Skip to content

build(deps-dev): bump the development-dependencies group across 1 directory with 7 updates - #22

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/development-dependencies-682384a4e7
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/development-dependencies-682384a4e7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 23, 2026

Copy link
Copy Markdown
Contributor

Bumps the development-dependencies group with 7 updates in the / directory:

Package From To
@oh-my-pi/pi-ai 18.1.13 18.2.1
@oh-my-pi/pi-coding-agent 18.1.13 18.2.1
@oh-my-pi/pi-tui 18.1.13 18.2.1
@oh-my-pi/omptype 18.1.13 18.2.1
@types/node 22.20.1 22.20.3
typebox 1.3.25 1.3.31
vitest 4.1.11 5.0.1

Updates @oh-my-pi/pi-ai from 18.1.13 to 18.2.1

Release notes

Sourced from @​oh-my-pi/pi-ai's releases.

v18.2.1

@​oh-my-pi/pi-agent-core

Added

  • Added optional queued-message preparation with cancellation-safe delivery and appended context (#11835 by @​andrebrait).

Fixed

  • Fixed streaming CPU blowup on long turns: per-delta message_update snapshots now deep-clone only the blocks the stream actually touched instead of the entire accumulated message, eliminating the quadratic cloning work that could freeze the TUI for tens of seconds to minutes while a subagent streams (#10605).
  • Native compaction now carries an existing local summary into the first provider-native request instead of losing the summarized history. (#11525 by @​rpie9)
  • Subsequent native compactions preserve messages appended between a speculative snapshot and its commit, while honoring /clear boundaries. (#11525 by @​rpie9)
  • Native replay compatibility checks the active provider and Responses API independently of whether future native compaction is enabled. (#11525 by @​rpie9)
  • Fixed compaction retaining oversized older steps beyond the recent-history budget and skipping previously retained history on later passes, preventing long tool loops from freeing enough context (#11365).
  • Fixed Codex remote compaction retries for both Bun and proxy socket-closure messages and stopped falling back to the unsupported /responses/compact endpoint after V2 failures.

@​oh-my-pi/pi-ai

Added

  • Added support for Cerebras Qwen 3.8-27b with improved reasoning effort control
  • Added optional host browser-session callbacks for Perplexity SSO login, keeping browser automation out of pi-ai and preserving email and authenticator-code login.

Fixed

  • Fixed the auth-gateway sending a model's own reasoning back to Anthropic as demoted plain text, which tripped the reasoning_extraction classifier on Fable, leaked reasoning into visible answers on Opus, Sonnet and Haiku, and broke the prompt cache prefix on every tool-calling turn. Replayed assistant turns now carry the model id the request resolves to and a stopReason derived from the turn's own tool calls, so same-model thinking blocks keep their signatures and replay natively (#12115 by @​Zhu-Aemon).
  • Fixed custom OpenAI-compatible Responses streams crashing on omitted delta payloads or reasoning-summary fields, and recovered text delivered only in completed snapshots (#11863 by @​moodiness).
  • Fixed streaming CPU blowup on long Responses turns: per-delta content-index lookups are now O(1) instead of re-scanning the accumulated content blocks, eliminating the quadratic work that could freeze the TUI for tens of seconds to minutes while a subagent streams (#10605).
  • Fixed sessions permanently wedged by 400 Invalid signature in thinking block after a failover proxy swapped upstream models mid-conversation (e.g. Claude -> GLM -> Claude): when the unsigned-demotion retry fails identically, the anthropic-messages transport now retries once with replayed thinking dropped and pins that mode for the session, so the conversation continues without starting a new session (#12006 by @​Damin-Lee).
  • Fixed OpenAI Codex backend rejecting requests with HTTP 400 (string_above_max_length) when replaying tool call IDs exceeding 64 characters or containing composite delimiters (|, \n) by sanitizing and deterministically clamping call IDs on the wire (#11342).
  • Fixed OpenRouter multi-turn tool-call sessions failing with 400 Referenced reasoning item ... was not found or has expired on Meta Muse Spark models by suppressing reasoning reconstruction when history is filtered and synthetic replay is disallowed, while preserving Anthropic and DeepSeek replay (#10966).
  • The auth gateway now keeps provider session state per session, so a model reached through it stops re-learning the same rejection every turn. Sticky fallbacks such as strict-tools and fast mode previously did nothing on the pi-native transport used by containerized and robomp deployments, because the state cannot cross the wire and the gateway kept none of its own (#12058 by @​camjac251).
  • Fixed full OpenAI Responses request-body timeout recovery so the exact HTTP 408 is surfaced for a changed-request recovery instead of repeated unchanged transport retries when eligible tool-result history can be safely elided (#11878 by @​hellofrommorgan).
  • Fixed Codex sessions producing unrelated visible output on later turns after a progress-only response. (#11466)
  • Fixed OpenRouter reasoning models (e.g. Meta Muse Spark) rejecting every turn with 400 Provider returned error after the session history contains a tool-call turn from another provider, by no longer sending a fabricated reasoning item id (#11791 by @​brndnmtthws).
  • Fixed statusless stream-drop diagnostics (stream disconnected/closed before response.completed, upstream stream interrupted or ended before its terminal chunk, socket disconnected before the secure TLS handshake) classifying as terminal errors, so they now retry like their status-tagged twins instead of settling the turn (#11805).
  • OpenAI-compatible endpoints that report ReasoningEffort in CamelCase now trigger effort-downgrade retries instead of terminating turns with HTTP 400 (#11804).
  • Fixed openai-responses replay wedging a repaired orphan tool-result note between another call's function_call and function_call_output, which broke round pairing on strict validators (e.g. DeepSeek) with 400 No tool output found for tool call …: orphan-output/call repair now runs before the interleaved-message hoist, so any injected note is relocated out of the tool-call batch (#11473).
  • A stale Anthropic tier block (tier:fable, tier:mythos) is now cleared once a live usage report shows headroom on both the tier row and the shared windows, instead of idling a usable account until the reported reset. Healing requires a live report, and a credential held by an unscoped block spends no usage request on a probe that cannot lift it (#11334 by @​AshishKumar4).
  • A running session now picks up credentials another process committed: adding an account in a second terminal is visible to credential selection and rotation without restarting the session, and a session's pinned account is re-resolved by row id so a row another process deleted cannot hand its slot to a sibling (#11329 by @​AshishKumar4).
  • Fixed rate-limit/overload failures that arrive inside an HTTP 200 body (Azure, LiteLLM-style aggregators, and reverse proxies that already committed to the stream) not advancing retry.fallbackChains: a {"error":{…}}/{"code":429} chunk or a plain-text throttle frame (429 Too Many Requests, an nginx page) is now classified as a retryable 429/5xx through the same path an HTTP-status 429 takes, so a busy provider backs off and fails over instead of ending the session. Only bodies the provider actually reported are used: no status is inferred from error wording, and an unreadable body can no longer consume a credential.
  • Fixed tool schema normalization and cycle detection for frozen, sealed, and nonextensible schemas.
  • Reduced memory retained by complete() and completeSimple() while streaming responses.
  • Antigravity quota summaries now identify Claude/GPT routing copies as one shared upstream pool while preserving model-specific quota selection (#11268).
  • Fixed the auth-gateway rejecting content: null on /v1/responses and /v1/chat/completions message items with a 400; Codex and other OpenAI clients that emit null content on empty turns now work, matching OpenAI's tolerance (#10956).
  • Fixed Azure GPT-6 Astra Chat Completions requests with function tools sending a non-none reasoning effort, which Azure rejects with HTTP 400 (#11052).
  • Fixed Z.AI and Zhipu usage-limit credential blocks and oneshot completion retries (titles, summaries, classifiers) resolving eight hours late when provider responses omit the reset timestamp timezone (#11014).
  • Fixed provider requests failing with ENOENT when another process removes a stale shared concurrency lock during acquisition.
  • Fixed Devin-hosted Gemini models rejecting turns that include nullable tool parameters by normalizing tool schemas to Gemini's supported JSON Schema dialect (#8647, #10233 by @​will-bogusz).
  • Fixed Devin gateway failures leaking raw proxy HTML into turn errors; HTTP status and retry metadata remain available for recovery (#10233 by @​will-bogusz).

... (truncated)

Changelog

Sourced from @​oh-my-pi/pi-ai's changelog.

[18.2.1] - 2026-09-15

Added

  • Added support for Cerebras Qwen 3.8-27b with improved reasoning effort control
  • Added optional host browser-session callbacks for Perplexity SSO login, keeping browser automation out of pi-ai and preserving email and authenticator-code login.

Fixed

  • Fixed the auth-gateway sending a model's own reasoning back to Anthropic as demoted plain text, which tripped the reasoning_extraction classifier on Fable, leaked reasoning into visible answers on Opus, Sonnet and Haiku, and broke the prompt cache prefix on every tool-calling turn. Replayed assistant turns now carry the model id the request resolves to and a stopReason derived from the turn's own tool calls, so same-model thinking blocks keep their signatures and replay natively (#12115 by @​Zhu-Aemon).
  • Fixed custom OpenAI-compatible Responses streams crashing on omitted delta payloads or reasoning-summary fields, and recovered text delivered only in completed snapshots (#11863 by @​moodiness).
  • Fixed streaming CPU blowup on long Responses turns: per-delta content-index lookups are now O(1) instead of re-scanning the accumulated content blocks, eliminating the quadratic work that could freeze the TUI for tens of seconds to minutes while a subagent streams (#10605).
  • Fixed sessions permanently wedged by 400 Invalid signature in thinking block after a failover proxy swapped upstream models mid-conversation (e.g. Claude -> GLM -> Claude): when the unsigned-demotion retry fails identically, the anthropic-messages transport now retries once with replayed thinking dropped and pins that mode for the session, so the conversation continues without starting a new session (#12006 by @​Damin-Lee).
  • Fixed OpenAI Codex backend rejecting requests with HTTP 400 (string_above_max_length) when replaying tool call IDs exceeding 64 characters or containing composite delimiters (|, \n) by sanitizing and deterministically clamping call IDs on the wire (#11342).
  • Fixed OpenRouter multi-turn tool-call sessions failing with 400 Referenced reasoning item ... was not found or has expired on Meta Muse Spark models by suppressing reasoning reconstruction when history is filtered and synthetic replay is disallowed, while preserving Anthropic and DeepSeek replay (#10966).
  • The auth gateway now keeps provider session state per session, so a model reached through it stops re-learning the same rejection every turn. Sticky fallbacks such as strict-tools and fast mode previously did nothing on the pi-native transport used by containerized and robomp deployments, because the state cannot cross the wire and the gateway kept none of its own (#12058 by @​camjac251).
  • Fixed full OpenAI Responses request-body timeout recovery so the exact HTTP 408 is surfaced for a changed-request recovery instead of repeated unchanged transport retries when eligible tool-result history can be safely elided (#11878 by @​hellofrommorgan).
  • Fixed Codex sessions producing unrelated visible output on later turns after a progress-only response. (#11466)
  • Fixed OpenRouter reasoning models (e.g. Meta Muse Spark) rejecting every turn with 400 Provider returned error after the session history contains a tool-call turn from another provider, by no longer sending a fabricated reasoning item id (#11791 by @​brndnmtthws).
  • Fixed statusless stream-drop diagnostics (stream disconnected/closed before response.completed, upstream stream interrupted or ended before its terminal chunk, socket disconnected before the secure TLS handshake) classifying as terminal errors, so they now retry like their status-tagged twins instead of settling the turn (#11805).
  • OpenAI-compatible endpoints that report ReasoningEffort in CamelCase now trigger effort-downgrade retries instead of terminating turns with HTTP 400 (#11804).
  • Fixed openai-responses replay wedging a repaired orphan tool-result note between another call's function_call and function_call_output, which broke round pairing on strict validators (e.g. DeepSeek) with 400 No tool output found for tool call …: orphan-output/call repair now runs before the interleaved-message hoist, so any injected note is relocated out of the tool-call batch (#11473).
  • A stale Anthropic tier block (tier:fable, tier:mythos) is now cleared once a live usage report shows headroom on both the tier row and the shared windows, instead of idling a usable account until the reported reset. Healing requires a live report, and a credential held by an unscoped block spends no usage request on a probe that cannot lift it (#11334 by @​AshishKumar4).
  • A running session now picks up credentials another process committed: adding an account in a second terminal is visible to credential selection and rotation without restarting the session, and a session's pinned account is re-resolved by row id so a row another process deleted cannot hand its slot to a sibling (#11329 by @​AshishKumar4).
  • Fixed rate-limit/overload failures that arrive inside an HTTP 200 body (Azure, LiteLLM-style aggregators, and reverse proxies that already committed to the stream) not advancing retry.fallbackChains: a {"error":{…}}/{"code":429} chunk or a plain-text throttle frame (429 Too Many Requests, an nginx page) is now classified as a retryable 429/5xx through the same path an HTTP-status 429 takes, so a busy provider backs off and fails over instead of ending the session. Only bodies the provider actually reported are used: no status is inferred from error wording, and an unreadable body can no longer consume a credential.
  • Fixed tool schema normalization and cycle detection for frozen, sealed, and nonextensible schemas.
  • Reduced memory retained by complete() and completeSimple() while streaming responses.
  • Antigravity quota summaries now identify Claude/GPT routing copies as one shared upstream pool while preserving model-specific quota selection (#11268).
  • Fixed the auth-gateway rejecting content: null on /v1/responses and /v1/chat/completions message items with a 400; Codex and other OpenAI clients that emit null content on empty turns now work, matching OpenAI's tolerance (#10956).
  • Fixed Azure GPT-6 Astra Chat Completions requests with function tools sending a non-none reasoning effort, which Azure rejects with HTTP 400 (#11052).
  • Fixed Z.AI and Zhipu usage-limit credential blocks and oneshot completion retries (titles, summaries, classifiers) resolving eight hours late when provider responses omit the reset timestamp timezone (#11014).
  • Fixed provider requests failing with ENOENT when another process removes a stale shared concurrency lock during acquisition.
  • Fixed Devin-hosted Gemini models rejecting turns that include nullable tool parameters by normalizing tool schemas to Gemini's supported JSON Schema dialect (#8647, #10233 by @​will-bogusz).
  • Fixed Devin gateway failures leaking raw proxy HTML into turn errors; HTTP status and retry metadata remain available for recovery (#10233 by @​will-bogusz).

[18.2.0] - 2026-09-15

Added

  • Assistant turns from Anthropic-compatible hosts (direct, or via OpenRouter's reasoning_details) carry upstreamModel, the serving model id recovered from the signed thinking block, so callers can detect a router substituting a different model than requested.

Fixed

  • Fixed OpenCode Go window-limit 429s (5-hour/Weekly/Monthly usage limit reached. Resets in …) not pinning the exhausted credential to the server-stated reset; the window phrasing is now covered by a regression test over the rotation classifier. (#12091 by @​H4vC)

[18.1.22] - 2026-09-14

Fixed

  • 400-request debug dumps now redact provider-specific auth headers (x-goog-api-key, x-amz-security-token, and any header whose name carries a key/token/secret), not just a fixed allow-list, so a shared dump can no longer leak a live API key (#12007).

... (truncated)

Commits
  • 238f5b8 chore: bump version to 18.2.1
  • 2c290ad feat(ai): added disabling reasoning support for Cerebras provider
  • 73c41f4 feat: added Cerebras Qwen compatibility, prevented DashScope thinking fields
  • d915ac7 Merge PR #12064: fix: support Perplexity SSO browser login (@​lance0)
  • dfa9b27 test(ai): reconciled Muse reasoning replay expectations with the filter policy
  • 73b7dd1 docs: placed every merged changelog entry under Unreleased
  • 313161c Merge PR #11015: fix(utils): interpret Zhipu reset times as UTC+8 (@​roboomp)
  • 9cfa89c Merge PR #11056: fix(azure): disable astra reasoning with function tools (@​ro...
  • 17b4472 Merge PR #10927: fix(catalog): correct Alibaba Qwen 3.8 reasoning (@​roboomp)
  • 863513b style: formatted merged TypeScript sources with oxfmt
  • Additional commits viewable in compare view

Updates @oh-my-pi/pi-coding-agent from 18.1.13 to 18.2.1

Release notes

Sourced from @​oh-my-pi/pi-coding-agent's releases.

v18.2.1

@​oh-my-pi/pi-agent-core

Added

  • Added optional queued-message preparation with cancellation-safe delivery and appended context (#11835 by @​andrebrait).

Fixed

  • Fixed streaming CPU blowup on long turns: per-delta message_update snapshots now deep-clone only the blocks the stream actually touched instead of the entire accumulated message, eliminating the quadratic cloning work that could freeze the TUI for tens of seconds to minutes while a subagent streams (#10605).
  • Native compaction now carries an existing local summary into the first provider-native request instead of losing the summarized history. (#11525 by @​rpie9)
  • Subsequent native compactions preserve messages appended between a speculative snapshot and its commit, while honoring /clear boundaries. (#11525 by @​rpie9)
  • Native replay compatibility checks the active provider and Responses API independently of whether future native compaction is enabled. (#11525 by @​rpie9)
  • Fixed compaction retaining oversized older steps beyond the recent-history budget and skipping previously retained history on later passes, preventing long tool loops from freeing enough context (#11365).
  • Fixed Codex remote compaction retries for both Bun and proxy socket-closure messages and stopped falling back to the unsupported /responses/compact endpoint after V2 failures.

@​oh-my-pi/pi-ai

Added

  • Added support for Cerebras Qwen 3.8-27b with improved reasoning effort control
  • Added optional host browser-session callbacks for Perplexity SSO login, keeping browser automation out of pi-ai and preserving email and authenticator-code login.

Fixed

  • Fixed the auth-gateway sending a model's own reasoning back to Anthropic as demoted plain text, which tripped the reasoning_extraction classifier on Fable, leaked reasoning into visible answers on Opus, Sonnet and Haiku, and broke the prompt cache prefix on every tool-calling turn. Replayed assistant turns now carry the model id the request resolves to and a stopReason derived from the turn's own tool calls, so same-model thinking blocks keep their signatures and replay natively (#12115 by @​Zhu-Aemon).
  • Fixed custom OpenAI-compatible Responses streams crashing on omitted delta payloads or reasoning-summary fields, and recovered text delivered only in completed snapshots (#11863 by @​moodiness).
  • Fixed streaming CPU blowup on long Responses turns: per-delta content-index lookups are now O(1) instead of re-scanning the accumulated content blocks, eliminating the quadratic work that could freeze the TUI for tens of seconds to minutes while a subagent streams (#10605).
  • Fixed sessions permanently wedged by 400 Invalid signature in thinking block after a failover proxy swapped upstream models mid-conversation (e.g. Claude -> GLM -> Claude): when the unsigned-demotion retry fails identically, the anthropic-messages transport now retries once with replayed thinking dropped and pins that mode for the session, so the conversation continues without starting a new session (#12006 by @​Damin-Lee).
  • Fixed OpenAI Codex backend rejecting requests with HTTP 400 (string_above_max_length) when replaying tool call IDs exceeding 64 characters or containing composite delimiters (|, \n) by sanitizing and deterministically clamping call IDs on the wire (#11342).
  • Fixed OpenRouter multi-turn tool-call sessions failing with 400 Referenced reasoning item ... was not found or has expired on Meta Muse Spark models by suppressing reasoning reconstruction when history is filtered and synthetic replay is disallowed, while preserving Anthropic and DeepSeek replay (#10966).
  • The auth gateway now keeps provider session state per session, so a model reached through it stops re-learning the same rejection every turn. Sticky fallbacks such as strict-tools and fast mode previously did nothing on the pi-native transport used by containerized and robomp deployments, because the state cannot cross the wire and the gateway kept none of its own (#12058 by @​camjac251).
  • Fixed full OpenAI Responses request-body timeout recovery so the exact HTTP 408 is surfaced for a changed-request recovery instead of repeated unchanged transport retries when eligible tool-result history can be safely elided (#11878 by @​hellofrommorgan).
  • Fixed Codex sessions producing unrelated visible output on later turns after a progress-only response. (#11466)
  • Fixed OpenRouter reasoning models (e.g. Meta Muse Spark) rejecting every turn with 400 Provider returned error after the session history contains a tool-call turn from another provider, by no longer sending a fabricated reasoning item id (#11791 by @​brndnmtthws).
  • Fixed statusless stream-drop diagnostics (stream disconnected/closed before response.completed, upstream stream interrupted or ended before its terminal chunk, socket disconnected before the secure TLS handshake) classifying as terminal errors, so they now retry like their status-tagged twins instead of settling the turn (#11805).
  • OpenAI-compatible endpoints that report ReasoningEffort in CamelCase now trigger effort-downgrade retries instead of terminating turns with HTTP 400 (#11804).
  • Fixed openai-responses replay wedging a repaired orphan tool-result note between another call's function_call and function_call_output, which broke round pairing on strict validators (e.g. DeepSeek) with 400 No tool output found for tool call …: orphan-output/call repair now runs before the interleaved-message hoist, so any injected note is relocated out of the tool-call batch (#11473).
  • A stale Anthropic tier block (tier:fable, tier:mythos) is now cleared once a live usage report shows headroom on both the tier row and the shared windows, instead of idling a usable account until the reported reset. Healing requires a live report, and a credential held by an unscoped block spends no usage request on a probe that cannot lift it (#11334 by @​AshishKumar4).
  • A running session now picks up credentials another process committed: adding an account in a second terminal is visible to credential selection and rotation without restarting the session, and a session's pinned account is re-resolved by row id so a row another process deleted cannot hand its slot to a sibling (#11329 by @​AshishKumar4).
  • Fixed rate-limit/overload failures that arrive inside an HTTP 200 body (Azure, LiteLLM-style aggregators, and reverse proxies that already committed to the stream) not advancing retry.fallbackChains: a {"error":{…}}/{"code":429} chunk or a plain-text throttle frame (429 Too Many Requests, an nginx page) is now classified as a retryable 429/5xx through the same path an HTTP-status 429 takes, so a busy provider backs off and fails over instead of ending the session. Only bodies the provider actually reported are used: no status is inferred from error wording, and an unreadable body can no longer consume a credential.
  • Fixed tool schema normalization and cycle detection for frozen, sealed, and nonextensible schemas.
  • Reduced memory retained by complete() and completeSimple() while streaming responses.
  • Antigravity quota summaries now identify Claude/GPT routing copies as one shared upstream pool while preserving model-specific quota selection (#11268).
  • Fixed the auth-gateway rejecting content: null on /v1/responses and /v1/chat/completions message items with a 400; Codex and other OpenAI clients that emit null content on empty turns now work, matching OpenAI's tolerance (#10956).
  • Fixed Azure GPT-6 Astra Chat Completions requests with function tools sending a non-none reasoning effort, which Azure rejects with HTTP 400 (#11052).
  • Fixed Z.AI and Zhipu usage-limit credential blocks and oneshot completion retries (titles, summaries, classifiers) resolving eight hours late when provider responses omit the reset timestamp timezone (#11014).
  • Fixed provider requests failing with ENOENT when another process removes a stale shared concurrency lock during acquisition.
  • Fixed Devin-hosted Gemini models rejecting turns that include nullable tool parameters by normalizing tool schemas to Gemini's supported JSON Schema dialect (#8647, #10233 by @​will-bogusz).
  • Fixed Devin gateway failures leaking raw proxy HTML into turn errors; HTTP status and retry metadata remain available for recovery (#10233 by @​will-bogusz).

... (truncated)

Changelog

Sourced from @​oh-my-pi/pi-coding-agent's changelog.

[18.2.10] - 2026-09-22

Added

  • Added live benchmark results table with real-time model ranking and per-kind performance metrics
  • Added dedicated prefill throughput reporting for prefill-focused benchmarks
  • Added /record slash command to capture terminal sessions as replayable .ompcast files
  • Added omp play CLI for terminal-based playback of session recordings
  • Added intent descriptions to judgment batching
  • Added live progress tracking for judgment batches in the TUI

Changed

  • Refined AI-assisted git staging verification to reduce false positives
  • Updated omp bench default profile to chat and improved CLI flag documentation
  • Coalesced judgment batch drain operations for better performance under high load

[18.2.9] - 2026-09-22

Added

  • Added Claude saved resets to usage views and /usage reset, with automatic blocked-limit recovery and expiring-reset redemption controlled by claudeResets.
  • Added support for searching embedded harness documentation with find and omp find using omp:// scopes, including file-specific searches and :start-end selectors; results open directly through canonical omp:// URLs.

Changed

  • Updated server-side fallback documentation and logic to target claude-opus-5-5
  • Added support for claude-opus-5-5 to model priority registry
  • Updated the read tool guidance to decode images inline by default and require an explicit :img selector for SVG rendering.
  • Improved model discovery and fallback behavior: authentication failures are surfaced in the /models hub, and models without a matching role-specific fallback now use the default fallback chain.
  • Improved resilience for subagents by retrying provider stream failures that occur after partial output and preserving configured ordered model fallbacks at startup.
  • MCP OAuth with Google issuers now requests offline access so refresh tokens can be issued; repeated auth-broker token rotations also preserve the required refresh and client metadata.
  • MCP servers from omp-plugins now expand ${CLAUDE_PLUGIN_ROOT} and ${OMP_PLUGIN_ROOT} in commands, arguments, and working directories.
  • /review now uses the session's current working directory after /move or /wt.
  • Pasted and dragged image files now retain their original filesystem paths so the agent can act on the source files directly.
  • Custom sessions can now be moved across filesystems without losing transcripts or artifacts.
  • hub jobs now returns a compact, non-consuming status summary instead of replaying completed output or consuming pending auto-delivery.
  • The display-reset shortcut now works while the ask dialog has keyboard focus, and tab.press() provides a clear error for the legacy argument order.
  • Wayland keyboard input now follows the compositor's active XKB layout instead of assuming a US layout.
  • LSP diagnostics now refresh when watched files are created or deleted and after a server reload.
  • Compiled bytecode binaries now start correctly when bundled dependencies use import.meta.resolve.

Fixed

  • Fixed JavaScript eval assignments in cells containing top-level await so they persist into subsequent cells.
  • Fixed skill hints becoming out of sync with the active prompt after discarded rebuilds and in advisor sessions.
  • Restored pi.pi.askToolRenderer for extensions that replace the built-in ask tool, preserving native rendering.
  • Fixed npm plugin upgrades and reinstalls leaving stale or duplicate manifest entries that could break bun install.
  • Fixed eval waits longer than approximately 24.8 days returning immediately because of native timer overflow.
  • Fixed deleted sessions being resurrected from stale rewrite backups.

... (truncated)

Commits
  • acf943d test: fixed linux-only ci failures in status-line and ptree tests
  • 1e57a90 fix(coding-agent): repaired test regressions surfaced by the release run
  • 217d4cb style(coding-agent): fix oxfmt import wrapping in selector-controller
  • d0ecc11 feat(coding-agent): add tui.titleSpinner terminal title spinner styles
  • 238f5b8 chore: bump version to 18.2.1
  • 73c41f4 feat: added Cerebras Qwen compatibility, prevented DashScope thinking fields
  • 48b07e0 fix(advisor): dropped the quarantine latch and cut the advise acks to one line
  • 42d74e1 feat(coding-agent): renamed /drop slash command to /delete
  • b6f1a66 Merge PR #9770: feat(web-search): support explicitly selected keyless Paralle...
  • c5a8e0e Merge pull request #12154 from korri123/fix/preserve-late-terminal-advisor-nits
  • Additional commits viewable in compare view

Updates @oh-my-pi/pi-tui from 18.1.13 to 18.2.1

Release notes

Sourced from @​oh-my-pi/pi-tui's releases.

v18.2.1

@​oh-my-pi/pi-agent-core

Added

  • Added optional queued-message preparation with cancellation-safe delivery and appended context (#11835 by @​andrebrait).

Fixed

  • Fixed streaming CPU blowup on long turns: per-delta message_update snapshots now deep-clone only the blocks the stream actually touched instead of the entire accumulated message, eliminating the quadratic cloning work that could freeze the TUI for tens of seconds to minutes while a subagent streams (#10605).
  • Native compaction now carries an existing local summary into the first provider-native request instead of losing the summarized history. (#11525 by @​rpie9)
  • Subsequent native compactions preserve messages appended between a speculative snapshot and its commit, while honoring /clear boundaries. (#11525 by @​rpie9)
  • Native replay compatibility checks the active provider and Responses API independently of whether future native compaction is enabled. (#11525 by @​rpie9)
  • Fixed compaction retaining oversized older steps beyond the recent-history budget and skipping previously retained history on later passes, preventing long tool loops from freeing enough context (#11365).
  • Fixed Codex remote compaction retries for both Bun and proxy socket-closure messages and stopped falling back to the unsupported /responses/compact endpoint after V2 failures.

@​oh-my-pi/pi-ai

Added

  • Added support for Cerebras Qwen 3.8-27b with improved reasoning effort control
  • Added optional host browser-session callbacks for Perplexity SSO login, keeping browser automation out of pi-ai and preserving email and authenticator-code login.

Fixed

  • Fixed the auth-gateway sending a model's own reasoning back to Anthropic as demoted plain text, which tripped the reasoning_extraction classifier on Fable, leaked reasoning into visible answers on Opus, Sonnet and Haiku, and broke the prompt cache prefix on every tool-calling turn. Replayed assistant turns now carry the model id the request resolves to and a stopReason derived from the turn's own tool calls, so same-model thinking blocks keep their signatures and replay natively (#12115 by @​Zhu-Aemon).
  • Fixed custom OpenAI-compatible Responses streams crashing on omitted delta payloads or reasoning-summary fields, and recovered text delivered only in completed snapshots (#11863 by @​moodiness).
  • Fixed streaming CPU blowup on long Responses turns: per-delta content-index lookups are now O(1) instead of re-scanning the accumulated content blocks, eliminating the quadratic work that could freeze the TUI for tens of seconds to minutes while a subagent streams (#10605).
  • Fixed sessions permanently wedged by 400 Invalid signature in thinking block after a failover proxy swapped upstream models mid-conversation (e.g. Claude -> GLM -> Claude): when the unsigned-demotion retry fails identically, the anthropic-messages transport now retries once with replayed thinking dropped and pins that mode for the session, so the conversation continues without starting a new session (#12006 by @​Damin-Lee).
  • Fixed OpenAI Codex backend rejecting requests with HTTP 400 (string_above_max_length) when replaying tool call IDs exceeding 64 characters or containing composite delimiters (|, \n) by sanitizing and deterministically clamping call IDs on the wire (#11342).
  • Fixed OpenRouter multi-turn tool-call sessions failing with 400 Referenced reasoning item ... was not found or has expired on Meta Muse Spark models by suppressing reasoning reconstruction when history is filtered and synthetic replay is disallowed, while preserving Anthropic and DeepSeek replay (#10966).
  • The auth gateway now keeps provider session state per session, so a model reached through it stops re-learning the same rejection every turn. Sticky fallbacks such as strict-tools and fast mode previously did nothing on the pi-native transport used by containerized and robomp deployments, because the state cannot cross the wire and the gateway kept none of its own (#12058 by @​camjac251).
  • Fixed full OpenAI Responses request-body timeout recovery so the exact HTTP 408 is surfaced for a changed-request recovery instead of repeated unchanged transport retries when eligible tool-result history can be safely elided (#11878 by @​hellofrommorgan).
  • Fixed Codex sessions producing unrelated visible output on later turns after a progress-only response. (#11466)
  • Fixed OpenRouter reasoning models (e.g. Meta Muse Spark) rejecting every turn with 400 Provider returned error after the session history contains a tool-call turn from another provider, by no longer sending a fabricated reasoning item id (#11791 by @​brndnmtthws).
  • Fixed statusless stream-drop diagnostics (stream disconnected/closed before response.completed, upstream stream interrupted or ended before its terminal chunk, socket disconnected before the secure TLS handshake) classifying as terminal errors, so they now retry like their status-tagged twins instead of settling the turn (#11805).
  • OpenAI-compatible endpoints that report ReasoningEffort in CamelCase now trigger effort-downgrade retries instead of terminating turns with HTTP 400 (#11804).
  • Fixed openai-responses replay wedging a repaired orphan tool-result note between another call's function_call and function_call_output, which broke round pairing on strict validators (e.g. DeepSeek) with 400 No tool output found for tool call …: orphan-output/call repair now runs before the interleaved-message hoist, so any injected note is relocated out of the tool-call batch (#11473).
  • A stale Anthropic tier block (tier:fable, tier:mythos) is now cleared once a live usage report shows headroom on both the tier row and the shared windows, instead of idling a usable account until the reported reset. Healing requires a live report, and a credential held by an unscoped block spends no usage request on a probe that cannot lift it (#11334 by @​AshishKumar4).
  • A running session now picks up credentials another process committed: adding an account in a second terminal is visible to credential selection and rotation without restarting the session, and a session's pinned account is re-resolved by row id so a row another process deleted cannot hand its slot to a sibling (#11329 by @​AshishKumar4).
  • Fixed rate-limit/overload failures that arrive inside an HTTP 200 body (Azure, LiteLLM-style aggregators, and reverse proxies that already committed to the stream) not advancing retry.fallbackChains: a {"error":{…}}/{"code":429} chunk or a plain-text throttle frame (429 Too Many Requests, an nginx page) is now classified as a retryable 429/5xx through the same path an HTTP-status 429 takes, so a busy provider backs off and fails over instead of ending the session. Only bodies the provider actually reported are used: no status is inferred from error wording, and an unreadable body can no longer consume a credential.
  • Fixed tool schema normalization and cycle detection for frozen, sealed, and nonextensible schemas.
  • Reduced memory retained by complete() and completeSimple() while streaming responses.
  • Antigravity quota summaries now identify Claude/GPT routing copies as one shared upstream pool while preserving model-specific quota selection (#11268).
  • Fixed the auth-gateway rejecting content: null on /v1/responses and /v1/chat/completions message items with a 400; Codex and other OpenAI clients that emit null content on empty turns now work, matching OpenAI's tolerance (#10956).
  • Fixed Azure GPT-6 Astra Chat Completions requests with function tools sending a non-none reasoning effort, which Azure rejects with HTTP 400 (#11052).
  • Fixed Z.AI and Zhipu usage-limit credential blocks and oneshot completion retries (titles, summaries, classifiers) resolving eight hours late when provider responses omit the reset timestamp timezone (#11014).
  • Fixed provider requests failing with ENOENT when another process removes a stale shared concurrency lock during acquisition.
  • Fixed Devin-hosted Gemini models rejecting turns that include nullable tool parameters by normalizing tool schemas to Gemini's supported JSON Schema dialect (#8647, #10233 by @​will-bogusz).
  • Fixed Devin gateway failures leaking raw proxy HTML into turn errors; HTTP status and retry metadata remain available for recovery (#10233 by @​will-bogusz).

... (truncated)

Changelog

Sourced from @​oh-my-pi/pi-tui's changelog.

[18.2.10] - 2026-09-22

Changed

  • Added support for multiple concurrent TUI paint listeners to enable simultaneous session recording and streaming
  • Coalesced status event updates for progress-based operations to reduce TUI render overhead

[18.2.9] - 2026-09-22

Added

  • Added Claude and Codex saved-reset counts, availability, and expiry to usage views, with provider-specific confirmation and uniquely identified account options.
  • Added terminal detection and capability support for otty and rio, including Kitty graphics and true-color support where available, plus otty hyperlinks and notifications.
  • Added the public stripTerminalSequences export for extensions that need to remove terminal control sequences.

Fixed

  • Composer shape previews now use the full available overlay width instead of being clipped at 96 columns.
  • Fixed cursor placement when recalling prompts from history, keeping single-line entries at the end and preserving the appropriate position for multi-line entries.
  • Restored modified-key handling and terminal notifications over SSH sessions running inside tmux.
  • Fixed typed Enter occasionally being interpreted as a literal newline when terminal input events are batched.

[18.2.8] - 2026-09-21

Changed

  • Improved Bash tool background-task notices by providing completed output as a follow-up and discouraging unnecessary polling.

[18.2.7] - 2026-09-21

Breaking Changes

  • Removed specialized keyword modules in favor of a centralized registration system

Added

  • Added find tool renderer to display search results with hit ranking and score visualization
  • Supported collapsing/expanding search hit details and range snippets
  • Enabled file hyperlinking for navigation to absolute paths in search results
  • Added streaming progress display for incomplete find tool operations
  • Added Glyph Protocol support for rendering icons without requiring patched fonts
  • Added setMagicKeywords for dynamic configuration of highlightable magic keywords

Fixed

  • Prevented magic keywords from triggering spelling autocorrect and underlining

[18.2.5] - 2026-09-17

Added

... (truncated)

Commits
  • 238f5b8 chore: bump version to 18.2.1
  • 73b7dd1 docs: placed every merged changelog entry under Unreleased
  • 35a1441 Merge PR #11013: fix(tui): detect wmux multiplexer so the transcript renders ...
  • 2c0b9c3 Merge PR #11061: fix(tui): refresh argument completions after spaces (@​roboomp)
  • a151e94 Merge PR #11112: fix(tui): guard synchronized output terminal identity (@​robo...
  • c7c6109 Merge PR #11242: fix(tui): evict retired Kitty images from terminal memory (@...
  • f159be2 Merge PR #11246: fix(coding-agent): make Ctrl+D delete draft text before exit...
  • 9cdb944 test(tui): model pending wrap across row advances
  • b45fd07 Merge PR #11948: fix(tui): prevent conpty status-line scroll leaks (@​roboomp)
  • 626e768 Merge PR #12000: fix(tui): match skill prefixes at hyphen boundaries (@​domeni...
  • Additional commits viewable in compare view

Updates @oh-my-pi/omptype from 18.1.13 to 18.2.1

Release notes

Sourced from @​oh-my-pi/omptype's releases.

v18.2.1

@​oh-my-pi/pi-agent-core

Added

  • Added optional queued-message preparation with cancellation-safe delivery and appended context (#11835 by @​andrebrait).

Fixed

  • Fixed streaming CPU blowup on long turns: per-delta message_update snapshots now deep-clone only the blocks the stream actually touched instead of the entire accumulated message, eliminating the quadratic cloning work that could freeze the TUI for tens of seconds to minutes while a subagent streams (#10605).
  • Native compaction now carries an existing local summary into the first provider-native request instead of losing the summarized history. (#11525 by @​rpie9)
  • Subsequent native compactions preserve messages appended between a speculative snapshot and its commit, while honoring /clear boundaries. (#11525 by

…ectory with 7 updates

Bumps the development-dependencies group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@oh-my-pi/pi-ai](https://github.com/can1357/oh-my-pi/tree/HEAD/packages/ai) | `18.1.13` | `18.2.1` |
| [@oh-my-pi/pi-coding-agent](https://github.com/can1357/oh-my-pi/tree/HEAD/packages/coding-agent) | `18.1.13` | `18.2.1` |
| [@oh-my-pi/pi-tui](https://github.com/can1357/oh-my-pi/tree/HEAD/packages/tui) | `18.1.13` | `18.2.1` |
| [@oh-my-pi/omptype](https://github.com/can1357/oh-my-pi/tree/HEAD/packages/omptype) | `18.1.13` | `18.2.1` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `22.20.1` | `22.20.3` |
| [typebox](https://github.com/sinclairzx81/typebox) | `1.3.25` | `1.3.31` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.11` | `5.0.1` |



Updates `@oh-my-pi/pi-ai` from 18.1.13 to 18.2.1
- [Release notes](https://github.com/can1357/oh-my-pi/releases)
- [Changelog](https://github.com/can1357/oh-my-pi/blob/main/packages/ai/CHANGELOG.md)
- [Commits](https://github.com/can1357/oh-my-pi/commits/v18.2.1/packages/ai)

Updates `@oh-my-pi/pi-coding-agent` from 18.1.13 to 18.2.1
- [Release notes](https://github.com/can1357/oh-my-pi/releases)
- [Changelog](https://github.com/can1357/oh-my-pi/blob/main/packages/coding-agent/CHANGELOG.md)
- [Commits](https://github.com/can1357/oh-my-pi/commits/v18.2.1/packages/coding-agent)

Updates `@oh-my-pi/pi-tui` from 18.1.13 to 18.2.1
- [Release notes](https://github.com/can1357/oh-my-pi/releases)
- [Changelog](https://github.com/can1357/oh-my-pi/blob/main/packages/tui/CHANGELOG.md)
- [Commits](https://github.com/can1357/oh-my-pi/commits/v18.2.1/packages/tui)

Updates `@oh-my-pi/omptype` from 18.1.13 to 18.2.1
- [Release notes](https://github.com/can1357/oh-my-pi/releases)
- [Changelog](https://github.com/can1357/oh-my-pi/blob/main/packages/omptype/CHANGELOG.md)
- [Commits](https://github.com/can1357/oh-my-pi/commits/v18.2.1/packages/omptype)

Updates `@types/node` from 22.20.1 to 22.20.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `typebox` from 1.3.25 to 1.3.31
- [Commits](sinclairzx81/typebox@1.3.25...1.3.31)

Updates `vitest` from 4.1.11 to 5.0.1
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/vitest)

---
updated-dependencies:
- dependency-name: "@oh-my-pi/pi-ai"
  dependency-version: 18.2.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: "@oh-my-pi/pi-coding-agent"
  dependency-version: 18.2.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: "@oh-my-pi/pi-tui"
  dependency-version: 18.2.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: "@oh-my-pi/omptype"
  dependency-version: 18.2.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: "@types/node"
  dependency-version: 22.20.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: typebox
  dependency-version: 1.3.31
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: vitest
  dependency-version: 5.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: development-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 23, 2026
@dependabot
dependabot Bot requested a review from alpertarhan as a code owner September 23, 2026 03:05
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants