Skip to content

deps(deps): bump @earendil-works/pi-agent-core from 0.84.3 to 0.99.2 - #84

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/earendil-works/pi-agent-core-0.99.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/earendil-works/pi-agent-core-0.99.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps @earendil-works/pi-agent-core from 0.84.3 to 0.99.2.

Release notes

Sourced from @​earendil-works/pi-agent-core's releases.

v0.99.2

New Features

  • MCP servers stay out of the way: servers with the default codemode exposure are no longer listed in the codemode description and no longer block the first prompt. They appear in a short system prompt section, and scripts find their tools with searchTools() and describeNamespace(). See Control tool exposure.
  • More MCP authentication options: oauth.clientName for servers that only accept known OAuth clients, and "auth": { "provider": "<provider>" } to authenticate HTTP servers with a provider's /login token. See Authenticate with OAuth.
  • Anthropic workload identity federation from the Anthropic SDK environment variables. See Use an API key from the environment.
  • /reload enables tools newly added to the defaultTools setting. See Tools.

Added

  • Added a description field for MCP servers (pi mcp add --description), shown with the server in the system prompt and used to rank its tools in tool search, and a describeNamespace(name) codemode helper that returns a namespace's instructions and tool names. describeNamespace() and searchTools() accept a namespace as mcp__dev-radius, mcp__dev_radius, dev-radius, or dev_radius.
  • Added an oauth.clientName setting for MCP servers (pi mcp add --oauth-client-name) to change the client name sent during OAuth client registration, for servers that only accept known clients (#10226).
  • Added "auth": { "provider": "<provider>" } for HTTP MCP servers to send a provider's current /login token as the bearer token instead of using MCP OAuth. The token is read on every request, so provider refreshes apply. Only allowed in the global mcp.json and from extensions, and requires https except on loopback hosts.
  • Added Anthropic workload identity federation from the ANTHROPIC_FEDERATION_RULE_ID, ANTHROPIC_ORGANIZATION_ID, and ANTHROPIC_IDENTITY_TOKEN_FILE environment variables (see Providers) (#10177, #10242 by @​philfreo).
  • /reload now enables tools newly added to the defaultTools setting. Tools removed from it stay enabled, tools turned off during the session stay off unless newly added, and --tools, --no-tools, and --no-builtin-tools still override the setting (#10245).

Changed

  • MCP servers with the default codemode exposure no longer appear in the codemode description; scripts find them with searchTools(). codemode-deferred is now an alias for codemode. Use direct exposure for tools the model should see without searching (#10212).
  • The codemode description no longer includes deferred tools, tool counts, or MCP server instructions, so it no longer changes when MCP servers connect or change their tools. The tool_search description no longer lists the servers whose tools it can load, for the same reason. Servers are listed instead in an mcp_servers system prompt section with a one-line summary, updated at the start of each prompt; a changed section is appended to the conversation. Scripts read server instructions with describeNamespace() (#10212).
  • The first prompt no longer waits for MCP servers without direct tools. They connect in the background and are waited for when a codemode script names them, a script searches tools, or tool_search runs (#10212).

Fixed

  • Fixed new sessions intermittently ignoring the saved default model, or warning that no models are available, when it belongs to an extension-registered native provider with a stored credential (#9962, #10190 by @​davidbrai).
  • Fixed the /mcp sign-in URL not being clickable when it wraps across lines, by emitting it as a terminal hyperlink with a Cmd/Ctrl+click to open line like /login (#10186).
  • Fixed codemode image() accepting malformed base64 data or unsupported image types, which persisted an invalid image block that made every later provider request fail with HTTP 400 (#10215).
  • Fixed codemode failing to start its script worker from the standalone Windows executable (#10204).
  • Fixed prompt submission slowing down with session length, because resolving the session's model selection looked up the model catalog once per assistant message (#10198).
  • Fixed model lookups slowing down for providers with a refreshed pi.dev catalog, because merging remote catalog models took quadratic time.
  • Fixed the built-in-tool-renderer.ts and minimal-mode.ts extension examples removing the built-in tools' summaries and guidelines from the system prompt (#10072, #10193 by @​christianklotz).
  • Fixed context overflow detection for Z.AI CN endpoint Prompt exceeds max length errors (#10208).
  • Fixed Anthropic requests failing when a tool schema uses keywords Anthropic strict tool use rejects, such as minimum/maximum; such tools are now sent non-strict (#9953).
  • Fixed provider retries firing immediately when a Retry-After header contains an unparseable date; they now use exponential backoff (#9571).
  • Fixed extension commands registered without a string name or handler crashing pi when typing /; the extension now fails to load with an error instead (#10054).
  • Fixed collapsed codemode and MCP tool results filling the screen when the output is one long line, such as minified JSON. Like bash output, the preview is now limited to wrapped lines instead of logical lines.
  • Fixed codemode.mode: "only" listing read, bash, edit, and write in the system prompt's tool list although requests only declare codemode (#10192).
  • Fixed codemode scripts calling the wrong MCP tool when two tool names differ only in - and _, such as read-file and read_file. Like in Codex, MCP tool and namespace names now replace - with _ (mcp__my-server__x is now mcp__my_server__x), colliding tools of a server all get a hash suffix, and server names that differ only in - and _ are rejected (#10239).

v0.99.1

New Features

  • GPT-6.1 Sol — Available on OpenAI, Azure OpenAI, and OpenAI Codex, and now the default OpenAI Codex model. See Select a model.

Added

  • Added GPT-6.1 Sol (gpt-6.1-sol) to the OpenAI, Azure OpenAI Responses, and OpenAI Codex providers.

Changed

... (truncated)

Changelog

Sourced from @​earendil-works/pi-agent-core's changelog.

[0.99.2] - 2026-09-30

[0.99.1] - 2026-09-29

[0.99.0] - 2026-09-29

Added

  • Added the onProviderStreamEvent agent option, which is passed to provider streams to observe parsed provider events before normalization (#9784, #9901 by @​davidbrai).
  • The agent loop now records the requested thinking level as thinkingLevel on each assistant message.

[0.87.1] - 2026-09-22

[0.87.0] - 2026-09-21

Breaking Changes

  • Removed AgentOptions.shouldStopAfterTurn and AgentLoopConfig.shouldStopAfterTurn. Use finishTurn and return { action: "end" } to stop after the completed turn:

    // Before
    shouldStopAfterTurn: async (turn, signal) => await shouldStop(turn, signal),
    // After
    finishTurn: async (turn, signal) => {
    // shouldStopAfterTurn previously ran only for normal responses.
    if (turn.message.stopReason === "error" || turn.message.stopReason === "aborted") return;
    return (await shouldStop(turn, signal)) ? { action: "end" } : undefined;
    },

    finishTurn runs after the assistant and all tool results are finalized but before turn_end; its decision is applied after turn_end. It also runs for error and aborted responses, whose decisions are ignored because those responses remain hard exits. The guard in the migration preserves the old hook's normal-response-only invocation, including avoiding predicate side effects on hard exits. Returning { action: "end" } leaves steering and follow-up queues untouched and skips prepareNextTurn.

Added

  • Added prepareRequest, which runs before every provider request, including the first. For example, return { context: { ...context, messages: persistedMessages } } to install canonical context after already-selected input is emitted without introducing another queue poll.
  • Added finishTurn, which runs after assistant/tool-result finalization and before turn_end for normal, error, and aborted responses. Return { action: "end" } to end a normal run after turn_end, or undefined to preserve normal scheduling. { action: "continue" } ensures one next provider request: existing tool-result, steering, or follow-up scheduling can satisfy that request without adding another one; otherwise the loop makes one context-only request. Error and aborted responses remain hard exits.
  • Added Agent.peekQueuedMessages() to preview the next queue-selected batch without consuming it.

Fixed

  • Fixed harness reads misclassifying text files beginning with GIF as images (#9755).

[0.86.1] - 2026-09-20

[0.86.0] - 2026-09-19

[0.85.1] - 2026-09-05

[0.85.0] - 2026-09-04

... (truncated)

Commits
  • 005af57 Release v0.99.2
  • 6a4af07 Add [Unreleased] section for next cycle
  • d86654a Release v0.99.1
  • 312184e Add [Unreleased] section for next cycle
  • 4b060d3 Release v0.99.0
  • f81cf55 docs: audit changelogs for 0.99.0
  • 8eb2bcc fix: bump vitest to 4.1.11 and gondolin's undici to 6.29.0
  • 8562bcf feat(coding-agent): codemode and MCP
  • 540e174 feat(coding-agent): Virtual models (#10035)
  • ca7460d feat: build with TypeScript 7 and run sources with plain node
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@earendil-works/pi-agent-core](https://github.com/earendil-works/pi/tree/HEAD/packages/agent) from 0.84.3 to 0.99.2.
- [Release notes](https://github.com/earendil-works/pi/releases)
- [Changelog](https://github.com/earendil-works/pi/blob/main/packages/agent/CHANGELOG.md)
- [Commits](https://github.com/earendil-works/pi/commits/v0.99.2/packages/agent)

---
updated-dependencies:
- dependency-name: "@earendil-works/pi-agent-core"
  dependency-version: 0.99.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Dependency updates npm npm dependency updates labels Oct 5, 2026
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates npm npm dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant