Skip to content

chore(deps): update dependency wrangler to v4.139.0 [automerge] - #385

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/wrangler-4.x
Sep 28, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/wrangler-4.x

Conversation

@renovate

@renovate renovate Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
wrangler (source) 4.138.0 → 4.139.0 age confidence

Release Notes

cloudflare/workers-sdk (wrangler)

v4.139.0

Compare Source

Minor Changes
  • #​15792 479e1e8 Thanks @​flakey5! - Configure SSH for experimental Durable Object-managed Containers

    Set containers[].ssh and containers[].authorized_keys when using scheduling_policy: "durable_object". These are application-wide settings that follow the same rules as the existing Durable Object-managed Container settings: normal deployments create missing applications and update explicitly configured values, while omitted settings preserve the existing application configuration.

    // wrangler.jsonc
    {
      "containers": [
        {
          "name": "sandbox",
          "class_name": "Sandbox",
          "scheduling_policy": "durable_object",
          "ssh": { "enabled": true },
          "authorized_keys": [
            { "name": "laptop", "public_key": "ssh-ed25519 AAAA..." }
          ]
        }
      ]
    }
  • #​15648 52c0e9f Thanks @​tpmmorris! - Expose configured Cron Triggers to local development consumers

    Wrangler now passes the active environment's exact Cron Trigger expressions to Miniflare so Local Explorer can display them. Headless agent sessions also advertise the Local Explorer scheduled invocation API.

  • #​15786 bdda4c3 Thanks @​ThomasRubini! - Support UDP connect handlers in local development

    The experimental connect configuration now accepts protocol: "udp", with optional idle_timeout_ms and max_pending_bytes settings. UDP datagrams are delivered to the Worker's connect() handler using workerd's value-mode socket streams, and can be tested with Miniflare#dispatchConnect({ protocol: "udp" }).

  • #​15779 fc3cbaa Thanks @​Naapperas! - Support workflow entries in the exports configuration map

    A Worker can now declare the Workflows it defines in exports, keyed by the WorkflowEntrypoint class name:

    {
      "exports": {
        "MyWorkflow": {
          "type": "workflow",
          "name": "my-workflow",
          "limits": { "steps": 100 },
          "schedules": "0 * * * *"
        }
      }
    }

    A workflow export accepts the same settings as a workflows binding: limits, concurrency, schedules, and default_retention. wrangler deploy and wrangler versions upload send these entries to the upload API by name, and wrangler deploy and wrangler triggers deploy provision the Workflow with its settings, just as they do for workflows bindings owned by the Worker. A Workflow may be declared both as a binding and as an export, as long as both declarations use the same class and do not set the same setting to different values. A binding to another Worker's Workflow cannot share a name with an export. @cloudflare/config adds the matching exports.workflow() helper. Local development does not yet act on these entries.

Patch Changes
  • #​15796 be72815 Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20260921.1 ^5.20260923.1
    workerd 1.20260921.1 1.20260923.1
  • #​14847 940c692 Thanks @​TheSaiEaranti! - Emulate the deterministic-ID uniqueness contract in the local Workflows binding

    The local Workflows binding now matches the documented production behavior for deterministic instance IDs: create({ id }) with an ID that already exists throws (instance.already_exists) and retains the existing instance, and createBatch() skips IDs that already exist or repeat within the batch, excluding them from the result instead of creating duplicate executions. Previously both paths silently created duplicates, so code relying on deterministic IDs for idempotency (for example a Queue consumer creating one workflow per message) appeared to work locally while double-executing workflow bodies.

  • #​15803 cd60c9c Thanks @​pmiguel! - Show --jurisdiction in help for wrangler kv namespace create

    The option was supported but omitted from the command's help output. Users can now discover how to create KV namespaces in a specific jurisdiction.

  • #​15838 15799d4 Thanks @​oddharsh! - Update smol-toml to 1.9.0 to fix slow parsing of very large TOML files

    Parse time for TOML config files now grows linearly with their size, instead of with its square: a 40,000-line file that took 259 ms to parse now takes 17 ms, while typical wrangler.toml files parse in the same time as before. This addresses the GHSA-r4xh-jqrq-34v2 advisory against earlier versions of the parser.

    Some TOML syntax errors now point at the character that caused them. For example, a wrangler.toml containing INVALID "FILE is now reported as illegal character in key at the ", rather than incomplete key-value at the start of the line.

  • Updated dependencies [52c0e9f, 44f5295, be72815, 940c692, bdda4c3, fc3cbaa]:


Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • "every weekend,on Friday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added merge: auto PR is eligible for automerge type/minor labels Sep 27, 2026
@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 9fe6df12-c817-4d0e-b0fe-08c9e92e977b

📥 Commits

Reviewing files that changed from the base of the PR and between b1c25e0 and f6acd7f.

📒 Files selected for processing (1)
  • workflow-templates/pages.yml

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The Pages workflow now uses Wrangler 4.139.0 instead of 4.138.0.

Changes

Pages workflow

Layer / File(s) Summary
Update configured Wrangler version
workflow-templates/pages.yml
The workflow’s configured Wrangler version changed from 4.138.0 to 4.139.0.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~5 minutes

Change: Other

Suggested reviewers: devsecninja

Merge Risk: ⚪ Minimal · up to f6acd

The Pages workflow will use Wrangler 4.139.0 for project creation and deployment. No actionable merge risk is established by the supplied change context.

Architecture Summary

Architecture risk: 🔵 Low · up to f6acd

The change affects 1 system.

Changed systems: workflow-templates

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — workflow-templates (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in workflow-templates/pages.yml: The configured Wrangler version changed from 4.138.0 to 4.139.0.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the Wrangler dependency update to version 4.139.0. The chore(deps) prefix and [automerge] suffix do not obscure the main change.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot merged commit c236487 into main Sep 28, 2026
20 checks passed
@renovate
renovate Bot deleted the renovate/wrangler-4.x branch September 28, 2026 03:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merge: auto PR is eligible for automerge type/minor

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants