chore(deps): bump wrangler from 4.118.0 to 4.123.0 - #1857
Closed
dependabot[bot] wants to merge 1 commit into
Closed
Conversation
Bumps [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler) from 4.118.0 to 4.123.0. - [Release notes](https://github.com/cloudflare/workers-sdk/releases) - [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.123.0/packages/wrangler) --- updated-dependencies: - dependency-name: wrangler dependency-version: 4.123.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
Contributor
simple-agent-manager Bot
pushed a commit
that referenced
this pull request
Aug 24, 2026
…batch Extends this batch from four PRs to nine so the whole stale Dependabot backlog lands as one CI run and one staging verification, per the project policy on consolidating staging sweeps onto a single pinned candidate. Taken as-is (their commits are merged above, SHAs preserved): - #1791 modernc.org/sqlite 1.55.0 -> 1.56.0 (packages/vm-agent) - #1853 anthropics/claude-code-action 1.0.189 -> 1.0.193 SHA 9d7150bc verified to be the commit v1.0.193 dereferences to. Applied by hand, because each needed a second half Dependabot cannot see: - #1855 cloudflare/sandbox 0.12.1 -> 0.12.7. This supersedes the 0.12.5 already on this branch (from the now-closed #1792). Dependabot only rewrites the FROM digest, so the npm client and the reviewed-source-tag comment were moved with it. Digest re-verified against the Docker Hub manifest rather than trusted from the PR body. The governance test added by this batch is what forces these three to move together. - #1856 react 19.2.7 -> 19.2.8, @types/react 19.2.17 -> 19.2.18. Dependabot groups react with @types/react but NOT react-dom, which ships from the same repo and must match react exactly. Left alone it would have landed react 19.2.8 against react-dom 19.2.7. Bumped react-dom to 19.2.8 as well and recorded the reason in pnpm-workspace.yaml, mirroring the existing typescript-eslint lockstep comment directly above it. - #1854 @commitlint/config-conventional 21.2.0 -> 21.2.2. Same shape: @commitlint/cli is released in lockstep and 21.2.2 exists, so both moved. - #1857 wrangler 4.118.0 -> 4.123.0 (catalog). All npm versions confirmed present on the registry before pinning. `pnpm quality:dependency-governance` passes 6/6, including the image<->SDK exact-pin invariant now asserting 0.12.7 on both sides.
Contributor
Author
|
Superseded by #1915. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Bumps wrangler from 4.118.0 to 4.123.0.
Release notes
Sourced from wrangler's releases.
... (truncated)
Commits
c576a82Version Packages (#15154)339509dAdd automatic update prompts for out-of-date Cloudflare agent skills (#14872)b8fd112feat: implement local dev for ctx.access (#15113)f0f2054Replace ignore-defaults with ignore-base-config CLI arg for Previews (#15152)e5d56e9Version Packages (#15145)3b02915[wrangler] Avoid stale remote binding sessions (#15142)d0c976cBump the workerd-and-workers-types group across 1 directory with 2 updates (#...15fc568Version Packages (#15118)5b1b930Fetch script metadata directly instead of listing all scripts (#15132)0aa8fa5SupportDO_NOT_TRACK=1(#14924)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)