sanemat / workers-qr

https://workers-qr.sanemat.workers.dev/
Apache License 2.0
1 stars 0 forks source link

chore(deps-dev): bump @cloudflare/wrangler from 1.19.5 to 1.19.6 #231

Closed dependabot[bot] closed 2 years ago

dependabot[bot] commented 2 years ago

Bumps @cloudflare/wrangler from 1.19.5 to 1.19.6.

Release notes

Sourced from @​cloudflare/wrangler's releases.

v1.19.6

  • Features

  • Fixes

    • Don't look for background updates unless Wrangler finished successfully - jyn514, pull/2150

      This works around a segfault due to OpenSSL's exit handlers not being thread-safe.

      See cloudflare/wrangler#1464 for an explanation and alternatives.

    • fix: incomplete binary with npm installation - 12f23eddde, pull/2149

      Closes #2148. This PR modifies binary-install.js (reference) to make sure the file stream is complete before the program finishes. I'm not a ... truncated

    • Get https websockets working - jyn514, pull/2153

      It turns out websocket upgrades with HTTP/2 require an HTTP extension, which Cloudflare doesn't currently support: https://datatracker.ietf.org/doc/html/rfc8441

      To avoid this, enable HTTP/1 for the remote client.

      This required an upd ... truncated

    • Get the audit CI job passing - jyn514, [pull/2151]

      Note that I didn't say "fix the vulnerabilities" - this just ignores the chrono and time vulnerabilities because they're both very hard to fix and not very common in practice.

... (truncated)

Changelog

Sourced from @​cloudflare/wrangler's changelog.

v1.19.6

  • Features

  • Fixes

    • Don't look for background updates unless Wrangler finished successfully - jyn514, pull/2150

      This works around a segfault due to OpenSSL's exit handlers not being thread-safe.

      See cloudflare/wrangler#1464 for an explanation and alternatives.

    • fix: incomplete binary with npm installation - 12f23eddde, pull/2149

      Closes #2148. This PR modifies binary-install.js (reference) to make sure the file stream is complete before the program finishes. I'm not a ... truncated

    • Get https websockets working - jyn514, pull/2153

      It turns out websocket upgrades with HTTP/2 require an HTTP extension, which Cloudflare doesn't currently support: https://datatracker.ietf.org/doc/html/rfc8441

      To avoid this, enable HTTP/1 for the remote client.

      This required an upd ... truncated

    • Get the audit CI job passing - jyn514, [pull/2151]

      Note that I didn't say "fix the vulnerabilities" - this just ignores the chrono and time vulnerabilities because they're both very hard to fix and not very common in practice.

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by threepointone, a new releaser for @​cloudflare/wrangler since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)