Skip to content

Bump undici, wrangler and @cloudflare/vite-plugin - #64

Open
dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/npm_and_yarn/multi-315506f2d1
Open

dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/npm_and_yarn/multi-315506f2d1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown

Bumps undici, wrangler and @cloudflare/vite-plugin. These dependencies needed to be updated together.
Updates undici from 7.29.0 to 7.29.1

Release notes

Sourced from undici's releases.

v7.29.1

⚠️ Security fixes

High severity

  • GHSA-w293-vg96-wgc3: BalancedPool could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves connect and legacy tls options when creating upstreams. Fixed by f690157d.
  • GHSA-rfgv-xxqx-mfg5: a WebSocket server could select a subprotocol when none was requested, causing an uncaught TypeError that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 6615e017.

Medium severity

  • GHSA-3wwx-pv8p-q78v: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by 63cf698b.
  • GHSA-rx4f-c7p8-82vq: an unclean WebSocketStream close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by 1858656e.
  • GHSA-2jfj-6hjv-fm6j: shared caches could store and replay responses containing Set-Cookie, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by b6c5a002.
  • GHSA-3xpg-4rpp-hhhm: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable maxSize. Fixed by 2c7d7e12.
  • GHSA-pmjh-fq2x-6v4x: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by 3c672659.

Low severity

  • GHSA-8436-99hf-9mmv: cache interceptors could store and replay responses to unsafe HTTP methods such as POST or DELETE. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by b61d9432.
  • GHSA-2gqq-gqf2-x968: the dump interceptor could treat an oversized chunked response as successfully truncated when no Content-Length was present. Undici now enforces maxSize against received bytes and aborts oversized responses. Fixed by 21693f40.
  • GHSA-r53p-7pc4-xj5r: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates Content-Range against the original response framing before resuming. Fixed by cd8af90b.

What's Changed

Full Changelog: nodejs/undici@v7.29.0...v7.29.1

Commits
  • d39a83e Bumped v7.29.1 (#5772)
  • 0d88464 fix(test): remove unused EventEmitter import
  • f57411b perf(h1): drop idle-socket timer floor with a ref'd setImmediate (#5707) (#5769)
  • 3c67265 fix(retry): settle exposed body on terminal failure
  • cd8af90 fix(retry): validate resumed response framing
  • 6615e01 fix(websocket): reject unrequested subprotocols
  • 2c7d7e1 fix(decompress): limit decompressed response size
  • b6c5a00 fix(cache): do not cache Set-Cookie in shared caches
  • 21693f4 fix(interceptor/dump): abort oversized chunked responses
  • f690157 fix: preserve BalancedPool connection options
  • Additional commits viewable in compare view

Updates wrangler from 4.120.1 to 4.144.0

Release notes

Sourced from wrangler's releases.

wrangler@4.144.0

Minor Changes

  • #15919 91a3606 Thanks @​flakey5! - Add --tty (-t) flag to wrangler containers ssh to force pseudo-terminal allocation

    OpenSSH only allocates a pseudo-terminal when no remote command is given, so interactive commands such as wrangler containers ssh <ID> -- bash previously ran without a prompt or line editing. Pass --tty to force one:

    wrangler containers ssh <ID> --tty -- bash

  • #15951 2a15ae2 Thanks @​flakey5! - Support SSH settings for Durable Object-managed Containers in the configuration API

    defineContainer now accepts ssh and authorizedKeys with schedulingPolicy: "durable-object", matching the ssh and authorized_keys fields that Wrangler already supports for these Containers. Previously the schema rejected them, so they could not be set from cloudflare.config.ts.

    defineContainer({
      name: "sandbox",
      schedulingPolicy: "durable-object",
      ssh: { enabled: true },
      authorizedKeys: [{ name: "laptop", publicKey: "ssh-ed25519 AAAA..." }],
    });

Patch Changes

wrangler@4.143.1

Patch Changes

  • #15159 7bb6eae Thanks @​veggiedefender! - Fix wrangler dev remote bindings for workers.dev subdomains protected by Access

    Running wrangler dev with remote bindings on an unpublished worker protected by Access (e.g. using a wildcard on your workers.dev domain) previously failed with a redirect loop. Wrangler now correctly authenticates remote bindings with Access in this situation.

  • #15923 60ccdbd Thanks @​petebacondarwin! - Upgrade the bundled capnweb implementation to 0.12.0

    This updates the RPC implementation shipped in Miniflare and remote-binding proxy workers to the latest capnweb release.

  • #15938 62fd03a Thanks @​dieub! - Resolve the affected Undici dependency in new Wrangler and Vite plugin installs

    Undici 7.29.1 fixes GHSA-3wwx-pv8p-q78v. Update the shared dependency catalog and matching types used by Miniflare and Wrangler so downstream installs can resolve the patched runtime without an application-level override. A published release is still required for consumers; this changeset does not alter already published package metadata.

  • #15903 06ed9c8 Thanks @​itsmunzir! - Fix custom-domain-only deploys failing for API tokens without Zone Workers Routes read permission

    When workers_dev was disabled and routes contained only entries with custom_domain: true, every deploy after the first one fetched /zones/:zoneId/workers/routes to check for route conflicts, even though custom domains are not zone Workers Routes. Tokens scoped to Workers Scripts edit plus custom domains - without Zone > Workers Routes > Read - failed with "No access to the specified resource" after the Worker version had already been uploaded. The conflict check now only covers non-custom-domain routes; custom domain conflicts continue to be reported by the custom domains changeset API.

  • #15887 86211fe Thanks @​alepacheco! - Report an unreachable auth server instead of an expired login when refreshing an OAuth token

    When the OAuth token endpoint could not be reached (for example a DNS failure or a connection timeout), the refresh failure was reported as "Your auth token has expired and could not be refreshed", with advice to run wrangler login; in an interactive terminal Wrangler also started a new browser login. A network failure says nothing about the stored refresh token, and a new login would need the same unreachable server. Wrangler now reports that the Cloudflare auth server could not be reached, leaves the stored credentials unchanged, and does not start a login, so the next run can refresh with the same token once the network is back.

... (truncated)

Commits

Updates @cloudflare/vite-plugin from 1.51.2 to 1.62.2

Release notes

Sourced from @​cloudflare/vite-plugin's releases.

@​cloudflare/vite-plugin@​1.62.2

Patch Changes

@​cloudflare/vite-plugin@​1.62.1

Patch Changes

@​cloudflare/vite-plugin@​1.62.0

Minor Changes

  • #15914 7f0734c Thanks @​jamesopstad! - Use cf/config for cloudflare.config.ts authoring

    Experimental cloudflare.config.ts projects must now import defineConfig, bindings, triggers, and related helpers from cf/config. Generated declarations from Wrangler and the Vite plugin also reference this package, so projects using the experimental configuration flow must add cf as a dependency.

    The Vite plugin no longer exports @cloudflare/vite-plugin/experimental-config. wrangler/experimental-config remains available for defineWranglerConfig, but no longer re-exports Cloudflare configuration helpers.

Patch Changes

  • #15878 e7915c1 Thanks @​dawNotPoi! - Keep dependency optimization caches stable on the first Vite dev server restart.

    The first dev server restart no longer re-optimizes unchanged dependencies, including in projects without Containers. Container images are still cleaned up when the server closes, even after a config reload removes the Cloudflare plugin.

  • Updated dependencies [7f0734c]:

    • wrangler@4.143.0

@​cloudflare/vite-plugin@​1.61.0

Minor Changes

  • #15856 4c2993b Thanks @​Naapperas! - Support Workflows declared in exports on ctx.exports in local development

    A Workflow declared in a Worker's exports is now available on ctx.exports in wrangler dev, the Vite plugin and the Vitest plugin, with the same API as a Workflow binding:

    const instance = await ctx.exports.MyWorkflow.create({
      params: { name: "World" },
    });

    ctx.exports and workflows bindings with the same Workflow name share their instances, including instances created before the Workflow was declared in exports. Two Workers can't export the same Workflow name, and a binding to an exported Workflow must refer to the Worker and class that export it. getPlatformProxy() ignores Workflows declared in exports, since it doesn't run the Worker's code.

... (truncated)

Changelog

Sourced from @​cloudflare/vite-plugin's changelog.

1.62.2

Patch Changes

1.62.1

Patch Changes

1.62.0

Minor Changes

  • #15914 7f0734c Thanks @​jamesopstad! - Use cf/config for cloudflare.config.ts authoring

    Experimental cloudflare.config.ts projects must now import defineConfig, bindings, triggers, and related helpers from cf/config. Generated declarations from Wrangler and the Vite plugin also reference this package, so projects using the experimental configuration flow must add cf as a dependency.

    The Vite plugin no longer exports @cloudflare/vite-plugin/experimental-config. wrangler/experimental-config remains available for defineWranglerConfig, but no longer re-exports Cloudflare configuration helpers.

Patch Changes

  • #15878 e7915c1 Thanks @​dawNotPoi! - Keep dependency optimization caches stable on the first Vite dev server restart.

    The first dev server restart no longer re-optimizes unchanged dependencies, including in projects without Containers. Container images are still cleaned up when the server closes, even after a config reload removes the Cloudflare plugin.

  • Updated dependencies [7f0734c]:

    • wrangler@4.143.0

1.61.0

Minor Changes

  • #15856 4c2993b Thanks @​Naapperas! - Support Workflows declared in exports on ctx.exports in local development

    A Workflow declared in a Worker's exports is now available on ctx.exports in wrangler dev, the Vite plugin and the Vitest plugin, with the same API as a Workflow binding:

    const instance = await ctx.exports.MyWorkflow.create({
      params: { name: "World" },

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [undici](https://github.com/nodejs/undici), [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler) and [@cloudflare/vite-plugin](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vite-plugin-cloudflare). These dependencies needed to be updated together.

Updates `undici` from 7.29.0 to 7.29.1
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.29.0...v7.29.1)

Updates `wrangler` from 4.120.1 to 4.144.0
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.144.0/packages/wrangler)

Updates `@cloudflare/vite-plugin` from 1.51.2 to 1.62.2
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Changelog](https://github.com/cloudflare/workers-sdk/blob/main/packages/vite-plugin-cloudflare/CHANGELOG.md)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/@cloudflare/vite-plugin@1.62.2/packages/vite-plugin-cloudflare)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 7.29.1
  dependency-type: indirect
- dependency-name: wrangler
  dependency-version: 4.144.0
  dependency-type: indirect
- dependency-name: "@cloudflare/vite-plugin"
  dependency-version: 1.62.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 29, 2026
@aws-amplify-us-west-1

Copy link
Copy Markdown

This pull request is automatically being deployed by Amplify Hosting (learn more).

Access this pull request here: https://pr-64.d1otfqlvqd3jby.amplifyapp.com

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants