Harden Wrangler bundling and resource commands - #16
Merged
Merged
Conversation
Keep project .env credentials out of Wrangler build hooks. Reject unmapped config fields and warn about non-inherited bindings. Improve Tail recovery, deletion safety, and CLI diagnostics. Sync examples, bilingual docs, and release checks. Signed-off-by: Lu Zhang <lu@wdl.dev>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Its broad, security-sensitive changes and lack of live integration testing warrant final human review.
Review effort: Balanced
Findings: None
What changed in this PR
Hardens Wrangler bundling, resource commands, credential handling, diagnostics, and deletion safety.
Changes:
- Isolates Wrangler from project dotenv credentials and validates configuration.
- Improves Tail recovery, migration diagnostics, output escaping, and deletion reporting.
- Updates tests, release security, scaffolding, and bilingual documentation.
| File | Description |
|---|---|
tests/unit/deploy-helpers.js |
Tests empty Wrangler env files. |
tests/unit/cli-wrangler-files.test.js |
Tests SQL modules and credential exclusions. |
tests/unit/cli-wrangler-config.test.js |
Tests configuration validation and projection. |
tests/unit/cli-wrangler-command.test.js |
Tests dotenv isolation and version errors. |
tests/unit/cli-wrangler-bindings.test.js |
Tests unmapped binding rejection. |
tests/unit/cli-tail.test.js |
Tests Tail retries and idle recovery. |
tests/unit/cli-r2.test.js |
Tests safe R2 output. |
tests/unit/cli-init.test.js |
Tests protected dry-run scaffolding. |
tests/unit/cli-deploy.test.js |
Tests deployment warnings and validation. |
tests/unit/cli-delete.test.js |
Tests storage-retention reporting. |
tests/unit/cli-d1.test.js |
Tests migration progress and safe output. |
tests/unit/cli-credentials.test.js |
Tests connection-override safety. |
tests/unit/cli-control-fetch.test.js |
Tests certificate validation. |
tests/unit/cli-config-doctor.test.js |
Tests escaped diagnostics. |
templates/AGENTS.md |
Updates generated agent guidance. |
README.md |
Documents Wrangler requirements. |
README-zh.md |
Updates Chinese prerequisites. |
lib/wrangler/config.js |
Tightens configuration and environment handling. |
lib/wrangler/command.js |
Isolates Wrangler from dotenv files. |
lib/wrangler/bindings.js |
Rejects unmapped binding fields. |
lib/wrangler/assets.js |
Expands credential-file exclusions. |
lib/wrangler-pack.js |
Hardens validation and bundling. |
lib/r2-format.js |
Escapes R2 output. |
lib/delete-format.js |
Reports retained Durable Object storage. |
lib/d1-format.js |
Escapes D1 output. |
lib/credentials.js |
Restricts unsafe connection overrides. |
lib/control-fetch.js |
Preserves TLS identity validation. |
lib/common.js |
Clarifies JSON option help. |
lib/bundle-modules.js |
Treats SQL modules as text. |
GUIDE.md |
Updates English operational guidance. |
GUIDE-zh.md |
Updates Chinese operational guidance. |
examples/inspection-demo/README.md |
Corrects deletion examples. |
docs/workflows.md |
Documents optional confirmation. |
docs/workflows-zh.md |
Updates Chinese workflow guidance. |
docs/token.md |
Documents connection safety. |
docs/token-zh.md |
Updates Chinese token guidance. |
docs/r2.md |
Documents deletion confirmation. |
docs/r2-zh.md |
Updates Chinese R2 guidance. |
docs/queues.md |
Documents queue restrictions. |
docs/queues-zh.md |
Updates Chinese queue guidance. |
docs/env-overrides.md |
Documents environment inheritance. |
docs/env-overrides-zh.md |
Updates Chinese environment guidance. |
docs/deploy.md |
Documents hardened deployment behavior. |
docs/deploy-zh.md |
Updates Chinese deployment guidance. |
docs/d1.md |
Documents partial migration failures. |
docs/d1-zh.md |
Updates Chinese D1 guidance. |
docs/assets.md |
Documents asset validation and exclusions. |
docs/assets-zh.md |
Updates Chinese asset guidance. |
commands/workflows.js |
Corrects workflow usage text. |
commands/tail.js |
Adds retry and idle recovery. |
commands/r2.js |
Improves deletion output and confirmation. |
commands/init.js |
Generates dotenv-safe dry-run configuration. |
commands/doctor.js |
Escapes remote diagnostics. |
commands/d1.js |
Reports partial migration progress. |
CHANGELOG.md |
Records user-visible changes. |
.github/workflows/release.yml |
Disables persisted checkout credentials. |
.claude/skills/wdl-deploy/SKILL.md |
Updates deployment guidance. |
.claude/rules/examples.md |
Updates scaffolding instructions. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Verification
Live integration was not run.