Skip to content

Accept @cloudflare/workers-types v5 in @fedify/cfworkers - #1260

Merged
dahlia merged 1 commit into
fedify-dev:2.0-maintenancefrom
dahlia:bugfix/cfworkers-types
Oct 6, 2026
Merged

dahlia merged 1 commit into
fedify-dev:2.0-maintenancefrom
dahlia:bugfix/cfworkers-types

Conversation

@dahlia

@dahlia dahlia commented Oct 6, 2026

Copy link
Copy Markdown
Member

Fixes #1255.

@fedify/cfworkers took its peer range on @cloudflare/workers-types from the pnpm catalog, so every 2.x release requires v4. Cloudflare stopped publishing v4 in July and recent Wrangler releases want v5, so npm fails with ERESOLVE when both are installed. pnpm only warns, so workspace installs never exposed the failure.

The built dist/mod.d.ts imports only Queue from the package, and its declaration is identical in v4 and v5. KV bindings go through our own structural interface. So the peer range is now written out as ^4.20250906.0 || ^5.0.0 instead of catalog:. The catalog stays on v4, and an explicit dev dependency on it in packages/cfworkers/package.json keeps workspace installs on v4.

Testing

The regression test, packages/cfworkers/test/peer-dependencies.check.mjs, runs under node --test since it checks packaging, not Workers behavior. It resolves catalog: through pnpm-workspace.yaml the way pnpm publish does, so the old manifest fails because v5 is rejected, not because catalog: is an invalid range. The .check.mjs name keeps Vitest from picking it up.

There is no v5 type check in the repository. Both an npm alias and a v5 dev dependency make Deno hoist v5 into the shared node_modules/, which breaks deno check for unrelated packages such as packages/cli/. Instead, I packed the packages locally and installed them into fresh npm projects. Before the fix, adding wrangler@4.147.0 failed with ERESOLVE. With the fix, the projects install and type-check with Wrangler 4.147.0, workers-types v5, or workers-types v4.

mise run check and mise run test-each cfworkers pass.

Forward-porting

2.3-maintenance and later use ^4.20260511.1 as the v4 floor. Keep that floor (^4.20260511.1 || ^5.0.0) and update the minimum and below-minimum versions in the regression test to match. Regenerate pnpm-lock.yaml and deno.lock on each branch with that branch's pinned Deno. Running Deno 2.9 on 2.0–2.3 also breaks local pnpm pack (#1259).

@fedify/cfworkers took its peer range on @cloudflare/workers-types from
the pnpm catalog, so every published release required ^4.20250906.0.
Cloudflare stopped publishing v4 at 4.20260702.1, and recent Wrangler
releases declare an optional peer on v5, so npm refused to install
@fedify/cfworkers next to them with ERESOLVE unless --legacy-peer-deps
or an override was used.

The only type the published declarations import from the package is
Queue, which is unchanged in v5; KV bindings are typed structurally.
The peer range is therefore widened to ^4.20250906.0 || ^5.0.0 and no
longer comes from the catalog.  The catalog entry stays on v4, and the
package now lists it as a devDependency so the workspace keeps
developing and testing against v4 instead of auto-installing whatever
the widened peer allows.

This commit includes the following changes:

- A Node regression test checking that the peer range accepts the
  v4 minimum, the last v4 release and v5 releases, and rejects older
  v4 and v6.  It resolves catalog: the way pnpm publish does, so it
  fails against the previous manifest for the actual reason.
- A type check that the public API accepts KVNamespace and Queue as
  declared by @cloudflare/workers-types itself.
- A changelog fragment for @fedify/cfworkers.

v5 compatibility was verified in npm consumer projects built from
locally packed tarballs: installing alongside wrangler@4.147.0,
@cloudflare/workers-types@5 and @cloudflare/workers-types@4 all
succeed and type-check.  An in-repo v5 type check was not added because
installing v5 into the shared node_modules makes Deno hoist it and
breaks unrelated type checks.

Fixes fedify-dev#1255

Assisted-by: Codex:gpt-6-astra
Assisted-by: Claude Code:claude-opus-5-5
@dahlia dahlia self-assigned this Oct 6, 2026
@dahlia dahlia added component/kv Key–value store related component/mq Message queue related runtime/cfworkers Cloudflare Workers runtime related component/build Build system and packaging dependencies Dependency updates and issues labels Oct 6, 2026
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: ac72881a-4b75-4827-983d-b2fa2cc5faca
📥 Commits

Reviewing files that changed from the base of the PR and between 406ee87 and 10ff6e8.

⛔ Files ignored due to path filters (2)
  • deno.lock is excluded by !**/*.lock
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • CHANGES.md
  • changes.d/cfworkers/workers-types-v5.md
  • packages/cfworkers/package.json
  • packages/cfworkers/test/peer-dependencies.check.mjs
  • packages/cfworkers/test/typecheck/workers-types.ts

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

The cfworkers package now accepts specified versions of @cloudflare/workers-types 4.x and 5.x as a peer dependency. The package adds checks for the declared range and type compatibility.

Changes

Cloudflare Workers types compatibility

Layer / File(s) Summary
Peer range and compatibility checks
packages/cfworkers/package.json, packages/cfworkers/test/peer-dependencies.check.mjs, packages/cfworkers/test/typecheck/workers-types.ts, CHANGES.md, changes.d/cfworkers/workers-types-v5.md
The peer dependency range accepts the specified 4.x and 5.x versions. A test checks the range, and a type-check fixture checks the Workers KV store and message queue types. The test script runs the new range check. Changelog entries document the change.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to 10ff6

No actionable issue remains from this review; the PR is mergeable after normal checks.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (3 skipped: 3 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely identifies the main change: accepting @cloudflare/workers-types v5 as a peer dependency.
Description check ✅ Passed The description explains the peer dependency conflict, the range change, and the regression testing. It is directly related to the changeset.
Linked Issues check ✅ Passed Issue #1255 requires @fedify/cfworkers to accept @cloudflare/workers-types v5. packages/cfworkers/package.json now declares ^4.20250906.0 || ^5.0.0. The regression test checks representative v…
Out of Scope Changes check ✅ Passed The manifest change, peer-range regression test, type-check fixture, and changelog entries all support the workers-types v5 compatibility objective in issue #1255. No unrelated changes appear in the s…
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (3 skipped: 3 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Oct 6, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.
see 1 file with indirect coverage changes

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@dahlia
dahlia merged commit a2414f9 into fedify-dev:2.0-maintenance Oct 6, 2026
17 checks passed
dahlia added a commit that referenced this pull request Oct 8, 2026
Carry the released fixes into 2.3.12 while preserving the 2.0.32,
2.1.28, and 2.2.17 changelog sections and destination package versions.

Keep the 2.3 Cloudflare types minimum and key lookup instrumentation.
Route JSON-LD context transport failures through the existing error
handling and verify their metric classifications and HTTP status codes.
Include the documentation and initializer CI fixes from 2.2.17.

AI assistance resolved conflicts and added metric regression checks.
Verified with mise check, mise test:deno, mise test:node, and
mise test:bun, in that order.

#1260
#1270

Assisted-by: Codex:gpt-6
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

component/build Build system and packaging component/kv Key–value store related component/mq Message queue related dependencies Dependency updates and issues runtime/cfworkers Cloudflare Workers runtime related

Projects

None yet

Development

Successfully merging this pull request may close these issues.

@fedify/cfworkers: support @cloudflare/workers-types v5.x in peerDependencies

1 participant