Skip to content

build(deps-dev): bump the npm group with 3 updates - #252

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/npm-02af167793
Open

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/npm-02af167793

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm group with 3 updates: boxen, esptool-js and wrangler.

Updates boxen from 8.0.1 to 9.0.0

Release notes

Sourced from boxen's releases.

v9.0.0

Breaking

  • Require Node.js 22 0aead27

Improvements

  • Add maxWidth option 5932ef4
  • Add footer option e719cec
  • Add titleColor option c0f18e7
  • Add borderBackgroundColor option (#100) 1373d4f
  • Lots of bug fixes

sindresorhus/boxen@v8.0.1...v9.0.0

Commits
  • a809729 9.0.0
  • 2e901c1 Measure a label with the corners it is drawn between
  • 6d377fb More tests
  • 427ac21 Give the box the height it is given when the text does not fit
  • 94db7a5 Write a border character the way a label is written
  • 804e1e7 Keep a styling escape whole when a backspace is applied
  • 9f8fabd Draw a padding and a margin as a whole number of columns
  • 986a49b Do not take columns for a margin that is not drawn
  • 2bc26cd Measure the border in columns
  • 7ed8da2 Read the height of the terminal from LINES
  • Additional commits viewable in compare view

Updates esptool-js from 0.6.1 to 0.7.0

Release notes

Sourced from esptool-js's releases.

Espressif ESPTOOL-JS v0.7.0

v0.7.0 - 2026-09-21

Features

Bug fixes

Breaking

  • detectFlashSize() now returns undefined when the SPI flash ID cannot be read or mapped, instead of silently defaulting to "4MB". TypeScript callers must handle undefined; JavaScript callers no longer always receive a string.

Added

  • LoaderOptions.romBaudrate (default 115200). Set it equal to baudrate to skip the post-stub port reopen.
  • Serial-port implementations can provide an optional setBaudRate() capability to change baud in place. Custom WebUSB transports can use device-specific control transfers and avoid closing the port.
  • WebUSBSerialPort CH340/CH341 adapter: in-place baud via vendor request 0x9A. The TypeScript example has an opt-in WebUSB (CH340) checkbox. On desktop OS the kernel usbserial driver often owns the device; Android/Chrome OTG is the reliable WebUSB case. See [PR #265](espressif/esptool-js#265)

Fixed

  • After a baud-rate change, drain leftover serial data and probe the chip. Native Web Serial still requires a port reopen; if this resets the board, fall back to the ROM baud rate and re-run the stub instead of failing with Invalid head of packet.
  • writeFlash throws if fileArray[].data is not a Uint8Array, instead of passing a binary string into deflate and corrupting the image (#266).
  • writeFlash({ flashSize: "detect" }) resolves the flash size (via detectFlashSize()) before the bounds check, so "detect" is no longer treated as size -1 (#254). Detection runs for every file in the write, not only a boot image at BOOTLOADER_FLASH_OFFSET.
  • ESP32-C6, C5, C61, and H2 use SPI_REG_BASE = 0x60003000, matching esptool. Flash ID reads on those chips no longer return 0 (#217).
  • ESP32-P4: postConnect() now runs powerOnFlash(), which was implemented but never called. On ECO6/ECO7 silicon (revisions v3.1 and v3.2) the flash is powered off by default, so the flash ID read returned garbage and the first flash command hung the stub. ECO7 parts with the DOWNLOAD_MODE_XPD_ON eFuse programmed release the ROM's flash force-on state instead of repeating the power-up sequence, matching esptool.
Changelog

Sourced from esptool-js's changelog.

v0.7.0 - 2026-09-21

Features

Bug fixes

Breaking

  • detectFlashSize() now returns undefined when the SPI flash ID cannot be read or mapped, instead of silently defaulting to "4MB". TypeScript callers must handle undefined; JavaScript callers no longer always receive a string.

Added

  • LoaderOptions.romBaudrate (default 115200). Set it equal to baudrate to skip the post-stub port reopen.
  • Serial-port implementations can provide an optional setBaudRate() capability to change baud in place. Custom WebUSB transports can use device-specific control transfers and avoid closing the port.
  • WebUSBSerialPort CH340/CH341 adapter: in-place baud via vendor request 0x9A. The TypeScript example has an opt-in WebUSB (CH340) checkbox. On desktop OS the kernel usbserial driver often owns the device; Android/Chrome OTG is the reliable WebUSB case. See [PR #265](espressif/esptool-js#265)

Fixed

  • After a baud-rate change, drain leftover serial data and probe the chip. Native Web Serial still requires a port reopen; if this resets the board, fall back to the ROM baud rate and re-run the stub instead of failing with Invalid head of packet.
  • writeFlash throws if fileArray[].data is not a Uint8Array, instead of passing a binary string into deflate and corrupting the image (#266).
  • writeFlash({ flashSize: "detect" }) resolves the flash size (via detectFlashSize()) before the bounds check, so "detect" is no longer treated as size -1 (#254). Detection runs for every file in the write, not only a boot image at BOOTLOADER_FLASH_OFFSET.
  • ESP32-C6, C5, C61, and H2 use SPI_REG_BASE = 0x60003000, matching esptool. Flash ID reads on those chips no longer return 0 (#217).
  • ESP32-P4: postConnect() now runs powerOnFlash(), which was implemented but never called. On ECO6/ECO7 silicon (revisions v3.1 and v3.2) the flash is powered off by default, so the flash ID read returned garbage and the first flash command hung the stub. ECO7 parts with the DOWNLOAD_MODE_XPD_ON eFuse programmed release the ROM's flash force-on state instead of repeating the power-up sequence, matching esptool.
Commits

Updates wrangler from 4.135.0 to 4.140.0

Release notes

Sourced from wrangler's releases.

wrangler@4.140.0

Minor Changes

Patch Changes

wrangler@4.139.0

Minor Changes

  • #15792 479e1e8 Thanks @​flakey5! - Configure SSH for experimental Durable Object-managed Containers

    Set containers[].ssh and containers[].authorized_keys when using scheduling_policy: "durable_object". These are application-wide settings that follow the same rules as the existing Durable Object-managed Container settings: normal deployments create missing applications and update explicitly configured values, while omitted settings preserve the existing application configuration.

    // wrangler.jsonc
    {
      "containers": [
        {
          "name": "sandbox",
          "class_name": "Sandbox",
          "scheduling_policy": "durable_object",
          "ssh": { "enabled": true },
          "authorized_keys": [
            { "name": "laptop", "public_key": "ssh-ed25519 AAAA..." }
          ]
        }
      ]
    }
  • #15648 52c0e9f Thanks @​tpmmorris! - Expose configured Cron Triggers to local development consumers

    Wrangler now passes the active environment's exact Cron Trigger expressions to Miniflare so Local Explorer can display them. Headless agent sessions also advertise the Local Explorer scheduled invocation API.

  • #15786 bdda4c3 Thanks @​ThomasRubini! - Support UDP connect handlers in local development

    The experimental connect configuration now accepts protocol: "udp", with optional idle_timeout_ms and max_pending_bytes settings. UDP datagrams are delivered to the Worker's connect() handler using workerd's value-mode socket streams, and can be tested with Miniflare#dispatchConnect({ protocol: "udp" }).

  • #15779 fc3cbaa Thanks @​Naapperas! - Support workflow entries in the exports configuration map

    A Worker can now declare the Workflows it defines in exports, keyed by the WorkflowEntrypoint class name:

    {
      "exports": {
        "MyWorkflow": {

... (truncated)

Commits
  • 84c819f Version Packages (#15857)
  • 8f7916c [deploy-helpers] Containers support for Worker Preview deployments in the Bui...
  • c59dae6 Version Packages (#15828)
  • 15799d4 [wrangler] Update smol-toml to 1.9.0 (#15838)
  • 479e1e8 Allow ssh config for DO containers (#15792)
  • 52c0e9f Add backend support for cron triggers in local explorer (#15648)
  • fc3cbaa [workers-utils,miniflare,wrangler] Accept workflow entries in the exports con...
  • cd60c9c [wrangler] chore: Show --jurisdiction flag in KV Create Namespace help (#15803)
  • bdda4c3 [wrangler] Support UDP connect handlers for local development (#15786)
  • 8d7e380 Version Packages (#15813)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the npm group with 3 updates: [boxen](https://github.com/sindresorhus/boxen), [esptool-js](https://github.com/espressif/esptool-js) and [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler).


Updates `boxen` from 8.0.1 to 9.0.0
- [Release notes](https://github.com/sindresorhus/boxen/releases)
- [Commits](sindresorhus/boxen@v8.0.1...v9.0.0)

Updates `esptool-js` from 0.6.1 to 0.7.0
- [Release notes](https://github.com/espressif/esptool-js/releases)
- [Changelog](https://github.com/espressif/esptool-js/blob/main/CHANGELOG.md)
- [Commits](espressif/esptool-js@v0.6.1...v0.7.0)

Updates `wrangler` from 4.135.0 to 4.140.0
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.140.0/packages/wrangler)

---
updated-dependencies:
- dependency-name: boxen
  dependency-version: 9.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm
- dependency-name: esptool-js
  dependency-version: 0.7.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: wrangler
  dependency-version: 4.140.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: c0489bf5-396a-47cc-9074-c7def9065c21

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
openshock-app-dev bcd019a Commit Preview URL

Branch Preview URL
Sep 28 2026, 10:07 AM

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants