v4.141.0 Sep 25, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from 40d9a18 to 97e600e Compare September 27, 2026 15:10
@renovate renovate Bot changed the title chore(deps): update dependency wrangler to v4.141.0 chore(deps): update dependency wrangler to v4.142.0 Sep 27, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from 97e600e to 1ef5120 Compare September 28, 2026 20:09
@renovate renovate Bot changed the title chore(deps): update dependency wrangler to v4.142.0 chore(deps): update dependency wrangler to v4.143.0 Sep 28, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from 1ef5120 to f137927 Compare September 29, 2026 19:15
@renovate renovate Bot changed the title chore(deps): update dependency wrangler to v4.143.0 chore(deps): update dependency wrangler to v4.143.1 Sep 29, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from f137927 to 3b0cd9a Compare September 30, 2026 00:20
@renovate renovate Bot changed the title chore(deps): update dependency wrangler to v4.143.1 chore(deps): update dependency wrangler to v4.144.0 Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant