Skip to content

chore(deps): bump the cloudflare group with 2 updates - #130

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/cloudflare-91a8d56cd0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/cloudflare-91a8d56cd0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the cloudflare group with 2 updates: @opennextjs/cloudflare and wrangler.

Updates @opennextjs/cloudflare from 1.15.1 to 1.20.7

Release notes

Sourced from @​opennextjs/cloudflare's releases.

@​opennextjs/cloudflare@​1.20.7

Patch Changes

  • #1403 dc3c0ab Thanks @​aa-sikkkk! - fix: replace the whole loadCustomCacheHandlers body so Next.js 16.3 chunks don't throw ReferenceError

    Next.js 16.3 rewrote loadCustomCacheHandlers: the declaration that binds cacheHandlers now also binds cacheMaxMemorySize, and the native method body consumes both. The composable cache patch replaced only that declaration, so on the minified runtime chunks (dist/compiled/next-server/*.runtime.prod.js) the surviving native code referenced bindings that were no longer declared. Every request to the Worker then failed with ReferenceError: <minified identifier> is not defined inside loadCustomCacheHandlers (site-wide 500s on Next.js 16.3.x), while builds stayed green because the unminified next-server.js short-circuits on if (!cacheHandlers) return before the orphaned binding is read.

    The patch now replaces the whole method body while preserving its signature and wires the composable cache registry to the static require() as before, so no native reference to a dropped binding can survive. The rule still matches pre-16.3 chunks, so older Next.js versions are unaffected.

  • #1399 2b3e3a1 Thanks @​JT1974! - fix: throw MODULE_NOT_FOUND from the stub of a missing optional dependency

    With React 18, every Pages Router page rendered by the Worker failed with TypeError: Cannot read properties of undefined (reading 'contexts'), caused by Error: Missing optional dependency "react-dom/server.edge". React 18 has no react-dom/server.edge, and Next.js falls back to react-dom/server.browser only when the error carries the MODULE_NOT_FOUND code. The stub now sets that code, so the fallback works again.

  • #1406 8ea9eb9 Thanks @​mgarbacz! - fix: only rename esbuild's __require helper, not __require properties

    Restoring esbuild's __require helper to a bare require was a text replacement over the whole bundle, so it also rewrote unrelated __require members. @rollup/plugin-commonjs emits exports.__require lazy-init wrappers, whose declarations the replacement never matched — leaving the two halves disagreeing and throwing TypeError: __webpack_require__(...).require is not a function when such a package was imported during SSR. Packages built that way (for example smartystreets-javascript-sdk) 500'd every route. The rename now skips property accesses.

  • #1404 ca4415b Thanks @​vicb! - chore: require Next.js 15.5.26 or 16.3.6

    Raise the supported Next.js version floor to 15.5.26 and 16.3.6. Next.js 16.2.0 through 16.3.5 are affected by the critical next/og remote code execution vulnerability CVE-2026-94545.

  • #1404 ca4415b Thanks @​vicb! - chore: bump @opennextjs/aws to 4.1.6

    See details at https://github.com/opennextjs/opennextjs-aws/releases/tag/v4.1.6

@​opennextjs/cloudflare@​1.20.6

Patch Changes

@​opennextjs/cloudflare@​1.20.5

Patch Changes

... (truncated)

Changelog

Sourced from @​opennextjs/cloudflare's changelog.

1.20.7

Patch Changes

  • #1403 dc3c0ab Thanks @​aa-sikkkk! - fix: replace the whole loadCustomCacheHandlers body so Next.js 16.3 chunks don't throw ReferenceError

    Next.js 16.3 rewrote loadCustomCacheHandlers: the declaration that binds cacheHandlers now also binds cacheMaxMemorySize, and the native method body consumes both. The composable cache patch replaced only that declaration, so on the minified runtime chunks (dist/compiled/next-server/*.runtime.prod.js) the surviving native code referenced bindings that were no longer declared. Every request to the Worker then failed with ReferenceError: <minified identifier> is not defined inside loadCustomCacheHandlers (site-wide 500s on Next.js 16.3.x), while builds stayed green because the unminified next-server.js short-circuits on if (!cacheHandlers) return before the orphaned binding is read.

    The patch now replaces the whole method body while preserving its signature and wires the composable cache registry to the static require() as before, so no native reference to a dropped binding can survive. The rule still matches pre-16.3 chunks, so older Next.js versions are unaffected.

  • #1399 2b3e3a1 Thanks @​JT1974! - fix: throw MODULE_NOT_FOUND from the stub of a missing optional dependency

    With React 18, every Pages Router page rendered by the Worker failed with TypeError: Cannot read properties of undefined (reading 'contexts'), caused by Error: Missing optional dependency "react-dom/server.edge". React 18 has no react-dom/server.edge, and Next.js falls back to react-dom/server.browser only when the error carries the MODULE_NOT_FOUND code. The stub now sets that code, so the fallback works again.

  • #1406 8ea9eb9 Thanks @​mgarbacz! - fix: only rename esbuild's __require helper, not __require properties

    Restoring esbuild's __require helper to a bare require was a text replacement over the whole bundle, so it also rewrote unrelated __require members. @rollup/plugin-commonjs emits exports.__require lazy-init wrappers, whose declarations the replacement never matched — leaving the two halves disagreeing and throwing TypeError: __webpack_require__(...).require is not a function when such a package was imported during SSR. Packages built that way (for example smartystreets-javascript-sdk) 500'd every route. The rename now skips property accesses.

  • #1404 ca4415b Thanks @​vicb! - chore: require Next.js 15.5.26 or 16.3.6

    Raise the supported Next.js version floor to 15.5.26 and 16.3.6. Next.js 16.2.0 through 16.3.5 are affected by the critical next/og remote code execution vulnerability CVE-2026-94545.

  • #1404 ca4415b Thanks @​vicb! - chore: bump @opennextjs/aws to 4.1.6

    See details at https://github.com/opennextjs/opennextjs-aws/releases/tag/v4.1.6

1.20.6

Patch Changes

1.20.5

... (truncated)

Commits

Updates wrangler from 4.142.0 to 4.146.0

Release notes

Sourced from wrangler's releases.

wrangler@4.146.0

Minor Changes

  • #15777 464a582 Thanks @​Naapperas! - Support the new Workflows createBatch() API in local development

    Local Workflows bindings now accept object-form batches that create instances from a count or a list of instance options. The result includes handles for created instances and indexed per-instance errors, matching the runtime API while preserving the deprecated array form.

  • #15639 aee2842 Thanks @​hugo-vicente11! - Add --allowed-mail to the experimental wrangler tunnel quick-start command

    The option forwards exact email addresses, comma-separated lists, and wildcard domains to cloudflared. It can be specified more than once to combine multiple recipient rules.

    Email-protected tunnels require cloudflared 2026.9.2 or later. Wrangler checks the selected binary before starting the tunnel and reports an upgrade error when it is incompatible.

Patch Changes

  • #15992 b8e7cc3 Thanks @​zebp! - Mark wrangler artifacts commands as open beta

    Artifacts has entered open beta, so the wrangler artifacts commands no longer display a "private beta" label in help output and warnings.

  • #15984 9d7b08e Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    @​cloudflare/workers-types ^5.20260930.2 ^5.20261001.1
    workerd 1.20260930.2 1.20261001.1
  • #15959 efd67e6 Thanks @​breken-ai! - Keep colons in wrangler tail --header filter values

    wrangler tail --header splits its argument into a header name and an optional value at the colon. It split at every colon and kept only the first two parts, so a value containing a colon was cut short: --header "Origin:https://app.example.com" filtered on https. The value now includes everything after the first colon, so URLs, ports and IPv6 addresses are sent to the tail filter intact.

  • Updated dependencies [b00ef4f, 9d7b08e, 464a582]:

wrangler@4.145.0

Minor Changes

  • #15685 b9f1cdc Thanks @​Ankcorn! - Add native support for the Analytics SQL binding

    Declare the zero-configuration binding in wrangler.json with "analytics": { "binding": "ANALYTICS" }. Wrangler uploads the analytics binding type and proxies it to the remote service during local development, so wrangler dev can call the binding without unsafe.bindings.

  • #15943 8468487 Thanks @​sejoker! - Graduate SQL, Catalog, and Pipelines under wrangler basin out of beta to stable

    Basin SQL is now available under wrangler basin sql, Basin Catalog operations are available under wrangler basin catalog, and Pipelines operations are available under wrangler basin pipelines. These commands are now stable, while the previous wrangler r2 sql, wrangler r2 bucket catalog, and wrangler pipelines command paths remain available as hidden compatibility aliases.

    The Basin SQL authentication environment variable is now WRANGLER_BASIN_SQL_AUTH_TOKEN. Update any existing WRANGLER_R2_SQL_AUTH_TOKEN configuration to use the new name. The fallback to CLOUDFLARE_API_TOKEN remains available.

  • #15948 a0712e5 Thanks @​akoval-cf! - Add beta K2 producer bindings for existing streams

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the cloudflare group with 2 updates: [@opennextjs/cloudflare](https://github.com/opennextjs/opennextjs-cloudflare/tree/HEAD/packages/cloudflare) and [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler).


Updates `@opennextjs/cloudflare` from 1.15.1 to 1.20.7
- [Release notes](https://github.com/opennextjs/opennextjs-cloudflare/releases)
- [Changelog](https://github.com/opennextjs/opennextjs-cloudflare/blob/main/packages/cloudflare/CHANGELOG.md)
- [Commits](https://github.com/opennextjs/opennextjs-cloudflare/commits/@opennextjs/cloudflare@1.20.7/packages/cloudflare)

Updates `wrangler` from 4.142.0 to 4.146.0
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.146.0/packages/wrangler)

---
updated-dependencies:
- dependency-name: "@opennextjs/cloudflare"
  dependency-version: 1.20.7
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cloudflare
- dependency-name: wrangler
  dependency-version: 4.146.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: cloudflare
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants