Version 1.9.1 was not published to npm. This release includes its changes;
the notes below cover the upgrade from 1.9.0 to 1.9.2.
Changed
- Upgrade the bundled Wrangler to 4.143.1 and reject the unmapped
durable_objects.code_update_strategyinstead of silently ignoring it. - Reject custom Wrangler module rules, unmapped queue, service, Durable Object,
and asset fields, and route objects instead of silently dropping their
effects. - Keep WDL
[[exports]]and[[platform_bindings]]scoped to the selected
environment and warn when they are omitted there; let env-levelrouteand
routesreplace each other. - Project-local Wrangler must support
--env-file(>=4.27.0 <5.0.0) for
version probing and bundling; older v4 installations take precedence over the
bundled release.
Fixed
- Treat bundled
.sqlmodules as text, reconnect idle or transiently failed
Tail streams while stopping on permanentctx_unavailable, and show partial
D1 migration progress after an apply error. - Keep asset directories out of Wrangler dry-run so excluded files cannot block
bundling before the CLI applies its asset ignore rules. - Show retained Durable Object storage in worker deletion output and avoid
forged human-output lines in D1, R2, and doctor summaries. - Correct
--jsonhelp text, optional--yesusage, and generated project
exclusions for.dev.vars*files.
Security
- Update
smol-tomlto 1.9.0 and Wrangler's transitive Undici to 7.29.1 to
address their dependency advisories without overrides. - Stop Wrangler from automatically loading the project's
.envinto its build
environment, including generatednpm run dry-runchecks; exclude.env*,
.dev.vars*, and.wdl-empty.envfrom assets by default, and prevent a
project.envfrom redirecting a higher-priority Control URL via
CONTROL_CONNECT_HOST. - Verify HTTPS certificates against the Control URL's IP authority even when
CONTROL_CONNECT_HOSToverrides the socket destination. - Avoid persisting checkout credentials in release jobs.
Full Changelog: v1.9.0...v1.9.2