fix(deps): update external fixes - #296
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate-external-fixes
branch
from
July 7, 2026 00:48
b055744 to
0d7ba91
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
renovate
Bot
force-pushed
the
renovate-external-fixes
branch
14 times, most recently
from
July 14, 2026 00:45
4a63323 to
3b9a9c5
Compare
renovate
Bot
force-pushed
the
renovate-external-fixes
branch
14 times, most recently
from
July 20, 2026 09:56
a3c3714 to
1610bea
Compare
renovate
Bot
force-pushed
the
renovate-external-fixes
branch
9 times, most recently
from
July 23, 2026 16:39
de7ab2b to
f09bcc4
Compare
Contributor
Author
|
renovate
Bot
force-pushed
the
renovate-external-fixes
branch
5 times, most recently
from
July 29, 2026 07:10
27c4454 to
c01ec0d
Compare
renovate
Bot
force-pushed
the
renovate-external-fixes
branch
2 times, most recently
from
August 1, 2026 03:09
3d5b21c to
5e76a91
Compare
renovate
Bot
force-pushed
the
renovate-external-fixes
branch
from
August 1, 2026 19:09
5e76a91 to
6c867b7
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.1069.0→3.1090.04.20260616.1→4.20260702.12.32.2→2.39.04.1.1→4.3.017.0.7→17.1.025.0.5→25.0.84.100.0→4.112.0Release Notes
aws/aws-sdk-js-v3 (@aws-sdk/s3-request-presigner)
v3.1090.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1089.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1088.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1087.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1086.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1085.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1084.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1083.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1082.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1081.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1080.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1079.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1078.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1077.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1076.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1075.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1074.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1073.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1072.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1071.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1070.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
cloudflare/workerd (@cloudflare/workers-types)
v4.20260702.1Compare Source
v4.20260701.1Compare Source
v4.20260630.1Compare Source
v4.20260629.1Compare Source
v4.20260628.1Compare Source
v4.20260627.1Compare Source
v4.20260626.1Compare Source
v4.20260625.1Compare Source
v4.20260624.1Compare Source
v4.20260623.1Compare Source
v4.20260621.1Compare Source
v4.20260620.1Compare Source
v4.20260619.1Compare Source
v4.20260617.1Compare Source
Redocly/redocly-cli (@redocly/cli)
v2.39.0Compare Source
Minor Changes
structrule to validate the contents of AsyncAPI protocol-specific bindings.Added typed definitions for the
sns,sqs,ibmmq,googlepubsub,pulsarandros2bindings.Patch Changes
v2.38.0Compare Source
Minor Changes
driftcommand that compares recorded HTTP traffic (HAR, Kong, Nginx/Apache JSON, NDJSON) against an OpenAPI description and reports undocumented endpoints, schema mismatches, and security findings.proxycommand that captures live HTTP traffic through a reverse proxy into a HAR file and optionally validates it against an OpenAPI description in real time.Patch Changes
v2.37.0Compare Source
Minor Changes
.graphql/.gql).Patch Changes
v2.36.0Compare Source
Minor Changes
build-docs, ensuring the script's integrity.v2.35.1Compare Source
Patch Changes
undicito the6.27.0version.v2.35.0Compare Source
Minor Changes
lintcommand.spec-step-mutually-exclusive-fieldsArazzo rule to flag steps that use more than one mutually exclusive operation field (operationId,operationPath,workflowId,channelPath, orx-operation).v2.34.0Compare Source
v2.33.2Compare Source
Patch Changes
splitcommand that might have written files outside the chosen--outDir.v2.33.1Compare Source
Patch Changes
v2.33.0Compare Source
Minor Changes
--component-names-strategyoption to thebundlecommand.This option allows a choice of how inline Schema components are named:
basename(default) ortitle(from each schema'stitlefield).Patch Changes
nodeca/js-yaml (js-yaml)
v4.3.0Compare Source
v4.2.0Compare Source
Added
docs/safety.mdwith notes about processing untrusted YAML.maxDepth(100) loader option. Not a problem, but gives a betterexception instead of RangeError on stack overflow.
maxMergeSeqLength(20) loader option. Not a problem aftermergefix,but an additional restriction for safety.
dist/builds.Changed
dist/files are no longer kept in the repository.Fixed
Security
elements (makes sense for malformed files > 10K).
lint-staged/lint-staged (lint-staged)
v17.1.0Compare Source
Minor Changes
#1816
7568d4f- The console output of lint-staged has been simplified so that there's less interactive spinners and more explicit messages like "Started…" -> "Done!". The primary purpose of this was to removeListr2, a very large dependency.Before:
Size of
node_modules/after installing:1561.7 kBwith 29 packages.Fancy interactive spinners, but output dynamically changes:
After:
Size of
node_modules/after installing:974.0 kBwith 5 packages (37.6 % smaller, 82.7 % less transitive dependencies).Simpler but more explicit output:
Patch Changes
#1816
c19079d- Try to restore hidden unstaged changes when using--no-revert.#1818
efb23a2- Console output colors are enabled/disabled more consistently.#1818
26112a1- Failed JS function tasks now properly kill other tasks, unless--continue-on-erroris used. Previously their failure didn't affect other tasks.v17.0.8Compare Source
Patch Changes
#1809
179b437- Fix lint-staged discarding the ongoing merge conflict status (.git/MERGE_HEAD) when using the--hide-unstagedor--hide-alloptions.#1811
3d0b2c0- Fix issues with Git commands that are successful but also emit warnings tostderr, by ignoring thestderroutput completely when the process exits with code 0. This was the behavior when usingnano-spawnandexeca, but when switching totinyexecin 16.3.0 bothstdoutandstderrwere used as interleaved output.semantic-release/semantic-release (semantic-release)
v25.0.8Compare Source
Bug Fixes
v25.0.7Compare Source
Bug Fixes
v25.0.6Compare Source
Bug Fixes
cloudflare/workers-sdk (wrangler)
v4.112.0Compare Source
Minor Changes
#14470
3de70dfThanks @DiogoSantoss! - Add a top-leveladdressesfield to Wrangler configuration for Email RoutingYou can now declare the inbound email addresses handled by your Worker directly in
wrangler.json:{ "name": "my-worker", "main": "src/index.ts", "compatibility_date": "2026-05-21", "addresses": ["support@example.com", "*@​example.com"] }#14706
cb6c3f9Thanks @edmundhung! - Add Durable Object storage access tocreateTestHarness()You can now execute SQL against a SQLite-backed Durable Object to seed or assert the storage state.
#14562
9f04a7eThanks @martijnwalraven! - Emit a typedruntimeErrorevent on theunstable_startWorkerDevEnv for uncaught Worker exceptionsUncaught Worker exceptions were only source-mapped and printed, so programmatic consumers had to scrape terminal output to observe them. The DevEnv now re-emits a
RuntimeErrorEvent(likereloadComplete) carrying the exception text and source-mapped stack — fed from Miniflare's pretty-error seam via the newhandleUncaughtErroroption for exceptions the runtime catches, and from the inspector for those it does not.Patch Changes
#14682
d39ae01Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#14725
c79504fThanks @edmundhung! - Support containers increateTestHarness()Workers configured with containers can now be tested using
createTestHarness(). The harness builds configured images and makes container-backed Durable Objects available during integration tests.#14696
c7dbe1aThanks @martijnwalraven! - Typeunstable_startWorker,DevEnv.startWorker, andConfigController.set/patchagainstWranglerStartDevWorkerInput, so the wrangler-specificdev.structuredLogsHandlerfield the runtime already honors is expressible through the public API. Previously the public signatures took the baseStartDevWorkerInput, and callers passing the handler needed a cast while internal callers (the test harness) routed the wider type around the signature.#14494
4e1a7a7Thanks @petebacondarwin! - Register a workers.dev subdomain before uploading a new WorkerDeploying a Worker for the first time on an account that has no workers.dev subdomain failed with an opaque API error raised by the upload request itself (code 10063, "You need a workers.dev subdomain in order to proceed"). Wrangler now checks for a workers.dev subdomain before uploading a brand-new Worker that publishes to workers.dev and prompts you to register one, so you get a clear, actionable message instead of a cryptic API failure. The check is skipped for deploys that don't target workers.dev (routes-only deploys, or
workers_dev: false) and for existing Workers, since their account already has a subdomain.Updated dependencies [
34e696d,d39ae01,9f04a7e,9f04a7e,cb30df3,cb6c3f9,3f3afbb,e6fbc4e]:v4.111.0Compare Source
Minor Changes
#14602
7692a61Thanks @edmundhung! - Add Durable Object eviction support tocreateTestHarnessYou can now gracefully evict a running Durable Object by class name or binding name to verify how it recovers after its instance is torn down:
#14620
899c297Thanks @penalosa! - Remove support for service environments and thelegacy_envconfiguration fieldService environments have been removed. Wrangler now always deploys each environment as its own Worker named
<name>-<environment>, which matches the behaviour of the previous default (legacy_env = true). The--legacy-envCLI flag has been removed, and thelegacy_envconfiguration field is no longer supported — including it in your configuration file will now raise an error.Because
legacy_env = truewas already the default, removing the field will not change how your Worker is deployed. If you were relying on service environments (legacy_env = false), each environment will now be deployed as a standalone Worker instead of as an environment of a single Worker. See https://developers.cloudflare.com/workers/wrangler/environments/ for more information.#14652
317ce1fThanks @jamesopstad! - Append Workers runtime types to the generated types under--x-new-config, with a newdev.types.includeRuntimeoptionWhen running
wrangler dev --x-new-config, the runtime types generated from your compatibility date and flags are now appended toworker-configuration.d.ts, alongside the types inferred fromcloudflare.config.ts. This is controlled by a newdev.types.includeRuntimeoption inwrangler.config.ts, which defaults totrue.This applies to the experimental new config path only and does not change type generation for existing
wrangler.jsonc/wrangler.tomlprojects.Patch Changes
#14627
ed33326Thanks @tpmmorris! - Add convenient logging for worker emails in the project directory. In addition to the system's temp directory, logs for emails sent by workers are also written to a local temp directory defined by the calling process, e.g for an simple text email sent via Wrangler this is.wrangler/tmp/email/<session>/email-text/<message-uuid>.txt(and related files) in the project root. Callers of Miniflare can control this location via the newdefaultProjectTmpPathoption, which Wrangler and Vite plugin now set automatically.#14642
018574bThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#14588
eb99ab1Thanks @emily-shen! - fix: Respect auth profiles when using remote bindings in the Vite pluginAuth profiles (configured via
wrangler auth createandwrangler auth activate) were previously being ignored when using remote bindings with the Vite plugin. This is now fixed.Note that the profile directory is resolved based on the Vite project root.
#14658
cdf3148Thanks @ATKasem! - Fixwrangler devcorrupting external hostnames in proxied response headersWhen a Worker was run with
routesconfigured,wrangler dev's proxy rewrote the host inside URL-valued headers (such asLocation) using a boundary-less substring replace. Any host that merely contained the route host as a substring was corrupted — e.g. with anexample.comroute, aLocation: https://books.example.com/read/ch01header becamehttps://books.127.0.0.1:8788/read/ch01, andhttps://myexample.com/pathbecamehttps://my127.0.0.1:8788/path.The proxy now only rewrites absolute URLs whose host is exactly the proxied host, swapping the scheme and host together (which also fixes a related case where an
https:scheme survived on a plain-HTTP dev address). Unrelated hosts and subdomains pass through untouched.#14601
3015320Thanks @MattieTK! - Improve the agent-facing--forceguidance for Pages-to-Workers delegationWhen an AI agent opts out of the Pages-to-Workers delegation by passing
--forcetowrangler pages deployorwrangler pages project create, Wrangler now prints a notice at the end of a successful command explaining that--forceonly needs to be passed once: the project then exists, so subsequent commands are no longer delegated and do not need the flag.#14569
9da77acThanks @dario-piotrowicz! - Suggest similar commands when a typo is detectedWhen an unknown command or subcommand is entered, wrangler now suggests the closest matching command if one exists within a reasonable edit distance. For example, running
wrangler whoamiowill displayDid you mean "wrangler whoami"?, and runningwrangler kv namespasewill displayDid you mean "wrangler kv namespace"?.Updated dependencies [
7692a61,ed33326,018574b,7692a61]:v4.110.0Compare Source
Minor Changes
#14591
0283a1fThanks @dario-piotrowicz! - Send npm package dependency metadata with worker uploadsWrangler now collects npm package dependency information from the project's
package.jsonat deploy and version upload time, and includes it in the upload metadata sent to the Cloudflare API. This enables dependency analytics and future features like vulnerability alerting.The collected data includes the package name, the version constraint from
package.json, and the exact installed version fromnode_modules. BothdependenciesanddevDependenciesare included, while workspace packages, local packages, and unresolvable packages are excluded. The list is capped at 200 entries per upload.To opt out, set
dependencies_instrumentation.enabledtofalsein your Wrangler configuration file:{ "dependencies_instrumentation": { "enabled": false } }#14535
1b965c5Thanks @Naapperas! - Support dynamic retry delays for Workflow steps in local devA step's
retries.delaycan now be a function that computes the delay per failed attempt, in addition to a static duration. The function receives{ ctx, error }and returns a delay (a number of milliseconds or a duration string like"30 seconds"), and its result is fed into the configuredbackoff.The function is invoked once per failed attempt with a 5 second timeout. If it throws, times out, or returns an invalid value, the step fails without further retries.
Patch Changes
#14589
7b28392Thanks @jamesopstad! - Fix runtime type caching whenwrangler devauto-regenerates typesWhen
dev.generate_types(orwrangler dev --types) regenerated an out-of-dateworker-configuration.d.ts, the written file omitted the// Begin runtime typesmarker (and the/* eslint-disable */header) thatwrangler typeswrites. As a result, later runs could not detect the cached runtime types and always regenerated them. The auto-regenerated file now matcheswrangler typesoutput, restoring the cache.Updated dependencies [
1b965c5]:v4.109.0Compare Source
Minor Changes
#14489
e3f0cd6Thanks @edmundhung! - AddlistDurableObjectIds()tocreateTestHarnessWorker handlesTests using
createTestHarnesscan now list persisted Durable Object instance IDs for a Durable Object binding. This helps integration tests discover objects created by app behavior without adding test-only endpoints.#14465
2fedb1fThanks @vaishnav-mk! - Add rollback support when terminating Workflow instancesWorkflowInstance.terminate({ rollback: true })now runs registered rollback handlers before marking a local Workflow instance as terminated. Wrangler also supports this viawrangler workflows instances terminate --rollback, including local mode.The rollback option is only sent for terminate operations and is rejected by the Local Explorer API for pause, resume, and restart actions.
#14511
17d2fc1Thanks @juleslemee! - Addwrangler turnstile widgetcommands for managing Turnstile widgetsYou can now create, list, inspect, update, and delete Turnstile widgets from the CLI:
All five subcommands accept
--jsonfor machine-readable output (getprints a formatted view by default; the rest print a short human summary).--domainaccepts comma-separated values, e.g.--domain a.com,b.com.delete --jsonrequires--skip-confirmation/-yto keep output pipeable.createprints the sitekey, the secret, and the canonicalchallenges.cloudflare.com/turnstile/v0/siteverifyendpoint for backend verification. The hint is backend-agnostic; it doesn't assume Workers. The secret is redacted fromlistandupdateoutput but remains available viagetfor retrieval later.deleteprompts for confirmation; pass--skip-confirmation/-yto bypass.The OAuth flow now requests the
challenge-widgets.writescope (the existing Bach-derived scope for Turnstile widget CRUD). Existing OAuth sessions need to runwrangler loginagain to pick it up. API token users need a token with theAccount.Turnstile:Editpermission.Patch Changes
#14596
8511ddfThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#14604
9f74a5fThanks @vaishnav-mk! - Improve the deploy error for cron-triggered Workflows on free plansWrangler now explains that Workflow schedules require a paid Workers plan instead of showing only the generic Workflows API request failure.
#14616
c782e2aThanks @penalosa! - Fixwrangler deployaborting in CI for autoconfigured projectsA recent change guarded non-interactive deploys against overwriting a same-named Worker whenever there was no config file naming it. This was too broad: a plain
wrangler deployrun in CI without a config file (for example an autoconfigured project whose generated config PR has not been merged) would fail with "A Worker named ... already exists in your account", even though re-deploying to that Worker is the intended behaviour.The guard is now limited to the Pages-to-Workers delegation, where the target name is a Pages project name that must not clobber an unrelated Worker. Plain deploys once again deploy normally.
Updated dependencies [
e3f0cd6,8511ddf,2fedb1f]:v4.108.0Compare Source
Minor Changes
#14312
54f74b8Thanks @MattieTK! - Delegate agent-driven static Pages deploys to WorkersWhen
wrangler pages deployorwrangler pages project createis run by an AI coding agent against a brand-new, purely static project, Wrangler now delegates it to Workers static assets (using autoconfig) instead of Cloudflare Pages. Accounts that already have Cloudflare Pages projects, non-agent (human) sessions, and projects using Pages features that can't be carried across to Workers (Pages Functions, a_worker.js, or a_routes.jsonfile) are unaffected and continue to use Pages. Passing--forceto either command opts out of the delegation and deploys to Pages directly. Once the Workers deploy starts it is not silently swapped back to Pages: if it fails, the error is surfaced and the--forceopt-out is suggested.Patch Changes
#14567
0852346Thanks @dependabot! - Update dependencies of "miniflare", "wrangler", "create-cloudflare"The following dependency versions have been updated:
#14312
54f74b8Thanks @MattieTK! - Avoid silently overwriting an existing Worker during non-interactive deploys that cannot prove they own the nameA non-interactive deploy (an agent, CI, or the agent-delegated
wrangler pages deploy) has no way to prompt before overwriting a Worker, so it now stops if the target name is already taken and this run cannot show it owns that Worker. This applies when there is no Wrangler configuration file naming the Worker and either the name was generated automatically or the deploy is the Pages-to-Workers delegation (where the name carried across is a Pages project name, not proof of Worker ownership). The check reuses the service metadata the deploy already fetches, so it adds no extra API calls.Deploys are unaffected when a configuration file names the Worker (so repeat deployments continue to update it), and interactive deploys keep their existing confirmation flow. To update an existing Worker in one of the guarded cases, add a Wrangler configuration file naming it, or deploy under a different name.
Updated dependencies [
0852346]:v4.107.1Compare Source
Patch Changes
#14514
d88555eThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#14564
5fd8beeThanks @jibin7jose! - Fix an issue wherewrangler devwould not override configvarswith values from.dev.varsduring local development when thesecretsfield was defined in the configuration file.[#14332](https
Configuration
📅 Schedule: (in timezone Europe/Zurich)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.