Skip to content

build(deps): bump undici and @earendil-works/pi-coding-agent - #38

Merged
pranshuchittora merged 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-4b5bc19fcc
Sep 30, 2026
Merged

pranshuchittora merged 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-4b5bc19fcc

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps undici to 8.10.2 and updates ancestor dependency @earendil-works/pi-coding-agent. These dependencies need to be updated together.

Updates undici from 8.9.0 to 8.10.2

Release notes

Sourced from undici's releases.

v8.10.2

⚠️ Security fixes

High severity

  • GHSA-vp8m-p9jh-q5pm: cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin, enabling cross-origin cache poisoning and data disclosure. Undici now derives interceptor identities from the dispatcher origin and bypasses origin-dependent interceptors when no authoritative origin exists. Fixed by caf6194d.
  • GHSA-w293-vg96-wgc3: BalancedPool could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves connect and legacy tls options when creating upstreams. Fixed by 8f5868fb.
  • GHSA-rfgv-xxqx-mfg5: a WebSocket server could select a subprotocol when none was requested, causing an uncaught TypeError that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 66e12816.

Medium severity

  • GHSA-3wwx-pv8p-q78v: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by 4411a238.
  • GHSA-rx4f-c7p8-82vq: an unclean WebSocketStream close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by 662d0ea6.
  • GHSA-2jfj-6hjv-fm6j: shared caches could store and replay responses containing Set-Cookie, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by cb75bbb3.
  • GHSA-3xpg-4rpp-hhhm: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable maxSize. Fixed by 7aac7f12.
  • GHSA-pmjh-fq2x-6v4x: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by e905b5b8.

Low severity

  • GHSA-8436-99hf-9mmv: cache interceptors could store and replay responses to unsafe HTTP methods such as POST or DELETE. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by 2be07bf9.
  • GHSA-2gqq-gqf2-x968: the dump interceptor could treat an oversized chunked response as successfully truncated when no Content-Length was present. Undici now enforces maxSize against received bytes and aborts oversized responses. Fixed by 6d583124.
  • GHSA-r53p-7pc4-xj5r: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates Content-Range against the original response framing before resuming. Fixed by 0160a719.

What's Changed

New Contributors

... (truncated)

Commits
  • 5e541e0 Bumped v8.10.2 (#5771)
  • eb04cc3 fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (#5738)
  • e905b5b fix(retry): settle exposed body on terminal failure
  • 0160a71 fix(retry): validate resumed response framing
  • 66e1281 fix(websocket): reject unrequested subprotocols
  • 7aac7f1 fix(decompress): limit decompressed response size
  • cb75bbb fix(cache): do not cache Set-Cookie in shared caches
  • 6d58312 fix(interceptor/dump): abort oversized chunked responses
  • 8f5868f fix: preserve BalancedPool connection options
  • 2be07bf fix(cache): reject unsafe method response caching
  • Additional commits viewable in compare view

Updates @earendil-works/pi-coding-agent from 0.85.1 to 0.99.2

Release notes

Sourced from @​earendil-works/pi-coding-agent's releases.

v0.99.2

New Features

  • MCP servers stay out of the way: servers with the default codemode exposure are no longer listed in the codemode description and no longer block the first prompt. They appear in a short system prompt section, and scripts find their tools with searchTools() and describeNamespace(). See Control tool exposure.
  • More MCP authentication options: oauth.clientName for servers that only accept known OAuth clients, and "auth": { "provider": "<provider>" } to authenticate HTTP servers with a provider's /login token. See Authenticate with OAuth.
  • Anthropic workload identity federation from the Anthropic SDK environment variables. See Use an API key from the environment.
  • /reload enables tools newly added to the defaultTools setting. See Tools.

Added

  • Added a description field for MCP servers (pi mcp add --description), shown with the server in the system prompt and used to rank its tools in tool search, and a describeNamespace(name) codemode helper that returns a namespace's instructions and tool names. describeNamespace() and searchTools() accept a namespace as mcp__dev-radius, mcp__dev_radius, dev-radius, or dev_radius.
  • Added an oauth.clientName setting for MCP servers (pi mcp add --oauth-client-name) to change the client name sent during OAuth client registration, for servers that only accept known clients (#10226).
  • Added "auth": { "provider": "<provider>" } for HTTP MCP servers to send a provider's current /login token as the bearer token instead of using MCP OAuth. The token is read on every request, so provider refreshes apply. Only allowed in the global mcp.json and from extensions, and requires https except on loopback hosts.
  • Added Anthropic workload identity federation from the ANTHROPIC_FEDERATION_RULE_ID, ANTHROPIC_ORGANIZATION_ID, and ANTHROPIC_IDENTITY_TOKEN_FILE environment variables (see Providers) (#10177, #10242 by @​philfreo).
  • /reload now enables tools newly added to the defaultTools setting. Tools removed from it stay enabled, tools turned off during the session stay off unless newly added, and --tools, --no-tools, and --no-builtin-tools still override the setting (#10245).

Changed

  • MCP servers with the default codemode exposure no longer appear in the codemode description; scripts find them with searchTools(). codemode-deferred is now an alias for codemode. Use direct exposure for tools the model should see without searching (#10212).
  • The codemode description no longer includes deferred tools, tool counts, or MCP server instructions, so it no longer changes when MCP servers connect or change their tools. The tool_search description no longer lists the servers whose tools it can load, for the same reason. Servers are listed instead in an mcp_servers system prompt section with a one-line summary, updated at the start of each prompt; a changed section is appended to the conversation. Scripts read server instructions with describeNamespace() (#10212).
  • The first prompt no longer waits for MCP servers without direct tools. They connect in the background and are waited for when a codemode script names them, a script searches tools, or tool_search runs (#10212).

Fixed

  • Fixed new sessions intermittently ignoring the saved default model, or warning that no models are available, when it belongs to an extension-registered native provider with a stored credential (#9962, #10190 by @​davidbrai).
  • Fixed the /mcp sign-in URL not being clickable when it wraps across lines, by emitting it as a terminal hyperlink with a Cmd/Ctrl+click to open line like /login (#10186).
  • Fixed codemode image() accepting malformed base64 data or unsupported image types, which persisted an invalid image block that made every later provider request fail with HTTP 400 (#10215).
  • Fixed codemode failing to start its script worker from the standalone Windows executable (#10204).
  • Fixed prompt submission slowing down with session length, because resolving the session's model selection looked up the model catalog once per assistant message (#10198).
  • Fixed model lookups slowing down for providers with a refreshed pi.dev catalog, because merging remote catalog models took quadratic time.
  • Fixed the built-in-tool-renderer.ts and minimal-mode.ts extension examples removing the built-in tools' summaries and guidelines from the system prompt (#10072, #10193 by @​christianklotz).
  • Fixed context overflow detection for Z.AI CN endpoint Prompt exceeds max length errors (#10208).
  • Fixed Anthropic requests failing when a tool schema uses keywords Anthropic strict tool use rejects, such as minimum/maximum; such tools are now sent non-strict (#9953).
  • Fixed provider retries firing immediately when a Retry-After header contains an unparseable date; they now use exponential backoff (#9571).
  • Fixed extension commands registered without a string name or handler crashing pi when typing /; the extension now fails to load with an error instead (#10054).
  • Fixed collapsed codemode and MCP tool results filling the screen when the output is one long line, such as minified JSON. Like bash output, the preview is now limited to wrapped lines instead of logical lines.
  • Fixed codemode.mode: "only" listing read, bash, edit, and write in the system prompt's tool list although requests only declare codemode (#10192).
  • Fixed codemode scripts calling the wrong MCP tool when two tool names differ only in - and _, such as read-file and read_file. Like in Codex, MCP tool and namespace names now replace - with _ (mcp__my-server__x is now mcp__my_server__x), colliding tools of a server all get a hash suffix, and server names that differ only in - and _ are rejected (#10239).

v0.99.1

New Features

  • GPT-6.1 Sol — Available on OpenAI, Azure OpenAI, and OpenAI Codex, and now the default OpenAI Codex model. See Select a model.

Added

  • Added GPT-6.1 Sol (gpt-6.1-sol) to the OpenAI, Azure OpenAI Responses, and OpenAI Codex providers.

Changed

... (truncated)

Changelog

Sourced from @​earendil-works/pi-coding-agent's changelog.

[0.99.2] - 2026-09-30

New Features

  • MCP servers stay out of the way: servers with the default codemode exposure are no longer listed in the codemode description and no longer block the first prompt. They appear in a short system prompt section, and scripts find their tools with searchTools() and describeNamespace(). See Control tool exposure.
  • More MCP authentication options: oauth.clientName for servers that only accept known OAuth clients, and "auth": { "provider": "<provider>" } to authenticate HTTP servers with a provider's /login token. See Authenticate with OAuth.
  • Anthropic workload identity federation from the Anthropic SDK environment variables. See Use an API key from the environment.
  • /reload enables tools newly added to the defaultTools setting. See Tools.

Added

  • Added a description field for MCP servers (pi mcp add --description), shown with the server in the system prompt and used to rank its tools in tool search, and a describeNamespace(name) codemode helper that returns a namespace's instructions and tool names. describeNamespace() and searchTools() accept a namespace as mcp__dev-radius, mcp__dev_radius, dev-radius, or dev_radius.
  • Added an oauth.clientName setting for MCP servers (pi mcp add --oauth-client-name) to change the client name sent during OAuth client registration, for servers that only accept known clients (#10226).
  • Added "auth": { "provider": "<provider>" } for HTTP MCP servers to send a provider's current /login token as the bearer token instead of using MCP OAuth. The token is read on every request, so provider refreshes apply. Only allowed in the global mcp.json and from extensions, and requires https except on loopback hosts.
  • Added Anthropic workload identity federation from the ANTHROPIC_FEDERATION_RULE_ID, ANTHROPIC_ORGANIZATION_ID, and ANTHROPIC_IDENTITY_TOKEN_FILE environment variables (see Providers) (#10177, #10242 by @​philfreo).
  • /reload now enables tools newly added to the defaultTools setting. Tools removed from it stay enabled, tools turned off during the session stay off unless newly added, and --tools, --no-tools, and --no-builtin-tools still override the setting (#10245).

Changed

  • MCP servers with the default codemode exposure no longer appear in the codemode description; scripts find them with searchTools(). codemode-deferred is now an alias for codemode. Use direct exposure for tools the model should see without searching (#10212).
  • The codemode description no longer includes deferred tools, tool counts, or MCP server instructions, so it no longer changes when MCP servers connect or change their tools. The tool_search description no longer lists the servers whose tools it can load, for the same reason. Servers are listed instead in an mcp_servers system prompt section with a one-line summary, updated at the start of each prompt; a changed section is appended to the conversation. Scripts read server instructions with describeNamespace() (#10212).
  • The first prompt no longer waits for MCP servers without direct tools. They connect in the background and are waited for when a codemode script names them, a script searches tools, or tool_search runs (#10212).

Fixed

  • Fixed new sessions intermittently ignoring the saved default model, or warning that no models are available, when it belongs to an extension-registered native provider with a stored credential (#9962, #10190 by @​davidbrai).
  • Fixed the /mcp sign-in URL not being clickable when it wraps across lines, by emitting it as a terminal hyperlink with a Cmd/Ctrl+click to open line like /login (#10186).
  • Fixed codemode image() accepting malformed base64 data or unsupported image types, which persisted an invalid image block that made every later provider request fail with HTTP 400 (#10215).
  • Fixed codemode failing to start its script worker from the standalone Windows executable (#10204).
  • Fixed prompt submission slowing down with session length, because resolving the session's model selection looked up the model catalog once per assistant message (#10198).
  • Fixed model lookups slowing down for providers with a refreshed pi.dev catalog, because merging remote catalog models took quadratic time.
  • Fixed the built-in-tool-renderer.ts and minimal-mode.ts extension examples removing the built-in tools' summaries and guidelines from the system prompt (#10072, #10193 by @​christianklotz).
  • Fixed context overflow detection for Z.AI CN endpoint Prompt exceeds max length errors (#10208).
  • Fixed Anthropic requests failing when a tool schema uses keywords Anthropic strict tool use rejects, such as minimum/maximum; such tools are now sent non-strict (#9953).
  • Fixed provider retries firing immediately when a Retry-After header contains an unparseable date; they now use exponential backoff (#9571).
  • Fixed extension commands registered without a string name or handler crashing pi when typing /; the extension now fails to load with an error instead (#10054).
  • Fixed collapsed codemode and MCP tool results filling the screen when the output is one long line, such as minified JSON. Like bash output, the preview is now limited to wrapped lines instead of logical lines.
  • Fixed codemode.mode: "only" listing read, bash, edit, and write in the system prompt's tool list although requests only declare codemode (#10192).
  • Fixed codemode scripts calling the wrong MCP tool when two tool names differ only in - and _, such as read-file and read_file. Like in Codex, MCP tool and namespace names now replace - with _ (mcp__my-server__x is now mcp__my_server__x), colliding tools of a server all get a hash suffix, and server names that differ only in - and _ are rejected (#10239).

[0.99.1] - 2026-09-29

New Features

  • GPT-6.1 Sol — Available on OpenAI, Azure OpenAI, and OpenAI Codex, and now the default OpenAI Codex model. See Select a model.

Added

  • Added GPT-6.1 Sol (gpt-6.1-sol) to the OpenAI, Azure OpenAI Responses, and OpenAI Codex providers.

... (truncated)

Commits
  • 005af57 Release v0.99.2
  • 002c183 docs(ai,coding-agent): audit unreleased changelog entries
  • a9424cd feat(ai): Anthropic workload identity federation (#10242)
  • 91f9f3b feat(coding-agent): let MCP servers authenticate with a provider login
  • b29db89 fix(coding-agent): align MCP tool names with codemode identifiers
  • db6cc71 feat(coding-agent): enable tools newly added to defaultTools on reload
  • 028c0ec fix(coding-agent): do not list codemode-hidden tools in the system prompt
  • 0582d9c fix(coding-agent): limit codemode and MCP result previews to wrapped lines
  • e029c3e feat(coding-agent): stop waiting for MCP servers on the first prompt
  • dc83372 fix(coding-agent): validate extension command registration
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [undici](https://github.com/nodejs/undici) to 8.10.2 and updates ancestor dependency [@earendil-works/pi-coding-agent](https://github.com/earendil-works/pi/tree/HEAD/packages/coding-agent). These dependencies need to be updated together.


Updates `undici` from 8.9.0 to 8.10.2
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v8.9.0...v8.10.2)

Updates `@earendil-works/pi-coding-agent` from 0.85.1 to 0.99.2
- [Release notes](https://github.com/earendil-works/pi/releases)
- [Changelog](https://github.com/earendil-works/pi/blob/main/packages/coding-agent/CHANGELOG.md)
- [Commits](https://github.com/earendil-works/pi/commits/v0.99.2/packages/coding-agent)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 8.10.2
  dependency-type: indirect
- dependency-name: "@earendil-works/pi-coding-agent"
  dependency-version: 0.99.2
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 30, 2026
@pranshuchittora
pranshuchittora merged commit 31a71be into main Sep 30, 2026
1 check passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/multi-4b5bc19fcc branch September 30, 2026 22:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant