Skip to content

Update dependency wrangler to v4.149.0 - #46

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/wrangler-4.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/wrangler-4.x

Conversation

@renovate

@renovate renovate Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
wrangler (source) 4.135.0 → 4.149.0 age confidence

Release Notes

cloudflare/workers-sdk (wrangler)

v4.149.0

Compare Source

Minor Changes
  • #​16036 9a58244 Thanks @​edevil! - Support temporary event accounts in R2 and Containers commands

    wrangler r2 and wrangler containers commands now accept the hidden --temporary flag, so accounts created for an event can manage buckets, objects and containers directly. Every command that supports --temporary now also accepts a hidden --event-code flag, so the first command a participant runs can create the event account:

    wrangler r2 bucket create my-bucket --temporary --event-code <code>

    R2 and Containers are only available on event accounts. R2 custom domains, Sippy, external container registries and wrangler cloudchamber commands still require a logged-in account.

Patch Changes
  • #​16139 2d1d563 Thanks @​cpojer! - Update esbuild to 0.28.2

    Align esbuild dependency with tooling using the latest 0.28 patch so package managers can share one installation instead of downloading a second native binary.

  • #​15632 85b14e7 Thanks @​petebacondarwin! - Honor Retry-After directives during static asset uploads

    Static asset uploads now pause retries and pending uploads until the latest outstanding deadline requested by the API. A per-request limiter also keeps gateway retries at the reduced concurrency after the pause ends, preventing a deployment from immediately overloading a constrained asset service again.

  • #​16098 fe607f9 Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    sharp 0.35.4 0.35.5
  • #​16093 ad7ff45 Thanks @​DiogoSantoss! - Document that addresses catch-all entries must use the zone apex

    A *@domain entry in addresses must use the zone apex, such as *@example.com. The zone catch-all also receives mail for every subdomain in the zone that has no literal rule.

  • #​16102 757faa6 Thanks @​tlq5l! - Keep Preview secrets when deploying to an existing Preview

    Secrets added to a Preview with wrangler preview secret put or wrangler preview secret bulk were lost the next time wrangler preview ran, because each new deployment was created from the Wrangler config, --var and --secrets-file values only.

    wrangler preview now carries over the secrets of the Preview's latest deployment. A value passed in this deployment (--secrets-file, --var or a previews binding with the same name) still replaces the existing secret, and wrangler preview secret delete removes one.

  • #​15617 93c1069 Thanks @​jpatel3! - Stop the update check from recommending deprecated versions

    Previously, the "update available" notice shown by wrangler and @cloudflare/vite-plugin always pointed at whichever version was tagged latest on npm, even after that version had been deprecated for shipping a bug. Deprecated versions are now never recommended: if the latest release has been deprecated, the newest non-deprecated stable release below it is suggested instead, or nothing at all if you are already on it.

    The check now reads the npm registry directly instead of going through the update-check package, which discarded the deprecation information. The on-disk cache location and one-hour refresh interval are unchanged.

  • #​16003 6947df3 Thanks @​oddharsh! - Ship using and await using declarations to the runtime as written, for smaller Worker bundles

    Workers and Pages Functions that use explicit resource management no longer carry about 1 KB of bundled helper code to emulate it. workerd supports using and await using natively at every compatibility date, so wrangler deploy, wrangler versions upload and Pages Functions builds now leave these declarations untouched.

  • #​15958 82acf3c Thanks @​breken-ai! - Apply each action's own condition in wrangler r2 bucket lifecycle add

    When a lifecycle rule was added with both expiration and Infrequent Access transition flags, both actions read their condition from the same list of flags, which checked --expire-days first. --expire-days 365 --ia-transition-days 30 therefore transitioned objects after 365 days instead of 30, and --expire-date 2027-01-01 --ia-transition-days 30 deleted objects after 30 days instead of on the given date. Expiration now only reads --expire-days/--expire-date, and transition only reads --ia-transition-days/--ia-transition-date.

  • Updated dependencies [2d1d563, e6f7663, fe607f9, 8de6b3c, ae29445, cc8e969, 417b186]:

v4.148.0

Compare Source

Minor Changes
  • #​16051 b4e1299 Thanks @​devteamaegis! - Add --source-namespace and --source-repo-name to wrangler queues subscription create for the artifacts.repo source

    The Event Subscriptions API requires source.namespace and source.repo_name for artifacts.repo subscriptions, but Wrangler had no way to pass them, so --source artifacts.repo always failed with a validation error. Both flags are now required for this source, and wrangler queues subscription get shows the subscription's resource as <namespace>/<repo-name>.

  • #​15998 b75421f Thanks @​dario-piotrowicz! - Add assets.base_path support to Workers Assets

    Serve an asset directory from a public URL prefix without changing its on-disk layout:

    {
      "assets": {
        "directory": "./public",
        "base_path": "/docs"
      }
    }

    Wrangler, preview, Miniflare, and generated build configuration preserve the explicitly selected value, while the Asset Worker normalizes it and strips the prefix only for asset lookup. Requests passed to a user Worker, request-facing headers, and redirects retain the public path. Relative pathname inputs are interpreted as root-relative prefixes, URL-shaped values are rejected, and omitting the option preserves existing root-path behavior.

    Authored _headers and _redirects rules continue to match full public paths. In particular, both the source and destination of an authored 200 asset rewrite must include the configured public prefix; Asset Worker-generated redirects are prefixed automatically.

  • #​16005 4d308f6 Thanks @​oOPa! - Add a --experimental-mode instant option to wrangler kv namespace create

    This lets entitled accounts create Workers KV Instant namespaces while the feature is in private beta.

  • #​16030 aa2f9b7 Thanks @​edmundhung! - Add email-protected Quick Tunnels to wrangler dev

    Pass one or more --tunnel-allowed-mail flags to require email authentication when exposing a local development server through a Quick Tunnel. Each value can be an exact email address or a domain pattern.

  • #​15283 2dde890 Thanks @​shubhxho! - Support deleting secrets with wrangler versions secret bulk

    Set a secret's value to null in JSON input to remove it from the new Worker version. Bulk output now distinguishes between created and deleted secrets, so retrying wrangler secret bulk with wrangler versions secret bulk preserves requested deletions. Deploy the new version with wrangler versions deploy to apply the changes to production traffic.

Patch Changes
  • #​15534 2b1a0ca Thanks @​vahidshaik1901! - Improve guidance for conflicting Wrangler configuration files

    When user and generated deploy configurations are found under different base paths, Wrangler now identifies the expected deploy configuration location, suggests how to resolve the conflict, and links to the relevant documentation.

  • #​16014 c492d63 Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20261001.1 ^5.20261005.1
    workerd 1.20261001.1 1.20261005.1
  • #​16079 ba52118 Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20261005.1 ^5.20261006.1
    workerd 1.20261005.1 1.20261006.1
  • #​15573 14f0339 Thanks @​xgame92! - Include default module rules in generated Worker types

    wrangler types now declares the built-in Text, Data, and WebAssembly module patterns even when they are not repeated in the Wrangler configuration, keeping generated types aligned with deployment behavior.

    Service-worker declaration files are emitted as global scripts so that the generated wildcard module types are visible to imports.

    Directory-specific rules retain their scope when TypeScript can represent it; ambiguous relative imports use a union of the possible deployed module types.

    When generating combined types for named environments, each environment's effective rules are resolved independently and differing import types are represented as unions.

  • #​15261 42c7219 Thanks @​ondraulehla! - Fix r2 object put and r2 bulk put storing a different key in local mode

    Keys that are not URL-safe were mangled on the way into local storage.

    • A key with a space or a non-ASCII character was stored under its percent-encoded name, so a later r2 object get for that key reported that the key does not exist.
    • Two keys that differ only after a # collapsed into a single object, and the second upload replaced the first.
    • A key with a % that is not a valid escape failed outright with "Invalid URL string.", and one with a valid escape, such as %41.txt, was stored as A.txt.

    Spaces, non-ASCII characters, # and % now survive the trip into local storage. Objects already in local state are left where they are.

  • #​15283 2dde890 Thanks @​shubhxho! - Show a useful error when wrangler secret bulk hits an undeployed latest version

    wrangler secret put already explained this case (API error 10215). secret bulk just dumped the raw API response, which for 10214 talks about logpush and tail_consumers even though you were only uploading secrets.

    Both commands now point at wrangler versions secret … instead.

  • #​16068 26e03e2 Thanks @​edevil! - Print temporary account notices to stderr

    The terms notice, the proof-of-work message, and the "Temporary account ready" claim details printed by --temporary now go to stderr instead of stdout. Previously they corrupted command output on stdout, such as the JSON from wrangler kv namespace list --temporary or the raw value from wrangler kv key get --temporary. Commands that lower the log level for --json, such as wrangler d1 execute --json --temporary, also hid the claim URL; it is now shown unless logging is disabled with WRANGLER_LOG=none.

    Scripts that read the claim URL from stdout should read stderr instead.

  • Updated dependencies [b75421f, 0ec13b7, c492d63, ba52118, 946aaa7, 48f3c04, 5606a74, f8cdcb9, e44cf6b, 0b51fec]:

v4.147.0

Compare Source

Minor Changes
  • #​15928 7f57b1c Thanks @​ichernetsky-cf! - Allow "us" as a jurisdiction for Container applications

    Container placement constraints now accept constraints.jurisdiction: "us" in Wrangler and typed Cloudflare configuration. This makes the US jurisdiction available alongside "eu" and "fedramp".

Patch Changes
  • #​15974 7f700ef Thanks @​martinezjandrew! - Fix wrangler containers list to report live instances

    The LIVE INSTANCES column now reports each application's active runtime instances instead of its configured instance count, matching the Cloudflare dashboard. JSON output continues to expose the configured count through the existing instances field.

  • #​15980 90e6a1b Thanks @​martinezjandrew! - Accept Durable Object application IDs in Containers commands

    wrangler containers instances and wrangler containers delete now accept the 32-character hexadecimal application IDs returned for Durable Object-backed applications, in addition to legacy dashed UUIDs.

  • #​15871 6a4b0fe Thanks @​tw4! - Retry transient API failures in wrangler workflows instances list and wrangler workflows instances describe

    Previously, a single temporary 5xx response or dropped connection made these read-only commands exit with an error, even though the next request would have succeeded. They now use Wrangler's existing bounded API retry handling. The read that resolves --id latest is retried too, which also benefits the other wrangler workflows instances commands that accept latest; the mutating requests they make afterwards are not retried. Persistent failures are still reported after the retries are exhausted, and under --json any retry notices are written to stderr so stdout stays valid JSON.

  • Updated dependencies []:

v4.146.0

Compare Source

Minor Changes
  • #​15777 464a582 Thanks @​Naapperas! - Support the new Workflows createBatch() API in local development

    Local Workflows bindings now accept object-form batches that create instances from a count or a list of instance options. The result includes handles for created instances and indexed per-instance errors, matching the runtime API while preserving the deprecated array form.

  • #​15639 aee2842 Thanks @​hugo-vicente11! - Add --allowed-mail to the experimental wrangler tunnel quick-start command

    The option forwards exact email addresses, comma-separated lists, and wildcard domains to cloudflared. It can be specified more than once to combine multiple recipient rules.

    Email-protected tunnels require cloudflared 2026.9.2 or later. Wrangler checks the selected binary before starting the tunnel and reports an upgrade error when it is incompatible.

Patch Changes
  • #​15992 b8e7cc3 Thanks @​zebp! - Mark wrangler artifacts commands as open beta

    Artifacts has entered open beta, so the wrangler artifacts commands no longer display a "private beta" label in help output and warnings.

  • #​15984 9d7b08e Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20260930.2 ^5.20261001.1
    workerd 1.20260930.2 1.20261001.1
  • #​15959 efd67e6 Thanks @​breken-ai! - Keep colons in wrangler tail --header filter values

    wrangler tail --header splits its argument into a header name and an optional value at the colon. It split at every colon and kept only the first two parts, so a value containing a colon was cut short: --header "Origin:https://app.example.com" filtered on https. The value now includes everything after the first colon, so URLs, ports and IPv6 addresses are sent to the tail filter intact.

  • Updated dependencies [b00ef4f, 9d7b08e, 464a582]:

v4.145.0

Compare Source

Minor Changes
  • #​15685 b9f1cdc Thanks @​Ankcorn! - Add native support for the Analytics SQL binding

    Declare the zero-configuration binding in wrangler.json with "analytics": { "binding": "ANALYTICS" }. Wrangler uploads the analytics binding type and proxies it to the remote service during local development, so wrangler dev can call the binding without unsafe.bindings.

  • #​15943 8468487 Thanks @​sejoker! - Graduate SQL, Catalog, and Pipelines under wrangler basin out of beta to stable

    Basin SQL is now available under wrangler basin sql, Basin Catalog operations are available under wrangler basin catalog, and Pipelines operations are available under wrangler basin pipelines. These commands are now stable, while the previous wrangler r2 sql, wrangler r2 bucket catalog, and wrangler pipelines command paths remain available as hidden compatibility aliases.

    The Basin SQL authentication environment variable is now WRANGLER_BASIN_SQL_AUTH_TOKEN. Update any existing WRANGLER_R2_SQL_AUTH_TOKEN configuration to use the new name. The fallback to CLOUDFLARE_API_TOKEN remains available.

  • #​15948 a0712e5 Thanks @​akoval-cf! - Add beta K2 producer bindings for existing streams

    Configure a stream created through Wrangler, the Dashboard, or the API in wrangler.json:

    {
      "k2": [
        {
          "binding": "ORDERS",
          "stream": "0123456789abcdef0123456789abcdef"
        }
      ]
    }

    The binding supports env.ORDERS.send([{ content: new TextEncoder().encode("order"), headers: { event: "order.created" } }]). Batches use either all ArrayBuffer or all Uint8Array content. Check the returned success value, handle rejected RPC promises, and retry only when the returned error explicitly allows it. Generated environment types describe this producer contract without requiring a separate application dependency.

    K2 requires an enabled account. Deployment credentials need Worker deployment and K2 configuration-read access. Default Wrangler logins now request the K2 OAuth scopes; existing OAuth users should run wrangler login again to grant the new permissions. Development always uses a real K2 stream and may incur usage charges; no local simulator is provided. The remote setting can be omitted, remote: true suppresses the usage warning, and remote: false is rejected. Consumption is not part of this Worker binding.

  • #​15948 a0712e5 Thanks @​akoval-cf! - Add beta K2 stream management commands

    Use wrangler k2 streams create order_events, wrangler k2 streams list, wrangler k2 streams get <stream-id>, and wrangler k2 streams delete <stream-id> to manage K2 streams. Creation enables Worker bindings but not HTTP ingestion by default, matching the dashboard. Pass --http-enabled to enable authenticated HTTP ingestion and print its endpoint. Creation prints the stream ID and a binding configuration with a YOUR_BINDING_NAME placeholder for the Worker's variable name, but does not edit the configuration file automatically.

    All four commands support --json. Deletion requires confirmation, or --force/-y to skip it; use --force --json for JSON deletion output. Creation also accepts retention, HTTP authentication, Worker-input, and CORS options; listing supports pagination and a name filter. Default Wrangler logins now request k2.read and k2.write; existing OAuth users should run wrangler login again, or use a custom API token granting K2 Config Write. The account must be enabled for K2.

Patch Changes

v4.144.0

Compare Source

Minor Changes
  • #​15919 91a3606 Thanks @​flakey5! - Add --tty (-t) flag to wrangler containers ssh to force pseudo-terminal allocation

    OpenSSH only allocates a pseudo-terminal when no remote command is given, so interactive commands such as wrangler containers ssh <ID> -- bash previously ran without a prompt or line editing. Pass --tty to force one:

    wrangler containers ssh <ID> --tty -- bash

  • #​15951 2a15ae2 Thanks @​flakey5! - Support SSH settings for Durable Object-managed Containers in the configuration API

    defineContainer now accepts ssh and authorizedKeys with schedulingPolicy: "durable-object", matching the ssh and authorized_keys fields that Wrangler already supports for these Containers. Previously the schema rejected them, so they could not be set from cloudflare.config.ts.

    defineContainer({
      name: "sandbox",
      schedulingPolicy: "durable-object",
      ssh: { enabled: true },
      authorizedKeys: [{ name: "laptop", publicKey: "ssh-ed25519 AAAA..." }],
    });
Patch Changes

v4.143.1

Compare Source

Patch Changes
  • #​15159 7bb6eae Thanks @​veggiedefender! - Fix wrangler dev remote bindings for workers.dev subdomains protected by Access

    Running wrangler dev with remote bindings on an unpublished worker protected by Access (e.g. using a wildcard on your workers.dev domain) previously failed with a redirect loop. Wrangler now correctly authenticates remote bindings with Access in this situation.

  • #​15923 60ccdbd Thanks @​petebacondarwin! - Upgrade the bundled capnweb implementation to 0.12.0

    This updates the RPC implementation shipped in Miniflare and remote-binding proxy workers to the latest capnweb release.

  • #​15938 62fd03a Thanks @​dieub! - Resolve the affected Undici dependency in new Wrangler and Vite plugin installs

    Undici 7.29.1 fixes GHSA-3wwx-pv8p-q78v. Update the shared dependency catalog and matching types used by Miniflare and Wrangler so downstream installs can resolve the patched runtime without an application-level override. A published release is still required for consumers; this changeset does not alter already published package metadata.

  • #​15903 06ed9c8 Thanks @​itsmunzir! - Fix custom-domain-only deploys failing for API tokens without Zone Workers Routes read permission

    When workers_dev was disabled and routes contained only entries with custom_domain: true, every deploy after the first one fetched /zones/:zoneId/workers/routes to check for route conflicts, even though custom domains are not zone Workers Routes. Tokens scoped to Workers Scripts edit plus custom domains - without Zone > Workers Routes > Read - failed with "No access to the specified resource" after the Worker version had already been uploaded. The conflict check now only covers non-custom-domain routes; custom domain conflicts continue to be reported by the custom domains changeset API.

  • #​15887 86211fe Thanks @​alepacheco! - Report an unreachable auth server instead of an expired login when refreshing an OAuth token

    When the OAuth token endpoint could not be reached (for example a DNS failure or a connection timeout), the refresh failure was reported as "Your auth token has expired and could not be refreshed", with advice to run wrangler login; in an interactive terminal Wrangler also started a new browser login. A network failure says nothing about the stored refresh token, and a new login would need the same unreachable server. Wrangler now reports that the Cloudflare auth server could not be reached, leaves the stored credentials unchanged, and does not start a login, so the next run can refresh with the same token once the network is back.

  • Updated dependencies [60ccdbd, 62fd03a, c2bb4c8, eb1efe0, 485cfb3]:

v4.143.0

Compare Source

Minor Changes
  • #​15914 7f0734c Thanks @​jamesopstad! - Use cf/config for cloudflare.config.ts authoring

    Experimental cloudflare.config.ts projects must now import defineConfig, bindings, triggers, and related helpers from cf/config. Generated declarations from Wrangler and the Vite plugin also reference this package, so projects using the experimental configuration flow must add cf as a dependency.

    The Vite plugin no longer exports @cloudflare/vite-plugin/experimental-config. wrangler/experimental-config remains available for defineWranglerConfig, but no longer re-exports Cloudflare configuration helpers.

v4.142.0

Compare Source

Minor Changes
  • #​15856 4c2993b Thanks @​Naapperas! - Support Workflows declared in exports on ctx.exports in local development

    A Workflow declared in a Worker's exports is now available on ctx.exports in wrangler dev, the Vite plugin and the Vitest plugin, with the same API as a Workflow binding:

    const instance = await ctx.exports.MyWorkflow.create({
      params: { name: "World" },
    });

    ctx.exports and workflows bindings with the same Workflow name share their instances, including instances created before the Workflow was declared in exports. Two Workers can't export the same Workflow name, and a binding to an exported Workflow must refer to the Worker and class that export it. getPlatformProxy() ignores Workflows declared in exports, since it doesn't run the Worker's code.

    wrangler workflows commands run with --local also work with Workflows declared only in exports, without a workflows binding.

    In the Vitest plugin, introspectWorkflow() and introspectWorkflowInstance() still need a Workflow binding, and now explain how to add one when passed a Workflow from ctx.exports. Instances created through ctx.exports are introspected too. A workflows binding whose script_name is the Worker's own name now resolves to the Worker itself again.

Patch Changes

v4.141.0

Compare Source

Minor Changes
  • #​15658 8280086 Thanks @​jqmmes! - Add Durable Objects code update strategies to Worker deployments

    Use --durable-objects-code-update-mode immediate with wrangler deploy, wrangler versions deploy, and wrangler rollback to update code without waiting for active instances to hibernate. Use --durable-objects-code-update-mode deferred 30s to set a maximum delay, or configure durable_objects.code_update_strategy with mode and max_delay. When unset, the strategy defaults to deferred with a 5-minute maximum delay; delays cannot exceed 24 hours and must use millisecond precision.

  • #​15800 bd56b98 Thanks @​Refaerds! - Add Browser Run as an event source for Queue subscriptions

    You can now create Queue subscriptions with --source browserRun.

Patch Changes

v4.140.0

Compare Source

Minor Changes
Patch Changes

v4.139.0

Compare Source

Minor Changes
  • #​15792 479e1e8 Thanks @​flakey5! - Configure SSH for experimental Durable Object-managed Containers

    Set containers[].ssh and containers[].authorized_keys when using scheduling_policy: "durable_object". These are application-wide settings that follow the same rules as the existing Durable Object-managed Container settings: normal deployments create missing applications and update explicitly configured values, while omitted settings preserve the existing application configuration.

    // wrangler.jsonc
    {
      "containers": [
        {
          "name": "sandbox",
          "class_name": "Sandbox",
          "scheduling_policy": "durable_object",
          "ssh": { "enabled": true },
          "authorized_keys": [
            { "name": "laptop", "public_key": "ssh-ed25519 AAAA..." }
          ]
        }
      ]
    }
  • #​15648 52c0e9f Thanks @​tpmmorris! - Expose configured Cron Triggers to local development consumers

    Wrangler now passes the active environment's exact Cron Trigger expressions to Miniflare so Local Explorer can display them. Headless agent sessions also advertise the Local Explorer scheduled invocation API.

  • #​15786 bdda4c3 Thanks @​ThomasRubini! - Support UDP connect handlers in local development

    The experimental connect configuration now accepts protocol: "udp", with optional idle_timeout_ms and max_pending_bytes settings. UDP datagrams are delivered to the Worker's connect() handler using workerd's value-mode socket streams, and can be tested with Miniflare#dispatchConnect({ protocol: "udp" }).

  • #​15779 fc3cbaa Thanks @​Naapperas! - Support workflow entries in the exports configuration map

    A Worker can now declare the Workflows it defines in exports, keyed by the WorkflowEntrypoint class name:

    {
      "exports": {
        "MyWorkflow": {
          "type": "workflow",
          "name": "my-workflow",
          "limits": { "steps": 100 },
          "schedules": "0 * * * *"
        }
      }
    }

    A workflow export accepts the same settings as a workflows binding: limits, concurrency, schedules, and default_retention. wrangler deploy and wrangler versions upload send these entries to the upload API by name, and wrangler deploy and wrangler triggers deploy provision the Workflow with its settings, just as they do for workflows bindings owned by the Worker. A Workflow may be declared both as a binding and as an export, as long as both declarations use the same class and do not set the same setting to different values. A binding to another Worker's Workflow cannot share a name with an export. @cloudflare/config adds the matching exports.workflow() helper. Local development does not yet act on these entries.

Patch Changes
  • #​15796 be72815 Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20260921.1 ^5.20260923.1
    workerd 1.20260921.1 1.20260923.1
  • #​14847 940c692 Thanks @​TheSaiEaranti! - Emulate the deterministic-ID uniqueness contract in the local Workflows binding

    The local Workflows binding now matches the documented production behavior for deterministic instance IDs: create({ id }) with an ID that already exists throws (instance.already_exists) and retains the existing instance, and createBatch() skips IDs that already exist or repeat within the batch, excluding them from the result instead of creating duplicate executions. Previously both paths silently created duplicates, so code relying on deterministic IDs for idempotency (for example a Queue consumer creating one workflow per message) appeared to work locally while double-executing workflow bodies.

  • #​15803 cd60c9c Thanks @​pmiguel! - Show --jurisdiction in help for wrangler kv namespace create

    The option was supported but omitted from the command's help output. Users can now discover how to create KV namespaces in a specific jurisdiction.

  • #​15838 15799d4 Thanks @​oddharsh! - Update smol-toml to 1.9.0 to fix slow parsing of very large TOML files

    Parse time for TOML config files now grows linearly with their size, instead of with its square: a 40,000-line file that took 259 ms to parse now takes 17 ms, while typical wrangler.toml files parse in the same time as before. This addresses the GHSA-r4xh-jqrq-34v2 advisory against earlier versions of the parser.

    Some TOML syntax errors now point at the character that caused them. For example, a wrangler.toml containing INVALID "FILE is now reported as illegal character in key at the ", rather than incomplete key-value at the start of the line.

  • Updated dependencies [52c0e9f, 44f5295, be72815, 940c692, bdda4c3, fc3cbaa]:

v4.138.0

Compare Source

Minor Changes
  • #​15776 b03f960 Thanks @​edevil! - Add event-code support to temporary Worker deployments

    Use wrangler deploy --temporary --event-code <code> to provision an account for an event. Wrangler requires explicit server acknowledgement before caching the account and keeps the event code out of its cache and telemetry.

  • #​15817 6e77c53 Thanks @​jamesopstad! - Allow framework commands to produce Preview Build Output with the experimental config

    When cf previews deploy invokes a framework build command, Preview intent is now preserved. Function-based cloudflare.config.ts files receive isPreview: true, and generated Build Output is marked as a Preview build.

Patch Changes

v4.137.0

Compare Source

Minor Changes
  • #​15778 cd7508c Thanks @​jamesopstad! - Generate types during development and supported builds with Vite's experimental.newConfig option or Wrangler's --experimental-new-config flag (and --experimental-cf-build-output for builds)

    When Wrangler's --experimental-new-config flag or Vite's experimental.newConfig option is enabled, inferred configuration and runtime declarations are now kept in `.cloudflare/types/index.d.

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from 3fad63d to 5de5c2a Compare September 22, 2026 14:05
@renovate renovate Bot changed the title Update dependency wrangler to v4.136.1 Update dependency wrangler to v4.136.2 Sep 22, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from 5de5c2a to ec1db2e Compare September 23, 2026 01:46
@renovate renovate Bot changed the title Update dependency wrangler to v4.136.2 Update dependency wrangler to v4.136.3 Sep 23, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from ec1db2e to 4e57237 Compare September 24, 2026 02:59
@renovate renovate Bot changed the title Update dependency wrangler to v4.136.3 Update dependency wrangler to v4.137.0 Sep 24, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from 4e57237 to 01dea8b Compare September 24, 2026 23:51
@renovate renovate Bot changed the title Update dependency wrangler to v4.137.0 Update dependency wrangler to v4.139.0 Sep 24, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from 01dea8b to 14291c2 Compare September 25, 2026 10:47
@renovate renovate Bot changed the title Update dependency wrangler to v4.139.0 Update dependency wrangler to v4.140.0 Sep 25, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from 14291c2 to 8f21bb0 Compare September 25, 2026 22:59
@renovate renovate Bot changed the title Update dependency wrangler to v4.140.0 Update dependency wrangler to v4.141.0 Sep 25, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from 8f21bb0 to c42bcd1 Compare September 27, 2026 15:04
@renovate renovate Bot changed the title Update dependency wrangler to v4.141.0 Update dependency wrangler to v4.142.0 Sep 27, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from c42bcd1 to 64193a9 Compare September 28, 2026 23:45
@renovate renovate Bot changed the title Update dependency wrangler to v4.142.0 Update dependency wrangler to v4.143.0 Sep 28, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from 64193a9 to 6c73f23 Compare September 29, 2026 19:27
@renovate renovate Bot changed the title Update dependency wrangler to v4.143.0 Update dependency wrangler to v4.143.1 Sep 29, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from 6c73f23 to cf801cd Compare September 29, 2026 21:55
@renovate renovate Bot changed the title Update dependency wrangler to v4.143.1 Update dependency wrangler to v4.144.0 Sep 29, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from cf801cd to d2bb033 Compare October 1, 2026 05:38
@renovate renovate Bot changed the title Update dependency wrangler to v4.144.0 Update dependency wrangler to v4.145.0 Oct 1, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from d2bb033 to 242b416 Compare October 1, 2026 17:38
@renovate renovate Bot changed the title Update dependency wrangler to v4.145.0 Update dependency wrangler to v4.146.0 Oct 1, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from 242b416 to 9d6712f Compare October 2, 2026 13:14
@renovate renovate Bot changed the title Update dependency wrangler to v4.146.0 Update dependency wrangler to v4.147.0 Oct 2, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from 9d6712f to 23e9652 Compare October 7, 2026 02:55
@renovate renovate Bot changed the title Update dependency wrangler to v4.147.0 Update dependency wrangler to v4.148.0 Oct 7, 2026
@renovate
renovate Bot force-pushed the renovate/wrangler-4.x branch from 23e9652 to 4186c5d Compare October 8, 2026 22:22
@renovate renovate Bot changed the title Update dependency wrangler to v4.148.0 Update dependency wrangler to v4.149.0 Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants