Skip to content

build(deps): bump undici and miniflare in /confidence-cloudflare-resolver/deployer - #636

Open
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/confidence-cloudflare-resolver/deployer/multi-ee55b829cf
Open

dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/confidence-cloudflare-resolver/deployer/multi-ee55b829cf

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps undici to 7.29.1 and updates ancestor dependency miniflare. These dependencies need to be updated together.

Updates undici from 7.28.0 to 7.29.1

Release notes

Sourced from undici's releases.

v7.29.1

⚠️ Security fixes

High severity

  • GHSA-w293-vg96-wgc3: BalancedPool could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves connect and legacy tls options when creating upstreams. Fixed by f690157d.
  • GHSA-rfgv-xxqx-mfg5: a WebSocket server could select a subprotocol when none was requested, causing an uncaught TypeError that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 6615e017.

Medium severity

  • GHSA-3wwx-pv8p-q78v: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by 63cf698b.
  • GHSA-rx4f-c7p8-82vq: an unclean WebSocketStream close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by 1858656e.
  • GHSA-2jfj-6hjv-fm6j: shared caches could store and replay responses containing Set-Cookie, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by b6c5a002.
  • GHSA-3xpg-4rpp-hhhm: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable maxSize. Fixed by 2c7d7e12.
  • GHSA-pmjh-fq2x-6v4x: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by 3c672659.

Low severity

  • GHSA-8436-99hf-9mmv: cache interceptors could store and replay responses to unsafe HTTP methods such as POST or DELETE. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by b61d9432.
  • GHSA-2gqq-gqf2-x968: the dump interceptor could treat an oversized chunked response as successfully truncated when no Content-Length was present. Undici now enforces maxSize against received bytes and aborts oversized responses. Fixed by 21693f40.
  • GHSA-r53p-7pc4-xj5r: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates Content-Range against the original response framing before resuming. Fixed by cd8af90b.

What's Changed

Full Changelog: nodejs/undici@v7.29.0...v7.29.1

v7.29.0

⚠️ Security fixes

High severity

  • GHSA-4cwx-7wf7-3272: malformed qualified private Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by 9f10f1e9, with regression coverage in 466e99d1.

Medium severity

  • GHSA-m8rv-5g2x-5cg5: a malicious type property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated content-type header. Undici now coerces and validates the value before adding it to the request. Fixed by 33928bc2.
  • GHSA-jr45-8vmc-qm54: optional whitespace around = in qualified no-cache and private directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by 98011a86.
  • GHSA-8xcm-r25x-g524: the retry interceptor could expose a stale Content-Length after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose Content-Length is inconsistent with Content-Range. Fixed by 1b5a5312, with corrected fixtures in 4a9dafb1.
  • GHSA-v3r7-h72x-cjcm: unsanitized domain and unparsed values passed to setCookie() could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by 3bf91ddb.

... (truncated)

Commits
  • d39a83e Bumped v7.29.1 (#5772)
  • 0d88464 fix(test): remove unused EventEmitter import
  • f57411b perf(h1): drop idle-socket timer floor with a ref'd setImmediate (#5707) (#5769)
  • 3c67265 fix(retry): settle exposed body on terminal failure
  • cd8af90 fix(retry): validate resumed response framing
  • 6615e01 fix(websocket): reject unrequested subprotocols
  • 2c7d7e1 fix(decompress): limit decompressed response size
  • b6c5a00 fix(cache): do not cache Set-Cookie in shared caches
  • 21693f4 fix(interceptor/dump): abort oversized chunked responses
  • f690157 fix: preserve BalancedPool connection options
  • Additional commits viewable in compare view

Updates miniflare from 4.20260730.0 to 5.20260930.0-alpha

Release notes

Sourced from miniflare's releases.

miniflare@5.20260926.1-alpha

Patch Changes

  • #15923 60ccdbd Thanks @​petebacondarwin! - Upgrade the bundled capnweb implementation to 0.12.0

    This updates the RPC implementation shipped in Miniflare and remote-binding proxy workers to the latest capnweb release.

  • #15938 62fd03a Thanks @​dieub! - Resolve the affected Undici dependency in new Wrangler and Vite plugin installs

    Undici 7.29.1 fixes GHSA-3wwx-pv8p-q78v. Update the shared dependency catalog and matching types used by Miniflare and Wrangler so downstream installs can resolve the patched runtime without an application-level override. A published release is still required for consumers; this changeset does not alter already published package metadata.

  • #15902 c2bb4c8 Thanks @​michealroberts! - Fix passing an R2ObjectBody#body back to R2Bucket#put() via Miniflare#getR2Bucket()

    Previously, a body returned by get() lost its length on the way back through the binding proxy, so put() rejected it with "Provided readable stream must have a known length", even though the same call works in a Worker. The proxy now forwards the stream's length and the body streams straight through without buffering.

  • #15906 eb1efe0 Thanks @​michealroberts! - Preserve the request body length in Miniflare#dispatchFetch()

    Previously, a request with a known-length body (e.g. a string) was sent to the Worker chunked, without a Content-Length. Passing its request.body to R2Bucket#put() then failed with "Provided readable stream must have a known length", even though the same request works in production. The body's length is now preserved.

  • #15910 485cfb3 Thanks @​james-elicx! - Raise the local R2 custom metadata limit to 8 KiB

    R2 put() now accepts up to 8,192 bytes of custom metadata, matching the documented R2 limit. Previously, Miniflare rejected metadata larger than 2 KiB.

    Multipart upload creation now enforces the same limit through both R2 bindings and the local S3 API. Oversized metadata is rejected with error 10012 through R2 bindings, or HTTP 400 MetadataTooLarge for S3 uploads, copies, and multipart initiation.

miniflare@5.20260926.0-alpha

Minor Changes

  • #15856 4c2993b Thanks @​Naapperas! - Support Workflows declared in exports on ctx.exports in local development

    A Workflow declared in a Worker's exports is now available on ctx.exports in wrangler dev, the Vite plugin and the Vitest plugin, with the same API as a Workflow binding:

    const instance = await ctx.exports.MyWorkflow.create({
      params: { name: "World" },
    });

    ctx.exports and workflows bindings with the same Workflow name share their instances, including instances created before the Workflow was declared in exports. Two Workers can't export the same Workflow name, and a binding to an exported Workflow must refer to the Worker and class that export it. getPlatformProxy() ignores Workflows declared in exports, since it doesn't run the Worker's code.

    wrangler workflows commands run with --local also work with Workflows declared only in exports, without a workflows binding.

    In the Vitest plugin, introspectWorkflow() and introspectWorkflowInstance() still need a Workflow binding, and now explain how to add one when passed a Workflow from ctx.exports. Instances created through ctx.exports are introspected too. A workflows binding whose script_name is the Worker's own name now resolves to the Worker itself again.

Patch Changes

  • #15891 8dc53ae Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

... (truncated)

Changelog

Sourced from miniflare's changelog.

5.20260930.0-alpha

Minor Changes

  • #15685 b9f1cdc Thanks @​Ankcorn! - Add native support for the Analytics SQL binding

    Declare the zero-configuration binding in wrangler.json with "analytics": { "binding": "ANALYTICS" }. Wrangler uploads the analytics binding type and proxies it to the remote service during local development, so wrangler dev can call the binding without unsafe.bindings.

  • #15948 a0712e5 Thanks @​akoval-cf! - Add beta K2 producer bindings for existing streams

    Configure a stream created through Wrangler, the Dashboard, or the API in wrangler.json:

    {
      "k2": [
        {
          "binding": "ORDERS",
          "stream": "0123456789abcdef0123456789abcdef"
        }
      ]
    }

    The binding supports env.ORDERS.send([{ content: new TextEncoder().encode("order"), headers: { event: "order.created" } }]). Batches use either all ArrayBuffer or all Uint8Array content. Check the returned success value, handle rejected RPC promises, and retry only when the returned error explicitly allows it. Generated environment types describe this producer contract without requiring a separate application dependency.

    K2 requires an enabled account. Deployment credentials need Worker deployment and K2 configuration-read access. Default Wrangler logins now request the K2 OAuth scopes; existing OAuth users should run wrangler login again to grant the new permissions. Development always uses a real K2 stream and may incur usage charges; no local simulator is provided. The remote setting can be omitted, remote: true suppresses the usage warning, and remote: false is rejected. Consumption is not part of this Worker binding.

Patch Changes

  • #15908 ddaa558 Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20260926.1 ^5.20260930.2
    workerd 1.20260926.1 1.20260930.2

5.20260926.1-alpha

Patch Changes

  • #15923 60ccdbd Thanks @​petebacondarwin! - Upgrade the bundled capnweb implementation to 0.12.0

    This updates the RPC implementation shipped in Miniflare and remote-binding proxy workers to the latest capnweb release.

  • #15938 62fd03a Thanks @​dieub! - Resolve the affected Undici dependency in new Wrangler and Vite plugin installs

    Undici 7.29.1 fixes GHSA-3wwx-pv8p-q78v. Update the shared dependency catalog and matching types used by Miniflare and Wrangler so downstream installs can resolve the patched runtime without an application-level override. A published release is still required for consumers; this changeset does not alter already published package metadata.

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [undici](https://github.com/nodejs/undici) to 7.29.1 and updates ancestor dependency [miniflare](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/miniflare). These dependencies need to be updated together.


Updates `undici` from 7.28.0 to 7.29.1
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.28.0...v7.29.1)

Updates `miniflare` from 4.20260730.0 to 5.20260930.0-alpha
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Changelog](https://github.com/cloudflare/workers-sdk/blob/main/packages/miniflare/CHANGELOG.md)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/HEAD/packages/miniflare)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 7.29.1
  dependency-type: indirect
- dependency-name: miniflare
  dependency-version: 5.20260930.0-alpha
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 30, 2026
Miniflare 5 removed the v4 top-level option shape (modulesRoot,
compatibilityDate, compatibilityFlags, modules, outboundService) and
rejects it with ERR_VALIDATION, making every deployment abort with
measurement_failed. Convert explicitly via convertV4MiniflareOptions.

Runtime-verified: real preflight against the built worker measures
identically to miniflare 4 (wasm 2.50 MiB + JS capacity 1.25 MiB =
3.75 MiB baseline, status pass).

Co-Authored-By: Snipe (glm-5-3-flash) <snipe-agent@users.noreply.ghe.spotify.net>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant