fix(deps): update all non-major dependencies - #69
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 29, 2026 17:49
de32e74 to
314d3ca
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
September 29, 2026 22:32
314d3ca to
0623067
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
October 2, 2026 04:49
0623067 to
1a0a92c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.87.1→0.99.20.61.0→0.62.00.24.0→0.25.013.2.2→13.2.33.0.3→3.1.00.14.1→0.14.2Release Notes
earendil-works/pi (@earendil-works/pi-coding-agent)
v0.99.2Compare Source
New Features
codemodeexposure are no longer listed in thecodemodedescription and no longer block the first prompt. They appear in a short system prompt section, and scripts find their tools withsearchTools()anddescribeNamespace(). See Control tool exposure.oauth.clientNamefor servers that only accept known OAuth clients, and"auth": { "provider": "<provider>" }to authenticate HTTP servers with a provider's/logintoken. See Authenticate with OAuth./reloadenables tools newly added to thedefaultToolssetting. See Tools.Added
descriptionfield for MCP servers (pi mcp add --description), shown with the server in the system prompt and used to rank its tools in tool search, and adescribeNamespace(name)codemode helper that returns a namespace's instructions and tool names.describeNamespace()andsearchTools()accept a namespace asmcp__dev-radius,mcp__dev_radius,dev-radius, ordev_radius.oauth.clientNamesetting for MCP servers (pi mcp add --oauth-client-name) to change the client name sent during OAuth client registration, for servers that only accept known clients (#10226)."auth": { "provider": "<provider>" }for HTTP MCP servers to send a provider's current/logintoken as the bearer token instead of using MCP OAuth. The token is read on every request, so provider refreshes apply. Only allowed in the globalmcp.jsonand from extensions, and requires https except on loopback hosts.ANTHROPIC_FEDERATION_RULE_ID,ANTHROPIC_ORGANIZATION_ID, andANTHROPIC_IDENTITY_TOKEN_FILEenvironment variables (see Providers) (#10177, #10242 by @philfreo)./reloadnow enables tools newly added to thedefaultToolssetting. Tools removed from it stay enabled, tools turned off during the session stay off unless newly added, and--tools,--no-tools, and--no-builtin-toolsstill override the setting (#10245).Changed
codemodeexposure no longer appear in thecodemodedescription; scripts find them withsearchTools().codemode-deferredis now an alias forcodemode. Usedirectexposure for tools the model should see without searching (#10212).codemodedescription no longer includes deferred tools, tool counts, or MCP server instructions, so it no longer changes when MCP servers connect or change their tools. Thetool_searchdescription no longer lists the servers whose tools it can load, for the same reason. Servers are listed instead in anmcp_serverssystem prompt section with a one-line summary, updated at the start of each prompt; a changed section is appended to the conversation. Scripts read server instructions withdescribeNamespace()(#10212).directtools. They connect in the background and are waited for when a codemode script names them, a script searches tools, ortool_searchruns (#10212).Fixed
/mcpsign-in URL not being clickable when it wraps across lines, by emitting it as a terminal hyperlink with aCmd/Ctrl+click to openline like/login(#10186).image()accepting malformed base64 data or unsupported image types, which persisted an invalid image block that made every later provider request fail with HTTP 400 (#10215).built-in-tool-renderer.tsandminimal-mode.tsextension examples removing the built-in tools' summaries and guidelines from the system prompt (#10072, #10193 by @christianklotz).Prompt exceeds max lengtherrors (#10208).minimum/maximum; such tools are now sent non-strict (#9953).Retry-Afterheader contains an unparseable date; they now use exponential backoff (#9571)./; the extension now fails to load with an error instead (#10054).codemodeand MCP tool results filling the screen when the output is one long line, such as minified JSON. Like bash output, the preview is now limited to wrapped lines instead of logical lines.codemode.mode: "only"listingread,bash,edit, andwritein the system prompt's tool list although requests only declarecodemode(#10192).-and_, such asread-fileandread_file. Like in Codex, MCP tool and namespace names now replace-with_(mcp__my-server__xis nowmcp__my_server__x), colliding tools of a server all get a hash suffix, and server names that differ only in-and_are rejected (#10239).v0.99.1Compare Source
New Features
Added
gpt-6.1-sol) to the OpenAI, Azure OpenAI Responses, and OpenAI Codex providers.Changed
gpt-6.1-sol).Fixed
/loginwith OpenAI failing in the bundled release with a missingopenai-chatgpt.jsmodule error.v0.99.0Compare Source
New Features
/login openai. See Authenticate interactively.Added
codemodetool runs model-written JavaScript in a QuickJS sandbox that calls pi's tools; enable it withdefaultToolsor--toolsand configure it withcodemode.modeandcodemode.inlineBudget.tool_searchfinds tools that are not declared to the model and declares them. MCP servers over stdio or streamable HTTP, with OAuth, come frommcp.json(global, or per project once trusted) orpi.registerMcpServer()and are managed with/mcpandpi mcp add|remove|list|login|logout. See MCP Servers and Enable codemode (#10040).exposure(direct,model-only,codemode,deferred, orhidden),namespace,annotations,outputSchemawithstructuredContent,isErrorresults,prepareLoadout(), andctx.executeTool()for nested tool calls, which emit events withparentToolCallIdand are recorded as boundednestedCallson the calling tool's result. See Tool exposure.pi.registerVirtualModel()and pick a physical model and thinking level for each request. The footer shows the routed model,/sessionlists cost per physical model, andexamples/extensions/jev-router.tsroutes with the Jev classifier. See Virtual Models./login, which uses a ChatGPT subscription with the OpenAI API. Pi stores a stabledeviceIdin the global settings for this login and omits it from bug reports.systemtheme, now the default, which derives pi's colors from the terminal's reported foreground, background, and ANSI palette and rebuilds them when the terminal switches between light and dark. See Use your terminal's colors.#rgb,oklch(), andokhsl()colors and an optionalappearancefield to theme files, andtheme.style(),theme.colors, andtheme.appearancefor extensions. See Themes and TUI.fullscreenWheelScrollLinessetting and/settingsentry for fullscreen mouse-wheel scrolling. The default"auto"accelerates fast wheel spins outside local macOS terminals (#9758).prompt,steer, andfollow_upresponses,AgentSession.steer()/followUp(), andRpcClient.prompt()/steer()/followUp();RpcClient.prompt()also acceptsstreamingBehavior(#9098, #9803).ModelRuntime:generateImages()with runtime-resolved auth (stored credentials, OAuth, runtime API keys,models.jsonheaders), plusgetModelsOfType(),getModelOfType(),getAvailableOfType(),getAllModels(), andgetAllAvailable(). OpenRouter image models are listed under theopenrouterprovider and share its credential; an upstream ID can have separate chat and image entries.models.jsonproviders and extension registrations without a model list keep built-in image generation. Extension model lists can include discriminated chat, image, and classifier entries with operation implementations; when supplied, they replace the provider catalog across every operation. Chat-facing reads (getModels(),getAvailableSnapshot(), the model picker) are unchanged.ModelRuntime, includingclassify(), classifier model accessors, runtime-resolved authentication, and the built-in TypeSafejev-latestmodel.types=chat,image,classifierto pi.dev model catalog requests so remote refreshes overlay every supported model type; entries of unknown model types are ignored.provider_stream_eventextension event for observing parsed provider events before normalization, with an opt-in/debug-providerexample viewer (#9784, #9901 by @davidbrai).H) in HTML exports for custom messages markeddisplay: false. Messages remain hidden by default and can also be revealed from the sidebar (#8896, #10020 by @rwachtler).pi configto disable the built-inmcp,llama.cpp,codemode, andtool-searchextensions globally or per project, stored as-builtin:<name>in theextensionssetting. SDK inline extensions opt in withbuiltin: true.+nameand-nameentries to thedefaultToolssetting to add or remove tools without repeating the defaults, for example"defaultTools": ["+codemode"]. Project entries of this form apply on top of the user setting. Documented how to enablecodemodewithout MCP and how to use classifier models such as Jev from codemode scripts.models.classify()calls to the codemode tool result, so they count toward the session cost; the codemode result shows each call's cost.Changed
tsxwith Node's built-in type stripping for running from source (#9965).[Themes]section from the startup banner. Custom themes remain available in/settings, and theme conflicts are still reported.darkandlightthemes to the revised pi colors, written in OKHSL.COLORFGBG. The first-time setup no longer shows the detected appearance.TERM=*-directas truecolor.builtin:<name>(for examplebuiltin:mcpandbuiltin:read) in errors, diagnostics, RPC source info, and bug reports, instead of<inline:name>and<builtin:name>. Their slash commands no longer carry a[t]autocomplete tag.--no-extensionsalso disables the built-in extensions, including the llama.cpp provider. Load one explicitly with-e builtin:<name>, for examplepi -ne -e builtin:mcp.key=valuepairs on the title line when collapsed and onekey: valueline per argument when expanded. MCP calls are titledserver/tooland their results collapse to 5 lines.bashandpowershellstructured results, which codemode scripts receive, now hold up to 1 MiB of output instead of the model-facing 2000 lines or 50KB, and addtruncatedandfull_output_path. Longer output keeps its first and last 512 KiB. Empty output is""instead of(no output).Fixed
dependencies(#9863).-econtinuing to use the first downloaded commit after the ref changes (#9982).RpcClientskipping the next event listener when a listener unsubscribes while handling an event, which could makewaitForIdle()time out aftercollectEvents()(#9990).readcalls rendering as:1when models sendnullfor omittedoffsetandlimit(#9996).terminal.trueColorand other terminal capability overrides and rendering with 256 colors (#9973, #10039 by @christianklotz).sanitizeBinaryOutput()no longer splits output into per-character arrays.ctx.executeTool(), for example from codemode scripts, being dropped from the session cost; it is now added to the calling tool's result usage./skillautocomplete appearing empty when loaded skill names did not contain the letters inskill(#9944).@autocomplete not working after opening wrappers such as(,[,{,<, or a backtick./settingssubmenu closed it.samplingParamsbeing dropped by directstream()/complete()calls on OpenAI-compatible APIs (#9506).qwen3.8-flashthinking being replayed as plain text on later turns (#10047).output_index, such as llama.cpp, running mixed-up tool calls; such streams now end with an error (#9974).google-gemini/gemini-cli (@google/gemini-cli)
v0.62.0Compare Source
What's Changed
Full Changelog: google-gemini/gemini-cli@v0.61.0...v0.62.0
grafana/grafana (grafana/grafana)
v13.2.3Security
openclaw/mcporter (mcporter)
v0.14.2Compare Source
Highlights: npm installs retain OAuth refresh protection, Windows daemon startup tolerates transient process-query failures, and long help flags remain readable.
Bundle the patched MCP client in npm releases so installed packages preserve request-correlated OAuth refresh locking; verify the installed tarball in CI and release gates.
Update the MCP client/server to 2.2.0, legacy SDK fixtures to 1.31.0, Hono to 4.13.10, pnpm to 10.34.6, and lint/format tooling; retain the OAuth correlation patch, Node 24 support, and the 48-hour dependency release-age policy.
Retry transient Windows process-query failures once before blocking daemon startup or retirement, while retaining strict ownership checks and refusing malformed observations.
Refresh MCP clients and fixtures, bundling and test tooling, and Hono; preserve OAuth refresh-token correlation when OAuth overrides a configured Authorization header, Node 24 support, and the 48-hour dependency release-age policy.
Size the top-level help's global-flag column to its longest flag, so
--log-level <debug|info|warn|error>no longer runs into its description. Thanks @KrasimirKralev.Verification: npm, registry tarball, native assets, and browser Gatekeeper proof. npm integrity:
sha512-3ajjKzPLe/39hN582XqMuOw3S9vHQfLpSBq72zVakT03xso3GDXHcht/eVLu/l2MDqulIOtLevnTKreUxymHJQ==.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.