chore(deps): update external dev fixes - #317
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Contributor
Author
|
renovate
Bot
force-pushed
the
renovate-external-dev-fixes
branch
5 times, most recently
from
September 8, 2026 09:29
682c314 to
7b78bc6
Compare
renovate
Bot
force-pushed
the
renovate-external-dev-fixes
branch
7 times, most recently
from
September 15, 2026 21:35
fda43e6 to
030c7ef
Compare
renovate
Bot
force-pushed
the
renovate-external-dev-fixes
branch
5 times, most recently
from
September 19, 2026 07:39
3d1f8a9 to
01636b2
Compare
renovate
Bot
force-pushed
the
renovate-external-dev-fixes
branch
from
September 21, 2026 23:07
01636b2 to
3288084
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.44.1→2.51.25.2.3→5.4.117.3.0→17.5.04.119.0→4.129.1Release Notes
Redocly/redocly-cli (@redocly/cli)
v2.51.2Compare Source
Patch Changes
fast-urito the3.1.7version to resolveCVE-2026-75931,CVE-2026-75975,CVE-2026-75899, andCVE-2026-76172.driftandcoveragefailing to match a path template whose segment mixes literal text with parameters, such as/instances/{worldId}:{instanceId}.v2.51.1Compare Source
Patch Changes
generate-arazzoproduced a malformed remote description URL insourceDescriptions(https://collapsed tohttps:/) when--output-filewas provided.$faker.string.email()used without options generated addresses at theundefined.comdomain.@faker-js/fakerto the10.6.0version to resolve the high severity advisoryGHSA-qxc2-j82w-r537.v2.51.0Compare Source
Minor Changes
generate-arazzocommand to print a ready-to-runrespectcommand after generation, including an--inputplaceholder for every workflow input.--with-ai,--ai-provider,--ai-model,--ai-concurrency, and--max-workflowsoptions to thegenerate-arazzocommand.--with-aiuses a local AI CLI (claude,codex, orcursor) and OpenAPI descriptions to redesign the generated one-workflow-per-operation skeleton into multi-step workflows.The AI designs at most
--max-workflowsworkflows (default 10), and the generated file is marked as AI-inferred.For descriptions that don't fit a single prompt, the AI first selects scenarios from a compact operation index, then it designs each workflow separately.
Patch Changes
respectand thex-security-scheme-required-valuesrule incorrectly rejectedx-securityHTTP schemes written with non-lowercase casing (such asBasic,Bearer, orDigest).RFC 7235 scheme names are case-insensitive.
v2.50.0Compare Source
Minor Changes
schemaassertion for configurable rules.The assertion validates a property value against a JSON Schema.
Patch Changes
v2.49.1Compare Source
Patch Changes
$refs pointed to the same path item.v2.49.0Compare Source
Minor Changes
Added the
no-illogical-composition-keywordsrule.Note: the rule is set to
warnin therecommendedruleset and toerrorinrecommended-strict. Existing API descriptions may report new problems.Patch Changes
npmwas not available.v2.48.0Compare Source
Minor Changes
python,go,php, andcligenerators beside the TypeScript client, each self-documenting with--docs, configurable per generator, and available as source in your own repository througheject-generator.Patch Changes
bundlecommand didn't resolve$refs inside an AsyncAPI 3 Multi Format Schema Object.respect --har-outputrecorded an emptypostDatafor every request.Request bodies are written to the HAR.
Captures replayed through
driftcan have their request bodies validated instead of silently passing.v2.47.0Compare Source
Minor Changes
statscommand that reports how many distinctx-extensions a description file uses and how often each one occurs.Patch Changes
statscommand reporting wrong parameter count for AsyncAPI descriptions.v2.46.2Compare Source
Patch Changes
v2.46.1Compare Source
Patch Changes
@redocly/ajvto^8.18.3.v2.46.0Compare Source
Minor Changes
spec-ref-siblingsrule that reports properties placed next to a$refwhich the specification does not allow.Patch Changes
v2.45.0Compare Source
Minor Changes
bundlecommand losing schema keywords (such astitle,properties, orrequired) written next to a$refwhen the referenced schemas started with their own$ref.Patch Changes
v2.44.2Compare Source
Patch Changes
security-definedrule for AsyncAPI 2.x and 3.x in therecommendedruleset fromerrortowarn.AsyncAPI descriptions with undefined or unresolved security no longer fail linting by default.
nodeca/js-yaml (js-yaml)
v5.4.1Compare Source
v5.4.0Compare Source
Added
scalarStyleRulesdumper option to customize string formatting.See Scalar styling for details.
Changed
and collection nodes now use
SCALAR_STYLEandCOLLECTION_STYLEvalues;explicit tags use the separate
taggedproperty. Alias nodes now containonly
kindandanchor. This only affects code that directly constructs oredits AST nodes.
sortKeysoption was rewritten using AST mutation to avoidside effects.
loaded values; in particular, whitespace-only strings are now double-quoted.
Fixed
quoteFlowKeysandflowSkipColonSpace,including alias and property-only keys, #786.
1024-character simple-key limit.
needed to preserve trailing newlines.
v5.3.0Compare Source
This release focuses on reworking the documentation and making small
architectural improvements before moving forward.
Added
DUMP_SCHEMA, the default schema used by the dumper.YAMLException.throwAt()for throwing an error at a source position.Changed
EVENT_ID,SCALAR_STYLE,COLLECTION_STYLE, andCHOMPING_MODE, along with their value types. The oldexports are still preserved, but deprecated.
identifymandatory for custom tag definitions. Useidentify: () => falsefor load-only tags.Deprecated
Removed
MERGE_KEYexport (not used anymore after last fixes).Fixed
<<sequence items at merge time, so aliased merge sources arechecked too.
<<outside of a mapping key as the plain string'<<', matchingv4, instead of leaking an internal symbol into the result.
lint-staged/lint-staged (lint-staged)
v17.5.0Compare Source
Minor Changes
f9063b7- Lint-staged now refuses to run when files were staged with--intent-to-add, because Git stash doesn't support them. Previously this was an unhandled error.Patch Changes
#1848
d718ccc- Lint-staged now handles color support better in non-TTY streams, and honors theFORCE_COLORenvironment variable.#1845
7e5ece8- Updatetinyexec@1.3.1so that local binaries fromnode_modules/.binare resolved starting from the directory of each lint-staged configuration file (in monorepo setups). This behavior was broken inlint-staged@16.3.0where they were only resolved from the current working directory and up.#1845
eb8a4e3- Do not try to restore untracked files when using--hide-alland there is no initial commit yet.v17.4.1Compare Source
Patch Changes
efe5b63- This is a version-bump-only release because the previous version17.4.0was not published to npmjs.com due to problems with GitHub Actions and Changesets.cloudflare/workers-sdk (wrangler)
v4.129.1Compare Source
Patch Changes
#15502
8bbcb9fThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15543
2b42d6fThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15323
ea5634eThanks @Sakshamm-Goyal! - Prevent Wrangler from exiting when a process capturing its output closes the pipe.Wrangler now ignores broken-pipe errors from stdout and stderr while preserving the existing failure behavior for other output errors.
#14001
c0c6504Thanks @for-the-kidz! - Update bundle size warning thresholds to use uncompressed size instead of gzip sizeThe compressed script size limits (3 MiB free / 10 MiB paid) have been removed server-side in favor of a single 64 MiB uncompressed limit. The bundle size reporter now compares the uncompressed bundle size against this 64 MiB limit for its color-coded warnings, instead of comparing gzip size against the old 3 MiB compressed limit.
#15499
ffc7efdThanks @WillTaylorDev! - Honor Workers Builds name overrides inwrangler previewPreview commands now target the Worker name supplied by Workers Builds instead of the name in local Wrangler configuration. This prevents preview builds from failing when the two names differ.
#15252
682cd44Thanks @GregoryCollett! -wrangler devno longer exits when a request to your Worker fails transientlyPreviously, a transient network failure on a single request — most commonly a request arriving just as an idle internal connection was closed, after roughly five seconds without traffic — could take down the whole dev server with an empty
✘ [ERROR], leaving the port unbound until restarted. In CI test suites, one such failure caused every remaining test to fail with connection errors.wrangler devnow automatically retries the affected request if it is safe to repeat (GET and HEAD requests). If a request still fails, it fails individually — the error is logged with the request method and URL — and the dev server keeps serving.Updated dependencies [
8bbcb9f,2b42d6f]:v4.129.0Compare Source
Minor Changes
#15460
93d72a5Thanks @QnJ1c2kNCg! - Support gzip compression for JSON Pipelines sinksPipelines is in open beta.
wrangler pipelines sinks createand the interactive setup flow now pass the selected JSON compression to the Pipelines API. JSON sinks acceptuncompressedorgzip, while Parquet retains its existing compression options andzstddefault.#15358
d2d8eeaThanks @pombosilva! - Add a--jsonflag to thewrangler workflowscommandsEvery
wrangler workflowscommand now accepts--json, which emits the raw API payload instead of the human-readable rendering. The formatted output remains the default, so existing usage is unaffected:wrangler workflows instances list my-workflow --jsonThe JSON output carries raw values rather than a serialisation of the formatted view: ISO timestamps instead of locale-formatted dates, plain status strings instead of emojified labels, and no presentation-only derived fields.
Patch Changes
#15469
d40a634Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15481
7c1b2a6Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15472
f6fb347Thanks @emily-shen! - Tolerate missing permissions duringwrangler deletecleanup checkswrangler deletenow warns and continues when it cannot inspect Worker dependencies or clean up legacy Workers Sites KV namespaces because of missing permissions. The Worker delete request itself still fails normally if the token cannot delete the Worker.#15472
f6fb347Thanks @emily-shen! - Tolerate missing resource permissions during resource provisioningWhen Wrangler cannot check whether a bound resource exists because the API returns a 403, it now skips automatic provisioning for that resource type and continues the deploy. The deploy may still fail later if the resource is missing.
#15476
dc24057Thanks @christhorwarth! - Fix remote development with static assets for API tokens using granular Worker permissionsWrangler now creates Workers.dev preview sessions through the Worker-scoped endpoint and derives the preview hostname from the session response. This avoids requiring account-level Workers subdomain access.
Updated dependencies [
00a9f2f,1dba24a,d40a634,7c1b2a6]:v4.128.0Compare Source
Minor Changes
#15454
dbbb795Thanks @jamesopstad! - Move binding utilities into@cloudflare/workers-utilsBinding conversion, printing, and local-development validation are now exported from
@cloudflare/workers-utilsso they can be shared by Wrangler, the Cloudflare Vite plugin, and other consumers.The corresponding exports have been removed from
@cloudflare/deploy-helpers. Consumers should import them directly from@cloudflare/workers-utilsinstead.Wrangler's
unstable_printBindingsAPI now accepts the bindings and an options object instead of five positional parameters.#15353
87a7acfThanks @pombosilva! - Add--date-startand--date-endfilters towrangler workflows instances listYou can now narrow an instance listing to a creation-time window:
wrangler workflows instances list my-workflow --date-start 2026-01-01 --date-end 2026-01-31Either flag can be used independently. Both accept an ISO 8601 date or timestamp and are normalised to UTC before being sent, so a date-only value such as
2026-01-01works as well as a full2026-01-01T13:00:00Z. The bounds are inclusive and compose with the existing--statusfilter.#15379
ea28cc3Thanks @ibbykhazanchi! - Add query string redaction to Workers observability configurationSet
observability.redact_query_stringinwrangler.jsonorobservability.redactQueryStringin the experimentalcloudflare.config.tsformat to remove query strings from request URLs in logs and traces.#14915
707cb6fThanks @longlho! - Include exact raw and gzip-compressed Worker bundle sizes in structureddeployandversion-uploadoutput.Patch Changes
#15436
200780fThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15406
b3f2628Thanks @james-elicx! - Reduce the installed bundle sizes of Wrangler and MiniflareWrangler now resolves bundled workspace dependencies from source during monorepo builds so unused exports can be removed. Miniflare, its shared CLI and container dependencies now use granular
@cloudflare/workers-utilsentry points instead of loading the package barrel, reducing the raw Wrangler and Miniflare artifacts by 6.16 MiB (31.4%) and 1.06 MiB (22.9%) respectively without changing runtime behavior or installed dependencies.#15398
1809c5eThanks @james-elicx! - Reduce Wrangler's published package sizeStop including the unused build metafile in the npm package, reducing its unpacked size by approximately 3.1 MiB.
#15382
b3fb2bfThanks @Om-singhaI! - Skip the skills install status lookup when telemetry is disabledTelemetry events include a
currentAgentSkillsInstalledproperty, and computing it can query the GitHub API. The lookup used to start before the telemetry permission was checked, so users who opted out viaWRANGLER_SEND_METRICS,DO_NOT_TRACK, orsend_metricsin their Wrangler config still triggered network requests on behalf of telemetry. The dispatcher now checks the permission first and only performs the lookup when telemetry is enabled.Updated dependencies [
200780f,b3f2628,87a7acf]:v4.127.1Compare Source
Patch Changes
#15383
eb01850Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15393
e1df91aThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
Updated dependencies [
eb01850,e1df91a,b23de74,015550a,015550a,015550a,3650d29,b23de74]:v4.127.0Compare Source
Minor Changes
#15356
fe265f8Thanks @rubuy-74! - Add support for configuring a per-workflow max concurrency limit viaworkflows[].concurrency.limitin your Wrangler config.The limit is the maximum number of Workflow instances that can run concurrently. It is validated as a positive integer and persisted on deploy; the ceiling is enforced server-side. Concurrency is ignored in local development.
{ "workflows": [ { "binding": "MY_WORKFLOW", "name": "my-workflow", "class_name": "MyWorkflow", "concurrency": { "limit": 10 } } ] }Patch Changes
#15367
412c79eThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15375
92874f6Thanks @WillTaylorDev! - Uploadwrangler previewmodules as multipart form datawrangler previewused to base64 the bundle, its modules, and any sourcemaps into a single JSON request body. Base64 inflates content by a third, so a Worker with a large sourcemap could exceed the API request size limit and fail to deploy.The preview deployment request is now
multipart/form-data. The deployment settings travel in ametadatapart and each module follows as its own part carrying raw bytes, matching howwrangler deployalready uploads a Worker.Updated dependencies [
412c79e]:v4.126.0Compare Source
Minor Changes
#15332
d1cc3afThanks @pombosilva! - Adddefault_retentionto Workflow bindings for configuring how long instances are retainedWorkflow instances are retained for an account-wide default period after they finish. You can now set a per-Workflow default in your Wrangler configuration, applied to instances that do not specify their own retention:
{ "workflows": [ { "binding": "MY_WORKFLOW", "name": "my-workflow", "class_name": "MyWorkflow", "default_retention": { "success_retention": "3 days", "error_retention": "7 days" } } ] }Each side is optional and accepts either a duration string such as
"3 days"or a whole number of milliseconds. Durations are interpreted by the Workflows API, which also caps them at your account's retention limit.#15064
693ca29Thanks @tpmmorris! - Include a chronological list of handler events in email test harness results, so programmatic local email tests can assert the order in which messages are received, forwarded, replied to, or rejected.#15065
ad89456Thanks @mtlemilio! - Add experimentalwrangler hyperdrive planetscale signaturefor provisioning Cloudflare-billed PlanetScale databaseswrangler hyperdrive planetscale signatureprints a signed authorization as JSON, proving to PlanetScale that Cloudflare will be billed for the database you are about to create:pscale database createdefaults to Vitess, so pass--engine postgresqlfor a Postgres database, and--format jsonis recommended when the output is consumed by an agent.This requires
pscalev0.313.0 or newer. Wrangler authorizes the Cloudflare billing side only, so your PlanetScale credentials stay between you andpscale.The signature is a cryptographically signed token that authorizes creating a database billed to your Cloudflare account. Treat it as a credential and do not share it. Piping it, as above, is recommended over passing it as a command line argument.
This command is experimental and its interface may change.
#15134
c66d2d5Thanks @gpanders! - Enable FUSE-capable local container developmentMiniflare now automatically passes the Docker privileges needed for FUSE to local Durable Object containers when using local rootless Docker on Linux with
/dev/fuseavailable, or a local Docker engine on macOS or through WSL where Linux containers run in a VM. This applies to Wrangler, the Cloudflare Vite plugin, and direct Miniflare use.#15326
9fcb1c9Thanks @jamesopstad! - Record the selected mode in the Build Output Specification top-levelconfig.jsonThe mode a build was produced in is now written to
.cloudflare/output/v0/config.jsonas amodefield, alongside the account and compliance settings.#14966
a4c3458Thanks @yomna-shousha! - Add pull request metadata towrangler previewdeploymentswrangler previewnow detects the pull request associated with the current CI run (GitHub Actions, GitLab CI, CircleCI, and a genericPULL_REQUEST_URL/PR_URL/CHANGE_URLfallback) and attaches it, along with the repository URL, to the preview deployment as annotations (workers/pull_request_number,workers/pull_request_url,workers/repository_url).This is best effort: if no pull request can be detected, nothing changes. When a pull request is detected, its URL is now also shown in the
wrangler previewcommand output.#15307
433fa98Thanks @for-the-kidz! - Add pull request title towrangler previewdeployment annotationswrangler previewnow also detects the title of the pull/merge request associated with the current CI run (GitHub Actions and GitLab CI, plus a genericPULL_REQUEST_TITLEfallback) and attaches it to the preview deployment as theworkers/pull_request_titleannotation, alongside the existing pull request number/URL, repository URL, and commit SHA annotations.This is best effort: if no pull request title can be detected, nothing changes.
Patch Changes
#15294
4a67a28Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15328
2d78137Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15346
04e8564Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15246
daefb3cThanks @edmundhung! - Prepare autoconfig for multiple configuration targetsAdd target-specific configuration output and command detection while preserving Wrangler's existing setup and deployment behavior.
#15320
c809851Thanks @Om-singhaI! - Fixwrangler login --use-keyringincorrectly reporting thatsecret-toolis missing on LinuxLibsecret's
secret-tooldoes not support--version; it prints usage and exits 2, which Wrangler previously interpreted as unavailable. Wrangler now reports it missing only when launching the executable fails.#15336
22182daThanks @podonnell-dev! -[private beta]: Explain unavailable Preview URLs afterwrangler previewdeploymentsWhen a Preview deployment has no active URLs, Wrangler now explains how to enable Preview Deployments on workers.dev or a custom domain.
#15296
d589d30Thanks @MattieTK! - Stop automatically offering to install Cloudflare skills for new usersWrangler will no longer prompt new users to install Cloudflare skills after commands complete. It will continue to offer updates to skills that Wrangler previously installed.
Updated dependencies [
aa54b49,4a67a28,2d78137,04e8564,693ca29,693ca29,693ca29,37ed753,f76b68e,c66d2d5,693ca29,74de3ab,0cb8690,dd5148d,82d11fc]:v4.125.0Compare Source
Minor Changes
#14995
59872c4Thanks @ThomasRubini! - Addconnecttrigger for raw socketsYou can now configure a Worker to receive raw socket connections during
wrangler dev, delivered directly to the Worker'sconnect(socket, env, ctx)handler:{ "connect": [{ "protocol": "tcp", "port": 5432 }] }Each entry opens a listening socket on
127.0.0.1(or the givenaddress) that forwards incoming connections straight to the Worker, bypassing the local dev HTTP entry point. This requires theexperimentalcompatibility flag. Only"tcp"is supported at the moment.@cloudflare/configalso supports declaring this trigger viatriggers.connect(...), which lowers to theconnectfield above:#15172
c68f9cbThanks @WillTaylorDev! - Add container support to worker previewsWorker previews now support containers through a new
previews.containersconfiguration block. Container configuration doesn't inherit, so declare containers explicitly in thepreviewsblock to enable them for previews. This mirrors howpreviews.durable_objectsworks today. Wrangler names each preview container application{worker_name}_{preview_slug}_{class_name}, normalising and shortening the result to what the API accepts. Either change appends a short digest of the composed name, so two names that would otherwise land on one stay distinct. An entry cannot set its ownname, because application names are unique to an account and a fixed name would collide between two previews of the same Worker. A Durable Object class is backed by at most one container application, so the validator rejects two entries that share aclass_name. Wrangler skips container applications bound to Durable Object classes that another Worker implements throughscript_name, because the implementing Worker owns its own container application. A binding is not required: a Durable Object declared throughmigrationsorexportsand reached only overctx.exportscan still back a container. Every entry must setclass_name. Apreviews.containersentry whoseclass_namematches no Durable Object class at all is rejected before the preview deployment is created, so a typo fails loudly instead of producing a preview with no container.Wrangler creates the container applications on
wrangler preview. Deleting a preview tears them down server side, sowrangler preview deletedoesn't remove them.Container build and deploy progress prints to stdout.
wrangler preview --jsonsuppresses wrangler's own output so it doesn't interleave with the payload, and warnings and errors still go to stderr. Docker's build output and the progress spinner write to stdout directly and bypass that suppression, so parse--jsonfrom a non interactive shell, where the spinner is skipped, and prefer a prebuiltimageover a Dockerfile.#15174
649f667Thanks @WillTaylorDev! - [private beta]: Create the parent Worker automatically whenwrangler previewtargets one that doesn't exist yetPreviews hang off a parent Worker, so running
wrangler previewbefore the Worker had ever been deployed failed with a raw API error naming the Preview endpoint. Wrangler now offers to create an empty parent Worker and then carries on creating the Preview. The parent uses the same workers.dev and Preview URL settings thatwrangler deploywould resolve, without applying routes or cron triggers. In non-interactive environments, Wrangler creates the Worker without asking.#14735
30c2d47Thanks @vaishnav-mk! - Add individual and batch Workflow instance deletion to the runtime and SDK.WorkflowInstance.delete()deletes one instance. Self-deletion stops the current execution.env.MY_WORKFLOW.deleteBatch(instanceIds)deletes up to 100 instances and returns{ deleted, errors }per input position.wrangler workflows instances delete <name> [id..]deletes instances remotely or with--local; IDs can also come from a JSON array passed with--filename, with a combined limit of 100.Patch Changes
5ae9d5b](https://redirect.github.com/cloudflare/wConfiguration
📅 Schedule: (in timezone Europe/Zurich)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.