Skip to content

fix(deps): update dependency pi-web-access to v0.34.0 - #205

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/all-minor-patch
Sep 30, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
pi-web-access 0.33.0 → 0.34.0 age confidence

Release Notes

nicobailon/pi-web-access (pi-web-access)

v0.34.0

Compare Source

Highlights
  • Turning on web tools no longer costs a prompt-cache miss on models like DeepSeek. New sessions now pick the activation style that suits the model.
  • Search with Z.ai's GLM Coding Plan and use your plan quota instead of paying per call.
  • fetch_content now gets past Cloudflare "Just a moment..." pages by handing off to your other fetch providers.
  • Fetching works on networks where only your configured proxy can resolve hostnames.
  • undici is updated to pick up fixes for known security advisories.
Added
  • Search with Z.ai's GLM Coding Plan web search when you select provider: "zai". Set ZAI_API_KEY or zaiApiKey to your plan key, and set zaiEndpoint: "china" if your key comes from bigmodel.cn. Searches use your plan quota instead of per-call billing. Thanks to @​nailuoGG for issue #​475 and for live-testing the China endpoint in issue #​479.
Changed
  • toolActivation now defaults to "auto". On models that can take tools added mid-conversation, new sessions start with web_enable as before. On other models, such as DeepSeek, every enabled web tool is available from the first request, so turning them on no longer makes Pi resend the whole conversation and miss the prompt cache. Set "dynamic" to always start with web_enable, or "eager" to never use it. Resumed sessions keep the tools they already had. The README's Tool activation section explains the trade-off. Thanks to @​tinoy1336 for issue #​484 and @​jordi9 for issue #​481.
  • Keyed Exa searches with default options or numResults: 5 now call Exa's /search endpoint instead of /answer, like every other keyed Exa search. Their answer text now comes from the search results instead of Exa's generated answer. If you route Exa through a custom exaBaseUrl gateway, it must support /search. Thanks to @​SuTang-vain for issue #​470.
  • When fetch_content can't get a page, its list of fallback options now explains how to turn on the keyless Jina Reader fallback. It names only the setting you still need and keeps your current or default provider order. The hint doesn't appear if Jina already ran for that fetch, and it warns that Jina's servers fetch the target URLs. Thanks to @​SuTang-vain for PR #​471.
Fixed
  • fetch_content now treats a Cloudflare "Just a moment..." challenge page returned with HTTP 200 as a failed fetch, so your configured fallback providers can retrieve the real page. Detection needs Cloudflare's cf-mitigated: challenge header or its challenge-page scripts, so a page that only says "Just a moment..." is unaffected. Raw mode still returns the response unchanged, and authenticated fetches report the challenge without falling back to other providers. Thanks to @​SuTang-vain for issue #​472.
  • With ssrf.trustEnvProxy: true, the proxy configured in web-search.json now resolves hostnames for web tools instead of your local DNS, so fetch_content works where only the proxy can resolve names. A per-call proxy with a different value is still checked against local DNS. When local resolution fails for a request going through the configured proxy, the error now names this setting. Thanks to @​ChenAuCarre for issue #​476.
  • Exa results without a title are now labeled with their site's hostname, such as cdn.jsdelivr.net, instead of Source N. Results whose URL has no hostname, such as mailto: or file: links, still use Source N. Thanks to @​SuTang-vain for PR #​469.
  • undici is updated to 8.11.2. Earlier 8.x releases, including the 8.10.0 this package previously installed, have known security advisories such as decompression denial of service and a TLS certificate validation bypass. Thanks to @​setanta00 for issue #​483.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge (squash) September 30, 2026 09:15
@renovate
renovate Bot merged commit 154daef into main Sep 30, 2026
2 checks passed
@renovate
renovate Bot deleted the renovate/all-minor-patch branch September 30, 2026 09:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants