fix(deps): update all non-major dependencies - #219
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
October 2, 2026 20:45
e6a8214 to
d1bdbaa
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
October 3, 2026 00:52
d1bdbaa to
10a4a9b
Compare
The mock writes pretty-printed JSON arrays, so wc counted five lines for one command. Bash 3.2 ignored the failed assertion while Ubuntu Bash stopped validation.
Skip non-object lines before parsing malformed history tails to avoid tens of thousands of exceptions and CI timeouts. Preserve whitespace-prefixed records and malformed objects. pi-subagents 0.75.0 makes the node peer export optional, replacing our 0.74.0 patch. Remove the obsolete patch and distinguish omitted optional exports from missing files.
soodoh
force-pushed
the
renovate/all-minor-patch
branch
from
October 3, 2026 04:33
10a4a9b to
cf0655c
Compare
Contributor
Author
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.37.8→2.37.95.5.1→5.6.00.74.0→0.75.0Release Notes
aws/aws-cli (aqua:aws/aws-cli)
v2.37.9Compare Source
======
securityagent: Adds trigger filters that control which pull request events, target branches, and labels start an automatic code review.mediapackagev2: Dynamic Multiview enables viewers to watch multiple live video streams in a single combined output. Static filter configuration allows users to configure endpoints with layouts and sources without using query parameters. The number of sources per multiview channel has been increased to 50.pinpoint-sms-voice-v2: AWS End User Messaging SMS CarrierLookup API now supports phone number cleansing on customer opt-in. when selected, the response includes the additional field "OriginalPhoneNumber". It can also return additional PhoneNumberType enums, VOIP and PREPAID.credentials: Include the web identity token in the credential cache key to prevent collisions across different tokens for the same role.cognito-idp: Amazon Cognito User Pools now supports the OIDC-standard authentication context class reference (ACR) and authentication methods reference (AMR) claims on issued access and Id tokens. Amazon Cognito User Pools also now supports step-up authentication via our existing authentication APIs.invoicing: API and doc updates related to adding MarketplacePunchOutEnabled and MarketplacePunchOutPreference fields to ProcurementPortalPreferences related APIslambda-web: Documentation update for AWS Lambda Web Functions, clarifies that the LambdaWeb APIs are experimental and not yet available to external customers.glue: Added refresh token grant type to Glue Connection supported OAuth 2.0 grant typesdocker/compose (aqua:docker/compose)
v5.6.0Compare Source
What's Changed
✨ Improvements
Jobs
Provider services
Other
docker compose portby @maxproske in #13577🐛 Fixes
🔧 Internal
⚙️ Dependencies
3e28d7eby @thaJeztah in #14240Full Changelog: docker/compose@v5.5.1...v5.6.0
nicobailon/pi-subagents (pi-subagents)
v0.75.0Compare Source
Highlights
claude-codeandclaude-code-writeragents can pick a Claude model and effort level per launch, for examplemodel: "claude-opus-5.5:high".claude-code,codex-exec, andcursor-agentcan now launch CLIs installed with npm.subagents.defaultModel, now launch and pass model verification.authorityPolicy,permissions, ortoolBudget. Loading the config fails instead.Added
claude-codeandclaude-code-writeragents accept a model and thinking level per launch or in agent frontmatter, and pass them to Claude Code as--modeland--effort. Before, the model could only be set in your global Claude Code settings.model: "claude-opus-5.5:high"sets both;model: ":high"sets only the effort. An unknown model or level fails the launch and names it.subagents.maxThinkingand an enforcedsubagents.modelScopeapply to these launches; with an enforced scope, a launch that sets no model fails, because Claude Code's default model cannot be checked. Other external runners still reject both fields. See agents. Thanks to @lexxbyte for #2602.bashcommand inside a native Pi child that is granted bothbashandsubagent_command:command.statusshows it,command.yieldlets the child continue while the command keeps running, andcommand.cancelstops only that command. The child can do the same itself withbash'syieldTimeMsand thesubagent_commandtool. Commands use Pi's own shell and are stopped when the child exits, and a child that finishes with a command still running fails. Thanks to @jiuai233 for #2598.registerRequiredChildExtensionscan passrequireForAllRunners: true. Only local Pi children can load those extensions, so with this flag a launch on an external CLI, an external job, or another machine is refused before it starts instead of running without them. The requirement stays with the run, including nested, resumed, and workflow children, even after the host removes its registration. Without the flag, external runners are skipped as before. See agents. Thanks to @doc-krieger for #2639.schedule.createaccepts an existingmissionId, so a scheduled workflow keeps the same mission state across runs and session restarts. Schedules with a mission are saved in a new format that older pi-subagents versions reject instead of silently dropping the mission; other schedules keep the old format. Thanks to @quifox for #2616.asyncWidgetCollapsed: truestarts the async widget under the editor folded to one line. Clicking its header still unfolds it, and the default is unchanged. Thanks to @unrelentingfox for #2621.Changed
0.86.1and1.0.0, as separate jobs with separate logs. Thanks to @EightDoor for #2648.Fixed
authorityPolicy,permissions, ortoolBudget. If the config file sets any of them, loading now fails instead of continuing with an empty config that would allow what those settings forbid. (#2622)registerRequiredChildExtensions) that throws duringsession_startnow stops the launch. Before, Pi only reported the error, so the child still started and could send model requests without the policy the extension was meant to set up. Ordinary extensions are unchanged: their startup errors are reported and the child still starts. Thanks to @doc-krieger for reporting #2639.claude-code,codex-exec, andcursor-agentfailed withEINVALwhen the CLI was installed with npm, because npm installs it as a.cmdfile that Node cannot start without a shell. The runner now runs the CLI's script with Node directly, still without a shell, and refuses any other.cmdor.batfile. Thanks to @lexxbyte for tracing the cause in #2631.pi.registerVirtualModel(), such as a router set assubagents.defaultModel. The child looked up its model before the extension's virtual models were registered, so the name matched a model on another provider and the launch failed on that provider's missing API key. Virtual models are now registered first, and a required extension whose registration fails stops the launch. Thanks to @mauroziux for #2636 (#2635).model_verification_failedeven when it ran correctly, because the check compared the launch model with the real model the router picked. For virtual models, the check now compares the child's selected model with the launch model. Other children are checked as before. Thanks to @mauroziux for reporting #2637 (#2635).expandstep runs an external-CLI agent such asclaude-codefailed with "Dynamic chain step N parallel does not support field 'runner'". Each item now runs through that agent's runner, and its output is collected like any parallel child. Thanks to @lexxbyte for reporting #2629.call_id|item_idform when both parts are at most 64 characters and use only letters, digits,_, or-. Other IDs are shortened as before. Thanks to @jtabke for #2628 (#2623).mcp:entries whose server or tool name contains-, such asmcp:srv/get-item, failed with "selects MCP tools that Pi's built-in MCP does not offer". pi-subagents now converts-to_the same way Pi names the tool, so you keep writing names as the server reports them. Thanks to @sheurich for #2607.workflow: trueas the string"true", which failed with an error asking forworkflow: true. The string now works the same as the boolean (#2600).action: "validate"now checks workflowargsagainst the same limits as a launch: 16 fields per object, 64 items per array, depth 8, and 16 KiB total. A script that validates no longer fails at launch because of itsargs. (#2608)run-history.jsonl. Before, only foreground runs were recorded, so per-agent lookups missed every background launch. Single-step runs record the same row as a foreground run, multi-step runs record one row per child step, and a paused run records asinterrupted, with a later resume recording again. Thanks to @limin411 for #2620./subagent-costand the RPCcostmethod now count every round of a resumed foreground workflow child. Before, every round after the first was dropped as a duplicate, so totals came out low with no warning. Results recorded before this fix still undercount. Thanks to @chagwood for #2601./subagent-costand the RPCcostmethod no longer log a missing-receipt error on every call for foreground workflows. An async workflow that has no receipt yet, such as one still running, is now listed asAsync child usage unavailableinstead of being left out of the total without notice. (#2614)machinevalue are now rejected when loaded or checked, before any settings are written.machine: falsestill clears a pin. Thanks to @quifox for #2619.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.