Skip to content

chore(deps): update dependency wrangler to v4.144.0 - #242

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/wrangler-4.x-lockfile
Oct 3, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/wrangler-4.x-lockfile

Conversation

@renovate

@renovate renovate Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Pending OpenSSF
wrangler (source) devDependencies minor 4.143.0 → 4.144.0 4.147.0 (+2) OpenSSF Scorecard

Release Notes

cloudflare/workers-sdk (wrangler)

v4.144.0

Compare Source

Minor Changes
  • #​15919 91a3606 Thanks @​flakey5! - Add --tty (-t) flag to wrangler containers ssh to force pseudo-terminal allocation

    OpenSSH only allocates a pseudo-terminal when no remote command is given, so interactive commands such as wrangler containers ssh <ID> -- bash previously ran without a prompt or line editing. Pass --tty to force one:

    wrangler containers ssh <ID> --tty -- bash

  • #​15951 2a15ae2 Thanks @​flakey5! - Support SSH settings for Durable Object-managed Containers in the configuration API

    defineContainer now accepts ssh and authorizedKeys with schedulingPolicy: "durable-object", matching the ssh and authorized_keys fields that Wrangler already supports for these Containers. Previously the schema rejected them, so they could not be set from cloudflare.config.ts.

    defineContainer({
      name: "sandbox",
      schedulingPolicy: "durable-object",
      ssh: { enabled: true },
      authorizedKeys: [{ name: "laptop", publicKey: "ssh-ed25519 AAAA..." }],
    });
Patch Changes

v4.143.1

Compare Source

Patch Changes
  • #​15159 7bb6eae Thanks @​veggiedefender! - Fix wrangler dev remote bindings for workers.dev subdomains protected by Access

    Running wrangler dev with remote bindings on an unpublished worker protected by Access (e.g. using a wildcard on your workers.dev domain) previously failed with a redirect loop. Wrangler now correctly authenticates remote bindings with Access in this situation.

  • #​15923 60ccdbd Thanks @​petebacondarwin! - Upgrade the bundled capnweb implementation to 0.12.0

    This updates the RPC implementation shipped in Miniflare and remote-binding proxy workers to the latest capnweb release.

  • #​15938 62fd03a Thanks @​dieub! - Resolve the affected Undici dependency in new Wrangler and Vite plugin installs

    Undici 7.29.1 fixes GHSA-3wwx-pv8p-q78v. Update the shared dependency catalog and matching types used by Miniflare and Wrangler so downstream installs can resolve the patched runtime without an application-level override. A published release is still required for consumers; this changeset does not alter already published package metadata.

  • #​15903 06ed9c8 Thanks @​itsmunzir! - Fix custom-domain-only deploys failing for API tokens without Zone Workers Routes read permission

    When workers_dev was disabled and routes contained only entries with custom_domain: true, every deploy after the first one fetched /zones/:zoneId/workers/routes to check for route conflicts, even though custom domains are not zone Workers Routes. Tokens scoped to Workers Scripts edit plus custom domains - without Zone > Workers Routes > Read - failed with "No access to the specified resource" after the Worker version had already been uploaded. The conflict check now only covers non-custom-domain routes; custom domain conflicts continue to be reported by the custom domains changeset API.

  • #​15887 86211fe Thanks @​alepacheco! - Report an unreachable auth server instead of an expired login when refreshing an OAuth token

    When the OAuth token endpoint could not be reached (for example a DNS failure or a connection timeout), the refresh failure was reported as "Your auth token has expired and could not be refreshed", with advice to run wrangler login; in an interactive terminal Wrangler also started a new browser login. A network failure says nothing about the stored refresh token, and a new login would need the same unreachable server. Wrangler now reports that the Cloudflare auth server could not be reached, leaves the stored credentials unchanged, and does not start a login, so the next run can refresh with the same token once the network is back.

  • Updated dependencies [60ccdbd, 62fd03a, c2bb4c8, eb1efe0, 485cfb3]:


Configuration

📅 Schedule: (in timezone Asia/Tokyo)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: ae77629d-6e3e-4bcb-8f82-fdc1ab934caf

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@socket-security

socket-security Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedwrangler@​4.143.0 ⏵ 4.144.0981009296 +1100

View full report

@renovate
renovate Bot force-pushed the renovate/wrangler-4.x-lockfile branch from 4f71109 to 24fc64f Compare October 2, 2026 22:31
@renovate renovate Bot changed the title chore(deps): update dependency wrangler to v4.143.1 chore(deps): update dependency wrangler to v4.144.0 Oct 2, 2026
@renovate
renovate Bot merged commit 5c86ebe into main Oct 3, 2026
9 checks passed
@renovate
renovate Bot deleted the renovate/wrangler-4.x-lockfile branch October 3, 2026 00:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants