Releases: wdl-dev/cli
Releases · wdl-dev/cli
Release list
v1.9.2
Version 1.9.1 was not published to npm. This release includes its changes;
the notes below cover the upgrade from 1.9.0 to 1.9.2.
Changed
- Upgrade the bundled Wrangler to 4.143.1 and reject the unmapped
durable_objects.code_update_strategyinstead of silently ignoring it. - Reject custom Wrangler module rules, unmapped queue, service, Durable Object,
and asset fields, and route objects instead of silently dropping their
effects. - Keep WDL
[[exports]]and[[platform_bindings]]scoped to the selected
environment and warn when they are omitted there; let env-levelrouteand
routesreplace each other. - Project-local Wrangler must support
--env-file(>=4.27.0 <5.0.0) for
version probing and bundling; older v4 installations take precedence over the
bundled release.
Fixed
- Treat bundled
.sqlmodules as text, reconnect idle or transiently failed
Tail streams while stopping on permanentctx_unavailable, and show partial
D1 migration progress after an apply error. - Keep asset directories out of Wrangler dry-run so excluded files cannot block
bundling before the CLI applies its asset ignore rules. - Show retained Durable Object storage in worker deletion output and avoid
forged human-output lines in D1, R2, and doctor summaries. - Correct
--jsonhelp text, optional--yesusage, and generated project
exclusions for.dev.vars*files.
Security
- Update
smol-tomlto 1.9.0 and Wrangler's transitive Undici to 7.29.1 to
address their dependency advisories without overrides. - Stop Wrangler from automatically loading the project's
.envinto its build
environment, including generatednpm run dry-runchecks; exclude.env*,
.dev.vars*, and.wdl-empty.envfrom assets by default, and prevent a
project.envfrom redirecting a higher-priority Control URL via
CONTROL_CONNECT_HOST. - Verify HTTPS certificates against the Control URL's IP authority even when
CONTROL_CONNECT_HOSToverrides the socket destination. - Avoid persisting checkout credentials in release jobs.
Full Changelog: v1.9.0...v1.9.2
v1.9.0
Changed
- Support
--limitand--cursorfor Workflow definition listing and display
continuation cursors even for empty definition pages. - Upgrade the bundled Wrangler to 4.131.0 and reject unmapped
[[connect]]TCP
listeners and[[workflows]]fields, includingschedules,limits,
default_retention, andconcurrency, instead of silently dropping them. - Disable Wrangler skills installation/update prompts during deploy. Bundling
keeps stdin closed even with--verbose, which still forwards stdout/stderr.
Fixed
- Distinguish empty intermediate Workflow instance pages from an empty result
set when Control returns a continuation cursor. - Explain how to restart Workflow definition listing after cursor metadata
contention, even when Control redacts the error message. - Explain how to set
--nsorWDL_NSwhen a required namespace is missing.
Security
- Update
smol-tomlto 1.7.1 and Wrangler's transitivesharpto 0.35.4,
clearing their dependency advisories without overrides.
v1.8.1
Changed
- Require Wrangler v4 and validate Workflow page limits locally as integers in
1..1000. - Document R2
--outoverwrite/symlink behavior and include token-store tasks
in deploy-skill discovery.
Fixed
- Keep
wdl config explainuseful when an attempted token-store read fails. - Fix the opt-in Windows
npxfallback and reject stable release tags with no
matching changelog section before publishing.
Security
- Require confirmation for
wdl delete versionand reject its unsupported
--dry-runflag, and cap assembled Tail SSE event data at 4 MiB. - Reject unsafe token-store files and POSIX ownership/permission states using a
descriptor-validated read path. - Reject Control URLs containing credentials, query strings, or fragments; treat
.localas network/mDNS rather than loopback for plaintext-token warnings;
and recognize the full127.0.0.0/8range. - Pin official GitHub Actions to fixed commit SHAs.
v1.8.0
Added
- Add
[ai]binding support andwdl aicommands for namespace-scoped
providers, credentials, and model discovery, including an offline provider
JSON initializer. - Add OpenAI-compatible SDK guidance and a bearer-protected Responses
function-tool agent example.
Changed
wdl ai,wdl secret, andwdl tokenreject flag-before-subcommand calls
whose option value is also a command word; put the subcommand first or use
--flag=value.
Security
- Redact invalid argument details for
wdl ai,wdl secret, andwdl tokenso
accidentally supplied credentials are not echoed to terminal or CI logs.
v1.7.1
Changed
- Bump the bundled Wrangler to 4.120.0, which includes undici 7.29.0 without the
package-level override.
Fixed
- Reject unsupported Wrangler
triggers.eventssubscriptions before bundling
instead of silently dropping them from the WDL deploy manifest.
v1.7.0
Added
[wdl] session_policy = "restart"opts a Worker into session restarts,
matching Cloudflare's default deploy behavior. The default remainspreserve.
wdl deployrefuses to promote when control does not confirm the policy.
Fixed
- Reject a bare TOML datetime where a config table is expected, instead of
reading it as an empty table and silently dropping the section. - Report an unknown promotion outcome when a timeout, transport failure, 3xx/5xx
or unconfirmed response answers the promote, instead of claiming the version
was not promoted.
Security
- Override
undicito^7.29.0and refreshbrace-expansionto 5.0.9,
clearing five undici advisories and GHSA-rgw5-rvv9-x895. Both reach this
repository's install tree only, through the miniflare dev server the CLI never
runs and through ESLint.
v1.6.1
Changed
- Pin Prettier and enforce repository formatting in CI and release validation.
v1.6.0
Added
- Routed Workers with at least one custom route can set
workers_dev = false
to disable their platform-domain URL. Deploy summaries print the active
platform URL and route-pattern URL hints, omitting the disabled URL.
v1.5.1
Security
- Bump the bundled
wranglerto 4.114.0, which vendors a patched sharp
(0.35.2) and clears a high-severity libvips advisory (GHSA-f88m-g3jw-g9cj)
reachable only through the miniflare dev server, which the CLI never runs.
v1.5.0
Changed
wdl workersandwdl workflows listnow expose workflow-definition state,
including retired definitions. Delete dry-runs report worker-secret and
workflow-definition presence without claiming blocked data will be deleted.- Local deploy URLs now preserve the scheme and port from
CONTROL_URL. wdl deploynow pins Wrangler 4.112.0, rejects unmappedaddressesand
dependencies_instrumentation, and suppresses Wrangler's banner, routine
update check, and telemetry during dry-run. Unknown-field diagnostics may
still query the npm registry.
Fixed
wdl deploynow explainscompatibility_flag_unsupportederrors.- Workflow human output now escapes control-plane fields without changing
--jsonoutput.