github cloudflare/workers-sdk @cloudflare/cli-shared-helpers@0.1.6

Patch Changes

  • #14112 3a746ac Thanks @penalosa! - Pin non-bundled runtime dependencies to exact versions

    Dependencies that are not bundled into a package's published output are installed directly into consumers' dependency trees, so they are now pinned to exact versions instead of semver ranges. This closes a supply-chain gap where an unpinned external dependency could resolve to a compromised upstream release on a fresh install. A new pnpm check:pinned-deps lint enforces this for all published packages (and for the shared pnpm catalog) going forward.

  • Updated dependencies [e86489a, 337e912, 65b5f9e]:

    • @cloudflare/workers-utils@0.22.1

Don't miss a new workers-sdk release

NewReleases is sending notifications on new releases.