Skip to content

Releases: wdl-dev/cli

v1.9.2

Choose a tag to compare

@github-actions github-actions released this 29 Sep 19:37
v1.9.2
b0bfb6d

Version 1.9.1 was not published to npm. This release includes its changes;
the notes below cover the upgrade from 1.9.0 to 1.9.2.

Changed

  • Upgrade the bundled Wrangler to 4.143.1 and reject the unmapped
    durable_objects.code_update_strategy instead of silently ignoring it.
  • Reject custom Wrangler module rules, unmapped queue, service, Durable Object,
    and asset fields, and route objects instead of silently dropping their
    effects.
  • Keep WDL [[exports]] and [[platform_bindings]] scoped to the selected
    environment and warn when they are omitted there; let env-level route and
    routes replace each other.
  • Project-local Wrangler must support --env-file (>=4.27.0 <5.0.0) for
    version probing and bundling; older v4 installations take precedence over the
    bundled release.

Fixed

  • Treat bundled .sql modules as text, reconnect idle or transiently failed
    Tail streams while stopping on permanent ctx_unavailable, and show partial
    D1 migration progress after an apply error.
  • Keep asset directories out of Wrangler dry-run so excluded files cannot block
    bundling before the CLI applies its asset ignore rules.
  • Show retained Durable Object storage in worker deletion output and avoid
    forged human-output lines in D1, R2, and doctor summaries.
  • Correct --json help text, optional --yes usage, and generated project
    exclusions for .dev.vars* files.

Security

  • Update smol-toml to 1.9.0 and Wrangler's transitive Undici to 7.29.1 to
    address their dependency advisories without overrides.
  • Stop Wrangler from automatically loading the project's .env into its build
    environment, including generated npm run dry-run checks; exclude .env*,
    .dev.vars*, and .wdl-empty.env from assets by default, and prevent a
    project .env from redirecting a higher-priority Control URL via
    CONTROL_CONNECT_HOST.
  • Verify HTTPS certificates against the Control URL's IP authority even when
    CONTROL_CONNECT_HOST overrides the socket destination.
  • Avoid persisting checkout credentials in release jobs.

Full Changelog: v1.9.0...v1.9.2

v1.9.0

Choose a tag to compare

@github-actions github-actions released this 12 Sep 18:19
v1.9.0
5fbebd4

Changed

  • Support --limit and --cursor for Workflow definition listing and display
    continuation cursors even for empty definition pages.
  • Upgrade the bundled Wrangler to 4.131.0 and reject unmapped [[connect]] TCP
    listeners and [[workflows]] fields, including schedules, limits,
    default_retention, and concurrency, instead of silently dropping them.
  • Disable Wrangler skills installation/update prompts during deploy. Bundling
    keeps stdin closed even with --verbose, which still forwards stdout/stderr.

Fixed

  • Distinguish empty intermediate Workflow instance pages from an empty result
    set when Control returns a continuation cursor.
  • Explain how to restart Workflow definition listing after cursor metadata
    contention, even when Control redacts the error message.
  • Explain how to set --ns or WDL_NS when a required namespace is missing.

Security

  • Update smol-toml to 1.7.1 and Wrangler's transitive sharp to 0.35.4,
    clearing their dependency advisories without overrides.

v1.8.1

Choose a tag to compare

@github-actions github-actions released this 19 Aug 18:19
v1.8.1
a908c35

Changed

  • Require Wrangler v4 and validate Workflow page limits locally as integers in
    1..1000.
  • Document R2 --out overwrite/symlink behavior and include token-store tasks
    in deploy-skill discovery.

Fixed

  • Keep wdl config explain useful when an attempted token-store read fails.
  • Fix the opt-in Windows npx fallback and reject stable release tags with no
    matching changelog section before publishing.

Security

  • Require confirmation for wdl delete version and reject its unsupported
    --dry-run flag, and cap assembled Tail SSE event data at 4 MiB.
  • Reject unsafe token-store files and POSIX ownership/permission states using a
    descriptor-validated read path.
  • Reject Control URLs containing credentials, query strings, or fragments; treat
    .local as network/mDNS rather than loopback for plaintext-token warnings;
    and recognize the full 127.0.0.0/8 range.
  • Pin official GitHub Actions to fixed commit SHAs.

v1.8.0

Choose a tag to compare

@github-actions github-actions released this 17 Aug 09:50
v1.8.0
db3e9fd

Added

  • Add [ai] binding support and wdl ai commands for namespace-scoped
    providers, credentials, and model discovery, including an offline provider
    JSON initializer.
  • Add OpenAI-compatible SDK guidance and a bearer-protected Responses
    function-tool agent example.

Changed

  • wdl ai, wdl secret, and wdl token reject flag-before-subcommand calls
    whose option value is also a command word; put the subcommand first or use
    --flag=value.

Security

  • Redact invalid argument details for wdl ai, wdl secret, and wdl token so
    accidentally supplied credentials are not echoed to terminal or CI logs.

v1.7.1

Choose a tag to compare

@github-actions github-actions released this 09 Aug 01:24
v1.7.1
fd77c20

Changed

  • Bump the bundled Wrangler to 4.120.0, which includes undici 7.29.0 without the
    package-level override.

Fixed

  • Reject unsupported Wrangler triggers.events subscriptions before bundling
    instead of silently dropping them from the WDL deploy manifest.

v1.7.0

Choose a tag to compare

@github-actions github-actions released this 07 Aug 05:02
68756ed

Added

  • [wdl] session_policy = "restart" opts a Worker into session restarts,
    matching Cloudflare's default deploy behavior. The default remains preserve.
    wdl deploy refuses to promote when control does not confirm the policy.

Fixed

  • Reject a bare TOML datetime where a config table is expected, instead of
    reading it as an empty table and silently dropping the section.
  • Report an unknown promotion outcome when a timeout, transport failure, 3xx/5xx
    or unconfirmed response answers the promote, instead of claiming the version
    was not promoted.

Security

  • Override undici to ^7.29.0 and refresh brace-expansion to 5.0.9,
    clearing five undici advisories and GHSA-rgw5-rvv9-x895. Both reach this
    repository's install tree only, through the miniflare dev server the CLI never
    runs and through ESLint.

v1.6.1

Choose a tag to compare

@github-actions github-actions released this 27 Jul 05:29
9a1c58f

Changed

  • Pin Prettier and enforce repository formatting in CI and release validation.

v1.6.0

Choose a tag to compare

@github-actions github-actions released this 27 Jul 03:33
4158dd3

Added

  • Routed Workers with at least one custom route can set workers_dev = false
    to disable their platform-domain URL. Deploy summaries print the active
    platform URL and route-pattern URL hints, omitting the disabled URL.

v1.5.1

Choose a tag to compare

@github-actions github-actions released this 25 Jul 12:00
dc78d05

Security

  • Bump the bundled wrangler to 4.114.0, which vendors a patched sharp
    (0.35.2) and clears a high-severity libvips advisory (GHSA-f88m-g3jw-g9cj)
    reachable only through the miniflare dev server, which the CLI never runs.

v1.5.0

Choose a tag to compare

@github-actions github-actions released this 19 Jul 03:31
v1.5.0
841be50

Changed

  • wdl workers and wdl workflows list now expose workflow-definition state,
    including retired definitions. Delete dry-runs report worker-secret and
    workflow-definition presence without claiming blocked data will be deleted.
  • Local deploy URLs now preserve the scheme and port from CONTROL_URL.
  • wdl deploy now pins Wrangler 4.112.0, rejects unmapped addresses and
    dependencies_instrumentation, and suppresses Wrangler's banner, routine
    update check, and telemetry during dry-run. Unknown-field diagnostics may
    still query the npm registry.

Fixed

  • wdl deploy now explains compatibility_flag_unsupported errors.
  • Workflow human output now escapes control-plane fields without changing
    --json output.