fix(deps): update dependency wrangler ( 4.118.0 ➔ 4.142.0 ) #33
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "renovate/cloudflare-tooling"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
4.118.0→4.142.0Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge.
Releasedis the upstream publish time.—means this datasource reports no release timestamp — normal for ghcr.io, quay.io and private/proxy registries — sominimumReleaseAgecannot hold the update back and it is eligible as soon as checks pass. A real date means the soak is enforced: add this update type'sminimumReleaseAgetoReleasedto get the eligibility moment.Release Notes
cloudflare/workers-sdk (wrangler)
v4.142.0Compare Source
Minor Changes
#15856
4c2993bThanks @Naapperas! - Support Workflows declared inexportsonctx.exportsin local developmentA Workflow declared in a Worker's
exportsis now available onctx.exportsinwrangler dev, the Vite plugin and the Vitest plugin, with the same API as a Workflow binding:ctx.exportsandworkflowsbindings with the same Workflownameshare their instances, including instances created before the Workflow was declared inexports. Two Workers can't export the same Workflow name, and a binding to an exported Workflow must refer to the Worker and class that export it.getPlatformProxy()ignores Workflows declared inexports, since it doesn't run the Worker's code.wrangler workflowscommands run with--localalso work with Workflows declared only inexports, without aworkflowsbinding.In the Vitest plugin,
introspectWorkflow()andintrospectWorkflowInstance()still need a Workflow binding, and now explain how to add one when passed a Workflow fromctx.exports. Instances created throughctx.exportsare introspected too. Aworkflowsbinding whosescript_nameis the Worker's own name now resolves to the Worker itself again.Patch Changes
#15891
8dc53aeThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
Updated dependencies [
8dc53ae,4c2993b]:v4.141.0Compare Source
Minor Changes
#15658
8280086Thanks @jqmmes! - Add Durable Objects code update strategies to Worker deploymentsUse
--durable-objects-code-update-mode immediatewithwrangler deploy,wrangler versions deploy, andwrangler rollbackto update code without waiting for active instances to hibernate. Use--durable-objects-code-update-mode deferred 30sto set a maximum delay, or configuredurable_objects.code_update_strategywithmodeandmax_delay. When unset, the strategy defaults to deferred with a 5-minute maximum delay; delays cannot exceed 24 hours and must use millisecond precision.#15800
bd56b98Thanks @Refaerds! - Add Browser Run as an event source for Queue subscriptionsYou can now create Queue subscriptions with
--source browserRun.Patch Changes
#15864
ee2b200Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15207
805af2fThanks @exKAZUu! - Show the stack and cause of failed proxied requests inwrangler devdebug logsWhen a request proxied to the local Worker fails, running with
--log-level debugnow shows the underlying error's stack and cause chain.Updated dependencies [
ee2b200,c91279b]:v4.140.0Compare Source
Minor Changes
8f7916cThanks @GregBrimble! - Support Containers in Worker Preview deployments with the Build Output.Patch Changes
v4.139.0Compare Source
Minor Changes
#15792
479e1e8Thanks @flakey5! - Configure SSH for experimental Durable Object-managed ContainersSet
containers[].sshandcontainers[].authorized_keyswhen usingscheduling_policy: "durable_object". These are application-wide settings that follow the same rules as the existing Durable Object-managed Container settings: normal deployments create missing applications and update explicitly configured values, while omitted settings preserve the existing application configuration.#15648
52c0e9fThanks @tpmmorris! - Expose configured Cron Triggers to local development consumersWrangler now passes the active environment's exact Cron Trigger expressions to Miniflare so Local Explorer can display them. Headless agent sessions also advertise the Local Explorer scheduled invocation API.
#15786
bdda4c3Thanks @ThomasRubini! - Support UDP connect handlers in local developmentThe experimental
connectconfiguration now acceptsprotocol: "udp", with optionalidle_timeout_msandmax_pending_bytessettings. UDP datagrams are delivered to the Worker'sconnect()handler using workerd's value-mode socket streams, and can be tested withMiniflare#dispatchConnect({ protocol: "udp" }).#15779
fc3cbaaThanks @Naapperas! - Supportworkflowentries in theexportsconfiguration mapA Worker can now declare the Workflows it defines in
exports, keyed by theWorkflowEntrypointclass name:A
workflowexport accepts the same settings as aworkflowsbinding:limits,concurrency,schedules, anddefault_retention.wrangler deployandwrangler versions uploadsend these entries to the upload API by name, andwrangler deployandwrangler triggers deployprovision the Workflow with its settings, just as they do forworkflowsbindings owned by the Worker. A Workflow may be declared both as a binding and as an export, as long as both declarations use the same class and do not set the same setting to different values. A binding to another Worker's Workflow cannot share a name with an export.@cloudflare/configadds the matchingexports.workflow()helper. Local development does not yet act on these entries.Patch Changes
#15796
be72815Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#14847
940c692Thanks @TheSaiEaranti! - Emulate the deterministic-ID uniqueness contract in the local Workflows bindingThe local Workflows binding now matches the documented production behavior for deterministic instance IDs:
create({ id })with an ID that already exists throws(instance.already_exists)and retains the existing instance, andcreateBatch()skips IDs that already exist or repeat within the batch, excluding them from the result instead of creating duplicate executions. Previously both paths silently created duplicates, so code relying on deterministic IDs for idempotency (for example a Queue consumer creating one workflow per message) appeared to work locally while double-executing workflow bodies.#15803
cd60c9cThanks @pmiguel! - Show--jurisdictionin help forwrangler kv namespace createThe option was supported but omitted from the command's help output. Users can now discover how to create KV namespaces in a specific jurisdiction.
#15838
15799d4Thanks @oddharsh! - Updatesmol-tomlto 1.9.0 to fix slow parsing of very large TOML filesParse time for TOML config files now grows linearly with their size, instead of with its square: a 40,000-line file that took 259 ms to parse now takes 17 ms, while typical
wrangler.tomlfiles parse in the same time as before. This addresses theGHSA-r4xh-jqrq-34v2advisory against earlier versions of the parser.Some TOML syntax errors now point at the character that caused them. For example, a
wrangler.tomlcontainingINVALID "FILEis now reported asillegal character in keyat the", rather thanincomplete key-valueat the start of the line.Updated dependencies [
52c0e9f,44f5295,be72815,940c692,bdda4c3,fc3cbaa]:v4.138.0Compare Source
Minor Changes
#15776
b03f960Thanks @edevil! - Add event-code support to temporary Worker deploymentsUse
wrangler deploy --temporary --event-code <code>to provision an account for an event. Wrangler requires explicit server acknowledgement before caching the account and keeps the event code out of its cache and telemetry.#15817
6e77c53Thanks @jamesopstad! - Allow framework commands to produce Preview Build Output with the experimental configWhen
cf previews deployinvokes a framework build command, Preview intent is now preserved. Function-basedcloudflare.config.tsfiles receiveisPreview: true, and generated Build Output is marked as a Preview build.Patch Changes
#15806
8fade73Thanks @NuroDev! - Standardize Zod validation error outputFormat validation errors with Zod's built-in
prettifyError()helper so Miniflare, Wrangler, the Vite plugin, and the Vitest plugin show consistent messages and property paths.Updated dependencies [
a71237a,8fade73]:v4.137.0Compare Source
Minor Changes
#15778
cd7508cThanks @jamesopstad! - Generate types during development and supported builds with Vite'sexperimental.newConfigoption or Wrangler's--experimental-new-configflag (and--experimental-cf-build-outputfor builds)When Wrangler's
--experimental-new-configflag or Vite'sexperimental.newConfigoption is enabled, inferred configuration and runtime declarations are now kept in.cloudflare/types/index.d.ts. Vite refreshes them during development and production builds. Wrangler refreshes them during development and when building with both--experimental-new-configand--experimental-cf-build-output. In the experimentalwrangler.config.tsformat, thetypesoption is now top-level because it applies to both commands.Patch Changes
#15765
1bdb96dThanks @th0m! - Prepare the required egress sidecar for local Containers without configured imagesWrangler dev and Vite dev/preview now pull the required sidecar for Durable Object-managed Containers that select their application image at start time. Previously, these Containers failed to start unless the sidecar image was already cached in Docker.
#15712
f5605f5Thanks @alsuren! - Match D1 SQL statement splitting to the local SQLite runtimeWrangler now uses SQLite's statement-completion state machine when splitting D1 SQL files. This keeps trigger, quoted identifier, comment, and keyword handling consistent with local execution.
v4.136.3Compare Source
Patch Changes
#15662
59267fcThanks @oddharsh! - Updatesmol-tomlto 1.8.0This updates the bundled TOML parser that reads
wrangler.tomlto a version that addresses two advisories against 1.5.2:GHSA-7w5x-hrqm-74c2(a value followed by a comment with no trailing newline, such asa=[1 #, put the parser in an infinite loop) andGHSA-v3rj-xjv7-4jmq(thousands of consecutive comment lines overflowed the stack). On the old version,wrangler deployagainst awrangler.tomlending ina=[1 #never returned; it now fails withInvalid TOML document: cannot find end of structure.#15760
6906bf0Thanks @yomna-shousha! - Warn whenwrangler previewreturns only non-custom-domain URLs even though custom-domain Preview URLs are configured.#15761
354ebdbThanks @podonnell-dev! - Fix Preview output artifacts to always include the resolved parent Worker namePreview artifacts now use Wrangler's resolved Worker name instead of relying on the Preview API response to include it.
Updated dependencies []:
v4.136.2Compare Source
Patch Changes
#15762
ad20547Thanks @podonnell-dev! - Fixwrangler typesgenerating runtime headers with trailing whitespaceRuntime type headers without compatibility flags now end at the compatibility date, keeping generated types reproducible when tools remove trailing whitespace.
#15703
02c1d83Thanks @KianNH! - Improve Container image listing and deletionList all image pages using read-only credentials, validate tags before deletion, and report successful deletion when the garbage-collection request fails.
#15700
275184dThanks @KianNH! - Fix Container SSH connection setup and shutdownPrevent SSH connections from stalling during setup and ensure proxy processes exit when sessions close.
#15759
bd59ecaThanks @petebacondarwin! - Show validsha256-prefixed tags in Container image listingsContainer image listings now distinguish valid OCI tags such as
sha256-releasefrom synthetic digest entries such assha256:<digest>.Updated dependencies []:
v4.136.1Compare Source
Patch Changes
#15744
0ed4c54Thanks @podonnell-dev! - Improvewrangler previewonboarding guidanceWrangler now displays placeholder replacement guidance directly beneath the suggested Preview configuration instead of as a separate warning. JSON output continues to include the guidance in its structured onboarding messages.
#15678
703922dThanks @christhorwarth! - Read workers.dev URLs from the Worker resource during deploymentWrangler no longer requires account-level subdomain permission to display Worker and version-preview URLs. It now uses the Worker-scoped URL fields while preserving account-level registration for accounts without a workers.dev subdomain.
Updated dependencies [
14d946d]:v4.136.0Compare Source
Minor Changes
#15713
3c75cadThanks @jamesopstad! - Identify experimental Build Output resource configs by filename and locationThe root remains
config.json, Worker configs are nowworker.config.json, and Container configs are nowcontainer.config.json. Resource configs no longer contain top-leveltypediscriminators, while settings and build context are stored together in the root config.#15713
3c75cadThanks @jamesopstad! - Define experimental Cloudflare configuration with a single default exportExperimental
cloudflare.config.tsfiles now define settings and resources together in a default-exporteddefineConfig()call. Add a Worker underworker, add Containers to thecontainersarray, or omit both to provide settings only.#15720
35668d7Thanks @alexkli! - Add experimental--zoneand--zone-idflags towrangler deployandwrangler triggers deployto attach a zone to routes passed via--routeRoutes passed on the command line were always sent to the Cloudflare API as bare patterns. Zones with an SSL for SaaS entitlement reject such routes with error 10082 ("When using wildcard host ssl for saas entitlement you must specify the zone per route using zone_id or zone_name"), and until now the only way to set a zone was in the config file, which
--routeoverrides.The new flags are experimental and must be enabled with
--experimental-route-zones(alias--x-route-zones). Pass a single zone to apply it to all routes, or one zone per route in the same order as the--routeflags:wrangler deploy --x-route-zones --route "app.example.com/*" --route "api.example.com/*" --zone example.comwrangler deploy --x-route-zones --route "a.example.com/*" --zone example.com --route "b.example.net/*" --zone example.net--zonesetszone_nameand--zone-idsetszone_idon each route. The two flags cannot be combined, and passing more than one zone requires exactly one per--route. Routes without zone flags behave exactly as before.#15699
45b3b81Thanks @skepticfx! - Remove the experimental Container image environment bindingDurable Object-managed Containers now use
ctx.container.imageswithout Wrangler generatingenv.EXPERIMENTAL_CLOUDFLARE_CONTAINER_IMAGES. Update code using the experimental environment binding to readctx.container.imagesand regenerate your Worker types.Version deployments identify managed applications from native named images, and
--containers-rollout=nonepreserves native Container metadata. Containers without named images must first be provisioned withwrangler deploy;versions uploadverifies that their applications already exist. The old binding is no longer read or reserved, including on previously uploaded versions.keep_varsretains existing variables as usual; redeploy without it to remove an existing experimental binding.#15702
8235e6aThanks @podonnell-dev! - Return structured configuration errors fromwrangler preview --jsonWhen a Worker is missing its Preview configuration, JSON mode now returns an
error, asuggested_configpatch, and any associated onboardingmessageswithout interactive output or terminal formatting. This changes the private-beta Preview command to make automated onboarding reliable.#15577
731a2eeThanks @sdnts! - Add support for jurisdictions to Queues subcommandsPatch Changes
#15711
91e2f86Thanks @ghostwriternr! - Allow local Container images without exposed portsWrangler and the Cloudflare Vite plugin no longer reject images that omit Docker
EXPOSEmetadata. Local Containers can run command-only workloads or serve traffic through workerd without declaring an unused image port.#15740
c5913a6Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15471
0751490Thanks @edmundhung! - Fix cf builds for static projects that serve assets from the project rootThe experimental Build Output path now omits the reserved
.cloudflaredirectory when the project root is used for static assets. This prevents recursive output copying in Wrangler while preserving the existing behaviour for other asset directories.#15440
43b1f85Thanks @HuzaifaAbdulRehman! - Rebase absolute non-JavaScript module specifiers whenpreserve_file_namesis enabledWith
preserve_file_namesset, a non-JS module imported by an absolute path kept that path as its module name. The build machine's filesystem layout ended up inside the deployed Worker, and the module was never written to--outdir. A local dry run reported success while the upload failed server-side with error code10021. Tooling that rewrites externals to absolute paths hits this, which is how it was found in@opennextjs/cloudflarewith WASM imports.Absolute specifiers are now rebased to
./<basename>, which is what the hashed branch of the same code already does minus the hash prefix. Relative specifiers keep the behaviour they had.Updated dependencies [
c5913a6,3c75cad]:v4.135.0Compare Source
Minor Changes
#15609
1f070c8Thanks @emily-shen! - Build Containers when emitting experimental Build OutputWrangler and the Cloudflare Vite plugin now build Dockerfile-backed Container images when experimental Build Output is enabled. Container configs are emitted under
.cloudflare/output/v0/containerswith local image references, while existing registry references pass through unchanged.#15329
c4c9b75Thanks @akshitsinha! - Evaluate Flagship flags locally during developmentFlagship bindings now use the local Miniflare store by default in Wrangler and the Vite plugin, keeping development offline and isolated from production flags. Set
remote: trueon a binding to continue using its remote app.Use
wrangler flagship flags pull <APP_ID>to seed the store from a remote app. Flag management commands also accept--localto read and update the local store directly.#15701
643e5ccThanks @WillTaylorDev! - Pass Preview intent todefineWorkerand upload its resolved configurationPreview builds now evaluate programmatic Worker configuration with
ctx.isPreviewset totrueand record that intent in Build Output. The shared Preview uploader deploys the resolved bindings and settings while preserving configured Preview base values when it creates a Preview.Patch Changes
#15705
a0485d5Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15587
629ddefThanks @Kuldeeep18! - Fix duration calculation for running workflow instances, steps, and attempts inwrangler workflows instances describewrangler workflows instances describepreviously distorted the elapsed duration of in-progress instances, steps, and attempts across non-UTC timezones by stripping" GMT"fromtoUTCString(), causingnew Date(...)to parse the timestamp in the local client timezone. The duration is now correctly computed against the current time.Updated dependencies [
a0485d5]:v4.134.0Compare Source
Minor Changes
#15684
6874aa9Thanks @Ankcorn! - Add support for configuring real-time Issues withobservability.issues.enabledWrangler now validates and uploads the Issues setting alongside the existing logs and traces observability options. The experimental configuration format supports the equivalent
observability.issues.enabledoption.#15681
d96b319Thanks @podonnell-dev! - Markwrangler previewcommands as open betaWrangler now labels Preview commands as open beta in help output and command warnings, matching the feature's public availability.
#15673
2b39fc2Thanks @ghostwriternr! - Support explicit named Container image selection in Wrangler local developmentWrangler builds or pulls named images configured through Wrangler JSON or TOML and exposes their local tags through
ctx.container.images. Pass one of those references toctx.container.start({ image })to select the image.This extends the experimental Durable Object-managed Containers interface. Named images are opt-in and do not become the Container's default image. A Container without a default image must supply an image or full Container snapshot when starting.
Patch Changes
#15689
876eea1Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
Updated dependencies [
2298cf1,876eea1]:v4.133.0Compare Source
Minor Changes
#15600
bac0c6aThanks @podonnell-dev! - Add placement configuration for PreviewsYou can now configure
placementin thepreviewsblock. Preview-specific placement overrides the top-level placement configuration for Preview Defaults and deployments.#15600
bac0c6aThanks @podonnell-dev! - Improve onboarding guidance for Previews (whenpreviewsblock is missing from configuration file)When a local
previewsblock is absent, Wrangler writes the Preview Base configuration to the local config file. When no Preview Base configuration exists, Wrangler prints a placeholder configuration derived from production bindings and warns against reusing production binding configuration.Patch Changes
#15483
71b6f10Thanks @tpmmorris! - Align Local Explorer Workflow instance status requests with productionLocal Explorer and Wrangler local mode now use the production-compatible
statusrequest field for pausing, resuming, restarting, and terminating Workflow instances. Direct Local Explorer API consumers must replace the previousactionfield withstatus.Successful Local Explorer status updates now return the production-compatible instance
statusand responsetimestampinstead of the local-onlyresult.successacknowledgement.#15665
ad23e6eThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15655
be2437aThanks @WillTaylorDev! - Send exports with Worker Preview deploymentswrangler previewdropped theexportsblock from deployment requests. Durable Objects reached throughctx.exportshad no Preview namespace, and cache settings for each entrypoint were lost too.Updated dependencies [
71b6f10,ad23e6e,6f3d7b5]:v4.132.0Compare Source
Minor Changes
#14587
76c0ce6Thanks @MattieTK! - Categorise the positional path argument towrangler deployandwrangler versions uploadin command telemetryCommand telemetry now records a coarse category for the entry-point/assets positional (
wrangler deploy <path>) undersanitizedArgs.path, so we can understand whether people pass a file, a directory, or a relational reference such as.or../example. The possible values arefile,directory,current-dir,parent-relative, andnot-found, ornullwhen no positional is provided. The raw path is never sent — only the category.#15597
a83d7acThanks @skepticfx! - Configure application-wide logs for experimental Durable Object-managed ContainersSet
containers[].observability.enabledorcontainers[].observability.logs.enabledwhen usingscheduling_policy: "durable_object". Normal deployments create missing applications and update explicitly configured log settings without a Container rollout. Omitted settings preserve the application configuration; root Worker observability is not inherited for this policy.Version uploads may initialize missing applications but preserve existing settings. Deploying or rolling back Worker versions also preserves existing application settings, and
--containers-rollout=noneskips their updates.#15597
a83d7acThanks @skepticfx! - Support per-image build options for experimental Durable Object-managed ContainersSet
build_contextandbuild_varsalongsidedockerfilein a Container's namedimagesentries. Context paths resolve relative to the Wrangler configuration file and default to the Dockerfile's directory. Build variables are passed as Docker build arguments. Entries using the same Dockerfile with different contexts or variables are built separately.#15638
fa79b26Thanks @G4brym! - Support AI Search bindings in Worker Previewswrangler previewnow acceptsai_searchandai_search_namespacesentries in thepreviewsblock and includes them in Preview deployment bindings. This lets Workers that use AI Search instance or namespace bindings attach existing resources to Preview deployments, including preview-specific instance or namespace names.These bindings are non-inheritable: declare them explicitly under
previews. They attach to existing AI Search resources; preview does not provision new isolated instances or namespaces.#15256
16d1310Thanks @theoephraim! - [private beta]: Add--secrets-fileand--varflags towrangler previewLike
wrangler deployandwrangler versions upload,wrangler previewnow accepts a--secrets-fileflag pointing to a JSON or .env format file, and--var KEY:VALUEpairs that are injected into the Preview deployment as plain text variables. CLI vars override same-named vars from thepreviewssection of your config file, and secrets from the file take precedence over both:wrangler preview --secrets-file .env.preview --var API_URL:https://api.example.com#15453
ca71205Thanks @G4brym! - Remove the gated Web Search binding and Wrangler commandThe unreleased search binding and its experimental command have been removed from Wrangler, Miniflare, and configuration APIs.
#15597
a83d7acThanks @skepticfx! - Allow experimental Durable Object-managed Containers to link by name through exportsContainers using
scheduling_policy: "durable_object"can now specifynameand link fromexports.<Class>.containerwithout repeatingclass_name. Deploy and version upload resolve that link for image preparation, Worker metadata, and Container application creation.Patch Changes
#14775
1be7b97Thanks @dario-piotrowicz! - Sync Local Explorer endpoint lists across agent hintsThe Local Explorer endpoint list is now consistent across the three places it appears: the AGENTS.md template in
create-cloudflare, the runtime agent hint inwrangler dev, and the Vite plugin agent hint. All three now include theobservability/clearendpoint, use the canonical/cdn-cgi/local/explorerpath, and have cross-reference comments pointing to each other.#15409
b149147Thanks @tpmmorris! - Fix per-query overrides forwrangler ai-search search--score-threshold,--max-num-results,--filter, and--rerankingare now sent using the AI Search request schema, so the service applies them to searches instead of ignoring them.#15633
7db596cThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#14906
a0856daThanks @exKAZUu! - Surface the original error message, name and stack when the dev server reports an internal errorPreviously
wrangler devcould exit with an empty✘ [ERROR]log that gave no indication of what went wrong (e.g.Network connection lost., see #14641). These errors now include their original message, name and stack, so the failure is actually diagnosable.#15179
cb0955fThanks @rioaguspermana! - Treat 502, 503, and 504 as gateway errors during asset upload retriesPages and Workers asset uploads now retry more patiently when the Cloudflare API responds with a 502, 503 or 504 gateway error, reducing concurrency and waiting longer between attempts instead of failing the deploy quickly.
#15399
982b806Thanks @tpmmorris! - Improve over-limitrun_worker_firsterrors when duplicate rules are presentThe error now reports distinct and duplicate-entry counts and lists duplicated rules, making it clear when removing redundant entries can bring the configuration within the limit.
#12369
ffabe74Thanks @43081j! - Replaceexecawithtinyexecfor running subprocesses, shrinking the bundled Wrangler output.#15633
7db596cThanks @dependabot! - Preserve service-worker middleware error propagation with spec-compliant event dispatchWrangler's synthetic service-worker events now propagate listener exceptions to middleware without changing the behavior of user-created
EventTargetinstances.#15400
e03822aThanks @james-elicx! - Reduce the size of Wrangler's published packageExclude test-only, build-only, and obsolete template files from the npm package while retaining all runtime templates.
#15631
c4a6279Thanks @petebacondarwin! - Restore static asset upload concurrency after gateway errorsStatic asset uploads previously remained at concurrency one for the rest of the deployment after any 524 response, which could make large deployments exceed the upload session lifetime. Successful uploads now restore the session's original concurrency gradually while retaining gateway throttling. Requests that were already in flight when throttling began do not restore capacity, so a burst of stale successes cannot immediately undo backpressure.
Updated dependencies [
7db596c,e35c4a1,d3565a5,ca71205,1015cfb,982b806,641df47]:v4.131.2Compare Source
Patch Changes
8997652]:v4.131.1Compare Source
Patch Changes
#15592
945aaa3Thanks @WillTaylorDev! - Add a provisioning delay note when custom domain Preview URLs changeWrangler now explains that DNS and TLS certificate provisioning may continue after a deploy adds a custom domain or enables its Preview URLs. Stable redeploys don't repeat the note.
This assumes that a request which matches the stored custom domain state doesn't restart provisioning. The client infers this from the API changeset and current domain record because this repository can't verify the backend behavior.
#15592
945aaa3Thanks @WillTaylorDev! - Clarify production status labels for custom domain routesWrangler now prefixes explicit custom domain production states with
production:so they match Preview labels. The updated labels appear in deployed trigger output andWRANGLER_OUTPUT_FILE_PATH.#15602
47d906fThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15592
945aaa3Thanks @WillTaylorDev! - Avoid replacement prompts for custom domains already on the WorkerWrangler now updates Preview settings without asking to replace a custom domain when that domain already belongs to the deployed Worker. It still asks before replacing domains attached to another Worker.
#15592
945aaa3Thanks @WillTaylorDev! - Explain how to enable Preview URLs when a Preview deployment has nonewrangler previewnow shows URL shapes and configuration snippets for Workers.dev and custom domains. The custom domain snippet preserves every configured route, and the guidance distinguishes missing settings from disabled ones.This changes a private beta feature. The warning also makes clear that
wrangler deploypublishes code from the current checkout.Updated dependencies [
47d906f,c2699bf]:v4.131.0Compare Source
Minor Changes
#15480
36aed7fThanks @skepticfx! - Add Durable Object-managed Containers to top-level container configurationWrangler now accepts
scheduling_policy: "durable_object"in the top-levelcontainersarray and creates its namespace-backed application after the Worker upload resolves the Durable Object namespace ID. The namespace ID is also the application ID, so repeated deploys idempotently ensure the same application without name-based lookup, modification, or a Containers rollout.Durable Object-managed entries accept
class_name,scheduling_policy, an optionalname, and an optional namedimagesmap. Scheduler-only fields are rejected. Each image provides either a localdockerfileor a digest-pinned managed-registryimage. Wrangler builds or resolves each image, waits while Cloudflare prepares it for the Containers runtime, and uploads the resulting references with the Worker version for access throughctx.container.imagesandenv.EXPERIMENTAL_CLOUDFLARE_CONTAINER_IMAGES. Local development support for these entries is deferred to a follow-up.Existing scheduler-backed entries and Durable Object migrations continue to work unchanged.
With
--containers-rollout=none, existing Workers retain their deployed Container metadata and image binding even when localcontainersis omitted or empty; local scheduler edits are also ignored. The upload stops if the deployed versions cannot be recovered. Existing Workers for Platforms dispatch scripts reject this flag before upload because their API does not expose enough metadata to preserve Container associations safely. First deployments can still skip Container preparation and rollout. Without this flag, removing managed Containers, including by omittingcontainersentirely, clears the experimental image binding even withkeep_vars.versions deployvalidates the selected versions before changing traffic and creates their Durable Object-managed applications only after deployment succeeds. Bothdeployandversions deployreport partial completion if application creation fails afterward, with instructions to retry the same command.EXPERIMENTAL_CLOUDFLARE_CONTAINER_IMAGESis a temporary, reserved Wrangler binding until native Container image metadata is available. Its class keys identify managed applications duringversions deploy, including classes with empty image maps. User configuration cannot declare a binding with this name; existing versions that already use it are treated as Container configuration.#15493
493e635Thanks @GregBrimble! - Removewrangler preview settingscommandsThe private-beta
wrangler preview settingsandwrangler preview settings updatecommands are no longer available.Patch Changes
#15411
0b43395Thanks @xgame92! - Failwrangler versions uploadearly when a Worker has a pending Durable Object migrationWrangler now directs users to run
wrangler deployto apply the migration instead of sending a version upload request that the API will reject.#15518
9d75006Thanks @taylorlee! - Detect named-only module Worker entrypoints correctlyWrangler now distinguishes named-only module Workers from legacy Service Workers that happen to have named exports. A default export identifies a module Worker; otherwise, legacy
addEventListenerregistration identifies Service Worker format.#15581
b605aa6Thanks @MattieTK! - Correct Pages-to-Workers delegation analytics for forced and ineligible commandsThe legacy
forcedresult counted every agent-driven Pages command using--force, including commands that could never have been delegated. Wrangler now emitseligible_forcedonly when--forceprevents an otherwise eligible delegation, and records other agent commands asineligiblewith a bounded reason and whether force was used.#15432
f45b596Thanks @razethion! - Prevent delayed internal errors from fetch-only remote bindingsFetch-only remote bindings such as D1 and R2 previously opened an unused WebSocket RPC session. RPC sessions are now created only when an RPC method is called.
#15585
f69f95aThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15554
bff525dThanks @XiaoZ-0218! - Add the missingtransferred_classesmigration to the config schemaDurableObjectMigrationdescribednew_classes,new_sqlite_classes,renamed_classesanddeleted_classes, but nottransferred_classes.normalizeAndValidateConfighas always validated that key, and the deploy path forwards it to the API along with the rest of the step, so Transfer migrations worked — butconfig-schema.jsonis generated from the type, so an editor resolving$schemareported a valid, documented migration as an unknown key.Adding the field to the type puts it in the generated schema. No runtime change.
#15584
96688b3Thanks @Svector-anu! - Bumpshell-quoteto 1.9.0+ to pick up two disclosed advisoriesshell-quote@1.8.1is affected by a ReDoS inparse()(CVE-2026-13311 / GHSA-395f-4hp3-45gv — an unauthenticated attacker who can feed a string intoparse()can block the event loop for tens of seconds with plain space-separated input, no shell metacharacters required) and by an object-token escaping bug inquote()(CVE-2026-9277 / GHSA-w7jw-789q-3m8p), both fixed upstream in1.9.0. Wrangler'sparse()wrapper (src/utils/shell-quote.ts) is reachable frompages dev/initcommand-line parsing, so the ReDoS applies; thequote()call site only ever passes string arguments, so the object-token issue was not reachable here, but there is no reason to stay on a vulnerable range once a patch exists.#15563
ed5797aThanks @Bortlesboat! - Encode filenames in Pages HTML redirectsFix
wrangler pages devreturning a 502 response when redirecting HTML paths containing Unicode characters. Keep reserved characters in filenames encoded in the redirect destination and preserve the request query string.#14889
128235aThanks @chinesepowered! - Fixwrangler types --strict-vars=falseemitting invalid TypeScript for an empty array varA var whose value was an empty array produced
()[], which is a syntax error. Because this lands in the generatedworker-configuration.d.ts, it did not just break that one line — the whole file failed to parse, so no binding types resolved at all. An empty array now generatesunknown[].#15494
f8aea7eThanks @GregBrimble! - Usepreviews_base_configfor Preview configurationPreview commands now read the Worker Previews Base configuration from the
previews_base_configAPI field.#15569
24ef86bThanks @RealBhupesh! - Fixwrangler workflows instances describecrashing on dynamic retry delaysThe Workflows API serializes function retry delays as
"[dynamic]". The describe command previously parsed that as a duration, produced an Invalid Date, and threwRangeError: Invalid time valuebefore printing remaining steps. It now rendersunknown (dynamic delay)and also tolerates attempts whoseendtimestamp is missing.Updated dependencies [
f45b596,f69f95a,a549e58,dbb3ff4,fea3cd0,6bd7b6c,15cd6e1,be1caec,dbc9506]:v4.130.0Compare Source
Minor Changes
#14372
dbf6aadThanks @ichernetsky-cf! - Addcontainers[].observabilitysupport towrangler deployWrangler now accepts container-specific observability settings via
containers[].observability, including application-level targeting fields for Containers. Rootobservabilitycontinues to work as a fallback when a container does not define its own observability settings.wrangler deploynow preserves legacyconfiguration.observabilityfor existing container apps that still use rollout-based observability, while using top-level application observability for new or already-migrated apps.Existing application diffs are now normalized even when stored resource limits cannot be mapped to a named instance type. API-only metadata and equivalent managed-registry image names no longer appear as edits or affect whether deployment changes require a rollout.
#15004
e20df20Thanks @MattieTK! - Delegate agent Pages project creation with a production branch to WorkersWhen run by an AI agent,
wrangler pages project create --production-branch <name>is now eligible for delegation to a Workers static-assets deploy. The production branch names the target that a Workers deploy would publish to, so it does not need to disqualify a brand-new project from delegation.wrangler pages deploy --branch <name>remains on Pages because an interactive new-project flow separately prompts for its production branch. The deployment branch may therefore represent a preview and cannot safely be converted into a production Workers deployment.#15004
e20df20Thanks @MattieTK! - Widen agent Pages-to-Workers delegation to new projects on accounts that already use PagesWhen run by an AI agent,
wrangler pages deployandwrangler pages project createnow delegate a brand-new static Pages project to a Workers static-assets deploy even when the account already has other Pages projects. The gate is now per-project rather than per-account: a command targeting a project that already exists stays on Pages, but a new project is delegated regardless of the account's other Pages projects.A project name restored from the Pages configuration cache is only used when the cache belongs to the currently authenticated account. An account-matching cached name remains on Pages even when the project is missing remotely, preserving the user's recorded Pages intent. After switching accounts, an otherwise unnamed deploy stays on Pages rather than treating a stale cached project name as a new project on the selected account.
Patch Changes
#15560
edb3631Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15557
63c7ff1Thanks @tomekancu! - Fixwrangler d1 execute --localbeing extremely slow with large SQL files or commandsThe local SQL splitter consumed quoted strings and comments character-by-character, re-checking the full accumulated string each time. This made splitting a large quoted value or comment quadratic, so seed files could take tens of seconds to run. The splitter now only inspects a bounded trailing window on each step, making splitting effectively linear. The remote path is unaffected as it imports the file server-side.
#15542
a4e41dfThanks @NAVEENKUMARKR777! - Fixwrangler devrunning the custom build command twice on startup and on every config changeWrangler already runs the custom
build.commandonce before startingwrangler dev, to resolve the Worker's entry point. Whendev.watchwasn't explicitly disabled,BundlerControllerthen unconditionally ran the same build command again the moment it started watching for changes, and repeated this on every subsequent config reload too.For fast build commands this just meant duplicate log output (e.g. a
vite buildvisibly running twice at startup). For slower or stateful build commands, running two builds concurrently against the same output files could corrupt the result or fail outright (for example, non-deterministicwasm-optfailures have been reported for Rust builds).The initial watcher setup now only bundles the output the build command already produced, instead of re-running the command. Real file changes detected by the watcher still re-run the build command as before.
Updated dependencies [
edb3631,bcebf08]:v4.129.1Compare Source
Patch Changes
#15502
8bbcb9fThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15543
2b42d6fThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15323
ea5634eThanks @Sakshamm-Goyal! - Prevent Wrangler from exiting when a process capturing its output closes the pipe.Wrangler now ignores broken-pipe errors from stdout and stderr while preserving the existing failure behavior for other output errors.
#14001
c0c6504Thanks @for-the-kidz! - Update bundle size warning thresholds to use uncompressed size instead of gzip sizeThe compressed script size limits (3 MiB free / 10 MiB paid) have been removed server-side in favor of a single 64 MiB uncompressed limit. The bundle size reporter now compares the uncompressed bundle size against this 64 MiB limit for its color-coded warnings, instead of comparing gzip size against the old 3 MiB compressed limit.
#15499
ffc7efdThanks @WillTaylorDev! - Honor Workers Builds name overrides inwrangler previewPreview commands now target the Worker name supplied by Workers Builds instead of the name in local Wrangler configuration. This prevents preview builds from failing when the two names differ.
#15252
682cd44Thanks @GregoryCollett! -wrangler devno longer exits when a request to your Worker fails transientlyPreviously, a transient network failure on a single request — most commonly a request arriving just as an idle internal connection was closed, after roughly five seconds without traffic — could take down the whole dev server with an empty
✘ [ERROR], leaving the port unbound until restarted. In CI test suites, one such failure caused every remaining test to fail with connection errors.wrangler devnow automatically retries the affected request if it is safe to repeat (GET and HEAD requests). If a request still fails, it fails individually — the error is logged with the request method and URL — and the dev server keeps serving.Updated dependencies [
8bbcb9f,2b42d6f]:v4.129.0Compare Source
Minor Changes
#15460
93d72a5Thanks @QnJ1c2kNCg! - Support gzip compression for JSON Pipelines sinksPipelines is in open beta.
wrangler pipelines sinks createand the interactive setup flow now pass the selected JSON compression to the Pipelines API. JSON sinks acceptuncompressedorgzip, while Parquet retains its existing compression options andzstddefault.#15358
d2d8eeaThanks @pombosilva! - Add a--jsonflag to thewrangler workflowscommandsEvery
wrangler workflowscommand now accepts--json, which emits the raw API payload instead of the human-readable rendering. The formatted output remains the default, so existing usage is unaffected:wrangler workflows instances list my-workflow --jsonThe JSON output carries raw values rather than a serialisation of the formatted view: ISO timestamps instead of locale-formatted dates, plain status strings instead of emojified labels, and no presentation-only derived fields.
Patch Changes
#15469
d40a634Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15481
7c1b2a6Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15472
f6fb347Thanks @emily-shen! - Tolerate missing permissions duringwrangler deletecleanup checkswrangler deletenow warns and continues when it cannot inspect Worker dependencies or clean up legacy Workers Sites KV namespaces because of missing permissions. The Worker delete request itself still fails normally if the token cannot delete the Worker.#15472
f6fb347Thanks @emily-shen! - Tolerate missing resource permissions during resource provisioningWhen Wrangler cannot check whether a bound resource exists because the API returns a 403, it now skips automatic provisioning for that resource type and continues the deploy. The deploy may still fail later if the resource is missing.
#15476
dc24057Thanks @christhorwarth! - Fix remote development with static assets for API tokens using granular Worker permissionsWrangler now creates Workers.dev preview sessions through the Worker-scoped endpoint and derives the preview hostname from the session response. This avoids requiring account-level Workers subdomain access.
Updated dependencies [
00a9f2f,1dba24a,d40a634,7c1b2a6]:v4.128.0Compare Source
Minor Changes
#15454
dbbb795Thanks @jamesopstad! - Move binding utilities into@cloudflare/workers-utilsBinding conversion, printing, and local-development validation are now exported from
@cloudflare/workers-utilsso they can be shared by Wrangler, the Cloudflare Vite plugin, and other consumers.The corresponding exports have been removed from
@cloudflare/deploy-helpers. Consumers should import them directly from@cloudflare/workers-utilsinstead.Wrangler's
unstable_printBindingsAPI now accepts the bindings and an options object instead of five positional parameters.#15353
87a7acfThanks @pombosilva! - Add--date-startand--date-endfilters towrangler workflows instances listYou can now narrow an instance listing to a creation-time window:
wrangler workflows instances list my-workflow --date-start 2026-01-01 --date-end 2026-01-31Either flag can be used independently. Both accept an ISO 8601 date or timestamp and are normalised to UTC before being sent, so a date-only value such as
2026-01-01works as well as a full2026-01-01T13:00:00Z. The bounds are inclusive and compose with the existing--statusfilter.#15379
ea28cc3Thanks @ibbykhazanchi! - Add query string redaction to Workers observability configurationSet
observability.redact_query_stringinwrangler.jsonorobservability.redactQueryStringin the experimentalcloudflare.config.tsformat to remove query strings from request URLs in logs and traces.#14915
707cb6fThanks @longlho! - Include exact raw and gzip-compressed Worker bundle sizes in structureddeployandversion-uploadoutput.Patch Changes
#15436
200780fThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15406
b3f2628Thanks @james-elicx! - Reduce the installed bundle sizes of Wrangler and MiniflareWrangler now resolves bundled workspace dependencies from source during monorepo builds so unused exports can be removed. Miniflare, its shared CLI and container dependencies now use granular
@cloudflare/workers-utilsentry points instead of loading the package barrel, reducing the raw Wrangler and Miniflare artifacts by 6.16 MiB (31.4%) and 1.06 MiB (22.9%) respectively without changing runtime behavior or installed dependencies.#15398
1809c5eThanks @james-elicx! - Reduce Wrangler's published package sizeStop including the unused build metafile in the npm package, reducing its unpacked size by approximately 3.1 MiB.
#15382
b3fb2bfThanks @Om-singhaI! - Skip the skills install status lookup when telemetry is disabledTelemetry events include a
currentAgentSkillsInstalledproperty, and computing it can query the GitHub API. The lookup used to start before the telemetry permission was checked, so users who opted out viaWRANGLER_SEND_METRICS,DO_NOT_TRACK, orsend_metricsin their Wrangler config still triggered network requests on behalf of telemetry. The dispatcher now checks the permission first and only performs the lookup when telemetry is enabled.Updated dependencies [
200780f,b3f2628,87a7acf]:v4.127.1Compare Source
Patch Changes
#15383
eb01850Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15393
e1df91aThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
Updated dependencies [
eb01850,e1df91a,b23de74,015550a,015550a,015550a,3650d29,b23de74]:v4.127.0Compare Source
Minor Changes
#15356
fe265f8Thanks @rubuy-74! - Add support for configuring a per-workflow max concurrency limit viaworkflows[].concurrency.limitin your Wrangler config.The limit is the maximum number of Workflow instances that can run concurrently. It is validated as a positive integer and persisted on deploy; the ceiling is enforced server-side. Concurrency is ignored in local development.
Patch Changes
#15367
412c79eThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15375
92874f6Thanks @WillTaylorDev! - Uploadwrangler previewmodules as multipart form datawrangler previewused to base64 the bundle, its modules, and any sourcemaps into a single JSON request body. Base64 inflates content by a third, so a Worker with a large sourcemap could exceed the API request size limit and fail to deploy.The preview deployment request is now
multipart/form-data. The deployment settings travel in ametadatapart and each module follows as its own part carrying raw bytes, matching howwrangler deployalready uploads a Worker.Updated dependencies [
412c79e]:v4.126.0Compare Source
Minor Changes
#15332
d1cc3afThanks @pombosilva! - Adddefault_retentionto Workflow bindings for configuring how long instances are retainedWorkflow instances are retained for an account-wide default period after they finish. You can now set a per-Workflow default in your Wrangler configuration, applied to instances that do not specify their own retention:
Each side is optional and accepts either a duration string such as
"3 days"or a whole number of milliseconds. Durations are interpreted by the Workflows API, which also caps them at your account's retention limit.#15064
693ca29Thanks @tpmmorris! - Include a chronological list of handler events in email test harness results, so programmatic local email tests can assert the order in which messages are received, forwarded, replied to, or rejected.#15065
ad89456Thanks @mtlemilio! - Add experimentalwrangler hyperdrive planetscale signaturefor provisioning Cloudflare-billed PlanetScale databaseswrangler hyperdrive planetscale signatureprints a signed authorization as JSON, proving to PlanetScale that Cloudflare will be billed for the database you are about to create:pscale database createdefaults to Vitess, so pass--engine postgresqlfor a Postgres database, and--format jsonis recommended when the output is consumed by an agent.This requires
pscalev0.313.0 or newer. Wrangler authorizes the Cloudflare billing side only, so your PlanetScale credentials stay between you andpscale.The signature is a cryptographically signed token that authorizes creating a database billed to your Cloudflare account. Treat it as a credential and do not share it. Piping it, as above, is recommended over passing it as a command line argument.
This command is experimental and its interface may change.
#15134
c66d2d5Thanks @gpanders! - Enable FUSE-capable local container developmentMiniflare now automatically passes the Docker privileges needed for FUSE to local Durable Object containers when using local rootless Docker on Linux with
/dev/fuseavailable, or a local Docker engine on macOS or through WSL where Linux containers run in a VM. This applies to Wrangler, the Cloudflare Vite plugin, and direct Miniflare use.#15326
9fcb1c9Thanks @jamesopstad! - Record the selected mode in the Build Output Specification top-levelconfig.jsonThe mode a build was produced in is now written to
.cloudflare/output/v0/config.jsonas amodefield, alongside the account and compliance settings.#14966
a4c3458Thanks @yomna-shousha! - Add pull request metadata towrangler previewdeploymentswrangler previewnow detects the pull request associated with the current CI run (GitHub Actions, GitLab CI, CircleCI, and a genericPULL_REQUEST_URL/PR_URL/CHANGE_URLfallback) and attaches it, along with the repository URL, to the preview deployment as annotations (workers/pull_request_number,workers/pull_request_url,workers/repository_url).This is best effort: if no pull request can be detected, nothing changes. When a pull request is detected, its URL is now also shown in the
wrangler previewcommand output.#15307
433fa98Thanks @for-the-kidz! - Add pull request title towrangler previewdeployment annotationswrangler previewnow also detects the title of the pull/merge request associated with the current CI run (GitHub Actions and GitLab CI, plus a genericPULL_REQUEST_TITLEfallback) and attaches it to the preview deployment as theworkers/pull_request_titleannotation, alongside the existing pull request number/URL, repository URL, and commit SHA annotations.This is best effort: if no pull request title can be detected, nothing changes.
Patch Changes
#15294
4a67a28Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15328
2d78137Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15346
04e8564Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15246
daefb3cThanks @edmundhung! - Prepare autoconfig for multiple configuration targetsAdd target-specific configuration output and command detection while preserving Wrangler's existing setup and deployment behavior.
#15320
c809851Thanks @Om-singhaI! - Fixwrangler login --use-keyringincorrectly reporting thatsecret-toolis missing on LinuxLibsecret's
secret-tooldoes not support--version; it prints usage and exits 2, which Wrangler previously interpreted as unavailable. Wrangler now reports it missing only when launching the executable fails.#15336
22182daThanks @podonnell-dev! -[private beta]: Explain unavailable Preview URLs afterwrangler previewdeploymentsWhen a Preview deployment has no active URLs, Wrangler now explains how to enable Preview Deployments on workers.dev or a custom domain.
#15296
d589d30Thanks @MattieTK! - Stop automatically offering to install Cloudflare skills for new usersWrangler will no longer prompt new users to install Cloudflare skills after commands complete. It will continue to offer updates to skills that Wrangler previously installed.
Updated dependencies [
aa54b49,4a67a28,2d78137,04e8564,693ca29,693ca29,693ca29,37ed753,f76b68e,c66d2d5,693ca29,74de3ab,0cb8690,dd5148d,82d11fc]:v4.125.0Compare Source
Minor Changes
#14995
59872c4Thanks @ThomasRubini! - Addconnecttrigger for raw socketsYou can now configure a Worker to receive raw socket connections during
wrangler dev, delivered directly to the Worker'sconnect(socket, env, ctx)handler:Each entry opens a listening socket on
127.0.0.1(or the givenaddress) that forwards incoming connections straight to the Worker, bypassing the local dev HTTP entry point. This requires theexperimentalcompatibility flag. Only"tcp"is supported at the moment.@cloudflare/configalso supports declaring this trigger viatriggers.connect(...), which lowers to theconnectfield above:#15172
c68f9cbThanks @WillTaylorDev! - Add container support to worker previewsWorker previews now support containers through a new
previews.containersconfiguration block. Container configuration doesn't inherit, so declare containers explicitly in thepreviewsblock to enable them for previews. This mirrors howpreviews.durable_objectsworks today. Wrangler names each preview container application{worker_name}_{preview_slug}_{class_name}, normalising and shortening the result to what the API accepts. Either change appends a short digest of the composed name, so two names that would otherwise land on one stay distinct. An entry cannot set its ownname, because application names are unique to an account and a fixed name would collide between two previews of the same Worker. A Durable Object class is backed by at most one container application, so the validator rejects two entries that share aclass_name. Wrangler skips container applications bound to Durable Object classes that another Worker implements throughscript_name, because the implementing Worker owns its own container application. A binding is not required: a Durable Object declared throughmigrationsorexportsand reached only overctx.exportscan still back a container. Every entry must setclass_name. Apreviews.containersentry whoseclass_namematches no Durable Object class at all is rejected before the preview deployment is created, so a typo fails loudly instead of producing a preview with no container.Wrangler creates the container applications on
wrangler preview. Deleting a preview tears them down server side, sowrangler preview deletedoesn't remove them.Container build and deploy progress prints to stdout.
wrangler preview --jsonsuppresses wrangler's own output so it doesn't interleave with the payload, and warnings and errors still go to stderr. Docker's build output and the progress spinner write to stdout directly and bypass that suppression, so parse--jsonfrom a non interactive shell, where the spinner is skipped, and prefer a prebuiltimageover a Dockerfile.#15174
649f667Thanks @WillTaylorDev! - [private beta]: Create the parent Worker automatically whenwrangler previewtargets one that doesn't exist yetPreviews hang off a parent Worker, so running
wrangler previewbefore the Worker had ever been deployed failed with a raw API error naming the Preview endpoint. Wrangler now offers to create an empty parent Worker and then carries on creating the Preview. The parent uses the same workers.dev and Preview URL settings thatwrangler deploywould resolve, without applying routes or cron triggers. In non-interactive environments, Wrangler creates the Worker without asking.#14735
30c2d47Thanks @vaishnav-mk! - Add individual and batch Workflow instance deletion to the runtime and SDK.WorkflowInstance.delete()deletes one instance. Self-deletion stops the current execution.env.MY_WORKFLOW.deleteBatch(instanceIds)deletes up to 100 instances and returns{ deleted, errors }per input position.wrangler workflows instances delete <name> [id..]deletes instances remotely or with--local; IDs can also come from a JSON array passed with--filename, with a combined limit of 100.Patch Changes
#15260
5ae9d5bThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15264
4b52975Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15277
ce9b151Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15192
ef73a28Thanks @ondraulehla! - Fixeskv bulk putcorrupting binary values written to local KVValues marked
base64: truewere stored incorrectly whenever they contained bytes that do not form valid UTF-8, which covers images, compressed data and most other binary payloads. A Worker reading such a key back underwrangler devgot a different, longer value than the one that was written: a 12 byte PNG header came back as 20 bytes.kv bulk putwrites to local KV by default, so the plain command was the affected one. Remote writes were never affected, and neither were entries withoutbase64or values written withkv key put.#15284
39dcea6Thanks @emily-shen! - Move deploy output writing into shared deploy helpers#15130
99a1f49Thanks @emily-shen! - Remove unsupportedremoteconfiguration from Workflow bindingsWorkflow bindings no longer accept
remotein configuration, as remote Workflow bindings have never actually been supported.#15278
f2437e6Thanks @Sosokker! - Fix the--temporaryerror on commands that authenticate more than one timewrangler d1 migrations apply --remote --temporaryfailed with this error:You're already authenticated with Cloudflare, so --temporary can't be used. The failure occurred with no login and with noCLOUDFLARE_API_TOKEN. This command authenticates one time for each statement that it runs. The first authentication makes a temporary preview account. The second authentication read the token of this new account as an earlier login.Wrangler now uses again the temporary account from the same command run. Commands that authenticate more than one time now work as
wrangler deploy --temporaryworks. If real credentials are available,--temporaryis still an error.Updated dependencies [
59872c4,99a1f49,5ae9d5b,4b52975,ce9b151,99a1f49,99a1f49,30c2d47]:v4.124.0Compare Source
Minor Changes
#15026
6529f0cThanks @petebacondarwin! - Allow containers to be attached to a Durable Object from itsexportsentryA container can now be linked to its Durable Object from the export side, using a new
containerfield that names an entry in thecontainersarray. As a resultcontainers[].class_nameis now optional — a container that is referenced this way only needs aname:The existing
containers[].class_namedirection keeps working and either direction may be used, but the two must agree: a container that names its Durable Object cannot also be claimed by a different one.containeris only valid on livedurable-objectexports (createdandexpecting-transfer) and requiresstorage: "sqlite". Wrangler now also reports an error when:containerreference names a container that does not existnameclass_namenames a Durable Object whosestorageislegacy-kvThat last case was previously accepted but could never work: workerd attaches a single container per Durable Object namespace, and in local development every container for a class builds into the same image tag, so one silently overwrote the other. If you have two containers on one
class_name, give each its own Durable Object class.Patch Changes
#15211
bc5726bThanks @nithin42! - Honoraccess.devwhen running Workers with@cloudflare/vitest-pool-workers, soctx.access.getIdentity()returns the configured identity just as it does withwrangler dev.#14999
ba54f0dThanks @mittalpk! - Fix.envloading on Windows leaking stale, differently-cased duplicate keysOn Windows,
wranglerloads.envvalues through a case-insensitiveProxywrapper so lookups likeenv.PATHandenv.Pathresolve to the same value, and this object is assigned directly toprocess.env. When a key was set again under a different casing (e.g. a value in.env.localoverriding one from.envwith different casing), the previous casing was never removed from the underlying object.env.PATH/env.Pathstill returned the correct, latest value, but anything that enumeratesprocess.env—Object.keys,for...in,JSON.stringify, object spread, or a spawned subprocess inheriting the environment — would see both the stale and current key.Duplicate entries no longer appear, so environment variables passed to subprocesses and any code that lists the environment now see only the latest value for each variable.
#15044
b7422b0Thanks @stareezy-1! - Normalize structural CRLF line endings before sending D1 commands to the remote query APIwrangler d1 migrations apply --remoteandwrangler d1 execute --remote --commandfailed withincomplete input: SQLITE_ERRORwhen the SQL contained CRLF line endings inside a compound statement such as aCREATE TRIGGER ... BEGIN ... END;body. Structural line endings are now normalized to LF before the command is sent to the D1 query API, while CRLF inside quoted values and identifiers remains unchanged.#15046
186339cThanks @erwinzhang7! - Fixes D1 SQL statements not handling lowercaseends correctlywrangler d1 executeandwrangler d1 migrations applysplit a SQL file into statements before running them. ABEGINorCASEblock closed with a lowercaseendwas not recognised as closed, so every statement after it was folded into that block instead of being run on its own. SQLite accepts either case, so a file like this applied only the trigger and silently skipped the table:Files written with an uppercase
ENDwere unaffected. Both cases now behave the same.#15231
4f922dcThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15248
4d74b8dThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15185
1f79aceThanks @jamesopstad! - Resolve--latestto the newest compatibility date supported by the installed runtimewrangler deploy --latestandwrangler versions upload --latestresolved the compatibility date to the current date, andwrangler pages download configdid the same for projects configured to always use the latest compatibility date. Both write that date into a configuration file for subsequent commands to use, so a date that the installedworkerddid not yet support left the project unable to runwrangler dev.These now resolve to the latest compatibility date supported by this version of Wrangler, which is the release date of the
workerdit ships with.#15151
49f73deThanks @maximilliangrand! - Fix spuriousTrailing comma jsonc(519)warnings forwrangler.jsoncin VS Code 1.131+Trailing commas in
wrangler.jsoncfiles that reference Wrangler's JSON schema are no longer reported as errors by recent versions of VS Code. Wrangler always accepted these files; only the editor warning was wrong.#14983
7cee278Thanks @kdelay! - RespectCLOUDFLARE_ACCOUNT_IDinwrangler pages project list,createanddeleteThese three commands could target a previously used account even when
CLOUDFLARE_ACCOUNT_IDwas set, failing withAuthentication error [code: 10000]in setups with more than one account. They now use the account named byCLOUDFLARE_ACCOUNT_ID, matching the rest ofwrangler pages. When the variable is unset, the previously used account is still selected, as before.#15153
265256aThanks @podonnell-dev! - Fixwrangler preview base-configcommands showing an inheritedscriptpositional#15185
1f79aceThanks @jamesopstad! - Use a fixed default compatibility date rather than the current dateWhen no compatibility date was set, Wrangler, C3 and the Vitest pool all defaulted to the current date.
workerdonly accepts a compatibility date up to 7 days beyond its own release, so whenever aworkerdrelease was delayed the default could get ahead of the runtime that had been installed, and local development would fail to start.The default is now fixed at the release date of the
workerdversion that ships with each release, which leaves a week of headroom and updates asworkerdis upgraded.@cloudflare/vite-pluginpreviously inlined the date at which it was built. It now shares the same default.#15239
f431166Thanks @jamesopstad! - Prevent date-enabled Node.js compatibility from adding conflicting globals to generated runtime typesRuntime type generation now treats Node.js compatibility enabled by a compatibility date the same way as an explicit
nodejs_compatflag. Node.js globals continue to come from@types/nodeinstead of being generated asanydeclarations that override those types.#15196
8fb2b87Thanks @skepticfx! - Use the FedRAMP High managed container registry when Wrangler targets the FedRAMP High compliance regionContainer builds, pushes, deployments, image commands, and local development now select the corresponding production or staging FedRAMP registry and API from either
compliance_regionorCLOUDFLARE_COMPLIANCE_REGION.#15082
75cf407Thanks @penalosa! - Enable the new configuration format in thecf-wranglerdev delegateProjects started through
cf devnow loadcloudflare.config.tsand optionalwrangler.config.ts, matching the configuration used by the delegate's build path.Updated dependencies [
1277a72,4f922dc,4d74b8d,2e0c962,8777180]:v4.123.0Compare Source
Minor Changes
#15113
b8fd112Thanks @BSFishy! - Add local dev simulation for Cloudflare Accessctx.access.getIdentity()You can now configure a mock Cloudflare Access identity in
wrangler.jsonso thatctx.access.getIdentity()returns it during local development.#15152
f0f2054Thanks @GregBrimble! - [private beta]: Updates the--ignore-defaultsflag to--ignore-base-configonwrangler previewcommands.--ignore-base-confignow only takes effect on Preview creation, rather than on each deployment, since Preview base configuration is now copy-on-create rather than inherit-on-deploy.#14872
339509dThanks @dario-piotrowicz! - Add automatic update prompts for out-of-date Cloudflare agent skillsWhen Cloudflare skills were previously installed by Wrangler and the upstream
cloudflare/skillsrepository has newer content, Wrangler now offers to update them after eligible commands complete.To reduce prompt fatigue, the update check only runs once a month (30 days since the last install or update). Declining suppresses the prompt until the next upstream change.
When declining an update, Wrangler offers the option to permanently disable future update prompts. This preference is stored globally in
~/.wrangler/agents-skills-install.jsonc. TheWRANGLER_NO_SKILLS_UPDATE_PROMPTS=trueenvironment variable can also be used to suppress prompts. The--install-skillsflag remains available regardless of these settings.Patch Changes
b8fd112]:v4.122.0Compare Source
Minor Changes
#15123
d0c976cThanks @dependabot! - Detect Node.js compatibility from the compatibility date, now thatnodejs_compatis enabled by defaultAs of compatibility date
2026-08-04, workerd enables thenodejs_compatandnodejs_compat_v2compatibility flags by default. Previously these tools only treated Node.js compatibility as enabled when one of those flags was listed explicitly, so a Worker on a compatibility date of2026-08-04or later without the flag would get Node.js APIs from the runtime but no Node.js polyfills from the bundler, andprocess.envcould be substituted with an empty object at build time. They now resolve these flags the same way workerd does, and honourno_nodejs_compatto opt out.To keep Node.js compatibility switched off on a newer compatibility date, specify both
no_nodejs_compatandno_nodejs_compat_v2, since each flag has its own default.@cloudflare/vitest-pool-workersneedsnodejs_compat_v2for its own test runner, so it continues to override a project that opts out of it. On a compatibility date that enables the flag anyway, it now drops the opt-out rather than adding the flag back, which workerd would reject — previously this stopped such a project from running any tests at all.wrangler typesalso no longer attributes its@types/nodesuggestion to "thenodejs_compatflag", which it can now make for Workers that do not set the flag at all.Patch Changes
#15123
d0c976cThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15148
0b82b15Thanks @jamesopstad! - Ignore anodejs_compatcompatibility flag that the compatibility date already enablesworkerd rejects a compatibility flag that its compatibility date enables by default, so a Worker configured with both a compatibility date of
2026-08-04or later andnodejs_compatfailed to start locally with "The compatibility flag nodejs_compat became the default as of 2026-08-04 so does not need to be specified anymore".The redundant
nodejs_compatandnodejs_compat_v2flags are now dropped when starting the runtime, which has no effect on the resulting Worker because the compatibility date enables both anyway.no_nodejs_compatandno_nodejs_compat_v2still switch Node.js compatibility off, and a flag specified alongside its own opt-out is left alone so that workerd still reports those as contradictory.#15123
d0c976cThanks @dependabot! - Stop adding a redundantnodejs_compatflag to generated Wrangler configurationscreate-cloudflareandwrangler setupwrite today's date as thecompatibility_date, and from2026-08-04that already enablesnodejs_compat. Adding the flag as well made the generated project fail to start with "The compatibility flag nodejs_compat became the default as of 2026-08-04 so does not need to be specified anymore", so the flag is now only added for earlier compatibility dates.create-cloudflarealso removes the flag when a template, or a framework's own scaffolder, already wrote it into a configuration that ends up using such a compatibility date, and still installs@types/nodefor these projects even though there is no longer a flag to detect them by.wrangler setupdoes the same for awrangler.json(c)that is already in the project: it writes today's date over whatever date that configuration was written for, so anodejs_compatit finds there is removed as part of writing the file.#15142
3b02915Thanks @penalosa! - Fix remote binding sessions reusing stale binding configurationsStarting a new remote bindings session that reuses a Worker name no longer picks up the bindings from a previous session, which could cause
Binding "..." not founderrors.Updated dependencies [
d0c976c,d0c976c,0b82b15,d0c976c,90dd5e5]:v4.121.0Compare Source
Minor Changes
#15079
15cad03Thanks @podonnell-dev! - Add Preview base config secret commandsWrangler now manages Worker Preview base config secrets with
wrangler preview base-config secret put,delete,list, andbulk. These commands update the Worker'spreviews_base_config.env, keeping shared defaults scoped to all of that Worker's Previews.wrangler preview base-config secret listreads from the Worker's Preview base config and prints secret names with values masked.wrangler preview base-config secret bulkdeletes a secret when its value isnull, matchingwrangler secret bulk.#15000
731b33aThanks @edmundhung! - Allow Wrangler projects to build a Worker once and reuse it increateTestHarness()Build the Worker once:
Then reuse the emitted Worker during test harness startup and reset:
#14737
e1b5b4bThanks @ttoino! - Addemail.sendingas an event subscription source for queueswrangler queues subscription createnow accepts--source email.sendingalongside two new flags,--zone-idand--domain, which identify the zone and the sending domain (zone apex or a verified subdomain) to subscribe to. Both flags are required for this source. The subscription's resource is displayed as the sending domain inwrangler queues subscription get.#15073
d669088Thanks @FlorentCollin! - Add US jurisdiction support towrangler d1 createYou can now create a D1 database in the US jurisdiction with
wrangler d1 create <name> --jurisdiction us. The new jurisdiction is also listed in the command's help output.#15079
15cad03Thanks @podonnell-dev! - Use Preview deployment PATCH APIs for Preview secret commandsWrangler now updates Worker Preview secrets by patching the named Preview's latest deployment instead of patching the Worker's Previews settings. This keeps secret changes scoped to one Preview, avoids affecting production or other Previews, and creates a new Preview deployment that goes live at 100% immediately.
wrangler preview secret listnow reads from the named Preview's latest deployment and prints secret names with values masked.wrangler preview secret bulknow deletes a secret when its value isnull, matchingwrangler secret bulk.#14924
0aa8fa5Thanks @ariesclark! - HonorDO_NOT_TRACK=1as a telemetry opt-outWrangler now disables telemetry when
DO_NOT_TRACK=1is set, regardless of other telemetry settings.Patch Changes
#15081
026e058Thanks @podonnell-dev! - Compactwrangler previewdeployment success outputwrangler previewnow prints a concise success summary with the Preview name, Preview URL, deployment ID, and Deployment URL instead of the previous box-art settings summary.#15132
5b1b930Thanks @dario-piotrowicz! - Fetch script metadata directly instead of listing all scriptsWhen resolving Durable Object migrations, fetch the specific script's service metadata via
/workers/services/{name}instead of listing all scripts in the account via/workers/scripts. This avoids downloading metadata for every Worker in the account just to find one script's migration tag.#15032
6e7d37dThanks @Sertug17! - Fixwrangler devcommands crashing withNo such module "wrangler:modules-watch"when"no_bundle": trueRunning
wrangler devorwrangler pages devwith bundling disabled ("no_bundle": trueinwrangler.json, or the--no-bundleflag) no longer crashes at startup withUncaught Error: No such module "wrangler:modules-watch". Live reloading on file changes continues to work as before.Updated dependencies [
c7aede7]:v4.120.1Compare Source
Patch Changes
#15072
6dbd192Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#14994
2194f88Thanks @emily-shen! - Update local development for Miniflare's config-based optionsWrangler now converts the Miniflare options it creates for local development to Miniflare's config-based
workersshape.Users should not expect to notice any changes.
Updated dependencies [
6dbd192,2194f88,2194f88,2194f88,2194f88,2194f88,2194f88]:v4.120.0Compare Source
Minor Changes
#15008
35c87e9Thanks @skepticfx! - Adds the ability to find container instances by exact ID or namewrangler containers instances <application_id> --search <instance_id_or_name>now searches every page and returns exact matches in human-readable or JSON output. JSON returns a top-level array, including an empty array when there is no match, while human-readable output prints a no-match message. If multiple instances have the same exact name, every matching instance is returned.#15008
35c87e9Thanks @skepticfx! - Add explicit pagination to container instance JSON outputUse
wrangler containers instances <application_id> --json --per-page <size>to return one page with machine-readableresult_info, then pass itsnext_page_tokento--page-tokento retrieve the next page. Plain--jsonremains backward-compatible: it requests the complete list and returns the existing top-level array.Patch Changes
#15013
8cf78c8Thanks @dario-piotrowicz! - Update undici from 7.28.0 to 7.29.0#15015
a60ff4dThanks @nickpatt! - Cut the per-request cost of local observability captureEvery tail event was written to the trace store as its own Durable Object call, so a request paid two or three round-trips per span. On a module-heavy app under the Vite plugin that dominated dev request latency. Rows are now buffered and written in batches, taking a request from roughly thirty calls to three.
Work in progress still shows up as it happens: the root span is written immediately, console logs and exceptions as they arrive, and a span's completion is written on the next event once 100ms has passed. An invocation that goes completely quiet writes nothing further until it ends, since the flush is driven by tail events rather than a timer.
The Vite plugin's own router, asset and proxy workers are also no longer captured. Their traces were noise the Observability views already hid, and skipping them cuts the spans recorded per request — a side benefit being that a trace's root is now your Worker rather than
__router-worker__.Updated dependencies [
b4f0c97,8cf78c8,a60ff4d,99eb50c]:v4.119.0Compare Source
Minor Changes
#14952
20470faThanks @nelsonjsduarte! - Add--parse-typeflag towrangler ai-search createwrangler ai-search createnow accepts--parse-typeto control how a website data source discovers URLs.sitemap(the default) reads XML sitemaps;discoverfollows links recursively.Previously the parse type could only be chosen through the interactive wizard, which was skipped whenever
--sourcewas supplied — so it was impossible to create adiscoverinstance from a script.The interactive wizard now offers
DiscoveralongsideSitemap.--parse-typeis only valid with--type web-crawler; passing it with--type builtinor--type r2is rejected, since the API stores the value for those source types but never reads it. When the flag is omitted in non-interactive mode the field is left unset and the API default (sitemap) applies.#14941
266172bThanks @nickpatt! - Improve the Local Explorer's Observability viewsconsole.logmessages now render the way the console would (JSON-encoded strings are unwrapped and multi-argument logs are joined), traces and events can be looked up by trace or span id from the search bar, and an event's "View trace" button jumps to the exact invocation that emitted it — even when a trace_id spans several invocations (e.g. a subrequest or self fetch).#14064
a9e5abbThanks @petebacondarwin! - Add support for OAuth 2.0 Device Authorization Grant towrangler loginRun
wrangler login --deviceto authenticate without a local callback server. Useful in containers, remote SSH sessions, Codespaces, and any other environment wherelocalhost:8976is unreachable from your browser.The new flow:
--browser=false),The verification URL is supplied by the authorization server, so it is rejected unless it is an
httpsURL on the same auth domain the device code was requested from — it is never printed or opened otherwise.--callback-hostand--callback-portcannot be combined with--device, since this flow does not start a local callback server.Patch Changes
#14984
9c74538Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#15012
0d33cb8Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
Updated dependencies [
9c74538,0d33cb8,a88d169,a88d169,daf65f2]:Configuration
📅 Schedule: (in timezone Europe/Amsterdam)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.
⚠️ Artifact update problem
Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.
♻ Renovate will retry this branch, including artifacts, only when one of the following happens:
The artifact failure details are included below:
File name: pnpm-lock.yaml
8989903b206e7059b9b7fix(deps): update dependency wrangler ( 4.118.0 ➔ 4.137.0 )to fix(deps): update dependency wrangler ( 4.118.0 ➔ 4.139.0 )6e7059b9b7cfa483812acfa483812a5e2eb5e5405e2eb5e54006650384e0fix(deps): update dependency wrangler ( 4.118.0 ➔ 4.139.0 )to fix(deps): update dependency wrangler ( 4.118.0 ➔ 4.141.0 )06650384e0820f3a0ef0820f3a0ef0e3e307a914e3e307a91429152d68b029152d68b037ce904f3efix(deps): update dependency wrangler ( 4.118.0 ➔ 4.141.0 )to fix(deps): update dependency wrangler ( 4.118.0 ➔ 4.142.0 )View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.