Skip to content

Harden Wrangler bundling and resource commands - #16

Merged
cnluzhang merged 1 commit into
mainfrom
fix/cli-audit-followup
Sep 23, 2026
Merged

cnluzhang merged 1 commit into
mainfrom
fix/cli-audit-followup

Conversation

@cnluzhang

Copy link
Copy Markdown
Contributor

Summary

  • Keep project .env credentials out of Wrangler build hooks, including generated dry-run checks; document the Wrangler v4.27+ requirement.
  • Reject unmapped Wrangler configuration before upload and warn when env-scoped AI, exports, or platform bindings are omitted.
  • Improve Tail recovery diagnostics, deletion safety and output, D1 migration failure reporting, and bilingual user and agent documentation.

Verification

  • npm run format:check
  • npm run lint
  • npm run typecheck
  • npm test (635 passed)
  • npm audit --audit-level=moderate (0 vulnerabilities)
  • npm pack --dry-run
  • actionlint .github/workflows/release.yml
  • git diff --cached --check

Live integration was not run.

Keep project .env credentials out of Wrangler build hooks.
Reject unmapped config fields and warn about non-inherited bindings.
Improve Tail recovery, deletion safety, and CLI diagnostics.
Sync examples, bilingual docs, and release checks.

Signed-off-by: Lu Zhang <lu@wdl.dev>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-23T04:15:55.203663Z 801c716 PR opened
🔒 Security Review ✅ Completed 2026-09-23T04:16:48.312781Z 801c716 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Its broad, security-sensitive changes and lack of live integration testing warrant final human review.

Review effort: Balanced
Findings: None

What changed in this PR

Hardens Wrangler bundling, resource commands, credential handling, diagnostics, and deletion safety.

Changes:

  • Isolates Wrangler from project dotenv credentials and validates configuration.
  • Improves Tail recovery, migration diagnostics, output escaping, and deletion reporting.
  • Updates tests, release security, scaffolding, and bilingual documentation.
File Description
tests/​unit/​deploy-helpers.js Tests empty Wrangler env files.
tests/​unit/​cli-wrangler-files.test.js Tests SQL modules and credential exclusions.
tests/​unit/​cli-wrangler-config.test.js Tests configuration validation and projection.
tests/​unit/​cli-wrangler-command.test.js Tests dotenv isolation and version errors.
tests/​unit/​cli-wrangler-bindings.test.js Tests unmapped binding rejection.
tests/​unit/​cli-tail.test.js Tests Tail retries and idle recovery.
tests/​unit/​cli-r2.test.js Tests safe R2 output.
tests/​unit/​cli-init.test.js Tests protected dry-run scaffolding.
tests/​unit/​cli-deploy.test.js Tests deployment warnings and validation.
tests/​unit/​cli-delete.test.js Tests storage-retention reporting.
tests/​unit/​cli-d1.test.js Tests migration progress and safe output.
tests/​unit/​cli-credentials.test.js Tests connection-override safety.
tests/​unit/​cli-control-fetch.test.js Tests certificate validation.
tests/​unit/​cli-config-doctor.test.js Tests escaped diagnostics.
templates/​AGENTS.md Updates generated agent guidance.
README.md Documents Wrangler requirements.
README-zh.md Updates Chinese prerequisites.
lib/​wrangler/​config.js Tightens configuration and environment handling.
lib/​wrangler/​command.js Isolates Wrangler from dotenv files.
lib/​wrangler/​bindings.js Rejects unmapped binding fields.
lib/​wrangler/​assets.js Expands credential-file exclusions.
lib/​wrangler-pack.js Hardens validation and bundling.
lib/​r2-format.js Escapes R2 output.
lib/​delete-format.js Reports retained Durable Object storage.
lib/​d1-format.js Escapes D1 output.
lib/​credentials.js Restricts unsafe connection overrides.
lib/​control-fetch.js Preserves TLS identity validation.
lib/​common.js Clarifies JSON option help.
lib/​bundle-modules.js Treats SQL modules as text.
GUIDE.md Updates English operational guidance.
GUIDE-zh.md Updates Chinese operational guidance.
examples/​inspection-demo/​README.md Corrects deletion examples.
docs/​workflows.md Documents optional confirmation.
docs/​workflows-zh.md Updates Chinese workflow guidance.
docs/​token.md Documents connection safety.
docs/​token-zh.md Updates Chinese token guidance.
docs/​r2.md Documents deletion confirmation.
docs/​r2-zh.md Updates Chinese R2 guidance.
docs/​queues.md Documents queue restrictions.
docs/​queues-zh.md Updates Chinese queue guidance.
docs/​env-overrides.md Documents environment inheritance.
docs/​env-overrides-zh.md Updates Chinese environment guidance.
docs/​deploy.md Documents hardened deployment behavior.
docs/​deploy-zh.md Updates Chinese deployment guidance.
docs/​d1.md Documents partial migration failures.
docs/​d1-zh.md Updates Chinese D1 guidance.
docs/​assets.md Documents asset validation and exclusions.
docs/​assets-zh.md Updates Chinese asset guidance.
commands/​workflows.js Corrects workflow usage text.
commands/​tail.js Adds retry and idle recovery.
commands/​r2.js Improves deletion output and confirmation.
commands/​init.js Generates dotenv-safe dry-run configuration.
commands/​doctor.js Escapes remote diagnostics.
commands/​d1.js Reports partial migration progress.
CHANGELOG.md Records user-visible changes.
.github/​workflows/​release.yml Disables persisted checkout credentials.
.claude/​skills/​wdl-deploy/​SKILL.md Updates deployment guidance.
.claude/​rules/​examples.md Updates scaffolding instructions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@cnluzhang
cnluzhang merged commit a3b5cff into main Sep 23, 2026
7 checks passed
@cnluzhang
cnluzhang deleted the fix/cli-audit-followup branch September 23, 2026 08:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants