Skip to content

chore(deps-dev): bump wrangler from 4.127.1 to 4.132.0 in /web - #6358

Merged
Hmbown merged 2 commits into
mainfrom
dependabot/npm_and_yarn/web/wrangler-4.132.0
Sep 21, 2026
Merged

Hmbown merged 2 commits into
mainfrom
dependabot/npm_and_yarn/web/wrangler-4.132.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 19, 2026

Copy link
Copy Markdown
Contributor

Bumps wrangler from 4.127.1 to 4.132.0.

Release notes

Sourced from wrangler's releases.

wrangler@4.132.0

Minor Changes

  • #14587 76c0ce6 Thanks @​MattieTK! - Categorise the positional path argument to wrangler deploy and wrangler versions upload in command telemetry

    Command telemetry now records a coarse category for the entry-point/assets positional (wrangler deploy <path>) under sanitizedArgs.path, so we can understand whether people pass a file, a directory, or a relational reference such as . or ../example. The possible values are file, directory, current-dir, parent-relative, and not-found, or null when no positional is provided. The raw path is never sent — only the category.

  • #15597 a83d7ac Thanks @​skepticfx! - Configure application-wide logs for experimental Durable Object-managed Containers

    Set containers[].observability.enabled or containers[].observability.logs.enabled when using scheduling_policy: "durable_object". Normal deployments create missing applications and update explicitly configured log settings without a Container rollout. Omitted settings preserve the application configuration; root Worker observability is not inherited for this policy.

    Version uploads may initialize missing applications but preserve existing settings. Deploying or rolling back Worker versions also preserves existing application settings, and --containers-rollout=none skips their updates.

  • #15597 a83d7ac Thanks @​skepticfx! - Support per-image build options for experimental Durable Object-managed Containers

    Set build_context and build_vars alongside dockerfile in a Container's named images entries. Context paths resolve relative to the Wrangler configuration file and default to the Dockerfile's directory. Build variables are passed as Docker build arguments. Entries using the same Dockerfile with different contexts or variables are built separately.

    {
      "containers": [
        {
          "class_name": "Sandbox",
          "scheduling_policy": "durable_object",
          "images": {
            "app": {
              "dockerfile": "./docker/Dockerfile",
              "build_context": ".",
              "build_vars": { "APP_ENV": "production" }
            }
          }
        }
      ]
    }
  • #15638 fa79b26 Thanks @​G4brym! - Support AI Search bindings in Worker Previews

    wrangler preview now accepts ai_search and ai_search_namespaces entries in the previews block and includes them in Preview deployment bindings. This lets Workers that use AI Search instance or namespace bindings attach existing resources to Preview deployments, including preview-specific instance or namespace names.

    These bindings are non-inheritable: declare them explicitly under previews. They attach to existing AI Search resources; preview does not provision new isolated instances or namespaces.

  • #15256 16d1310 Thanks @​theoephraim! - [private beta]: Add --secrets-file and --var flags to wrangler preview

    Like wrangler deploy and wrangler versions upload, wrangler preview now accepts a --secrets-file flag pointing to a JSON or .env format file, and --var KEY:VALUE pairs that are injected into the Preview deployment as plain text variables. CLI vars override same-named vars from the previews section of your config file, and secrets from the file take precedence over both:

    wrangler preview --secrets-file .env.preview --var API_URL:https://api.example.com

  • #15453 ca71205 Thanks @​G4brym! - Remove the gated Web Search binding and Wrangler command

    The unreleased search binding and its experimental command have been removed from Wrangler, Miniflare, and configuration APIs.

... (truncated)

Commits
  • bbf2f79 Version Packages (#15634)
  • 7db596c Bump the workerd-and-workers-types group across 1 directory with 2 updates (#...
  • a83d7ac CC-8364 Support Durable Object container settings and exports (#15597)
  • 74bf083 [deploy-helpers] Extract Worker startup profiling from Wrangler (#15612)
  • ffabe74 perf(wrangler): remove execa (#12369)
  • b149147 [wrangler] Send AI search options in correct Schema (#15409)
  • 16d1310 [wrangler] Add --secrets-file and --var flags to wrangler preview (#15256)
  • ca71205 Remove Web Search binding and commands (#15453)
  • 76c0ce6 [wrangler] Categorise deploy positional path in command telemetry (#14587)
  • fa79b26 [wrangler] Support AI Search bindings in Worker Previews (#15638)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler) from 4.127.1 to 4.132.0.
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.132.0/packages/wrangler)

---
updated-dependencies:
- dependency-name: wrangler
  dependency-version: 4.132.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 19, 2026
@dependabot
dependabot Bot requested a review from Hmbown as a code owner September 19, 2026 00:39
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 19, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thanks @dependabot[bot] for taking the time to contribute.

This repository is observing a maintainer-managed PR intake gate in dry-run mode, so this pull request is staying open. This note helps maintainers prepare the allowlist before any enforcement is considered.

Please read CONTRIBUTING.md for the expected contribution shape. A maintainer can grant recurring PR access by commenting /lgtm on a pull request.

Hmbown commented Sep 21, 2026 •

Copy link
Copy Markdown
Owner

Brought this branch up to date with main (green since ccbef2c) so CI runs against a base that passes; the earlier red lanes were inherited from the red main this PR was opened on. Merging once the re-run is green.


Generated by Claude Code

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

@claude

claude Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @Hmbown's task in 38s —— View job


Review: bump wrangler 4.127.1 → 4.132.0 (web/)

  • Gather context (diff, changed files)
  • Check for provider/model/route safety implications
  • Check for correctness/security concerns in dependency bump
  • Post final summary

Scope: web/package.json + web/package-lock.json only — a devDependencies bump of wrangler (and its transitive workerd/miniflare/sharp pins). No Rust workspace files, no application source, no web/wrangler.toml config changes.

Findings:

  • Provider/model/route safety (EPIC v0.8.65 EPIC: Separate provider facts, model facts, offerings, and route resolution #2608): Not applicable — this touches Cloudflare's wrangler CLI toolchain, unrelated to model/provider routing logic. No concerns.
  • Correctness: Straightforward semver-compatible minor bump (^4.107.0 → ^4.132.0... note the caret range actually widened from ^4.107.0 to ^4.132.0, which is expected/correct for a version bump). Lockfile entries for workerd, miniflare, and sharp (0.35.2 → 0.35.4) are updated consistently and match the new wrangler version's own package.json dependency pins — no mismatched transitive versions.
  • @cloudflare/workers-types peer dependency: wrangler's peer dep bumped to ^5.20260915.1, but it's optional: true in peerDependenciesMeta and isn't a direct dependency in web/package.json, so this doesn't require any action here.
  • Reuse/simplification/tests/security: N/A for a pure lockfile + version-string dependency bump.

No issues found. This is a routine, low-risk devDependency update — safe to merge pending normal CI checks (build/typecheck for web/).

@codewhale-agent

Copy link
Copy Markdown

Codewhale review did not run

codewhale review --pr 6358 (provider: deepseek) could not reach the model: Review pass 1/1 request failed: Responses API request failed: LLM error: HTTP 402: Insufficient Balance; no partial review was accepted or posted; publication: n.
This is a provider funding/config problem, not a finding about this PR. The check stays advisory; a maintainer with secret access needs to fund or rotate the review key (see .github/workflows/codewhale-review.yml). Re-run the workflow after that.

@Hmbown
Hmbown merged commit cb537a8 into main Sep 21, 2026
30 checks passed
@Hmbown
Hmbown deleted the dependabot/npm_and_yarn/web/wrangler-4.132.0 branch September 21, 2026 15:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant