Skip to content

deps(deps): bump @earendil-works/pi-ai from 0.84.4 to 0.99.2 - #85

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/earendil-works/pi-ai-0.99.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/earendil-works/pi-ai-0.99.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps @earendil-works/pi-ai from 0.84.4 to 0.99.2.

Release notes

Sourced from @​earendil-works/pi-ai's releases.

v0.99.2

New Features

  • MCP servers stay out of the way: servers with the default codemode exposure are no longer listed in the codemode description and no longer block the first prompt. They appear in a short system prompt section, and scripts find their tools with searchTools() and describeNamespace(). See Control tool exposure.
  • More MCP authentication options: oauth.clientName for servers that only accept known OAuth clients, and "auth": { "provider": "<provider>" } to authenticate HTTP servers with a provider's /login token. See Authenticate with OAuth.
  • Anthropic workload identity federation from the Anthropic SDK environment variables. See Use an API key from the environment.
  • /reload enables tools newly added to the defaultTools setting. See Tools.

Added

  • Added a description field for MCP servers (pi mcp add --description), shown with the server in the system prompt and used to rank its tools in tool search, and a describeNamespace(name) codemode helper that returns a namespace's instructions and tool names. describeNamespace() and searchTools() accept a namespace as mcp__dev-radius, mcp__dev_radius, dev-radius, or dev_radius.
  • Added an oauth.clientName setting for MCP servers (pi mcp add --oauth-client-name) to change the client name sent during OAuth client registration, for servers that only accept known clients (#10226).
  • Added "auth": { "provider": "<provider>" } for HTTP MCP servers to send a provider's current /login token as the bearer token instead of using MCP OAuth. The token is read on every request, so provider refreshes apply. Only allowed in the global mcp.json and from extensions, and requires https except on loopback hosts.
  • Added Anthropic workload identity federation from the ANTHROPIC_FEDERATION_RULE_ID, ANTHROPIC_ORGANIZATION_ID, and ANTHROPIC_IDENTITY_TOKEN_FILE environment variables (see Providers) (#10177, #10242 by @​philfreo).
  • /reload now enables tools newly added to the defaultTools setting. Tools removed from it stay enabled, tools turned off during the session stay off unless newly added, and --tools, --no-tools, and --no-builtin-tools still override the setting (#10245).

Changed

  • MCP servers with the default codemode exposure no longer appear in the codemode description; scripts find them with searchTools(). codemode-deferred is now an alias for codemode. Use direct exposure for tools the model should see without searching (#10212).
  • The codemode description no longer includes deferred tools, tool counts, or MCP server instructions, so it no longer changes when MCP servers connect or change their tools. The tool_search description no longer lists the servers whose tools it can load, for the same reason. Servers are listed instead in an mcp_servers system prompt section with a one-line summary, updated at the start of each prompt; a changed section is appended to the conversation. Scripts read server instructions with describeNamespace() (#10212).
  • The first prompt no longer waits for MCP servers without direct tools. They connect in the background and are waited for when a codemode script names them, a script searches tools, or tool_search runs (#10212).

Fixed

  • Fixed new sessions intermittently ignoring the saved default model, or warning that no models are available, when it belongs to an extension-registered native provider with a stored credential (#9962, #10190 by @​davidbrai).
  • Fixed the /mcp sign-in URL not being clickable when it wraps across lines, by emitting it as a terminal hyperlink with a Cmd/Ctrl+click to open line like /login (#10186).
  • Fixed codemode image() accepting malformed base64 data or unsupported image types, which persisted an invalid image block that made every later provider request fail with HTTP 400 (#10215).
  • Fixed codemode failing to start its script worker from the standalone Windows executable (#10204).
  • Fixed prompt submission slowing down with session length, because resolving the session's model selection looked up the model catalog once per assistant message (#10198).
  • Fixed model lookups slowing down for providers with a refreshed pi.dev catalog, because merging remote catalog models took quadratic time.
  • Fixed the built-in-tool-renderer.ts and minimal-mode.ts extension examples removing the built-in tools' summaries and guidelines from the system prompt (#10072, #10193 by @​christianklotz).
  • Fixed context overflow detection for Z.AI CN endpoint Prompt exceeds max length errors (#10208).
  • Fixed Anthropic requests failing when a tool schema uses keywords Anthropic strict tool use rejects, such as minimum/maximum; such tools are now sent non-strict (#9953).
  • Fixed provider retries firing immediately when a Retry-After header contains an unparseable date; they now use exponential backoff (#9571).
  • Fixed extension commands registered without a string name or handler crashing pi when typing /; the extension now fails to load with an error instead (#10054).
  • Fixed collapsed codemode and MCP tool results filling the screen when the output is one long line, such as minified JSON. Like bash output, the preview is now limited to wrapped lines instead of logical lines.
  • Fixed codemode.mode: "only" listing read, bash, edit, and write in the system prompt's tool list although requests only declare codemode (#10192).
  • Fixed codemode scripts calling the wrong MCP tool when two tool names differ only in - and _, such as read-file and read_file. Like in Codex, MCP tool and namespace names now replace - with _ (mcp__my-server__x is now mcp__my_server__x), colliding tools of a server all get a hash suffix, and server names that differ only in - and _ are rejected (#10239).

v0.99.1

New Features

  • GPT-6.1 Sol — Available on OpenAI, Azure OpenAI, and OpenAI Codex, and now the default OpenAI Codex model. See Select a model.

Added

  • Added GPT-6.1 Sol (gpt-6.1-sol) to the OpenAI, Azure OpenAI Responses, and OpenAI Codex providers.

Changed

... (truncated)

Changelog

Sourced from @​earendil-works/pi-ai's changelog.

[0.99.2] - 2026-09-30

Added

  • Added the lightweight @earendil-works/pi-ai/models entry point for model collections and provider construction without loading TypeBox, built-in catalogs, or provider SDKs.
  • Added Anthropic workload identity federation from the Anthropic SDK environment variables ANTHROPIC_FEDERATION_RULE_ID, ANTHROPIC_ORGANIZATION_ID, and ANTHROPIC_IDENTITY_TOKEN_FILE (plus optional ANTHROPIC_SERVICE_ACCOUNT_ID and ANTHROPIC_WORKSPACE_ID). API keys and ANTHROPIC_AUTH_TOKEN take precedence (#10177, #10242 by @​philfreo)

Fixed

  • Fixed context overflow detection for Z.AI CN endpoint Prompt exceeds max length errors (#10208)
  • Fixed Anthropic requests failing when a strict: "prefer" tool schema uses keywords Anthropic strict tool use rejects, such as minimum/maximum; such tools are now sent non-strict (#9953)
  • Fixed provider retries firing immediately when a Retry-After header contains an unparseable date; they now use exponential backoff (#9571)

[0.99.1] - 2026-09-29

Added

  • Added GPT-6.1 Sol (gpt-6.1-sol) to the OpenAI, Azure OpenAI Responses, and OpenAI Codex providers.

[0.99.0] - 2026-09-29

Breaking Changes

  • Unified image models into the regular Provider/Models surface. The separate ImagesModels collection is removed: createImagesModels(), createImagesProvider(), ImagesProvider, openrouterImagesProvider(), builtinImagesProviders(), and builtinImagesModels() are gone. Use builtinModels(), models.getModelOfType("image", ...), models.generateImages(), and createProvider({ models, images }) instead. Existing unqualified reads remain chat-only.
  • Image models are now ImageModel with a required type: "image" and share BaseModel with chat models. The old plural image type names (ImagesModel, ImagesApi, KnownImagesApi, KnownImagesProvider, and ImagesProviderId) are removed. generateImages() accepts only image models. Output modalities (output) remain on image models only.
  • Generated model data schema is now version 6: every entry carries type, operation-specific catalogs include chat, image, and classifier models, and one upstream ID may have separate entries per type. OpenRouter image models live in the openrouter-images api group of openrouter.json; image-models.generated.ts and scripts/generate-image-models.ts are removed. Run npm run hydrate:model-data.

Added

  • Added Models.generateImages() with provider-resolved auth, Provider.generateImages?, and createProvider({ images }) keyed by model.api. createProvider() models and fetchModels accept models of every type, and api is optional when images or classifiers is given.
  • Added an optional model type ("chat", "image", or "classifier"). Chat models may omit it, so existing chat models, providers, and stores keep working unchanged. Narrow mixed lists with the new isModelType() guard or read the effective type with getModelType().
  • Added getModelsOfType(), getModelOfType(), getAvailableOfType(), getAllModels(), and getAllAvailable() on Models; optional Provider.getAllModels() and Provider.filterAllModels(); corresponding generated-catalog accessors; and the AnyModel and ModelTypeMap types. hasApi(), calculateCost(), and modelsAreEqual() accept AnyModel.
  • Added support for models of every type in ModelsStoreEntry.models. Stored and fetched models of unknown types are dropped instead of failing a refresh.
  • Added classifier models and Models.classify() with a provider-neutral JEV-style choice/score/bool contract. The built-in TypeSafe provider exposes models.dev's jev-latest through the System One API and translates public bool questions to TypeSafe's noul wire format.
  • Added Jev classifier models on OpenRouter (typesafe/jev-1.13, ~typesafe/jev-latest) through its TypeSafe-compatible System One endpoint, and on Cloudflare Workers AI (typesafe/jev) through the new cloudflare-workers-ai-system-one classifier API.
  • Added Jev classifier models on Vercel AI Gateway (typesafe-ai/jev, generated from its evaluation model catalog) and OpenCode Zen (jev-1.13, jev-1.13-free) through their TypeSafe-compatible System One endpoints.
  • Added usage to ClassifierResult: System One classifications report token counts, priced from the model catalog like chat usage.
  • Added a runtime chat-model check to the Models stream entry points so non-chat models fail with a clear ModelsError instead of a missing-api stream error.
  • Added array-based models.all.json and providers/{id}.all.json variants to the generated and published JSON catalog, allowing the same upstream ID once per model type; the existing keyed models.json and providers/{id}.json stay chat-only for released clients.
  • Added onProviderStreamEvent to observe parsed provider stream events before normalization, including provider-specific fields not retained in assistant messages (#9784, #9901 by @​davidbrai).
  • Added Claude Sonnet 5.5 to the built-in Anthropic model catalog with adaptive thinking, mid-conversation effort, 1M context, and official pricing metadata.
  • Added Sign in with ChatGPT to the openai provider: an OAuth login that uses a ChatGPT subscription with the OpenAI API. Models.login() accepts LoginOptions with getDeviceId(), which supplies a stable installation ID to login flows that need one. Subscription usage-limit errors are not retried and link to the ChatGPT usage page; temporary usage errors are retried.
  • Added the llama-cpp-classify classifier API, which answers classifier questions from llama-server's next-token probabilities for single-token answer labels.
  • Added optional AssistantMessage.thinkingLevel, which records the thinking level the agent loop requested for a response.

Changed

  • Renamed the OpenAI Codex provider to "OpenAI Codex (legacy)"; Sign in with ChatGPT on the openai provider supersedes it.
  • Unified the Anthropic, OpenAI Codex, OpenRouter, and Radius browser sign-in callback servers into one shared implementation with the same browser pages. The OAuth page helpers are now available as @earendil-works/pi-ai/utils/oauth-page.
  • Changed Radius browser sign-in to exchange the authorization code before showing the browser page, so token exchange failures are shown in the browser.

... (truncated)

Commits
  • 005af57 Release v0.99.2
  • 002c183 docs(ai,coding-agent): audit unreleased changelog entries
  • a9424cd feat(ai): Anthropic workload identity federation (#10242)
  • 2bbfcca fix(ai): use exponential backoff when Retry-After is unparseable
  • 295cc72 fix(ai): send Anthropic tools non-strict when schema has rejected keywords
  • 3dd803d fix(ai): detect Z.AI CN endpoint context overflow errors
  • ba7d5fb feat(ai,durable): add lightweight pi-ai/models entry and avoid TypeBox in dur...
  • 6a4af07 Add [Unreleased] section for next cycle
  • d86654a Release v0.99.1
  • 12c416e feat(ai,coding-agent): add GPT-6.1 Sol and make it the Codex default
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@earendil-works/pi-ai](https://github.com/earendil-works/pi/tree/HEAD/packages/ai) from 0.84.4 to 0.99.2.
- [Release notes](https://github.com/earendil-works/pi/releases)
- [Changelog](https://github.com/earendil-works/pi/blob/main/packages/ai/CHANGELOG.md)
- [Commits](https://github.com/earendil-works/pi/commits/v0.99.2/packages/ai)

---
updated-dependencies:
- dependency-name: "@earendil-works/pi-ai"
  dependency-version: 0.99.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Dependency updates npm npm dependency updates labels Oct 5, 2026
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates npm npm dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant