Skip to content

fix(deps): update all non-major dependencies - #219

Merged
renovate[bot] merged 3 commits into
mainfrom
renovate/all-minor-patch
Oct 3, 2026
Merged

renovate[bot] merged 3 commits into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Age Confidence
aqua:aws/aws-cli tools patch 2.37.8 → 2.37.9 age confidence
aqua:docker/compose tools minor 5.5.1 → 5.6.0 age confidence
pi-subagents dependencies minor 0.74.0 → 0.75.0 age confidence

Release Notes

aws/aws-cli (aqua:aws/aws-cli)

v2.37.9

Compare Source

======

  • api-change:securityagent: Adds trigger filters that control which pull request events, target branches, and labels start an automatic code review.
  • api-change:mediapackagev2: Dynamic Multiview enables viewers to watch multiple live video streams in a single combined output. Static filter configuration allows users to configure endpoints with layouts and sources without using query parameters. The number of sources per multiview channel has been increased to 50.
  • api-change:pinpoint-sms-voice-v2: AWS End User Messaging SMS CarrierLookup API now supports phone number cleansing on customer opt-in. when selected, the response includes the additional field "OriginalPhoneNumber". It can also return additional PhoneNumberType enums, VOIP and PREPAID.
  • bugfix:credentials: Include the web identity token in the credential cache key to prevent collisions across different tokens for the same role.
  • api-change:cognito-idp: Amazon Cognito User Pools now supports the OIDC-standard authentication context class reference (ACR) and authentication methods reference (AMR) claims on issued access and Id tokens. Amazon Cognito User Pools also now supports step-up authentication via our existing authentication APIs.
  • api-change:invoicing: API and doc updates related to adding MarketplacePunchOutEnabled and MarketplacePunchOutPreference fields to ProcurementPortalPreferences related APIs
  • api-change:lambda-web: Documentation update for AWS Lambda Web Functions, clarifies that the LambdaWeb APIs are experimental and not yet available to external customers.
  • api-change:glue: Added refresh token grant type to Glue Connection supported OAuth 2.0 grant types
docker/compose (aqua:docker/compose)

v5.6.0

Compare Source

What's Changed

ℹ️ This release adds partial support for jobs: only manually-triggered jobs are supported for now, scheduled jobs are not yet available. Full job support will land once the corresponding Docker Engine support is merged.

✨ Improvements

Jobs

Provider services

Other

🐛 Fixes
🔧 Internal
⚙️ Dependencies

Full Changelog: docker/compose@v5.5.1...v5.6.0

nicobailon/pi-subagents (pi-subagents)

v0.75.0

Compare Source

Highlights
  • Background subagents work on Pi 1.0.0 again. In 0.74.0 they failed to start with "does not provide @​earendil-works/pi-agent-core/node".
  • The built-in claude-code and claude-code-writer agents can pick a Claude model and effort level per launch, for example model: "claude-opus-5.5:high".
  • On Windows, claude-code, codex-exec, and cursor-agent can now launch CLIs installed with npm.
  • Children on a virtual model from an extension, such as a model router set as subagents.defaultModel, now launch and pass model verification.
  • An invalid config value no longer silently turns off authorityPolicy, permissions, or toolBudget. Loading the config fails instead.
Added
  • The built-in claude-code and claude-code-writer agents accept a model and thinking level per launch or in agent frontmatter, and pass them to Claude Code as --model and --effort. Before, the model could only be set in your global Claude Code settings. model: "claude-opus-5.5:high" sets both; model: ":high" sets only the effort. An unknown model or level fails the launch and names it. subagents.maxThinking and an enforced subagents.modelScope apply to these launches; with an enforced scope, a launch that sets no model fails, because Claude Code's default model cannot be checked. Other external runners still reject both fields. See agents. Thanks to @​lexxbyte for #​2602.
  • The parent can now manage a long bash command inside a native Pi child that is granted both bash and subagent_command: command.status shows it, command.yield lets the child continue while the command keeps running, and command.cancel stops only that command. The child can do the same itself with bash's yieldTimeMs and the subagent_command tool. Commands use Pi's own shell and are stopped when the child exits, and a child that finishes with a command still running fails. Thanks to @​jiuai233 for #​2598.
  • Hosts that require child extensions with registerRequiredChildExtensions can pass requireForAllRunners: true. Only local Pi children can load those extensions, so with this flag a launch on an external CLI, an external job, or another machine is refused before it starts instead of running without them. The requirement stays with the run, including nested, resumed, and workflow children, even after the host removes its registration. Without the flag, external runners are skipped as before. See agents. Thanks to @​doc-krieger for #​2639.
  • schedule.create accepts an existing missionId, so a scheduled workflow keeps the same mission state across runs and session restarts. Schedules with a mission are saved in a new format that older pi-subagents versions reject instead of silently dropping the mission; other schedules keep the old format. Thanks to @​quifox for #​2616.
  • asyncWidgetCollapsed: true starts the async widget under the editor folded to one line. Clicking its header still unfolds it, and the default is unchanged. Thanks to @​unrelentingfox for #​2621.
Changed
  • CI now runs the clean-install test against both Pi 0.86.1 and 1.0.0, as separate jobs with separate logs. Thanks to @​EightDoor for #​2648.
Fixed
  • Background subagents failed to start on Pi 1.0.0 with "does not provide @​earendil-works/pi-agent-core/node", because Pi 1.0.0 no longer ships that module. They now start without it, and still fail if Pi includes the module but the file is missing. Thanks to @​albertgwo for #​2634.
  • An invalid value for any config key no longer silently drops authorityPolicy, permissions, or toolBudget. If the config file sets any of them, loading now fails instead of continuing with an empty config that would allow what those settings forbid. (#​2622)
  • A required child extension (registerRequiredChildExtensions) that throws during session_start now stops the launch. Before, Pi only reported the error, so the child still started and could send model requests without the policy the extension was meant to set up. Ordinary extensions are unchanged: their startup errors are reported and the child still starts. Thanks to @​doc-krieger for reporting #​2639.
  • On Windows, external-CLI agents such as claude-code, codex-exec, and cursor-agent failed with EINVAL when the CLI was installed with npm, because npm installs it as a .cmd file that Node cannot start without a shell. The runner now runs the CLI's script with Node directly, still without a shell, and refuses any other .cmd or .bat file. Thanks to @​lexxbyte for tracing the cause in #​2631.
  • A child could not launch on a virtual model that an extension registers with pi.registerVirtualModel(), such as a router set as subagents.defaultModel. The child looked up its model before the extension's virtual models were registered, so the name matched a model on another provider and the launch failed on that provider's missing API key. Virtual models are now registered first, and a required extension whose registration fails stops the launch. Thanks to @​mauroziux for #​2636 (#​2635).
  • A child on a virtual model failed with model_verification_failed even when it ran correctly, because the check compared the launch model with the real model the router picked. For virtual models, the check now compares the child's selected model with the launch model. Other children are checked as before. Thanks to @​mauroziux for reporting #​2637 (#​2635).
  • A background chain whose expand step runs an external-CLI agent such as claude-code failed with "Dynamic chain step N parallel does not support field 'runner'". Each item now runs through that agent's runner, and its output is collected like any parallel child. Thanks to @​lexxbyte for reporting #​2629.
  • Saving builtin agent overrides no longer risks a half-written settings file: if the save is interrupted, the previous settings stay readable. Thanks to @​quifox for #​2627.
  • Codex children now keep tool-call IDs in the call_id|item_id form when both parts are at most 64 characters and use only letters, digits, _, or -. Other IDs are shortened as before. Thanks to @​jtabke for #​2628 (#​2623).
  • With Pi's built-in MCP, mcp: entries whose server or tool name contains -, such as mcp:srv/get-item, failed with "selects MCP tools that Pi's built-in MCP does not offer". pi-subagents now converts - to _ the same way Pi names the tool, so you keep writing names as the server reports them. Thanks to @​sheurich for #​2607.
  • Some MCP clients, such as pi-claude-bridge, send workflow: true as the string "true", which failed with an error asking for workflow: true. The string now works the same as the boolean (#​2600).
  • action: "validate" now checks workflow args against the same limits as a launch: 16 fields per object, 64 items per array, depth 8, and 16 KiB total. A script that validates no longer fails at launch because of its args. (#​2608)
  • The parent is now told about every tool call that stays open past the attention threshold, not only the first one in each child. Thanks to @​jiuai233 for #​2598.
  • Async runs now reach run-history.jsonl. Before, only foreground runs were recorded, so per-agent lookups missed every background launch. Single-step runs record the same row as a foreground run, multi-step runs record one row per child step, and a paused run records as interrupted, with a later resume recording again. Thanks to @​limin411 for #​2620.
  • /subagent-cost and the RPC cost method now count every round of a resumed foreground workflow child. Before, every round after the first was dropped as a duplicate, so totals came out low with no warning. Results recorded before this fix still undercount. Thanks to @​chagwood for #​2601.
  • /subagent-cost and the RPC cost method no longer log a missing-receipt error on every call for foreground workflows. An async workflow that has no receipt yet, such as one still running, is now listed as Async child usage unavailable instead of being left out of the total without notice. (#​2614)
  • The global mission list now takes title, status, update time, and latest run from each mission's own record, so a mission no longer looks out of date because its index entry is stale. Thanks to @​quifox for #​2618.
  • Headless sessions now deliver goal-mission notices even when finishing background work fails. The failure is still reported to the caller. Thanks to @​quifox for #​2605.
  • One mission with a damaged run status or state no longer stops continuation notices for healthy goal missions. The damaged mission is reported separately. Thanks to @​quifox for #​2604.
  • On Linux, a runner process that exited but was not yet cleaned up by the system no longer leaves its run marked as running, or a workflow waiting for a result that will never arrive. Thanks to @​quifox for #​2606.
  • Saved subagent profiles with an invalid machine value are now rejected when loaded or checked, before any settings are written. machine: false still clears a pin. Thanks to @​quifox for #​2619.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge (squash) October 2, 2026 16:51
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from e6a8214 to d1bdbaa Compare October 2, 2026 20:45
@renovate renovate Bot changed the title chore(deps): update dependency aqua:docker/compose to v5.6.0 fix(deps): update all non-major dependencies Oct 2, 2026
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from d1bdbaa to 10a4a9b Compare October 3, 2026 00:52
renovate Bot and others added 3 commits October 2, 2026 21:28
The mock writes pretty-printed JSON arrays, so wc counted five lines for one command.
Bash 3.2 ignored the failed assertion while Ubuntu Bash stopped validation.
Skip non-object lines before parsing malformed history tails to avoid tens of thousands
of exceptions and CI timeouts. Preserve whitespace-prefixed records and malformed objects.

pi-subagents 0.75.0 makes the node peer export optional, replacing our 0.74.0 patch.
Remove the obsolete patch and distinguish omitted optional exports from missing files.
@soodoh
soodoh force-pushed the renovate/all-minor-patch branch from 10a4a9b to cf0655c Compare October 3, 2026 04:33
@renovate

renovate Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@renovate
renovate Bot merged commit 106411a into main Oct 3, 2026
2 checks passed
@renovate
renovate Bot deleted the renovate/all-minor-patch branch October 3, 2026 04:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant