Skip to content

build(deps-dev): bump the dev-dependencies group with 6 updates - #53

Merged
code-yeongyu merged 2 commits into
mainfrom
dependabot/npm_and_yarn/dev-dependencies-a3bc2b2e7a
Oct 9, 2026
Merged

code-yeongyu merged 2 commits into
mainfrom
dependabot/npm_and_yarn/dev-dependencies-a3bc2b2e7a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the dev-dependencies group with 6 updates:

Package From To
@biomejs/biome 2.5.14 2.5.15
@earendil-works/pi-agent-core 0.99.1 1.0.4
@earendil-works/pi-ai 0.99.1 1.0.4
@earendil-works/pi-coding-agent 0.99.1 1.0.4
@earendil-works/pi-tui 0.99.1 1.0.4
@types/node 26.6.3 26.6.4

Updates @biomejs/biome from 2.5.14 to 2.5.15

Release notes

Sourced from @​biomejs/biome's releases.

Biome CLI v2.5.15

2.5.15

Patch Changes

  • #10634 b436ba0 Thanks @​subaru-hello! - Added the new nursery rule noReactObjectTypeAsDefaultProp, which disallows array, object, and function values as default props in React components.

    For example, the following snippet triggers the rule.

    function Component({ items = [] }) {
      return items;
    }
  • #11956 faa8b37 Thanks @​dyc3! - Added the nursery rule noSvelteExportLet, which disallows declaring Svelte component props with the legacy export let syntax. Use the $props() rune instead.

    <script>
      export let name;
    </script>
  • #10816 1b9479e Thanks @​Th3S4mur41! - Added a new nursery rule useLogicalProperties that enforces the use of logical properties in CSS, promoting better internationalization and accessibility practices. The rule supports a direction option with "ltr" as the default and "rtl" as the alternative. This is a first rule covering parts of #9034

    {
      "linter": {
        "rules": {
          "nursery": {
            "useLogicalProperties": {
              "level": "warn",
              "options": {
                "direction": "rtl"
              }
            }
          }
        }
      }
    }
  • #11960 1fdb5c2 Thanks @​dyc3! - Added the nursery rule useSvelteKitRuneImports, which reports imports from the deprecated $app/stores module and suggests $app/state instead.

    import { page } from "$app/stores";

... (truncated)

Changelog

Sourced from @​biomejs/biome's changelog.

2.5.15

Patch Changes

  • #10634 b436ba0 Thanks @​subaru-hello! - Added the new nursery rule noReactObjectTypeAsDefaultProp, which disallows array, object, and function values as default props in React components.

    For example, the following snippet triggers the rule.

    function Component({ items = [] }) {
      return items;
    }
  • #11956 faa8b37 Thanks @​dyc3! - Added the nursery rule noSvelteExportLet, which disallows declaring Svelte component props with the legacy export let syntax. Use the $props() rune instead.

    <script>
      export let name;
    </script>
  • #10816 1b9479e Thanks @​Th3S4mur41! - Added a new nursery rule useLogicalProperties that enforces the use of logical properties in CSS, promoting better internationalization and accessibility practices. The rule supports a direction option with "ltr" as the default and "rtl" as the alternative. This is a first rule covering parts of #9034

    {
      "linter": {
        "rules": {
          "nursery": {
            "useLogicalProperties": {
              "level": "warn",
              "options": {
                "direction": "rtl"
              }
            }
          }
        }
      }
    }
  • #11960 1fdb5c2 Thanks @​dyc3! - Added the nursery rule useSvelteKitRuneImports, which reports imports from the deprecated $app/stores module and suggests $app/state instead.

    import { page } from "$app/stores";
  • #11723 3b429d1 Thanks @​m1handr! - Fixed #11656: noAstroSetHtmlDirective now correctly reports set:html directives inside Astro template expressions.

... (truncated)

Commits

Updates @earendil-works/pi-agent-core from 0.99.1 to 1.0.4

Release notes

Sourced from @​earendil-works/pi-agent-core's releases.

v1.0.4

New Features

  • Tool patterns and --no-mcp: --tools and --exclude-tools accept * patterns, for example --tools read,codemode,'mcp__radius__*' keeps only one MCP server's tools. --tools now keeps MCP tools unless an entry starts with mcp__, and --no-mcp turns off MCP for one run. See Tools and MCP tools.
  • Codemode persists images: tools.read() on an image file now gives back an image block that image() can show. See Call tools.

Added

  • Added * patterns to --tools and --exclude-tools, for example --tools read,codemode,'mcp__radius__*'
  • Added --no-mcp to disable the built-in MCP support for one run

Fixed

  • Fixed syntax highlighting losing colors after the first line of multiline strings and comments in fenced code blocks (#10143)
  • Fixed codemode scripts not receiving images from read: tools.read() now resolves to an image block for image files, which image() shows (#10251)
  • Fixed MCP OAuth sign-in failing with invalid_redirect_uri on servers with OpenID Connect client registration, such as mcp.modem.dev: pi now registers as a native client (#10493)
  • Fixed --tools removing MCP tools, which left pi --tools codemode without any MCP servers. --tools now keeps MCP tools unless an entry starts with mcp__
  • Fixed MCP session shutdown returning while a server was still connecting, leaving its transport open until the server answered or timed out (#10249)
  • Fixed system prompt rules and the skills hint naming tools hidden by prepareLoadout. Hidden tools are left out of the rules, the skills hint names no tool when the file reader is hidden, and codemode shows each tool's prompt guidelines with its declaration; ToolLoadout gains getPromptGuidelines() (#10343)
  • Fixed Bedrock requests that fail with The pending stream has been canceled after a stalled HTTP/2 connection not being retried automatically (#10379)
  • Fixed codemode scripts that patch built-ins (for example Array.prototype.toJSON = ...) crashing pi and leaving the tool call unsettled. Built-ins are now frozen before the script runs, so such patches have no effect (#10444)

v1.0.3

New Features

  • Azure Foundry Chat Completions — The azure provider (renamed from azure-openai-responses) now also serves Foundry Chat Completions deployments, starting with azure/deepseek-v4-pro. See Azure OpenAI.
  • Codemode images saved to files — image() also writes each image to a temp file and names the path in the result, so later turns can copy or move generated images. See Generate images.

Breaking Changes

  • Renamed the Azure provider from azure-openai-responses to azure. Rename the provider key in auth.json (or run /login again), in models.json, and in settings.json (defaultProvider, enabledModels patterns, and modelThinkingLevels keys). Sessions that used the old provider fall back to another model when resumed, and their prompt cache is not reused. The AZURE_OPENAI_* environment variables are unchanged (#9714 by @​jsanter27)

Added

  • Added Azure Foundry Chat Completions deployments, starting with azure/deepseek-v4-pro (#9645, #9714 by @​jsanter27)

Changed

  • Codemode image() now also saves each image to a temp file and names the path in the result, so later turns can copy or move generated images (#10310)
  • Output files (full text of truncated tool output, binary MCP resources, codemode images) are now readable only by the user
  • Home/End now always move the editor cursor to the line start/end; fullscreen transcript top/bottom moved to Ctrl+Home/Ctrl+End, which no longer move the editor cursor (#10314)

Fixed

  • Fixed subscription logins such as Sign in with ChatGPT failing with refresh_token_invalidated after a request was cancelled during an OAuth token refresh
  • Fixed codemode failing for the rest of a session after a pnpm global update removed the running install, and added a restart hint when errors occur after pi was updated or removed on disk (#10439)
  • Fixed interactive sessions reporting a read EIO or setRawMode EIO crash (and asking to run /bug) when the terminal went away, e.g. after closing the window or resuming a suspended pi in a closed terminal

v1.0.2

New Features

... (truncated)

Changelog

Sourced from @​earendil-works/pi-agent-core's changelog.

[1.0.4] - 2026-10-05

[1.0.3] - 2026-10-05

[1.0.2] - 2026-10-04

[1.0.1] - 2026-10-03

[1.0.0] - 2026-10-01

Breaking Changes

  • Removed the experimental harness from @earendil-works/pi-agent-core: AgentHarness, sessions and session storage, the durable runtime, pico3, harness tools, compaction, skills, prompt templates, system prompt helpers, telemetry schemas, the search service types, and the uuidv7 and pi-telemetry re-exports. The ./node, ./harness/*, and ./experimental/pico3 subpath exports are gone. The package now contains only Agent, the agent loop, the proxy stream, and their types. Use @earendil-works/pi-durable for durable sessions.

[0.99.2] - 2026-09-30

Commits
  • 7c10bd4 Release v1.0.4
  • 997d31f Add [Unreleased] section for next cycle
  • d78dc83 Release v1.0.3
  • 2003871 Add [Unreleased] section for next cycle
  • cd32f77 Release v1.0.2
  • 4c6fb7c Add [Unreleased] section for next cycle
  • a7229dd Release v1.0.1
  • 86dfcee Add [Unreleased] section for next cycle
  • a13d35a Release v1.0.0
  • 7fd478a feat(agent): remove the experimental harness from pi-agent-core
  • Additional commits viewable in compare view

Updates @earendil-works/pi-ai from 0.99.1 to 1.0.4

Release notes

Sourced from @​earendil-works/pi-ai's releases.

v1.0.4

New Features

  • Tool patterns and --no-mcp: --tools and --exclude-tools accept * patterns, for example --tools read,codemode,'mcp__radius__*' keeps only one MCP server's tools. --tools now keeps MCP tools unless an entry starts with mcp__, and --no-mcp turns off MCP for one run. See Tools and MCP tools.
  • Codemode persists images: tools.read() on an image file now gives back an image block that image() can show. See Call tools.

Added

  • Added * patterns to --tools and --exclude-tools, for example --tools read,codemode,'mcp__radius__*'
  • Added --no-mcp to disable the built-in MCP support for one run

Fixed

  • Fixed syntax highlighting losing colors after the first line of multiline strings and comments in fenced code blocks (#10143)
  • Fixed codemode scripts not receiving images from read: tools.read() now resolves to an image block for image files, which image() shows (#10251)
  • Fixed MCP OAuth sign-in failing with invalid_redirect_uri on servers with OpenID Connect client registration, such as mcp.modem.dev: pi now registers as a native client (#10493)
  • Fixed --tools removing MCP tools, which left pi --tools codemode without any MCP servers. --tools now keeps MCP tools unless an entry starts with mcp__
  • Fixed MCP session shutdown returning while a server was still connecting, leaving its transport open until the server answered or timed out (#10249)
  • Fixed system prompt rules and the skills hint naming tools hidden by prepareLoadout. Hidden tools are left out of the rules, the skills hint names no tool when the file reader is hidden, and codemode shows each tool's prompt guidelines with its declaration; ToolLoadout gains getPromptGuidelines() (#10343)
  • Fixed Bedrock requests that fail with The pending stream has been canceled after a stalled HTTP/2 connection not being retried automatically (#10379)
  • Fixed codemode scripts that patch built-ins (for example Array.prototype.toJSON = ...) crashing pi and leaving the tool call unsettled. Built-ins are now frozen before the script runs, so such patches have no effect (#10444)

v1.0.3

New Features

  • Azure Foundry Chat Completions — The azure provider (renamed from azure-openai-responses) now also serves Foundry Chat Completions deployments, starting with azure/deepseek-v4-pro. See Azure OpenAI.
  • Codemode images saved to files — image() also writes each image to a temp file and names the path in the result, so later turns can copy or move generated images. See Generate images.

Breaking Changes

  • Renamed the Azure provider from azure-openai-responses to azure. Rename the provider key in auth.json (or run /login again), in models.json, and in settings.json (defaultProvider, enabledModels patterns, and modelThinkingLevels keys). Sessions that used the old provider fall back to another model when resumed, and their prompt cache is not reused. The AZURE_OPENAI_* environment variables are unchanged (#9714 by @​jsanter27)

Added

  • Added Azure Foundry Chat Completions deployments, starting with azure/deepseek-v4-pro (#9645, #9714 by @​jsanter27)

Changed

  • Codemode image() now also saves each image to a temp file and names the path in the result, so later turns can copy or move generated images (#10310)
  • Output files (full text of truncated tool output, binary MCP resources, codemode images) are now readable only by the user
  • Home/End now always move the editor cursor to the line start/end; fullscreen transcript top/bottom moved to Ctrl+Home/Ctrl+End, which no longer move the editor cursor (#10314)

Fixed

  • Fixed subscription logins such as Sign in with ChatGPT failing with refresh_token_invalidated after a request was cancelled during an OAuth token refresh
  • Fixed codemode failing for the rest of a session after a pnpm global update removed the running install, and added a restart hint when errors occur after pi was updated or removed on disk (#10439)
  • Fixed interactive sessions reporting a read EIO or setRawMode EIO crash (and asking to run /bug) when the terminal went away, e.g. after closing the window or resuming a suspended pi in a closed terminal

v1.0.2

New Features

... (truncated)

Changelog

Sourced from @​earendil-works/pi-ai's changelog.

[1.0.4] - 2026-10-05

Fixed

  • Fixed Bedrock requests that fail with The pending stream has been canceled after a stalled HTTP/2 connection not being retried automatically (#10379)

[1.0.3] - 2026-10-05

Breaking Changes

  • Renamed the Azure provider from azure-openai-responses to azure, since it now serves Chat Completions as well as the Responses API. Use getModel("azure", ...), and import azureProvider and AZURE_MODELS from @earendil-works/pi-ai/providers/azure instead of azureOpenAIResponsesProvider and AZURE_OPENAI_RESPONSES_MODELS from providers/azure-openai-responses. The azure-openai-responses api id and the AZURE_OPENAI_* environment variables are unchanged (#9714 by @​jsanter27)

Added

  • Added Chat Completions support to the Azure provider for Foundry deployments, with DeepSeek V4 Pro in the built-in catalog. Other Foundry models can be added under the azure provider with api: "openai-completions", and AZURE_OPENAI_DEPLOYMENT_NAME_MAP and azureDeploymentName apply to both APIs (#9645, #9714 by @​jsanter27)

Fixed

  • Fixed OAuth credentials being invalidated when a request or model refresh was cancelled or superseded during a token refresh: a token refresh that has started now completes and persists the rotated refresh token

[1.0.2] - 2026-10-04

Added

  • Added per-thinking-level sampling parameter overrides (samplingParamsByThinkingLevel) for openai-completions, openai-responses, and azure-openai-responses requests (#9776 by @​mrexodia)

[1.0.1] - 2026-10-03

Added

Changed

  • Anthropic models with native mid-conversation tool changes now use the inline-tools-2026-09-15 beta: later tools are defined by value in tool_addition blocks instead of being appended to the top-level tool list, and redefining a tool under the same name no longer falls back to resending the full tool list, so the prompt cache survives it. Upgraded @anthropic-ai/sdk to 0.129.0.
  • Deprecated hasToolRedefinitions(); no built-in transport needs it anymore.

Fixed

  • Fixed "Selected model is at capacity" provider errors ending the turn instead of being retried (#10278)
  • Fixed Cloudflare AI Gateway Claude models failing with a 404 by using dashed model IDs (claude-opus-5-5 instead of claude-opus-5.5), which Anthropic requires
  • Fixed Sign in with ChatGPT continuing when its callback port is taken by another login, which made the browser show "OAuth state mismatch"; it now fails with a port-in-use error (#10265)
  • Fixed Amazon Bedrock OpenAI models costing requests above 272k input tokens at the short-context rate; Bedrock models now include the pricing tiers listed on models.dev (#10326)
  • Fixed Amazon Bedrock Claude requests failing with "Invalid signature in thinking block" after the system prompt or tools changed; Claude Opus 4.7+, Sonnet 5+, and Fable 5 now drop stale thinking blocks like the Anthropic provider (#10324)
  • Fixed Together DeepSeek V4 Pro losing its thinking level controls after Together renamed it to deepseek-ai/DeepSeek-V4-Pro-0813 (#10336 by @​cv)

[1.0.0] - 2026-10-01

Added

... (truncated)

Commits
  • 7c10bd4 Release v1.0.4
  • 5b6c792 fix(ai): retry HTTP/2 pending stream cancellation
  • 997d31f Add [Unreleased] section for next cycle
  • d78dc83 Release v1.0.3
  • a37306d feat(ai): support Azure Foundry Chat Completions deployments (#9714)
  • bde882c fix(ai,coding-agent): persist rotated OAuth tokens when a refresh is cancelled
  • 2003871 Add [Unreleased] section for next cycle
  • cd32f77 Release v1.0.2
  • 750105c docs(ai,coding-agent): move #9776 changelog entries to Unreleased
  • 76dfb88 feat(ai): add per-thinking-level sampling parameters (#9776)
  • Additional commits viewable in compare view

Updates @earendil-works/pi-coding-agent from 0.99.1 to 1.0.4

Release notes

Sourced from @​earendil-works/pi-coding-agent's releases.

v1.0.4

New Features

  • Tool patterns and --no-mcp: --tools and --exclude-tools accept * patterns, for example --tools read,codemode,'mcp__radius__*' keeps only one MCP server's tools. --tools now keeps MCP tools unless an entry starts with mcp__, and --no-mcp turns off MCP for one run. See Tools and MCP tools.
  • Codemode persists images: tools.read() on an image file now gives back an image block that image() can show. See Call tools.

Added

  • Added * patterns to --tools and --exclude-tools, for example --tools read,codemode,'mcp__radius__*'
  • Added --no-mcp to disable the built-in MCP support for one run

Fixed

  • Fixed syntax highlighting losing colors after the first line of multiline strings and comments in fenced code blocks (#10143)
  • Fixed codemode scripts not receiving images from read: tools.read() now resolves to an image block for image files, which image() shows (#10251)
  • Fixed MCP OAuth sign-in failing with invalid_redirect_uri on servers with OpenID Connect client registration, such as mcp.modem.dev: pi now registers as a native client (#10493)
  • Fixed --tools removing MCP tools, which left pi --tools codemode without any MCP servers. --tools now keeps MCP tools unless an entry starts with mcp__
  • Fixed MCP session shutdown returning while a server was still connecting, leaving its transport open until the server answered or timed out (#10249)
  • Fixed system prompt rules and the skills hint naming tools hidden by prepareLoadout. Hidden tools are left out of the rules, the skills hint names no tool when the file reader is hidden, and codemode shows each tool's prompt guidelines with its declaration; ToolLoadout gains getPromptGuidelines() (#10343)
  • Fixed Bedrock requests that fail with The pending stream has been canceled after a stalled HTTP/2 connection not being retried automatically (#10379)
  • Fixed codemode scripts that patch built-ins (for example Array.prototype.toJSON = ...) crashing pi and leaving the tool call unsettled. Built-ins are now frozen before the script runs, so such patches have no effect (#10444)

v1.0.3

New Features

  • Azure Foundry Chat Completions — The azure provider (renamed from azure-openai-responses) now also serves Foundry Chat Completions deployments, starting with azure/deepseek-v4-pro. See Azure OpenAI.
  • Codemode images saved to files — image() also writes each image to a temp file and names the path in the result, so later turns can copy or move generated images. See Generate images.

Breaking Changes

  • Renamed the Azure provider from azure-openai-responses to azure. Rename the provider key in auth.json (or run /login again), in models.json, and in settings.json (defaultProvider, enabledModels patterns, and modelThinkingLevels keys). Sessions that used the old provider fall back to another model when resumed, and their prompt cache is not reused. The AZURE_OPENAI_* environment variables are unchanged (#9714 by @​jsanter27)

Added

  • Added Azure Foundry Chat Completions deployments, starting with azure/deepseek-v4-pro (#9645, #9714 by @​jsanter27)

Changed

  • Codemode image() now also saves each image to a temp file and names the path in the result, so later turns can copy or move generated images (#10310)
  • Output files (full text of truncated tool output, binary MCP resources, codemode images) are now readable only by the user
  • Home/End now always move the editor cursor to the line start/end; fullscreen transcript top/bottom moved to Ctrl+Home/Ctrl+End, which no longer move the editor cursor (#10314)

Fixed

  • Fixed subscription logins such as Sign in with ChatGPT failing with refresh_token_invalidated after a request was cancelled during an OAuth token refresh
  • Fixed codemode failing for the rest of a session after a pnpm global update removed the running install, and added a restart hint when errors occur after pi was updated or removed on disk (#10439)
  • Fixed interactive sessions reporting a read EIO or setRawMode EIO crash (and asking to run /bug) when the terminal went away, e.g. after closing the window or resuming a suspended pi in a closed terminal

v1.0.2

New Features

... (truncated)

Changelog

Sourced from @​earendil-works/pi-coding-agent's changelog.

[1.0.4] - 2026-10-05

New Features

  • Tool patterns and --no-mcp: --tools and --exclude-tools accept * patterns, for example --tools read,codemode,'mcp__radius__*' keeps only one MCP server's tools. --tools now keeps MCP tools unless an entry starts with mcp__, and --no-mcp turns off MCP for one run. See Tools and MCP tools.
  • Codemode persists images: tools.read() on an image file now gives back an image block that image() can show. See Call tools.

Added

  • Added * patterns to --tools and --exclude-tools, for example --tools read,codemode,'mcp__radius__*'
  • Added --no-mcp to disable the built-in MCP support for one run

Fixed

  • Fixed syntax highlighting losing colors after the first line of multiline strings and comments in fenced code blocks (#10143)
  • Fixed codemode scripts not receiving images from read: tools.read() now resolves to an image block for image files, which image() shows (#10251)
  • Fixed MCP OAuth sign-in failing with invalid_redirect_uri on servers with OpenID Connect client registration, such as mcp.modem.dev: pi now registers as a native client (#10493)
  • Fixed --tools removing MCP tools, which left pi --tools codemode without any MCP servers. --tools now keeps MCP tools unless an entry starts with mcp__
  • Fixed MCP session shutdown returning while a server was still connecting, leaving its transport open until the server answered or timed out (#10249)
  • Fixed system prompt rules and the skills hint naming tools hidden by prepareLoadout. Hidden tools are left out of the rules, the skills hint names no tool when the file reader is hidden, and codemode shows each tool's prompt guidelines with its declaration; ToolLoadout gains getPromptGuidelines() (#10343)
  • Fixed Bedrock requests that fail with The pending stream has been canceled after a stalled HTTP/2 connection not being retried automatically (#10379)
  • Fixed codemode scripts that patch built-ins (for example Array.prototype.toJSON = ...) crashing pi and leaving the tool call unsettled. Built-ins are now frozen before the script runs, so such patches have no effect (#10444)

[1.0.3] - 2026-10-05

New Features

  • Azure Foundry Chat Completions — The azure provider (renamed from azure-openai-responses) now also serves Foundry Chat Completions deployments, starting with azure/deepseek-v4-pro. See Azure OpenAI.
  • Codemode images saved to files — image() also writes each image to a temp file and names the path in the result, so later turns can copy or move generated images. See Generate images.

Breaking Changes

  • Renamed the Azure provider from azure-openai-responses to azure. Rename the provider key in auth.json (or run /login again), in models.json, and in settings.json (defaultProvider, enabledModels patterns, and modelThinkingLevels keys). Sessions that used the old provider fall back to another model when resumed, and their prompt cache is not reused. The AZURE_OPENAI_* environment variables are unchanged (#9714 by @​jsanter27)

Added

  • Added Azure Foundry Chat Completions deployments, starting with azure/deepseek-v4-pro (#9645, #9714 by @​jsanter27)

Changed

  • Codemode image() now also saves each image to a temp file and names the path in the result, so later turns can copy or move generated images (#10310)
  • Output files (full text of truncated tool output, binary MCP resources, codemode images) are now readable only by the user
  • Home/End now always move the editor cursor to the line start/end; fullscreen transcript top/bottom moved to Ctrl+Home/Ctrl+End, which no longer move the editor cursor (#10314)

Fixed

  • Fixed subscription logins such as Sign in with ChatGPT failing with refresh_token_invalidated after a request was cancelled during an OAuth token refresh
  • Fixed codemode failing for the rest of a session after a pnpm global update removed the running install, and added a restart hint when errors occur after pi was updated or removed on disk (#10439)
  • Fixed interactive sessions reporting a read EIO or setRawMode EIO crash (and asking to run /bug) when the terminal went away, e.g. after closing the window or resuming a suspended pi in a closed terminal

... (truncated)

Commits
  • 7c10bd4 Release v1.0.4
  • 3cdfbec docs(coding-agent): audit changelog for next release
  • c30840c fix(coding-agent): keep hidden tools out of prompt rules and skills hint
  • 8c91179 fix(coding-agent): close MCP connections that are still connecting on shutdown
  • 04b97ef fix(coding-agent): keep MCP tools with --tools, add tool patterns and --no-mcp
  • 147b502 fix(mcp): send application_type in OAuth dynamic client registration
  • 021eae6 fix(coding-agent): resolve codemode read calls on images to image blocks
  • b9ab918 fix(coding-agent): keep syntax colors on multiline tokens (#10356)
  • 997d31f Add [Unreleased] section for next cycle
  • d78dc83 Release v1.0.3
  • Additional commits viewable in compare view

Updates @earendil-works/pi-tui from 0.99.1 to 1.0.4

Release notes

Sourced from @​earendil-works/pi-tui's releases.

v1.0.4

New Features

  • Tool patterns and --no-mcp: --tools and --exclude-tools accept * patterns, for example --tools read,codemode,'mcp__radius__*' keeps only one MCP server's tools. --tools now keeps MCP tools unless an entry starts with mcp__, and --no-mcp turns off MCP for one run. See Tools and MCP tools.
  • Codemode persists images: tools.read() on an image file now gives back an image block that image() can show. See Call tools.

Added

  • Added * patterns to --tools and --exclude-tools, for example --tools read,codemode,'mcp__radius__*'
  • Added --no-mcp to disable the built-in MCP support for one run

Fixed

  • Fixed syntax highlighting losing colors after the first line of multiline strings and comments in fenced code blocks (#10143)
  • Fixed codemode scripts not receiving images from read: tools.read() now resolves to an image block for image files, which image() shows (#10251)
  • Fixed MCP OAuth sign-in failing with invalid_redirect_uri on servers with OpenID Connect client registration, such as mcp.modem.dev: pi now registers as a native client (#10493)
  • Fixed --tools removing MCP tools, which left pi --tools codemode without any MCP servers. --tools now keeps MCP tools unless an entry starts with mcp__
  • Fixed MCP session shutdown returning while a server was still connecting, leaving its transport open until the server answered or timed out (#10249)
  • Fixed system prompt rules and the skills hint naming tools hidden by prepareLoadout. Hidden tools are left out of the rules, the skills hint names no tool when the file reader is hidden, and codemode shows each tool's prompt guidelines with its declaration; ToolLoadout gains getPromptGuidelines() (#10343)
  • Fixed Bedrock requests that fail with The pending stream has been canceled after a stalled HTTP/2 connection not being retried automatically (#10379)
  • Fixed codemode scripts that patch built-ins (for example Array.prototype.toJSON = ...) crashing pi and leaving the tool call unsettled. Built-ins are now frozen before the script runs, so such patches have no effect (#10444)

v1.0.3

New Features

  • Azure Foundry Chat Completions — The azure provider (renamed from azure-openai-responses) now also serves Foundry Chat Completions deployments, starting with azure/deepseek-v4-pro. See Azure OpenAI.
  • Codemode images saved to files — image() also writes each image to a temp file and names the path in the result, so later turns can copy or move generated images. See Generate images.

Breaking Changes

  • Renamed the Azure provider from azure-openai-responses to azure. Rename the provider key in auth.json (or run /login again), in models.json, and in settings.json (defaultProvider, enabledModels patterns, and modelThinkingLevels keys). Sessions that used the old provider fall back to another model when resumed, and their prompt cache is not reused. The AZURE_OPENAI_* environment variables are unchanged (#9714 by @​jsanter27)

Added

  • Added Azure Foundry Chat Completions deployments, starting with azure/deepseek-v4-pro (#9645, #9714 by @​jsanter27)

Changed

  • Codemode image() now also saves each image to a temp file and names the path in the result, so later turns can copy or move generated images (#10310)
  • Output files (full text of truncated tool output, binary MCP resources, codemode images) are now readable only by the user
  • Home/End now always move the editor cursor to the line start/end; fullscreen transcript top/bottom moved to Ctrl+Home/Ctrl+End, which no longer move the editor cursor (#10314)

Fixed

  • Fixed subscription logins such as Sign in with ChatGPT failing with refresh_token_invalidated after a request was cancelled during an OAuth token refresh
  • Fixed codemode failing for the rest of a session after a pnpm global update removed the running install, and added a restart hint when errors occur after pi was updated or removed on disk (#10439)
  • Fixed interactive sessions reporting a read EIO or setRawMode EIO crash (and asking to run /bug) when the terminal went away, e.g. after closing the window or resuming a suspended pi in a closed terminal

v1.0.2

New Features

... (truncated)

Changelog

Sourced from @​earendil-works/pi-tui's changelog.

[1.0.4] - 2026-10-05

[1.0.3] - 2026-10-05

Changed

  • Home/End now always move the editor cursor to the line start/end; fullscreen transcript top/bottom moved to Ctrl+Home/Ctrl+End, which no longer move the editor cursor (#10314)

[1.0.2] - 2026-10-04

[1.0.1] - 2026-10-03

Added

  • Added setImageTranscoder(), which lets Image convert JPEG, GIF, and WebP images to PNG for the Kitty graphics protocol (#10292)

Fixed

  • Fixed non-PNG images rendering as nothing on Kitty-protocol terminals: without a registered transcoder, or when conversion fails, Image now shows its text fallback (#10292)
  • Fixed fullscreen Kitty images collapsing to a one-row strip after scrolling in WezTerm (#10319).

[1.0.0] - 2026-10-01

Added

  • Added TuiAltScreen.getScreenLines(), which returns the lines of the last rendered frame.

Fixed

  • Fixed color bleeding past mouse selections and search highlights in fullscreen mode when a styled token ends at the highlight boundary (#10169)
  • Fixed memory retained per rendered message: Markdown holds its parsed tokens weakly, and Markdown, Text, and Box flatten their cached lines. A long assistant message keeps about a fifth of the heap it kept before.
  • Fixed slash command autocompletion not triggering when the input starts with whitespace (#10218 by @​haoqixu)

[0.99.2] - 2026-09-30

Commits
  • 7c10bd4 Release v1.0.4
  • 997d31f Add [Unreleased] section for next cycle
  • d78dc83 Release v1.0.3
  • 6100fe5 fix(tui): keep Home/End for the editor in fullscreen mode
  • 2003871 Add [Unreleased] section for next cycle
  • cd32f77 Release v1.0.2
  • 4c6fb7c Add [Unreleased] section for next cycle
  • a7229dd Release v1.0.1
  • a276dab fix(tui,coding-agent): convert non-PNG images for Kitty in Image
  • 672000c fix(tui): preserve WezTerm images while scrolling
  • Additional commits viewable in compare view

Updates @types/node from 26.6.3 to 26.6.4

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

View guided diff

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 9, 2026
@dependabot
dependabot Bot requested a review from code-yeongyu as a code owner October 9, 2026 07:06
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 9, 2026
@code-yeongyu

Copy link
Copy Markdown
Owner

The test matrix failed before any test ran: bun install --frozen-lockfile stopped with "lockfile had changes, but lockfile is frozen". Dependabot's npm updater changes package.json and package-lock.json but not bun.lock, which CI installs from. It wasn't a behaviour change from the dev-dependencies group.

I pushed fce5359, which refreshes only bun.lock (bun install). Locally that gave a frozen install that passes, 76/76 tests, and a passing bun run check. On that head, all 4 test legs (ubuntu/macOS, node 22/24), the npm-consumer check and GitGuardian are green.

dependabot Bot and others added 2 commits October 9, 2026 16:22
Bumps the dev-dependencies group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) | `2.5.14` | `2.5.15` |
| [@earendil-works/pi-agent-core](https://github.com/earendil-works/pi/tree/HEAD/packages/agent) | `0.99.1` | `1.0.4` |
| [@earendil-works/pi-ai](https://github.com/earendil-works/pi/tree/HEAD/packages/ai) | `0.99.1` | `1.0.4` |
| [@earendil-works/pi-coding-agent](https://github.com/earendil-works/pi/tree/HEAD/packages/coding-agent) | `0.99.1` | `1.0.4` |
| [@earendil-works/pi-tui](https://github.com/earendil-works/pi/tree/HEAD/packages/tui) | `0.99.1` | `1.0.4` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.3` | `26.6.4` |


Updates `@biomejs/biome` from 2.5.14 to 2.5.15
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.15/packages/@biomejs/biome)

Updates `@earendil-works/pi-agent-core` from 0.99.1 to 1.0.4
- [Release notes](https://github.com/earendil-works/pi/releases)
- [Changelog](https://github.com/earendil-works/pi/blob/main/packages/agent/CHANGELOG.md)
- [Commits](https://github.com/earendil-works/pi/commits/v1.0.4/packages/agent)

Updates `@earendil-works/pi-ai` from 0.99.1 to 1.0.4
- [Release notes](https://github.com/earendil-works/pi/releases)
- [Changelog](https://github.com/earendil-works/pi/blob/main/packages/ai/CHANGELOG.md)
- [Commits](https://github.com/earendil-works/pi/commits/v1.0.4/packages/ai)

Updates `@earendil-works/pi-coding-agent` from 0.99.1 to 1.0.4
- [Release notes](https://github.com/earendil-works/pi/releases)
- [Changelog](https://github.com/earendil-works/pi/blob/main/packages/coding-agent/CHANGELOG.md)
- [Commits](https://github.com/earendil-works/pi/commits/v1.0.4/packages/coding-agent)

Updates `@earendil-works/pi-tui` from 0.99.1 to 1.0.4
- [Release notes](https://github.com/earendil-works/pi/releases)
- [Changelog](https://github.com/earendil-works/pi/blob/main/packages/tui/CHANGELOG.md)
- [Commits](https://github.com/earendil-works/pi/commits/v1.0.4/packages/tui)

Updates `@types/node` from 26.6.3 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@biomejs/biome"
  dependency-version: 2.5.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: "@earendil-works/pi-agent-core"
  dependency-version: 1.0.4
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dev-dependencies
- dependency-name: "@earendil-works/pi-ai"
  dependency-version: 1.0.4
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dev-dependencies
- dependency-name: "@earendil-works/pi-coding-agent"
  dependency-version: 1.0.4
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dev-dependencies
- dependency-name: "@earendil-works/pi-tui"
  dependency-version: 1.0.4
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dev-dependencies
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@code-yeongyu
code-yeongyu force-pushed the dependabot/npm_and_yarn/dev-dependencies-a3bc2b2e7a branch from fce5359 to 42963a5 Compare October 9, 2026 07:22

@code-yeongyu code-yeongyu left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dev-dependency bumps; bun.lock refreshed on top of #54; CI green on all legs.

@code-yeongyu
code-yeongyu merged commit 53ab1e0 into main Oct 9, 2026
7 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/dev-dependencies-a3bc2b2e7a branch October 9, 2026 07:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant