From 43c3d135548d2e45afe8ba783b10024b9a14b46a Mon Sep 17 00:00:00 2001 From: Lucas Carlson Date: Fri, 2 Oct 2026 09:40:05 -0700 Subject: [PATCH 1/2] test: give Cloudflare polls a 10 s limit The Cloudflare tests wait for durable work with expect.poll, and 23 of its 24 calls used the Vitest default limit of 1 s. The retry failure envelope needs five alarm-driven delivery attempts and a callback turn. In CI run 36884020000, attempt 1, every Cloudflare test file ran 5 to 12 times slower than usual, and that chain took more than 1 s. Set a 10 s poll limit for the whole Cloudflare suite. A poll still returns as soon as its condition holds, and a lost callback still fails with the poll error before the 15 s test timeout. --- vitest.cloudflare.config.ts | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/vitest.cloudflare.config.ts b/vitest.cloudflare.config.ts index 89a520c..e5c4b7a 100644 --- a/vitest.cloudflare.config.ts +++ b/vitest.cloudflare.config.ts @@ -3,5 +3,9 @@ import { cloudflareTest } from "@cloudflare/vitest-plugin" export default defineConfig({ plugins: [cloudflareTest({ wrangler: { configPath: "./test/cloudflare/wrangler.jsonc" } })], - test: { include: ["test/cloudflare/**/*.test.ts"], testTimeout: 15_000 }, + test: { + include: ["test/cloudflare/**/*.test.ts"], + testTimeout: 15_000, + expect: { poll: { timeout: 10_000 } }, + }, }) From 48aec85ba7f1d06a8299e5bef163d1252e119154 Mon Sep 17 00:00:00 2001 From: Lucas Carlson Date: Fri, 2 Oct 2026 10:06:35 -0700 Subject: [PATCH 2/2] fix: Patch Undici in Cloudflare tooling pnpm audit --audit-level=high fails on main since two high Undici advisories were published: a WebSocket subprotocol denial of service and a TLS certificate validation bypass. Both reach this repository only through Miniflare in the Cloudflare development tooling. Override Undici 7.29.0 with the patched 7.29.1 release, the same change as e128a95 on feat/portable-observability. That branch also records the patch in the changelog, so this commit does not. --- pnpm-lock.yaml | 9 +++++---- pnpm-workspace.yaml | 1 + 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 11e0d4c..06d19ca 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -5,6 +5,7 @@ settings: excludeLinksFromLockfile: false overrides: + undici@7.29.0: 7.29.1 sharp@<0.35.4: ^0.35.4 importers: @@ -1082,8 +1083,8 @@ packages: undici-types@7.18.2: resolution: {integrity: sha512-AsuCzffGHJybSaRrmr5eHr81mwJU3kjw6M+uprWvCXiNeN9SOGwQ3Jn8jb8m3Z6izVgknn1R0FTCEAP2QrLY/w==} - undici@7.29.0: - resolution: {integrity: sha512-IDxfleLmmbSskfWSUATiN1nfn2rDuvnMOqb5CWR92iIfojA0Ud+ulOAAEQ57LPr9rWmsreUyf5lwyao+7GNNVw==} + undici@7.29.1: + resolution: {integrity: sha512-RYONW2MeafgYlkVOKYKkA/Ag7BmXqgIWCa8t1m0JcxrQg9pI9lEqRhAOruOBCbAohOa/gkCF+iPi9hrgvTzu6Q==} engines: {node: '>=20.18.1'} unenv@2.0.0-rc.24: @@ -1838,7 +1839,7 @@ snapshots: dependencies: '@cspotcode/source-map-support': 0.8.1 sharp: 0.35.4(@types/node@24.13.3) - undici: 7.29.0 + undici: 7.29.1 workerd: 1.20260903.1 ws: 8.21.0 youch: 4.1.0-beta.10 @@ -2041,7 +2042,7 @@ snapshots: undici-types@7.18.2: {} - undici@7.29.0: {} + undici@7.29.1: {} unenv@2.0.0-rc.24: dependencies: diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index 0f8fd9d..61f7a64 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -6,4 +6,5 @@ minimumReleaseAgeExclude: - "@vitest/mocker@4.1.11" - sharp@0.35.4 overrides: + undici@7.29.0: 7.29.1 sharp@<0.35.4: ^0.35.4