Skip to content

Bump the sandbox-harnesses group across 1 directory with 5 updates - #831

Merged
czpython merged 1 commit into
mainfrom
dependabot/npm_and_yarn/deploy/sandbox/sandbox-harnesses-e3f2de53bf
Oct 6, 2026
Merged

czpython merged 1 commit into
mainfrom
dependabot/npm_and_yarn/deploy/sandbox/sandbox-harnesses-e3f2de53bf

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the sandbox-harnesses group with 5 updates in the /deploy/sandbox directory:

Package From To
@anthropic-ai/claude-code 2.1.284 2.1.288
@earendil-works/pi-coding-agent 0.87.1 1.0.0
@openai/codex 0.158.0 0.160.0
opencode-ai 1.18.33 1.18.34
pi-mcp-adapter 3.2.0 5.0.0

Updates @anthropic-ai/claude-code from 2.1.284 to 2.1.288

Release notes

Sourced from @​anthropic-ai/claude-code's releases.

v2.1.288

What's changed

  • Added $.ui.selection() for mods: returns the text you last selected in fullscreen mode and, when the selection lies within one transcript row, that row
  • Added a built-in gh api to cloud sessions whose image has no GitHub CLI, and fixed the built-in sending control characters from file names, jq filters or GitHub errors to the terminal
  • Added recovery for a prompt cleared with Ctrl+C: pressing Up on the empty prompt brings the draft back, including pasted text and images
  • Added a re-authenticate prompt when an MCP server asks for more OAuth scope during a tool call
  • Added --max-findings <n>|all to /code-review to report more or fewer findings than the usual limit; the choice is reused until you pass --max-findings default
  • Added Ctrl+F to find a session by name and Alt+↑/↓ to jump between groups in the agents view; both, and rename, can be rebound in keybindings.json
  • Added a screen reader mode announcement of the new permission mode when you approve a plan, including with Shift+Tab
  • Fixed mid-response API timeouts failing the turn: non-interactive sessions and subagents now continue from the partial response, and thinking-only responses are retried
  • Fixed long conversations failing with "Prompt is too long" instead of auto-compacting when the last reply reported zero token usage
  • Fixed --resume sometimes dropping files and other context that a compaction had just restored
  • Fixed a resumed session sometimes not saving the last response of a turn, so that the next --resume showed the prompt unanswered
  • Fixed resume occasionally loading a transcript cut short when the same session rewrote the file during the load
  • Fixed resuming a conversation started on 2.1.286 or earlier dropping the model's earlier thinking
  • Fixed session titles, memory recall and prompt hooks failing on Mantle or behind gateways that reject structured outputs; added CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS to turn structured outputs off
  • Fixed auto mode denials pointing Claude at a Bash permission rule when the blocked tool was not Bash
  • Fixed auto mode on Bedrock and Mantle switching to the local classifier for the rest of the session after a request to an older model, such as a WebFetch summary or a sonnet subagent
  • Fixed cloud sessions that restarted on a newly picked model replying with that model after the server refused it
  • Fixed Cowork cloud sessions staying marked as waiting for input after a WebFetch permission prompt for an unapproved URL went unanswered for five minutes
  • Fixed prompt suggestions not appearing on a phone that joins a Cowork cloud session started on another device
  • Fixed a mod's button sometimes running a different button's action when pressed on a view drawn before Claude Code restarted
  • Fixed a plugin's pane showing nothing when one Code element held a diff that does not parse; it now draws as plain code
  • Fixed plugin LSP servers receiving literal ${user_config.*} and ${CLAUDE_PLUGIN_ROOT} placeholders in initializationOptions and settings instead of substituted values or manifest defaults
  • Fixed a plugin's tool.call hook making Bash fail and file searches read the wrong folder in subagents that run in a worktree
  • Fixed git-subdir plugin installs failing, or caching an incomplete plugin, on older git (before 2.39, e.g. Ubuntu 22.04's 2.34)
  • Fixed plugins loaded with --plugin-dir not showing "Configure options" in /plugin
  • Fixed background sessions ending when a plugin was reloaded or disabled while one of its timers or reads was still running
  • Fixed sandboxed heredocs with an unquoted delimiter (python3 <<EOF) asking for approval on every run under sandbox auto-allow when the body holds only plain text and simple $VAR references
  • Fixed Bash tool permission check to prompt before a BASHPID assignment whose value the shell would evaluate as arithmetic, instead of allowing it silently
  • Fixed fullscreen sessions exiting with "unrecoverable interface error" when opening the background tasks dialog while a plugin or mod showed rows above the prompt
  • Fixed Claude reporting a message to another session as delivered when that session held it: the notice now says it wasn't delivered and names the session, and in SDK sessions Claude can now learn of it mid-turn
  • Fixed OpenTelemetry claude_code.tool.blocked_on_user spans reporting unknown source or decision in -p and SDK sessions and for PreToolUse hook approvals
  • Fixed permission asks that ended unanswered, in -p or on an interrupted turn, emitting no tool_decision event
  • Fixed Edit and Retry in Cowork cloud sessions refusing a message sent before /compact even though its history was still saved
  • Fixed unattended sessions (CLAUDE_CODE_RETRY_WATCHDOG) retrying for hours after a very long response stream failed; Claude Code now streams again, and gives up after three timeouts
  • Fixed /loginanthropics/claude-code#73861
  • Fixed a Stop during Bedrock credential lookup sometimes moving the session to a fallback model instead of ending the request
  • Fixed a second gcpAuthRefresh/awsAuthRefresh browser sign-in opening when a laptop wakes from sleep while another Claude Code process is signing in
  • Fixed agent teams: a plugin-defined agent spawned by name now runs with its own prompt, tools, disallowedTools and effort instead of the defaults
  • Fixed headless (-p / SDK) sessions occasionally ignoring SIGTERM when a supervisor such as timeout or systemd sends SIGCONT alongside it
  • Fixed restarted cloud sessions restoring a model that the organization's enforced model list refuses
  • Fixed MCP tool calls sometimes running twice when a remote server's result was over 16 MB or could not be parsed
  • Fixed subagents in Claude Desktop's Code tab getting none of the tools of a user-configured MCP server named memory
  • Fixed Claude in Chrome asking before every screenshot and page read on a site you allowed when auto mode is unavailable (such as with disableAutoMode or an older model); typing, navigation and JavaScript still ask
  • Fixed claude plugin install failing for GitHub-source plugins on macOS and Linux machines with no GitHub SSH key: the clone now falls back to HTTPS and prints a notice
  • Fixed sandbox.credentials.files entries on git config files not taking effect while permissions.blockReadsOutsideWorkingDirectories is on
  • Fixed Claude leaving out your organization's design systems when starting slides or a design with the Artifact tool on Team and Enterprise plans or machines with managed settings
  • Fixed the keyboard not working on Windows after Claude Code restarts itself (first sign-in to a Claude apps gateway, provider setup, /tui)

... (truncated)

Changelog

Sourced from @​anthropic-ai/claude-code's changelog.

2.1.288

  • Added $.ui.selection() for mods: returns the text you last selected in fullscreen mode and, when the selection lies within one transcript row, that row
  • Added a built-in gh api to cloud sessions whose image has no GitHub CLI, and fixed the built-in sending control characters from file names, jq filters or GitHub errors to the terminal
  • Added recovery for a prompt cleared with Ctrl+C: pressing Up on the empty prompt brings the draft back, including pasted text and images
  • Added a re-authenticate prompt when an MCP server asks for more OAuth scope during a tool call
  • Added --max-findings <n>|all to /code-review to report more or fewer findings than the usual limit; the choice is reused until you pass --max-findings default
  • Added Ctrl+F to find a session by name and Alt+↑/↓ to jump between groups in the agents view; both, and rename, can be rebound in keybindings.json
  • Added a screen reader mode announcement of the new permission mode when you approve a plan, including with Shift+Tab
  • Fixed mid-response API timeouts failing the turn: non-interactive sessions and subagents now continue from the partial response, and thinking-only responses are retried
  • Fixed long conversations failing with "Prompt is too long" instead of auto-compacting when the last reply reported zero token usage
  • Fixed --resume sometimes dropping files and other context that a compaction had just restored
  • Fixed a resumed session sometimes not saving the last response of a turn, so that the next --resume showed the prompt unanswered
  • Fixed resume occasionally loading a transcript cut short when the same session rewrote the file during the load
  • Fixed resuming a conversation started on 2.1.286 or earlier dropping the model's earlier thinking
  • Fixed session titles, memory recall and prompt hooks failing on Mantle or behind gateways that reject structured outputs; added CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS to turn structured outputs off
  • Fixed auto mode denials pointing Claude at a Bash permission rule when the blocked tool was not Bash
  • Fixed auto mode on Bedrock and Mantle switching to the local classifier for the rest of the session after a request to an older model, such as a WebFetch summary or a sonnet subagent
  • Fixed cloud sessions that restarted on a newly picked model replying with that model after the server refused it
  • Fixed Cowork cloud sessions staying marked as waiting for input after a WebFetch permission prompt for an unapproved URL went unanswered for five minutes
  • Fixed prompt suggestions not appearing on a phone that joins a Cowork cloud session started on another device
  • Fixed a mod's button sometimes running a different button's action when pressed on a view drawn before Claude Code restarted
  • Fixed a plugin's pane showing nothing when one Code element held a diff that does not parse; it now draws as plain code
  • Fixed plugin LSP servers receiving literal ${user_config.*} and ${CLAUDE_PLUGIN_ROOT} placeholders in initializationOptions and settings instead of substituted values or manifest defaults
  • Fixed a plugin's tool.call hook making Bash fail and file searches read the wrong folder in subagents that run in a worktree
  • Fixed git-subdir plugin installs failing, or caching an incomplete plugin, on older git (before 2.39, e.g. Ubuntu 22.04's 2.34)
  • Fixed plugins loaded with --plugin-dir not showing "Configure options" in /plugin
  • Fixed background sessions ending when a plugin was reloaded or disabled while one of its timers or reads was still running
  • Fixed sandboxed heredocs with an unquoted delimiter (python3 <<EOF) asking for approval on every run under sandbox auto-allow when the body holds only plain text and simple $VAR references
  • Fixed Bash tool permission check to prompt before a BASHPID assignment whose value the shell would evaluate as arithmetic, instead of allowing it silently
  • Fixed fullscreen sessions exiting with "unrecoverable interface error" when opening the background tasks dialog while a plugin or mod showed rows above the prompt
  • Fixed Claude reporting a message to another session as delivered when that session held it: the notice now says it wasn't delivered and names the session, and in SDK sessions Claude can now learn of it mid-turn
  • Fixed OpenTelemetry claude_code.tool.blocked_on_user spans reporting unknown source or decision in -p and SDK sessions and for PreToolUse hook approvals
  • Fixed permission asks that ended unanswered, in -p or on an interrupted turn, emitting no tool_decision event
  • Fixed Edit and Retry in Cowork cloud sessions refusing a message sent before /compact even though its history was still saved
  • Fixed unattended sessions (CLAUDE_CODE_RETRY_WATCHDOG) retrying for hours after a very long response stream failed; Claude Code now streams again, and gives up after three timeouts
  • Fixed /loginanthropics/claude-code#73861
  • Fixed a Stop during Bedrock credential lookup sometimes moving the session to a fallback model instead of ending the request
  • Fixed a second gcpAuthRefresh/awsAuthRefresh browser sign-in opening when a laptop wakes from sleep while another Claude Code process is signing in
  • Fixed agent teams: a plugin-defined agent spawned by name now runs with its own prompt, tools, disallowedTools and effort instead of the defaults
  • Fixed headless (-p / SDK) sessions occasionally ignoring SIGTERM when a supervisor such as timeout or systemd sends SIGCONT alongside it
  • Fixed restarted cloud sessions restoring a model that the organization's enforced model list refuses
  • Fixed MCP tool calls sometimes running twice when a remote server's result was over 16 MB or could not be parsed
  • Fixed subagents in Claude Desktop's Code tab getting none of the tools of a user-configured MCP server named memory
  • Fixed Claude in Chrome asking before every screenshot and page read on a site you allowed when auto mode is unavailable (such as with disableAutoMode or an older model); typing, navigation and JavaScript still ask
  • Fixed claude plugin install failing for GitHub-source plugins on macOS and Linux machines with no GitHub SSH key: the clone now falls back to HTTPS and prints a notice
  • Fixed sandbox.credentials.files entries on git config files not taking effect while permissions.blockReadsOutsideWorkingDirectories is on
  • Fixed Claude leaving out your organization's design systems when starting slides or a design with the Artifact tool on Team and Enterprise plans or machines with managed settings
  • Fixed the keyboard not working on Windows after Claude Code restarts itself (first sign-in to a Claude apps gateway, provider setup, /tui)
  • Fixed a stall when launching an agent whose tools: lists very many Agent(...) entries

... (truncated)

Commits
  • 1c229fc chore: Update CHANGELOG.md and feed.xml
  • 52c7644 chore: Update CHANGELOG.md and feed.xml
  • 816ec21 chore: Update CHANGELOG.md and feed.xml
  • 6160717 diff: the dialog opens every file it lists, and says nothing when closed (#98...
  • 525d3b3 diff: the pane notices a finished merge by itself, and stays quiet on an unus...
  • 292c5b8 diff: the pane reads every file's hunks with one git process, where it starte...
  • 9778ad7 diff: the pane reads the diff again after a rebase that finished (#98374)
  • f5f6025 chore: Update CHANGELOG.md and feed.xml
  • 732e167 Merge pull request #97952 from anthropics/security-hardening-gh-actions
  • 89c73ce Remove a compiled Python file committed by mistake
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​anthropic-ai/claude-code since your current version.


Updates @earendil-works/pi-coding-agent from 0.87.1 to 1.0.0

Release notes

Sourced from @​earendil-works/pi-coding-agent's releases.

v1.0.0

New Features

  • Fullscreen by default — The TUI now runs fullscreen. Set tuiMode to "regular" to keep the terminal's normal scrollback. See Terminal and display.
  • Leaner codemode — About 40% fewer prompt tokens, and errors that tell the model how to recover. See Codemode.
  • Image generation in codemode — Scripts call models.generateImages() with the session's credentials. See Generate images and Use image models.
  • Radius in /login — Sign in with Radius and set up its MCP server in one step. See Radius.
  • Anthropic copy code login — Sign in when the browser runs on another machine. See Authenticate interactively.
  • MCP OAuth hardening — oauth.authServerMetadataUrl, RFC 9207 iss checks, credentials per server, and step-up sign-in that keeps granted scopes. See Authenticate with OAuth.
  • Header-only quiet startup — quietStartup: "header" keeps the version and key hints and hides the rest. See Terminal and display.

Added

  • Added an oauth.authServerMetadataUrl setting for MCP servers that advertise a wrong OAuth authorization server or none. Pi uses the configured metadata document instead of discovery (#10172).
  • Added quietStartup: "header", which keeps the startup header with version and key hints but hides the model scope line and loaded-resource listing.
  • Added models.generateImages() to codemode scripts. It runs image models such as OpenRouter's with the session's credentials and returns base64 image blocks that image() attaches to the result; usage counts toward the session cost like models.classify(). Extensions can call ctx.modelRegistry.generateImages(). See Use image models.
  • Added a copy code login method to Anthropic /login for headless setups where the browser runs on another machine (#10194 by @​lucasmeijer).

Changed

  • Changed the default TUI mode to fullscreen. Set tuiMode to "regular" or pass --tui-mode regular to keep the terminal's normal scrollback.
  • /login now offers "Sign in with Radius" at the top level, as the last option, with its status. After a Radius sign-in, /login offers to configure the Radius MCP server in the global mcp.json with "auth": { "provider": "radius" } and reloads. Cancelling a login returns to the menu it was started from.
  • The provider docs page is renamed to Providers, its "Cloud Providers" section is now "Provider Specific Config", and it documents Radius first.
  • MCP OAuth credentials are now stored per server name and URL, so MCP servers with the same URL can sign in with different accounts. Credentials stored by URL alone move to the first server that uses them (#10252).
  • Codemode costs far fewer prompt tokens: with the default tools and codemode active, a GPT-5.6 request shrinks from about 5,300 to 3,300 tokens. The codemode description lists the script globals in one line each and points to the new Codemode reference for the models API, which the model reads when it needs it. Declared tools say in one line how scripts call them and what the call resolves to, instead of repeating their full declaration, and the system prompt's codemode guidance and MCP server section are shorter.
  • Codemode errors now say how to recover: reading a tool or models member that does not exist names the close matches (tools.Bash suggests tools.bash), models.classify() and models.generateImages() reject malformed arguments with the expected shape, an unknown model points to models.getAvailableOfType(), an oversized store() value explains what the store is for, and a script that generates images without showing them gets a note. Scripts that probed for a tool with typeof tools.name must use "name" in tools.
  • /login and /logout now label providers without credentials as "not configured" instead of "unconfigured".
  • OAuth browser pages now show the color Pi logo.

Fixed

  • Fixed MCP OAuth sign-in accepting an authorization response whose iss parameter names another authorization server; the code is now rejected before it is exchanged (RFC 9207).
  • Fixed MCP OAuth sign-in failing with Invalid scope when the token response contains "scope": "", and similar failures for other empty or null optional OAuth fields (#10266).
  • Fixed the sign-in URL printed by /mcp login not being clickable when it wraps (#10186).
  • Fixed --provider without --model being silently ignored and running the default model from another provider; it now fails with an error (#10236).
  • Fixed MCP servers that ask for more scope (insufficient_scope) requesting sign-in over and over. The new sign-in requested only the missing scopes, so the new token lost access the previous one had; it now keeps the granted scopes.
  • Fixed user messages in the transcript keeping two full-width copies of every rendered line; they keep one, with identical output.
  • Fixed /login and /logout labeling every OAuth sign-in, including Radius, as a subscription; only subscription-backed providers say "subscription", other OAuth sign-ins say "account".
  • Fixed the startup header logo rendering with gaps in Apple Terminal; it now shows a colored "Pi" with the version instead.
  • Fixed deferred MCP tools that tool_search loaded being dropped on resume and /reload even when their server reconnected before the next prompt, because the session restored its tools before the MCP servers reconnected.
  • Fixed the system theme making pastel palettes such as Catppuccin Frappe much more vivid; palette colors now keep their chroma (#10255, #10293 by @​dgtlntv).
  • Fixed slash command autocompletion not triggering when the input starts with whitespace (#10218 by @​haoqixu).
  • Fixed color bleeding past mouse selections and search highlights in fullscreen mode when a styled token ends at the highlight boundary (#10169).
  • Fixed memory retained per rendered message in the transcript; a long assistant message keeps about a fifth of the heap it kept before.

v0.99.2

New Features

  • MCP servers stay out of the way: servers with the default codemode exposure are no longer listed in the codemode description and no longer block the first prompt. They appear in a short system prompt section, and scripts find their tools with searchTools() and describeNamespace(). See Control tool exposure.
  • More MCP authentication options: oauth.clientName for servers that only accept known OAuth clients, and "auth": { "provider": "<provider>" } to authenticate HTTP servers with a provider's /login token. See Authenticate with OAuth.

... (truncated)

Changelog

Sourced from @​earendil-works/pi-coding-agent's changelog.

[1.0.0] - 2026-10-01

New Features

  • Fullscreen by default — The TUI now runs fullscreen. Set tuiMode to "regular" to keep the terminal's normal scrollback. See Terminal and display.
  • Leaner codemode — About 40% fewer prompt tokens, and errors that tell the model how to recover. See Codemode.
  • Image generation in codemode — Scripts call models.generateImages() with the session's credentials. See Generate images and Use image models.
  • Radius in /login — Sign in with Radius and set up its MCP server in one step. See Radius.
  • Anthropic copy code login — Sign in when the browser runs on another machine. See Authenticate interactively.
  • MCP OAuth hardening — oauth.authServerMetadataUrl, RFC 9207 iss checks, credentials per server, and step-up sign-in that keeps granted scopes. See Authenticate with OAuth.
  • Header-only quiet startup — quietStartup: "header" keeps the version and key hints and hides the rest. See Terminal and display.

Added

  • Added an oauth.authServerMetadataUrl setting for MCP servers that advertise a wrong OAuth authorization server or none. Pi uses the configured metadata document instead of discovery (#10172).
  • Added quietStartup: "header", which keeps the startup header with version and key hints but hides the model scope line and loaded-resource listing.
  • Added models.generateImages() to codemode scripts. It runs image models such as OpenRouter's with the session's credentials and returns base64 image blocks that image() attaches to the result; usage counts toward the session cost like models.classify(). Extensions can call ctx.modelRegistry.generateImages(). See Use image models.
  • Added a copy code login method to Anthropic /login for headless setups where the browser runs on another machine (#10194 by @​lucasmeijer).

Changed

  • Changed the default TUI mode to fullscreen. Set tuiMode to "regular" or pass --tui-mode regular to keep the terminal's normal scrollback.
  • /login now offers "Sign in with Radius" at the top level, as the last option, with its status. After a Radius sign-in, /login offers to configure the Radius MCP server in the global mcp.json with "auth": { "provider": "radius" } and reloads. Cancelling a login returns to the menu it was started from.
  • The provider docs page is renamed to Providers, its "Cloud Providers" section is now "Provider Specific Config", and it documents Radius first.
  • MCP OAuth credentials are now stored per server name and URL, so MCP servers with the same URL can sign in with different accounts. Credentials stored by URL alone move to the first server that uses them (#10252).
  • Codemode costs far fewer prompt tokens: with the default tools and codemode active, a GPT-5.6 request shrinks from about 5,300 to 3,300 tokens. The codemode description lists the script globals in one line each and points to the new Codemode reference for the models API, which the model reads when it needs it. Declared tools say in one line how scripts call them and what the call resolves to, instead of repeating their full declaration, and the system prompt's codemode guidance and MCP server section are shorter.
  • Codemode errors now say how to recover: reading a tool or models member that does not exist names the close matches (tools.Bash suggests tools.bash), models.classify() and models.generateImages() reject malformed arguments with the expected shape, an unknown model points to models.getAvailableOfType(), an oversized store() value explains what the store is for, and a script that generates images without showing them gets a note. Scripts that probed for a tool with typeof tools.name must use "name" in tools.
  • /login and /logout now label providers without credentials as "not configured" instead of "unconfigured".
  • OAuth browser pages now show the color Pi logo.

Fixed

  • Fixed MCP OAuth sign-in accepting an authorization response whose iss parameter names another authorization server; the code is now rejected before it is exchanged (RFC 9207).
  • Fixed MCP OAuth sign-in failing with Invalid scope when the token response contains "scope": "", and similar failures for other empty or null optional OAuth fields (#10266).
  • Fixed the sign-in URL printed by /mcp login not being clickable when it wraps (#10186).
  • Fixed --provider without --model being silently ignored and running the default model from another provider; it now fails with an error (#10236).
  • Fixed MCP servers that ask for more scope (insufficient_scope) requesting sign-in over and over. The new sign-in requested only the missing scopes, so the new token lost access the previous one had; it now keeps the granted scopes.
  • Fixed user messages in the transcript keeping two full-width copies of every rendered line; they keep one, with identical output.
  • Fixed /login and /logout labeling every OAuth sign-in, including Radius, as a subscription; only subscription-backed providers say "subscription", other OAuth sign-ins say "account".
  • Fixed the startup header logo rendering with gaps in Apple Terminal; it now shows a colored "Pi" with the version instead.
  • Fixed deferred MCP tools that tool_search loaded being dropped on resume and /reload even when their server reconnected before the next prompt, because the session restored its tools before the MCP servers reconnected.
  • Fixed the system theme making pastel palettes such as Catppuccin Frappe much more vivid; palette colors now keep their chroma (#10255, #10293 by @​dgtlntv).
  • Fixed slash command autocompletion not triggering when the input starts with whitespace (#10218 by @​haoqixu).
  • Fixed color bleeding past mouse selections and search highlights in fullscreen mode when a styled token ends at the highlight boundary (#10169).
  • Fixed memory retained per rendered message in the transcript; a long assistant message keeps about a fifth of the heap it kept before.

[0.99.2] - 2026-09-30

New Features

... (truncated)

Commits
  • a13d35a Release v1.0.0
  • 92fc452 docs: audit changelogs and add new features for next release
  • 395315f feat(coding-agent): experimental durable vacation planner demo
  • 6f1072c feat(coding-agent): shrink codemode prompt and guide scripts back from errors
  • 88ff80b feat(coding-agent): make fullscreen the default TUI mode
  • c2f65d8 docs(coding-agent): add Radius to providers page, rename provider docs sections
  • ca9c925 fix(coding-agent): show text wordmark instead of logo in Apple Terminal
  • aab34df feat(coding-agent): add models.generateImages() to codemode
  • ed8b3bc feat(coding-agent): offer Radius sign-in and MCP setup in /login
  • 48dd1e2 feat(coding-agent): port the experimental client/server to pi-durable
  • Additional commits viewable in compare view

Updates @openai/codex from 0.158.0 to 0.160.0
Updates opencode-ai from 1.18.33 to 1.18.34

Release notes

Sourced from opencode-ai's releases.

v1.18.34

Core

Bugfixes

  • Send namespaced session and parent-session identity headers with model requests.
  • Re-sign locally compiled macOS binaries so they run reliably on macOS 27+. (@​ryangamerdev)
  • Sign macOS CLI release binaries with a Developer ID.

Thank you to 3 community contributors:

Commits
  • aec0b9a release: v1.18.34
  • e9f8a21 fix(opencode): add namespaced session identity headers (#52370)
  • 9b4882d fix(opencode): ad-hoc re-sign darwin binaries after local compile (#52183)
  • 97a86b7 fix(tui): use path.sep for plugin name extraction in /status dialog (#52328)
  • 2fa3363 docs(web): correct GPT 6.1 Sol cache pricing (#52176)
  • f66b86c fix(ci): sign macOS CLI with Developer ID
  • 7945de2 Merge branch 'dev' of github.com:anomalyco/opencode into dev
  • 8d05153 chore: generate
  • d1dc00d feat(console): refresh Go page hero and plans to match design (#51933)
  • 90853b2 chore: generate
  • Additional commits viewable in compare view

Updates pi-mcp-adapter from 3.2.0 to 5.0.0

Release notes

Sourced from pi-mcp-adapter's releases.

v5.0.0

pi-mcp-adapter 5.0.0 makes the adapter the one place Pi runs MCP. Servers you added with pi mcp add, servers other extensions register, sign-ins from Pi's built-in MCP, and tokens from Pi's /login all work here now. It also runs far fewer servers: each one is discovered at startup and then stopped until you use it, so a big server list no longer means a big pile of running processes. Servers you rarely use stay searchable, long tools that report progress no longer time out, and a stray Enter can no longer approve a project server.

Highlights

  • Works with Pi's own MCP setup. Pi's mcp.json files, pi.registerMcpServer() servers, built-in MCP sign-ins, and /login provider tokens all work in the adapter.
  • Only the servers you use stay running. With 100 servers installed and 3 in use, 3 run instead of 100.
  • Rarely used servers stay searchable. Cached tools no longer expire after a week.
  • pi-mcp-adapter doctor checks your servers from a shell or CI.
  • Fewer surprises. Long tools that report progress keep going, and the project-server approval prompt now starts on "Don't allow".

Need to know

If you… What changes
Use Pi 0.99 or later The adapter replaces Pi's built-in MCP in sessions and turns the built-in off once in Pi's settings. /mcp opens the adapter. To go back, turn the built-in on in pi config → Built-in.
Import pi-mcp-adapter/config getLegacyPiMcpGlobalConfigPath() and getLegacyProjectPiMcpConfigPath() are now getPiMcpGlobalConfigPath() and getProjectPiMcpConfigPath().

Full changelog

Highlights

  • The adapter now works with Pi's own MCP setup: servers added with pi mcp add, servers other extensions register, sign-ins made with Pi's built-in MCP, and provider tokens from Pi's /login all work here.
  • Far fewer servers stay running. Servers are discovered at startup and then stopped until you use them, so with 100 servers installed and 3 in use, only those 3 run.
  • Servers you rarely use stay searchable. Cached tools no longer expire after a week.
  • pi-mcp-adapter doctor checks your servers from a shell or CI.
  • Long tools that report progress no longer time out, and a stray Enter can no longer approve a project server.

Breaking

  • On Pi 0.99 and later, the adapter replaces Pi's built-in MCP extension in sessions, except when a host supplies its own config through createMcpAdapter(): /mcp opens the adapter, and the built-in no longer connects servers. On the first start after you install or update the adapter, it also turns the built-in off in Pi's user settings ("-builtin:mcp", as pi config writes), so Pi stops warning that the built-in was not loaded. Turning it back on in pi config sticks. Shell pi mcp commands still use Pi's own files. See Pi's built-in MCP.
  • pi-mcp-adapter/config exports getPiMcpGlobalConfigPath() and getProjectPiMcpConfigPath() instead of getLegacyPiMcpGlobalConfigPath() and getLegacyProjectPiMcpConfigPath().

Added

  • On Pi 0.99 and later, the adapter also reads Pi's ~/.pi/agent/mcp.json and .pi/mcp.json, so servers added with pi mcp add work here. Each file sits right below the mcp-adapter.json in its folder. Pi settings without an exact adapter equivalent are ignored, and entries the adapter can't run, such as SSE servers, are skipped; both are reported at startup, and a loaded server's ignored settings are also listed under it in /mcp-adapter. .pi/mcp.json servers need project trust and approval, and exclusive mode reads neither file. See configuration.
  • On Pi 0.99 and later, the adapter connects servers that other extensions add with Pi's pi.registerMcpServer(), so Pi no longer reports them as unconnected. They are translated like Pi's mcp.json entries and are proxy-only: direct and deferred exposure are ignored and reported. A config entry or an earlier registerMcpServer() registration of the same name wins, and the registration is reported as overridden. Registering a name again with a different config replaces the server, and unregistering disconnects it. See the extension API.
  • On Pi 0.99 and later, sign-ins made with Pi's built-in MCP can be imported: interactive sessions ask once per OAuth server whose exact URL has a sign-in in Pi's ~/.pi/agent/mcp-auth.json and none in the adapter, and ctrl+p in /mcp-adapter imports every eligible server. If the server rotates refresh tokens, the adapter's first refresh can sign Pi's shell pi mcp commands out. See Import a sign-in from Pi's built-in MCP.
  • HTTP servers accept "auth": { "provider": "<name>" }, in adapter config and Pi's mcp.json, to send the token of a provider you signed in to with Pi's /login (Pi 0.99.2 or later). The token is read on every request and sent only to the server's origin, never through a redirect. User-global config only, and https except on loopback. Without a token the server needs /login <provider>; it never starts MCP OAuth. See Pi provider tokens.
  • pi-mcp-adapter doctor [--json] checks your MCP servers from a shell or CI: each enabled server's state, tool count, and error or hint, exiting 1 when one fails. The report prints before connections close, and a failed shutdown also exits 1. It follows project trust and never starts OAuth. See Check servers from a shell.
  • Server entries accept a description, the same key as Pi's mcp.json. mcp({ server }) shows it, mcp({ search }) ranks the server's tools by it, and the /mcp-adapter panel shows it when you expand the server, falling back to the first line of the server's instructions.

Changed

  • Startup no longer leaves every server running until the idle timeout. At each start, the adapter discovers servers whose cached tools are missing, from an older config, or past a server-declared TTL, 10 at a time, saves them together, and stops plain lazy servers right away; they start again on first use. Before, only the first session discovered servers, so a server added later stayed unsearchable until it was used. A lazy or lazy-keep-alive server that fails discovery or needs sign-in is tried once per config: later sessions don't start it until its config changes or it is used. Temporary HTTP outages are retried next session.
  • Cached tool metadata no longer expires after 7 days. Servers you rarely use used to drop out of search a week after the first session. An entry now stays valid until the server's config changes or a TTL the server declared runs out, and it is refreshed the next time the server connects. A prompt command whose cached arguments are out of date no longer rejects the call: it connects, refreshes them, and checks again.
  • A tool call's timeout (requestTimeoutMs, or the MCP SDK default of 60 seconds) now restarts whenever the tool reports progress, as in Pi's built-in MCP, so a long tool that keeps reporting progress no longer times out. Tool calls always ask the server for progress, with or without a UI.
  • On Pi 0.99 and later, directTools: "search" tools are Pi deferred tools. Pi's tool_search finds them, and Pi keeps their activation on the session branch, so it survives a resume. Permission extensions see their MCP annotations, and codemode scripts get their CallToolResult. Calls still go through the adapter's approval and output limits. See search-activated direct tools.
  • Choosing direct tools is faster when many servers use includeTools or excludeTools: with 100 servers × 50 tools, about 1 second → 60 ms.
  • The README is now a short overview. The full reference moved into docs/: configuration, server options, authentication (formerly OAUTH.md), using MCP tools, scripting, prompts and MCP UI, and the extension API.

... (truncated)

Changelog

Sourced from pi-mcp-adapter's changelog.

[5.0.0] - 2026-10-01

Highlights

  • The adapter now works with Pi's own MCP setup: servers added with pi mcp add, servers other extensions register, sign-ins made with Pi's built-in MCP, and provider tokens from Pi's /login all work here.
  • Far fewer servers stay running. Servers are discovered at startup and then stopped until you use them, so with 100 servers installed and 3 in use, only those 3 run.
  • Servers you rarely use stay searchable. Cached tools no longer expire after a week.
  • pi-mcp-adapter doctor checks your servers from a shell or CI.
  • Long tools that report progress no longer time out, and a stray Enter can no longer approve a project server.

Breaking

  • On Pi 0.99 and later, the adapter replaces Pi's built-in MCP extension in sessions, except when a host supplies its own config through createMcpAdapter(): /mcp opens the adapter, and the built-in no longer connects servers. On the first start after you install or update the adapter, it also turns the built-in off in Pi's user settings ("-builtin:mcp", as pi config writes), so Pi stops warning that the built-in was not loaded. Turning it back on in pi config sticks. Shell pi mcp commands still use Pi's own files. See Pi's built-in MCP.
  • pi-mcp-adapter/config exports getPiMcpGlobalConfigPath() and getProjectPiMcpConfigPath() instead of getLegacyPiMcpGlobalConfigPath() and getLegacyProjectPiMcpConfigPath().

Added

  • On Pi 0.99 and later, the adapter also reads Pi's ~/.pi/agent/mcp.json and .pi/mcp.json, so servers added with pi mcp add work here. Each file sits right below the mcp-adapter.json in its folder. Pi settings without an exact adapter equivalent are ignored, and entries the adapter can't run, such as SSE servers, are skipped; both are reported at startup, and a loaded server's ignored settings are also listed under it in /mcp-adapter. .pi/mcp.json servers need project trust and approval, and exclusive mode reads neither file. See configuration.
  • On Pi 0.99 and later, the adapter connects servers that other extensions add with Pi's pi.registerMcpServer(), so Pi no longer reports them as unconnected. They are translated like Pi's mcp.json entries and are proxy-only: direct and deferred exposure are ignored and reported. A config entry or an earlier registerMcpServer() registration of the same name wins, and the registration is reported as overridden. Registering a name again with a different config replaces the server, and unregistering disconnects it. See the extension API.
  • On Pi 0.99 and later, sign-ins made with Pi's built-in MCP can be imported: interactive sessions ask once per OAuth server whose exact URL has a sign-in in Pi's ~/.pi/agent/mcp-auth.json and none in the adapter, and ctrl+p in /mcp-adapter imports every eligible server. If the server rotates refresh tokens, the adapter's first refresh can sign Pi's shell pi mcp commands out. See Import a sign-in from Pi's built-in MCP.
  • HTTP servers accept "auth": { "provider": "<name>" }, in adapter config and Pi's mcp.json, to send the token of a provider you signed in to with Pi's /login (Pi 0.99.2 or later). The token is read on every request and sent only to the server's origin, never through a redirect. User-global config only, and https except on loopback. Without a token the server needs /login <provider>; it never starts MCP OAuth. See Pi provider tokens.
  • pi-mcp-adapter doctor [--json] checks your MCP servers from a shell or CI: each enabled server's state, tool count, and error or hint, exiting 1 when one fails. The report prints before connections close, and a failed shutdown also exits 1. It follows project trust and never starts OAuth. See Check servers from a shell.
  • Server entries accept a description, the same key as Pi's mcp.json. mcp({ server }) shows it, mcp({ search }) ranks the server's tools by it, and the /mcp-adapter panel shows it when you expand the server, falling back to the first line of the server's instructions.

Changed

  • Startup no longer leaves every server running until the idle timeout. At each start, the adapter discovers servers whose cached tools are missing, from an older config, or past a server-declared TTL, 10 at a time, saves them together, and stops plain lazy servers right away; they start again on first use. Before, only the first session discovered servers, so a server added later stayed unsearchable until it was used. A lazy or lazy-keep-alive server that fails discovery or needs sign-in is tried once per config: later sessions don't start it until its config changes or it is used. Temporary HTTP outages are retried next session.
  • Cached tool metadata no longer expires after 7 days. Servers you rarely use used to drop out of search a week after the first session. An entry now stays valid until the server's config changes or a TTL the server declared runs out, and it is refreshed the next time the server connects. A prompt command whose cached arguments are out of date no longer rejects the call: it connects, refreshes them, and checks again.
  • A tool call's timeout (requestTimeoutMs, or the MCP SDK default of 60 seconds) now restarts whenever the tool reports progress, as in Pi's built-in MCP, so a long tool that keeps reporting progress no longer times out. Tool calls always ask the server for progress, with or without a UI.
  • On Pi 0.99 and later, directTools: "search" tools are Pi deferred tools. Pi's tool_search finds them, and Pi keeps their activation on the session branch, so it survives a resume. Permission extensions see their MCP annotations, and codemode scripts get their CallToolResult. Calls still go through the adapter's approval and output limits. See search-activated direct tools.
  • Choosing direct tools is faster when many servers use includeTools or excludeTools: with 100 servers × 50 tools, about 1 second → 60 ms.
  • The README is now a short overview. The full reference moved into docs/: configuration, server options, authentication (formerly OAUTH.md), using MCP tools, scripting, prompts and MCP UI, and the extension API.
  • The README compares the adapter with Pi's built-in MCP on what you get by switching: with 100 servers installed and 3 used, Pi 0.99.2 keeps all 100 running (7.0 GB) while the adapter runs only the 3 in use; single tool lookups cost 10–33% fewer tokens than the built-in's default codemode; and with a System One key, semantic search put the right tool first in 10 of 11 test requests, where word search did in 5. See the full comparison.

Fixed

  • Pressing Enter at the project-server approval prompt no longer approves the server. The prompt now starts on "Don't allow", so a first prompt typed while it is open can't approve a server by accident; choose "Allow" to approve it. Thanks to @​meirm for #797.
  • Idle shutdown no longer closes a server that is still in use. A tool call waiting for approval, an open MCP UI page, and an accepted browser (URL) request now keep the server running, so the approved call, a UI button, or the retry after the browser step no longer fails because the server was stopped meanwhile.
  • Ending or switching a session no longer prints MCP: runtime cleanup failed: Cannot access 'scopedMaterializedResourceSessions' before initialization, and temp files from binary MCP resources are removed again. Thanks to @​wu546526 for #781.
  • Connecting to Figma (desktop) while its server is off now says nothing is listening on 127.0.0.1:3845 instead of a bare fetch failed.
  • /mcp-adapter setup adds Figma (desktop) to the global config instead of writing .mcp.json into whatever project you opened setup from.
  • /mcp-adapter setup warns when a server you add won't be used, because another config file already defines or disables it, or the current config mode doesn't read the file it was written to.
  • A bearer token or header value that isn't a valid HTTP header value, such as one containing a newline, no longer appears in connection errors. This covers bearerToken (including Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026
@dependabot
dependabot Bot requested a review from czpython as a code owner October 5, 2026 07:37
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026
---
updated-dependencies:
- dependency-name: "@anthropic-ai/claude-code"
  dependency-version: 2.1.287
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: sandbox-harnesses
- dependency-name: "@earendil-works/pi-coding-agent"
  dependency-version: 1.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: sandbox-harnesses
- dependency-name: "@openai/codex"
  dependency-version: 0.160.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: sandbox-harnesses
- dependency-name: opencode-ai
  dependency-version: 1.18.34
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: sandbox-harnesses
- dependency-name: pi-mcp-adapter
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: sandbox-harnesses
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump the sandbox-harnesses group in /deploy/sandbox with 5 updates Bump the sandbox-harnesses group across 1 directory with 5 updates Oct 6, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/deploy/sandbox/sandbox-harnesses-e3f2de53bf branch from 0b1e754 to d48688d Compare October 6, 2026 07:38
@czpython
czpython merged commit d3936c9 into main Oct 6, 2026
7 checks passed
@czpython
czpython deleted the dependabot/npm_and_yarn/deploy/sandbox/sandbox-harnesses-e3f2de53bf branch October 6, 2026 18:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant