Skip to content

chore(deps): bump node-forge and wrangler in /miniflare/example - #180

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/miniflare/example/multi-b33bd0d4ff
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/miniflare/example/multi-b33bd0d4ff

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Removes node-forge. It's no longer used after updating ancestor dependency wrangler. These dependencies need to be updated together.

Removes node-forge

Updates wrangler from 2.6.2 to 4.149.0

Release notes

Sourced from wrangler's releases.

wrangler@4.149.0

Minor Changes

  • #16036 9a58244 Thanks @鈥媏devil! - Support temporary event accounts in R2 and Containers commands

    wrangler r2 and wrangler containers commands now accept the hidden --temporary flag, so accounts created for an event can manage buckets, objects and containers directly. Every command that supports --temporary now also accepts a hidden --event-code flag, so the first command a participant runs can create the event account:

    wrangler r2 bucket create my-bucket --temporary --event-code <code>

    R2 and Containers are only available on event accounts. R2 custom domains, Sippy, external container registries and wrangler cloudchamber commands still require a logged-in account.

Patch Changes

  • #16139 2d1d563 Thanks @鈥媍pojer! - Update esbuild to 0.28.2

    Align esbuild dependency with tooling using the latest 0.28 patch so package managers can share one installation instead of downloading a second native binary.

  • #15632 85b14e7 Thanks @鈥媝etebacondarwin! - Honor Retry-After directives during static asset uploads

    Static asset uploads now pause retries and pending uploads until the latest outstanding deadline requested by the API. A per-request limiter also keeps gateway retries at the reduced concurrency after the pause ends, preventing a deployment from immediately overloading a constrained asset service again.

  • #16098 fe607f9 Thanks @鈥媎ependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    sharp 0.35.4 0.35.5
  • #16093 ad7ff45 Thanks @鈥婦iogoSantoss! - Document that addresses catch-all entries must use the zone apex

    A *@domain entry in addresses must use the zone apex, such as *@example.com. The zone catch-all also receives mail for every subdomain in the zone that has no literal rule.

  • #16102 757faa6 Thanks @鈥媡lq5l! - Keep Preview secrets when deploying to an existing Preview

    Secrets added to a Preview with wrangler preview secret put or wrangler preview secret bulk were lost the next time wrangler preview ran, because each new deployment was created from the Wrangler config, --var and --secrets-file values only.

    wrangler preview now carries over the secrets of the Preview's latest deployment. A value passed in this deployment (--secrets-file, --var or a previews binding with the same name) still replaces the existing secret, and wrangler preview secret delete removes one.

  • #15617 93c1069 Thanks @鈥媕patel3! - Stop the update check from recommending deprecated versions

    Previously, the "update available" notice shown by wrangler and @cloudflare/vite-plugin always pointed at whichever version was tagged latest on npm, even after that version had been deprecated for shipping a bug. Deprecated versions are now never recommended: if the latest release has been deprecated, the newest non-deprecated stable release below it is suggested instead, or nothing at all if you are already on it.

    The check now reads the npm registry directly instead of going through the update-check package, which discarded the deprecation information. The on-disk cache location and one-hour refresh interval are unchanged.

  • #16003 6947df3 Thanks @鈥媜ddharsh! - Ship using and await using declarations to the runtime as written, for smaller Worker bundles

    Workers and Pages Functions that use explicit resource management no longer carry about 1 KB of bundled helper code to emulate it. workerd supports using and await using natively at every compatibility date, so wrangler deploy, wrangler versions upload and Pages Functions builds now leave these declarations untouched.

  • #15958 82acf3c Thanks @鈥媌reken-ai! - Apply each action's own condition in wrangler r2 bucket lifecycle add

... (truncated)

Commits
  • 84c4e95 Version Packages (#16099)
  • 82acf3c [wrangler] Apply each action's own condition in r2 bucket lifecycle add (#1...
  • 757faa6 [wrangler] Keep Preview secrets when deploying to an existing Preview (#16102)
  • 85b14e7 [deploy-helpers] respect Retry-After during asset uploads (#15632)
  • 6947df3 [wrangler][vite-plugin] Preserve using declarations when bundling (#16003)
  • 9a58244 [wrangler] Support temporary event accounts in R2 and Containers commands (#1...
  • 540f084 Version Packages (#16034)
  • 42c7219 [wrangler] Fix r2 object put and r2 bulk put storing a different key in local...
  • 2dde890 [wrangler] Clarify secret version errors and support versions bulk deletions ...
  • b4e1299 [wrangler] Add --source-namespace and --source-repo-name for artifacts.repo q...
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for wrangler since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Removes [node-forge](https://github.com/digitalbazaar/forge). It's no longer used after updating ancestor dependency [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler). These dependencies need to be updated together.


Removes `node-forge`

Updates `wrangler` from 2.6.2 to 4.149.0
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.149.0/packages/wrangler)

---
updated-dependencies:
- dependency-name: node-forge
  dependency-version:
  dependency-type: indirect
- dependency-name: wrangler
  dependency-version: 4.149.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 9, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants