fix(deps): update dependency pi-web-access to v0.34.0 - #205
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.33.0→0.34.0Release Notes
nicobailon/pi-web-access (pi-web-access)
v0.34.0Compare Source
Highlights
fetch_contentnow gets past Cloudflare "Just a moment..." pages by handing off to your other fetch providers.undiciis updated to pick up fixes for known security advisories.Added
provider: "zai". SetZAI_API_KEYorzaiApiKeyto your plan key, and setzaiEndpoint: "china"if your key comes from bigmodel.cn. Searches use your plan quota instead of per-call billing. Thanks to @nailuoGG for issue #475 and for live-testing the China endpoint in issue #479.Changed
toolActivationnow defaults to"auto". On models that can take tools added mid-conversation, new sessions start withweb_enableas before. On other models, such as DeepSeek, every enabled web tool is available from the first request, so turning them on no longer makes Pi resend the whole conversation and miss the prompt cache. Set"dynamic"to always start withweb_enable, or"eager"to never use it. Resumed sessions keep the tools they already had. The README's Tool activation section explains the trade-off. Thanks to @tinoy1336 for issue #484 and @jordi9 for issue #481.numResults: 5now call Exa's/searchendpoint instead of/answer, like every other keyed Exa search. Their answer text now comes from the search results instead of Exa's generated answer. If you route Exa through a customexaBaseUrlgateway, it must support/search. Thanks to @SuTang-vain for issue #470.fetch_contentcan't get a page, its list of fallback options now explains how to turn on the keyless Jina Reader fallback. It names only the setting you still need and keeps your current or default provider order. The hint doesn't appear if Jina already ran for that fetch, and it warns that Jina's servers fetch the target URLs. Thanks to @SuTang-vain for PR #471.Fixed
fetch_contentnow treats a Cloudflare "Just a moment..." challenge page returned with HTTP 200 as a failed fetch, so your configured fallback providers can retrieve the real page. Detection needs Cloudflare'scf-mitigated: challengeheader or its challenge-page scripts, so a page that only says "Just a moment..." is unaffected. Raw mode still returns the response unchanged, and authenticated fetches report the challenge without falling back to other providers. Thanks to @SuTang-vain for issue #472.ssrf.trustEnvProxy: true, theproxyconfigured inweb-search.jsonnow resolves hostnames for web tools instead of your local DNS, sofetch_contentworks where only the proxy can resolve names. A per-callproxywith a different value is still checked against local DNS. When local resolution fails for a request going through the configured proxy, the error now names this setting. Thanks to @ChenAuCarre for issue #476.cdn.jsdelivr.net, instead ofSource N. Results whose URL has no hostname, such asmailto:orfile:links, still useSource N. Thanks to @SuTang-vain for PR #469.undiciis updated to 8.11.2. Earlier 8.x releases, including the 8.10.0 this package previously installed, have known security advisories such as decompression denial of service and a TLS certificate validation bypass. Thanks to @setanta00 for issue #483.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.