Skip to content

Bump undici and wrangler - #43

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-5f014a320a
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-5f014a320a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown

Bumps undici to 7.30.0 and updates ancestor dependency wrangler. These dependencies need to be updated together.

Updates undici from 7.29.0 to 7.30.0

Release notes

Sourced from undici's releases.

v7.30.0

What's Changed

Full Changelog: nodejs/undici@v7.29.1...v7.30.0

v7.29.1

⚠️ Security fixes

High severity

  • GHSA-w293-vg96-wgc3: BalancedPool could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves connect and legacy tls options when creating upstreams. Fixed by f690157d.
  • GHSA-rfgv-xxqx-mfg5: a WebSocket server could select a subprotocol when none was requested, causing an uncaught TypeError that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 6615e017.

Medium severity

  • GHSA-3wwx-pv8p-q78v: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by 63cf698b.
  • GHSA-rx4f-c7p8-82vq: an unclean WebSocketStream close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by 1858656e.
  • GHSA-2jfj-6hjv-fm6j: shared caches could store and replay responses containing Set-Cookie, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by b6c5a002.
  • GHSA-3xpg-4rpp-hhhm: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable maxSize. Fixed by 2c7d7e12.
  • GHSA-pmjh-fq2x-6v4x: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by 3c672659.

Low severity

  • GHSA-8436-99hf-9mmv: cache interceptors could store and replay responses to unsafe HTTP methods such as POST or DELETE. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by b61d9432.
  • GHSA-2gqq-gqf2-x968: the dump interceptor could treat an oversized chunked response as successfully truncated when no Content-Length was present. Undici now enforces maxSize against received bytes and aborts oversized responses. Fixed by 21693f40.
  • GHSA-r53p-7pc4-xj5r: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates Content-Range against the original response framing before resuming. Fixed by cd8af90b.

What's Changed

Full Changelog: nodejs/undici@v7.29.0...v7.29.1

Commits

Updates wrangler from 4.128.0 to 4.147.0

Release notes

Sourced from wrangler's releases.

wrangler@4.147.0

Minor Changes

  • #15928 7f57b1c Thanks @​ichernetsky-cf! - Allow "us" as a jurisdiction for Container applications

    Container placement constraints now accept constraints.jurisdiction: "us" in Wrangler and typed Cloudflare configuration. This makes the US jurisdiction available alongside "eu" and "fedramp".

Patch Changes

  • #15974 7f700ef Thanks @​martinezjandrew! - Fix wrangler containers list to report live instances

    The LIVE INSTANCES column now reports each application's active runtime instances instead of its configured instance count, matching the Cloudflare dashboard. JSON output continues to expose the configured count through the existing instances field.

  • #15980 90e6a1b Thanks @​martinezjandrew! - Accept Durable Object application IDs in Containers commands

    wrangler containers instances and wrangler containers delete now accept the 32-character hexadecimal application IDs returned for Durable Object-backed applications, in addition to legacy dashed UUIDs.

  • #15871 6a4b0fe Thanks @​tw4! - Retry transient API failures in wrangler workflows instances list and wrangler workflows instances describe

    Previously, a single temporary 5xx response or dropped connection made these read-only commands exit with an error, even though the next request would have succeeded. They now use Wrangler's existing bounded API retry handling. The read that resolves --id latest is retried too, which also benefits the other wrangler workflows instances commands that accept latest; the mutating requests they make afterwards are not retried. Persistent failures are still reported after the retries are exhausted, and under --json any retry notices are written to stderr so stdout stays valid JSON.

  • Updated dependencies []:

wrangler@4.146.0

Minor Changes

  • #15777 464a582 Thanks @​Naapperas! - Support the new Workflows createBatch() API in local development

    Local Workflows bindings now accept object-form batches that create instances from a count or a list of instance options. The result includes handles for created instances and indexed per-instance errors, matching the runtime API while preserving the deprecated array form.

  • #15639 aee2842 Thanks @​hugo-vicente11! - Add --allowed-mail to the experimental wrangler tunnel quick-start command

    The option forwards exact email addresses, comma-separated lists, and wildcard domains to cloudflared. It can be specified more than once to combine multiple recipient rules.

    Email-protected tunnels require cloudflared 2026.9.2 or later. Wrangler checks the selected binary before starting the tunnel and reports an upgrade error when it is incompatible.

Patch Changes

  • #15992 b8e7cc3 Thanks @​zebp! - Mark wrangler artifacts commands as open beta

    Artifacts has entered open beta, so the wrangler artifacts commands no longer display a "private beta" label in help output and warnings.

  • #15984 9d7b08e Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20260930.2 ^5.20261001.1

... (truncated)

Commits
  • 64c1337 Version Packages (#15996)
  • 6a4b0fe [wrangler] Retry transient failures in workflows instances list and describe ...
  • 7f700ef CC-8799: report active instead of configured instances in containers list (#1...
  • 90e6a1b CC-8800: accept durable object app ids in container commands (#15980)
  • b4954c1 Version Packages (#15983)
  • b8e7cc3 [wrangler] Mark Artifacts commands as open beta (#15992)
  • aee2842 [wrangler] Support email-protected Quick Tunnels (#15639)
  • efd67e6 [wrangler] Keep colons in wrangler tail --header filter values (#15959)
  • 89061a4 Version Packages (#15957)
  • 4a5ab6c Preserve existing secret bindings during Worker deployments (#15964)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [undici](https://github.com/nodejs/undici) to 7.30.0 and updates ancestor dependency [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler). These dependencies need to be updated together.


Updates `undici` from 7.29.0 to 7.30.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.29.0...v7.30.0)

Updates `wrangler` from 4.128.0 to 4.147.0
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.147.0/packages/wrangler)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 7.30.0
  dependency-type: indirect
- dependency-name: wrangler
  dependency-version: 4.147.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 3, 2026
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
stack-web 7bf1ea5 Commit Preview URL

Branch Preview URL
Oct 03 2026, 03:38 AM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants