Skip to content

chore(deps): bump undici and wrangler in /packages/infra-alert-bridge - #882

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/packages/infra-alert-bridge/multi-ca625267f0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/packages/infra-alert-bridge/multi-ca625267f0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Bumps undici to 7.29.1 and updates ancestor dependency wrangler. These dependencies need to be updated together.

Updates undici from 7.29.0 to 7.29.1

Release notes

Sourced from undici's releases.

v7.29.1

⚠️ Security fixes

High severity

  • GHSA-w293-vg96-wgc3: BalancedPool could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves connect and legacy tls options when creating upstreams. Fixed by f690157d.
  • GHSA-rfgv-xxqx-mfg5: a WebSocket server could select a subprotocol when none was requested, causing an uncaught TypeError that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 6615e017.

Medium severity

  • GHSA-3wwx-pv8p-q78v: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by 63cf698b.
  • GHSA-rx4f-c7p8-82vq: an unclean WebSocketStream close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by 1858656e.
  • GHSA-2jfj-6hjv-fm6j: shared caches could store and replay responses containing Set-Cookie, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by b6c5a002.
  • GHSA-3xpg-4rpp-hhhm: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable maxSize. Fixed by 2c7d7e12.
  • GHSA-pmjh-fq2x-6v4x: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by 3c672659.

Low severity

  • GHSA-8436-99hf-9mmv: cache interceptors could store and replay responses to unsafe HTTP methods such as POST or DELETE. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by b61d9432.
  • GHSA-2gqq-gqf2-x968: the dump interceptor could treat an oversized chunked response as successfully truncated when no Content-Length was present. Undici now enforces maxSize against received bytes and aborts oversized responses. Fixed by 21693f40.
  • GHSA-r53p-7pc4-xj5r: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates Content-Range against the original response framing before resuming. Fixed by cd8af90b.

What's Changed

Full Changelog: nodejs/undici@v7.29.0...v7.29.1

Commits
  • d39a83e Bumped v7.29.1 (#5772)
  • 0d88464 fix(test): remove unused EventEmitter import
  • f57411b perf(h1): drop idle-socket timer floor with a ref'd setImmediate (#5707) (#5769)
  • 3c67265 fix(retry): settle exposed body on terminal failure
  • cd8af90 fix(retry): validate resumed response framing
  • 6615e01 fix(websocket): reject unrequested subprotocols
  • 2c7d7e1 fix(decompress): limit decompressed response size
  • b6c5a00 fix(cache): do not cache Set-Cookie in shared caches
  • 21693f4 fix(interceptor/dump): abort oversized chunked responses
  • f690157 fix: preserve BalancedPool connection options
  • Additional commits viewable in compare view

Updates wrangler from 4.143.0 to 4.146.0

Release notes

Sourced from wrangler's releases.

wrangler@4.146.0

Minor Changes

  • #15777 464a582 Thanks @​Naapperas! - Support the new Workflows createBatch() API in local development

    Local Workflows bindings now accept object-form batches that create instances from a count or a list of instance options. The result includes handles for created instances and indexed per-instance errors, matching the runtime API while preserving the deprecated array form.

  • #15639 aee2842 Thanks @​hugo-vicente11! - Add --allowed-mail to the experimental wrangler tunnel quick-start command

    The option forwards exact email addresses, comma-separated lists, and wildcard domains to cloudflared. It can be specified more than once to combine multiple recipient rules.

    Email-protected tunnels require cloudflared 2026.9.2 or later. Wrangler checks the selected binary before starting the tunnel and reports an upgrade error when it is incompatible.

Patch Changes

  • #15992 b8e7cc3 Thanks @​zebp! - Mark wrangler artifacts commands as open beta

    Artifacts has entered open beta, so the wrangler artifacts commands no longer display a "private beta" label in help output and warnings.

  • #15984 9d7b08e Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20260930.2 ^5.20261001.1
    workerd 1.20260930.2 1.20261001.1
  • #15959 efd67e6 Thanks @​breken-ai! - Keep colons in wrangler tail --header filter values

    wrangler tail --header splits its argument into a header name and an optional value at the colon. It split at every colon and kept only the first two parts, so a value containing a colon was cut short: --header "Origin:https://app.example.com" filtered on https. The value now includes everything after the first colon, so URLs, ports and IPv6 addresses are sent to the tail filter intact.

  • Updated dependencies [b00ef4f, 9d7b08e, 464a582]:

wrangler@4.145.0

Minor Changes

  • #15685 b9f1cdc Thanks @​Ankcorn! - Add native support for the Analytics SQL binding

    Declare the zero-configuration binding in wrangler.json with "analytics": { "binding": "ANALYTICS" }. Wrangler uploads the analytics binding type and proxies it to the remote service during local development, so wrangler dev can call the binding without unsafe.bindings.

  • #15943 8468487 Thanks @​sejoker! - Graduate SQL, Catalog, and Pipelines under wrangler basin out of beta to stable

    Basin SQL is now available under wrangler basin sql, Basin Catalog operations are available under wrangler basin catalog, and Pipelines operations are available under wrangler basin pipelines. These commands are now stable, while the previous wrangler r2 sql, wrangler r2 bucket catalog, and wrangler pipelines command paths remain available as hidden compatibility aliases.

    The Basin SQL authentication environment variable is now WRANGLER_BASIN_SQL_AUTH_TOKEN. Update any existing WRANGLER_R2_SQL_AUTH_TOKEN configuration to use the new name. The fallback to CLOUDFLARE_API_TOKEN remains available.

  • #15948 a0712e5 Thanks @​akoval-cf! - Add beta K2 producer bindings for existing streams

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency javascript Pull requests that update javascript code labels Sep 30, 2026
@github-actions
github-actions Bot enabled auto-merge September 30, 2026 18:15
Bumps [undici](https://github.com/nodejs/undici) to 7.29.1 and updates ancestor dependency [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler). These dependencies need to be updated together.


Updates `undici` from 7.29.0 to 7.29.1
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.29.0...v7.29.1)

Updates `wrangler` from 4.143.0 to 4.146.0
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.146.0/packages/wrangler)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 7.29.1
  dependency-type: indirect
- dependency-name: wrangler
  dependency-version: 4.145.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/packages/infra-alert-bridge/multi-ca625267f0 branch from 7864acd to ed5d254 Compare October 1, 2026 18:16

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants