Skip to content

chore(deps): update cloudflare wrangler packages - #895

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/cloudflare-wrangler-packages
Oct 3, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/cloudflare-wrangler-packages

Conversation

@renovate

@renovate renovate Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@cloudflare/vite-plugin (source) 1.62.0 → 1.62.3 age confidence
wrangler (source) 4.143.0 → 4.145.0 age confidence

Release Notes

cloudflare/workers-sdk (@​cloudflare/vite-plugin)

v1.62.3

Compare Source

Patch Changes

v1.62.2

Compare Source

Patch Changes

v1.62.1

Compare Source

Patch Changes
cloudflare/workers-sdk (wrangler)

v4.145.0

Compare Source

Minor Changes
  • #​15685 b9f1cdc Thanks @​Ankcorn! - Add native support for the Analytics SQL binding

    Declare the zero-configuration binding in wrangler.json with "analytics": { "binding": "ANALYTICS" }. Wrangler uploads the analytics binding type and proxies it to the remote service during local development, so wrangler dev can call the binding without unsafe.bindings.

  • #​15943 8468487 Thanks @​sejoker! - Graduate SQL, Catalog, and Pipelines under wrangler basin out of beta to stable

    Basin SQL is now available under wrangler basin sql, Basin Catalog operations are available under wrangler basin catalog, and Pipelines operations are available under wrangler basin pipelines. These commands are now stable, while the previous wrangler r2 sql, wrangler r2 bucket catalog, and wrangler pipelines command paths remain available as hidden compatibility aliases.

    The Basin SQL authentication environment variable is now WRANGLER_BASIN_SQL_AUTH_TOKEN. Update any existing WRANGLER_R2_SQL_AUTH_TOKEN configuration to use the new name. The fallback to CLOUDFLARE_API_TOKEN remains available.

  • #​15948 a0712e5 Thanks @​akoval-cf! - Add beta K2 producer bindings for existing streams

    Configure a stream created through Wrangler, the Dashboard, or the API in wrangler.json:

    {
      "k2": [
        {
          "binding": "ORDERS",
          "stream": "0123456789abcdef0123456789abcdef"
        }
      ]
    }

    The binding supports env.ORDERS.send([{ content: new TextEncoder().encode("order"), headers: { event: "order.created" } }]). Batches use either all ArrayBuffer or all Uint8Array content. Check the returned success value, handle rejected RPC promises, and retry only when the returned error explicitly allows it. Generated environment types describe this producer contract without requiring a separate application dependency.

    K2 requires an enabled account. Deployment credentials need Worker deployment and K2 configuration-read access. Default Wrangler logins now request the K2 OAuth scopes; existing OAuth users should run wrangler login again to grant the new permissions. Development always uses a real K2 stream and may incur usage charges; no local simulator is provided. The remote setting can be omitted, remote: true suppresses the usage warning, and remote: false is rejected. Consumption is not part of this Worker binding.

  • #​15948 a0712e5 Thanks @​akoval-cf! - Add beta K2 stream management commands

    Use wrangler k2 streams create order_events, wrangler k2 streams list, wrangler k2 streams get <stream-id>, and wrangler k2 streams delete <stream-id> to manage K2 streams. Creation enables Worker bindings but not HTTP ingestion by default, matching the dashboard. Pass --http-enabled to enable authenticated HTTP ingestion and print its endpoint. Creation prints the stream ID and a binding configuration with a YOUR_BINDING_NAME placeholder for the Worker's variable name, but does not edit the configuration file automatically.

    All four commands support --json. Deletion requires confirmation, or --force/-y to skip it; use --force --json for JSON deletion output. Creation also accepts retention, HTTP authentication, Worker-input, and CORS options; listing supports pagination and a name filter. Default Wrangler logins now request k2.read and k2.write; existing OAuth users should run wrangler login again, or use a custom API token granting K2 Config Write. The account must be enabled for K2.

Patch Changes

v4.144.0

Compare Source

Minor Changes
  • #​15919 91a3606 Thanks @​flakey5! - Add --tty (-t) flag to wrangler containers ssh to force pseudo-terminal allocation

    OpenSSH only allocates a pseudo-terminal when no remote command is given, so interactive commands such as wrangler containers ssh <ID> -- bash previously ran without a prompt or line editing. Pass --tty to force one:

    wrangler containers ssh <ID> --tty -- bash

  • #​15951 2a15ae2 Thanks @​flakey5! - Support SSH settings for Durable Object-managed Containers in the configuration API

    defineContainer now accepts ssh and authorizedKeys with schedulingPolicy: "durable-object", matching the ssh and authorized_keys fields that Wrangler already supports for these Containers. Previously the schema rejected them, so they could not be set from cloudflare.config.ts.

    defineContainer({
      name: "sandbox",
      schedulingPolicy: "durable-object",
      ssh: { enabled: true },
      authorizedKeys: [{ name: "laptop", publicKey: "ssh-ed25519 AAAA..." }],
    });
Patch Changes

v4.143.1

Compare Source

Patch Changes
  • #​15159 7bb6eae Thanks @​veggiedefender! - Fix wrangler dev remote bindings for workers.dev subdomains protected by Access

    Running wrangler dev with remote bindings on an unpublished worker protected by Access (e.g. using a wildcard on your workers.dev domain) previously failed with a redirect loop. Wrangler now correctly authenticates remote bindings with Access in this situation.

  • #​15923 60ccdbd Thanks @​petebacondarwin! - Upgrade the bundled capnweb implementation to 0.12.0

    This updates the RPC implementation shipped in Miniflare and remote-binding proxy workers to the latest capnweb release.

  • #​15938 62fd03a Thanks @​dieub! - Resolve the affected Undici dependency in new Wrangler and Vite plugin installs

    Undici 7.29.1 fixes GHSA-3wwx-pv8p-q78v. Update the shared dependency catalog and matching types used by Miniflare and Wrangler so downstream installs can resolve the patched runtime without an application-level override. A published release is still required for consumers; this changeset does not alter already published package metadata.

  • #​15903 06ed9c8 Thanks @​itsmunzir! - Fix custom-domain-only deploys failing for API tokens without Zone Workers Routes read permission

    When workers_dev was disabled and routes contained only entries with custom_domain: true, every deploy after the first one fetched /zones/:zoneId/workers/routes to check for route conflicts, even though custom domains are not zone Workers Routes. Tokens scoped to Workers Scripts edit plus custom domains - without Zone > Workers Routes > Read - failed with "No access to the specified resource" after the Worker version had already been uploaded. The conflict check now only covers non-custom-domain routes; custom domain conflicts continue to be reported by the custom domains changeset API.

  • #​15887 86211fe Thanks @​alepacheco! - Report an unreachable auth server instead of an expired login when refreshing an OAuth token

    When the OAuth token endpoint could not be reached (for example a DNS failure or a connection timeout), the refresh failure was reported as "Your auth token has expired and could not be refreshed", with advice to run wrangler login; in an interactive terminal Wrangler also started a new browser login. A network failure says nothing about the stored refresh token, and a new login would need the same unreachable server. Wrangler now reports that the Cloudflare auth server could not be reached, leaves the stored credentials unchanged, and does not start a login, so the next run can refresh with the same token once the network is back.

  • Updated dependencies [60ccdbd, 62fd03a, c2bb4c8, eb1efe0, 485cfb3]:


Configuration

📅 Schedule: (in timezone Asia/Tokyo)

  • Branch creation
    • "before 3am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the T: renovate Automatic renewal by renovate label Oct 3, 2026
@renovate
renovate Bot enabled auto-merge October 3, 2026 17:39
@renovate
renovate Bot added this pull request to the merge queue Oct 3, 2026
Merged via the queue into main with commit 2fedeb1 Oct 3, 2026
2 checks passed
@renovate
renovate Bot deleted the renovate/cloudflare-wrangler-packages branch October 3, 2026 17:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T: renovate Automatic renewal by renovate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants