# Workers - Send npm package dependency metadata with Worker uploads

Publisher-attributed story with a reviewed brief or permitted publisher paragraph. The original publisher is responsible for the linked reporting.

- Publisher: Cloudflare Developers
- Category: Cloud
- Original publication time: 2026-07-09T00:00:00Z
- First observed by NexusTechWire: 2026-10-01T15:54:33Z
- Original source: https://developers.cloudflare.com/changelog/post/2026-07-07-wrangler-deploy-upload-dependencies-metadata/
- NexusTechWire record: https://nexustechwire.com/news/news-cc2449df7dd580bc8888

## From the publisher

Wrangler now collects npm package dependency information from your project's package.json during wrangler deploy and wrangler versions upload, and includes it in the upload metadata sent to the Cloudflare API. This data, each dependency's name, declared version range, and exact installed version, enables dependency analytics and future supply chain security features such as vulnerability alerting. To opt out, set dependencies\_instrumentation.enabled to false in your Wrangler configuration file: \{ "dependencies\_instrumentation": \{ "enabled": false \} \} \[dependencies\_instrumentation\] enabled = false For more details, refer to Wrangler configuration.

Source license: [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/). Publisher excerpt shortened and converted to plain text. Original source license applies.

Read the full original: [Cloudflare Developers](https://developers.cloudflare.com/changelog/post/2026-07-07-wrangler-deploy-upload-dependencies-metadata/)

This record does not reproduce the complete article or represent independent confirmation of every source claim.
