Skip to content

chore(deps): update all non-major dependencies - #4669

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@cloudflare/workers-types ^5.20260921.1 → ^5.20260926.1 age confidence
@cloudflare/workers-utils (source) ^0.41.0 → ^0.44.0 age confidence
@scalar/api-reference (source) ^1.70.0 → ^1.72.1 age confidence
@scalar/openapi-types (source) ^0.9.6 → ^0.9.7 age confidence
@types/node (source) ^26.6.2 → ^26.6.3 age confidence
@​vercel/queue ^0.6.0 → ^0.7.0 age confidence
dotenv ^18.0.2 → ^18.0.4 age confidence
env-runner ^0.2.3 → ^0.3.0 age confidence
pnpm (source) 11.27.1 → 11.28.0 age confidence
pretty-bytes ^7.1.3 → ^7.2.0 age confidence
rolldown (source) ^1.2.9 → ^1.2.11 age confidence
rollup (source) ^4.63.4 → ^4.63.5 age confidence
undocs 0.10.1-20260909-093809-9b3fed7 → 0.10.1-20260922-215730-10f5034 age confidence
vite (source) ^8.3.0 → ^8.3.1 age confidence
wrangler (source) ^4.136.1 → ^4.141.0 age confidence
zephyr-agent (source) ^1.4.0 → ^1.4.1 age confidence

⚠️ Renovate does not enforce Minimum Release Age for bump, lockfileUpdate, or rollback updates, so these are raised without a Minimum Release Age check. You will need to manually validate the Minimum Release Age for these package(s).


Release Notes

cloudflare/workers-sdk (@​cloudflare/workers-utils)

v0.44.0

Compare Source

Minor Changes
  • #​15658 8280086 Thanks @​jqmmes! - Add Durable Objects code update strategies to Worker deployments

    Use --durable-objects-code-update-mode immediate with wrangler deploy, wrangler versions deploy, and wrangler rollback to update code without waiting for active instances to hibernate. Use --durable-objects-code-update-mode deferred 30s to set a maximum delay, or configure durable_objects.code_update_strategy with mode and max_delay. When unset, the strategy defaults to deferred with a 5-minute maximum delay; delays cannot exceed 24 hours and must use millisecond precision.

Patch Changes
  • #​15870 8c4b8a3 Thanks @​dario-piotrowicz! - Keep Node.js ESM packages working when consumers rebundle them as CommonJS

    Node.js-targeted ESM bundles now provide a real require implementation for bundled CommonJS dependencies. This avoids downstream patches for dynamic require calls and keeps the packages usable when a consumer rebundles them to CommonJS.

v0.43.0

Compare Source

Minor Changes
  • #​15822 8f7916c Thanks @​GregBrimble! - Expose a helper for identifying live Durable Object exports

    Use isLiveDurableObjectExport() to distinguish created and incoming-transfer exports from deleted, renamed, and transferred tombstones.

v0.42.0

Compare Source

Minor Changes
  • #​15792 479e1e8 Thanks @​flakey5! - Configure SSH for experimental Durable Object-managed Containers

    Set containers[].ssh and containers[].authorized_keys when using scheduling_policy: "durable_object". These are application-wide settings that follow the same rules as the existing Durable Object-managed Container settings: normal deployments create missing applications and update explicitly configured values, while omitted settings preserve the existing application configuration.

    // wrangler.jsonc
    {
      "containers": [
        {
          "name": "sandbox",
          "class_name": "Sandbox",
          "scheduling_policy": "durable_object",
          "ssh": { "enabled": true },
          "authorized_keys": [
            { "name": "laptop", "public_key": "ssh-ed25519 AAAA..." }
          ]
        }
      ]
    }
  • #​15786 bdda4c3 Thanks @​ThomasRubini! - Support UDP connect handlers in local development

    The experimental connect configuration now accepts protocol: "udp", with optional idle_timeout_ms and max_pending_bytes settings. UDP datagrams are delivered to the Worker's connect() handler using workerd's value-mode socket streams, and can be tested with Miniflare#dispatchConnect({ protocol: "udp" }).

  • #​15779 fc3cbaa Thanks @​Naapperas! - Support workflow entries in the exports configuration map

    A Worker can now declare the Workflows it defines in exports, keyed by the WorkflowEntrypoint class name:

    {
      "exports": {
        "MyWorkflow": {
          "type": "workflow",
          "name": "my-workflow",
          "limits": { "steps": 100 },
          "schedules": "0 * * * *"
        }
      }
    }

    A workflow export accepts the same settings as a workflows binding: limits, concurrency, schedules, and default_retention. wrangler deploy and wrangler versions upload send these entries to the upload API by name, and wrangler deploy and wrangler triggers deploy provision the Workflow with its settings, just as they do for workflows bindings owned by the Worker. A Workflow may be declared both as a binding and as an export, as long as both declarations use the same class and do not set the same setting to different values. A binding to another Worker's Workflow cannot share a name with an export. @cloudflare/config adds the matching exports.workflow() helper. Local development does not yet act on these entries.

Patch Changes
  • #​15838 15799d4 Thanks @​oddharsh! - Update smol-toml to 1.9.0 to fix slow parsing of very large TOML files

    Parse time for TOML config files now grows linearly with their size, instead of with its square: a 40,000-line file that took 259 ms to parse now takes 17 ms, while typical wrangler.toml files parse in the same time as before. This addresses the GHSA-r4xh-jqrq-34v2 advisory against earlier versions of the parser.

    Some TOML syntax errors now point at the character that caused them. For example, a wrangler.toml containing INVALID "FILE is now reported as illegal character in key at the ", rather than incomplete key-value at the start of the line.

unjs/env-runner (env-runner)

v0.3.0

Compare Source

compare changes

🚀 Enhancements
  • miniflare: Support a module specifier for exports (#​60)
  • ⚠️ Virtual modules improvements (#​61)
🩹 Fixes
  • miniflare: Return worker redirects instead of following them (d01fca7)
  • miniflare: Keep IPC env across requests (358bff6)
  • miniflare: Support miniflare v5 (0838ef3)
🏡 Chore
⚠️ Breaking Changes
  • ⚠️ Virtual modules improvements (#​61)
❤️ Contributors
pnpm/pnpm (pnpm)

v11.28.0

Compare Source

unjs/undocs (undocs)

v0.10.1-20260922-215730-10f5034

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "after 1am and before 5am"
  • Automerge
    • "after 2am and before 5am"

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from pi0 as a code owner September 26, 2026 01:04
@vercel

vercel Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
nitro.build Ready Ready Preview Sep 29, 2026 2:41pm UTC

Request Review

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 86f87377-e73e-4fdb-8592-3c7d54099386

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@socket-security

socket-security Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​cloudflare/​workers-utils@​0.41.2 ⏵ 0.44.09110078 +198 +1100
Updatedundocs-nightly@​0.10.1-20260909-093809-9b3fed7 ⏵ 0.10.1-20260922-215730-10f503478 +11009696100
Addedenv-runner@​0.3.21001001009580
Updated@​vercel/​queue@​0.6.0 ⏵ 0.7.096100100 +198 +1100

View full report

@pkg-pr-new

pkg-pr-new Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/nitro@4669

commit: d970aa0

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 35ca183 to c65dd28 Compare September 26, 2026 06:51
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from c65dd28 to 497063c Compare September 26, 2026 17:34
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 497063c to f8a0640 Compare September 27, 2026 01:57
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from f8a0640 to dca8e58 Compare September 27, 2026 13:11
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from dca8e58 to 644901c Compare September 27, 2026 16:30
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 644901c to 55e78b6 Compare September 27, 2026 21:02
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 55e78b6 to 84bfbc6 Compare September 28, 2026 04:23
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 84bfbc6 to e1ae3d0 Compare September 28, 2026 10:05
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from e1ae3d0 to 3faacb5 Compare September 28, 2026 10:36
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 3faacb5 to abea582 Compare September 29, 2026 00:15
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from abea582 to 91f77ca Compare September 29, 2026 03:35
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 91f77ca to d970aa0 Compare September 29, 2026 14:40

This branch was successfully deployed

1 active deployment
Preview — d970aa04 Deployed Sep 29, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants