chore(deps): update bump-dependencies#56
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.1.208→2.1.2150.80.6→0.80.100.50.0→0.51.00.144.5→0.144.6v1.71.0→v1.72.01.17.20→1.18.3Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
anthropics/claude-code (@anthropic-ai/claude-code)
v2.1.215Compare Source
/verifyand/code-reviewskills on its own; invoke them with/verifyor/code-reviewwhen you want themv2.1.214dir/**allow rules likeEdit(src/**)auto-approving writes to nesteddir/directories anywhere in the tree instead of only<cwd>/dir[[ ]]comparisons as inert text — these commands now prompt for approvalhelpandmancommands that could run unsafe options, command substitutions, or backslash pathsmodifiedtimestamp to memory file frontmattermessage.uuid,client_request_id, andtool_sourceattributes to OpenTelemetry log events for message-level correlation and tool provenanceCLAUDE_CODE_OTEL_CONTENT_MAX_LENGTHto configure the 60 KB truncation limit on OpenTelemetry content attributessubagentStatusLinepayload, so custom agent rows can render model and effortdockercommands (including the Podmandockershim) carrying daemon-redirect flags (--url,--connection,--identity, and Podman's remote mode) that previously ran without onepkill -fpattern accidentally matched the CLI's own process (Linux)--settingspoints at a device file or multi-GB file; oversized (>2 MiB) settings files now fail at startup with a clear errorwhere.exe,fc.exe, anddiff.exeas errors when they return a valid negative answer (Windows)>and>>under the PowerShell tool on Windows PowerShell 5.1 writing UTF-16LE files that other tools couldn't read as UTF-8←or/backgroundand left idle keeping the background daemon and a worker process alive indefinitelyclaude rmor the agent view once the background service had gone idle/install-github-appand the/mcpsettings menu being blocked in agent-view sessions — they're now refused only in background sessions with no terminal attached--settingsCLI flag not loading (regression since v2.1.181)/ultrareviewrefusing to run in repos with no merge base — it now offers to review all tracked filesclaude updateandclaude doctorhanging silently, and the/statusSystem diagnostics section going blank, when a shell-config path is a directory#when memory files are savedmessage_deltaframesclaude rcworkspace-trust error in the home directory to say trust there is never saved and to suggest running from a project directorydir/**hookif:conditions to match only<cwd>/dir; write**/dir/**for any-depth matching.deny/askpermission rules keep their any-depth match.filecommands using-m/--magic-fileor-f/--files-fromto require permission instead of being auto-allowed as read-only"fork"when a session begins as a fork instead of"resume"v2.1.212Compare Source
/forknow copies your conversation into a new background session (its own row inclaude agents) while you keep working; the in-session subagent it used to launch is now/subtaskclaude auto-mode resetto restore the default auto-mode configuration, with a confirmation prompt (pass--yesto skip)CLAUDE_CODE_MAX_WEB_SEARCHES_PER_SESSION) to stop runaway search loopsCLAUDE_CODE_MAX_SUBAGENTS_PER_SESSION) to stop runaway delegation loops;/clearresets the budgetCLAUDE_CODE_MCP_AUTO_BACKGROUND_MS/resumein the agent view now opens a picker of past sessions — including sessions deleted from the list — and resumes your pick as a background sessiontouch,rm) without a permission prompt or SDKcanUseToolcallback.claude/worktrees, which could create files outside the repositorycontinue:falsehook's halt being dropped when the tool fails or completes mid-stream, and hook infrastructure errors being misreported as user rejections/backgroundandclaude --bgfailing with "EUNKNOWN: unknown error, uv_spawn" on Windows when Group Policy blocks PowerShell 5.1; the daemon now prefers PowerShell 7!) not executing commands containing file paths while the path autocomplete popup was open?help overlay/ultrareviewrejecting PR references like#123,PR 123, and pasted PR URLs; error hints now name the command you actually typed/ultrareview <branch>not fetching the branch from origin when it exists remotely; it now suggests the closest branch name on typos/ultrareviewskipping the billing confirmation in a new conversation after/clear/ultrareview's "not a git repository" error on Claude Desktop now suggesting the project's repository folder instead of terminal commandsExitWorktreefailing with "no active EnterWorktree session" after resuming a session with--continue/--resumein print/SDK mode/forklosing their live-parent protection after a state write failuretrace_id/span_idwhenTRACEPARENTis set in SDK/headless modeSendMessagebodies are no longer duplicated into replayed history and tool results/forkto name the copy after your prompt when the session has no title, so the row is recognizable in the agent view/btwto reopen the side-question panel on your most recent exchange so you can browse earlier answers←footer hint to pulseN donefor a moment when a background agent finishes while nothing needs your inputmodeparameter (now ignored); subagents inherit the parent session's permission mode by defaultforceLoginMethodto be enforced for VS Code extension, SDK,setup-token, andinstall-github-applogins, not just the terminalset_modelcontrol request mid-turn; the next model round-trip uses the new model instead of waiting for the next turnclaude agents --json: sessions waiting on a sandbox, MCP-input, or managed-settings prompt now show as "Needs input" instead of "Working"v2.1.211Compare Source
--forward-subagent-textflag andCLAUDE_CODE_FORWARD_SUBAGENT_TEXTenvironment variable to include subagent text and thinking in stream-json outputaskdecision for unsandboxed Bash — a hookasknow floors the decision at a prompt.claude/rules/*.mdfiles loading even when setting sources exclude project settings.prn) or trailing dot are now accepted, and files with multiple hard links are refused/loophiding the session from/resumeafter a single use/terminal-setupor onboarding terminal setupANTHROPIC_AUTH_TOKEN+ANTHROPIC_BASE_URL) coming back "Not logged in" after the daemon respawns themclaude agentsjobs becoming permanently undeletable when git no longer recognizes their worktree — the row now shows why the delete was refused instead of silently reappearing/clearnot resetting the session cost counter — the statusline's cost now starts at $0 after/clear/clear1e6and64_000/usage-creditsto ask for confirmation before sending a request to organization adminssandS(substitute char/line) to work in NORMAL mode, matching vim behaviorsave_to_diskon screenshot actions now writes the image to disk and returns the path; previously it did nothingv2.1.210Compare Source
Write(path),NotebookEdit(path), andGlob(path)permission rules — useEdit(path)orRead(path)insteadisolation: 'worktree'subagents being able to run git-mutating commands against the main repo checkout instead of their own isolated worktreeultracodekeyword opt-in firing on non-human-originated input such as webhook payloads and relayed PR commentsclaude attachsometimes failing with "job not found" or "agent is still starting" errors during session transitions — attach now waits for the daemon to settle, and terminal resizes during a slow attach are applied once it completescdtook effect after its command was moved to the background; the tool result now states the working directory is unchanged/doctorskipping its auto-mode-default proposal on Bedrock, Vertex, and Foundry, where auto mode no longer needs an opt-in$1/$2positional placeholders in skills and commands being silently stripped; they are now preserved verbatimclaude agents --effort ultracodenot reaching dispatched sessions; the value was silently droppedgit worktree lockbehind; the periodic sweep now releases locks whose owning process is goneinitializecontrol request waiting until the next turn to start connectingCLAUDE_CODE_DISABLE_ALTERNATE_SCREEN=1.claude/*symlinks not being reconciled into the sandbox deny-write listv2.1.209Compare Source
claude agentsbackground sessions (reverts an overly broad guard)earendil-works/pi (@earendil-works/pi-coding-agent)
v0.80.10Compare Source
New Features
maxlevel and supports replaying empty-signature thinking blocks. See Kimi For Coding setup and Model Options.Fixed
kimi-for-coding.maxlevel (#6737).v0.80.9Compare Source
New Features
kimi-deferred-tools.tsexample.Added
kimi-deferred-tools.tsexample.Changed
Fixed
Removed
v0.80.8Compare Source
New Features
ModelRuntimecentralizes model configuration, provider-owned/login, and dynamic provider catalogs. See Providers./modelrefreshes configured providers in the background, andpi update --modelsforces an immediate refresh. See Install and Manage.Breaking Changes
CreateAgentSessionOptions.authStorageandmodelRegistryoptions with the asyncmodelRuntimeoption.AuthStorageand its storage backends are no longer exported; useModelRuntime(or a custom pi-aiCredentialStore), orreadStoredCredential()for one-off reads of auth.json.ModelRuntime.getAll(),find(),getSnapshot(), andgetAuthOptions()projections. Use the pi-aiModelsmethodsgetModels(),getModel(),getProviders(), andcheckAuth()directly.ModelRegistry.getApiKeyAndHeaders()withModelRuntime.getAuth(). Passing a provider ID returns provider-scoped auth; passing a model also resolves built-in,models.json, and extension model headers.ModelRegistry.refresh()from synchronousvoidtoPromise<void>becausemodels.jsonloading is asynchronous. Extensions must await it before making synchronous registry reads.ModelRuntime.refresh()/pi-aiModels.refresh(). Legacy extension OAuthmodifyModelsremains supported as a synchronous compatibility projection after credential initialization.Added
ModelRuntimeas the canonical async SDK and internal model/auth facade while preserving the synchronous extension-facingModelRegistryAPI.ModelRuntime.create()accepts any pi-aiCredentialStorethrough itscredentialsoption./logindiscovery directly from registered pi-ai providers, including ambient auth status and informational links.models-store.json, per-provider pi.dev catalog overlays, and Radius gateway support including offline migration from legacy credential-cached catalogs.refreshModels(context)support for dynamic model discovery with optional provider-controlled persistence.pi update --modelsto force an immediate model catalog refresh without updating pi or extensions.Changed
ModelRuntimeto compose built-in providers, immutablemodels.jsonconfiguration, and extension overlays through ad-hoc pi-ai provider methods.ModelRuntimeto own final request assembly:getAuth(model)includes configured model headers, stream methods resolve auth once, andbefore_provider_headersruns as the Models-only header transform before provider dispatch./modelto render the current model snapshot immediately, refresh configured providers in the background, and update the open selector with partial results or timeout errors.Fixed
/model.v0.80.7Compare Source
Breaking Changes
openai-responsescompat.sendSessionIdHeaderflag frommodels.json. Session-affinity behavior is now controlled bycompat.sessionAffinityFormat("openai","openai-nosession", or"openrouter"). ReplacesendSessionIdHeader: falsewithsessionAffinityFormat: "openai-nosession"(#6496 by @petrroll).New Features
Ctrl+Xcopies the last assistant message in the transcript or the selected message in/tree, making older and branched messages directly copyable. See Display and Message Queue.xhighandmaxthinking - Nativexhighandmaxthinking levels are available across generated provider catalogs. See Model Options.Added
xhighandmaxthinking levels for Claude Fable 5 across all generated provider catalogs (#6490 by @davidbrai).Ctrl+Xto copy the last assistant message, or the selected message in/tree.toolChoicesupport for OpenAI and Codex Responses, including required and named tool selection (#6588 by @xl0).Fixed
x-session-idheader instead of OpenAI-specific session-affinity fields (#6496 by @petrroll).Ctrl+Vto paste clipboard text when the pasteboard does not contain an image./login amazon-bedrockto prompt for and save a Bedrock API key instead of only displaying ambient AWS credential setup instructions.Alt+,andAlt+.(#6523 by @ribelo).mai-code-1-flash-pickermodel to route through the/responsesendpoint (#6544 by @petrroll).An unknown error occurred(#6598 by @davidbrai).encrypted_contentappears only in the terminal response event (#6608 by @davidbrai).usagefrommessage_deltaevents (#6611 by @davidbrai).session-idheader while preserving other cache-affinity data (#6645 by @davidbrai).google-gemini/gemini-cli (@google/gemini-cli)
v0.51.0Compare Source
What's Changed
Full Changelog: google-gemini/gemini-cli@v0.50.0...v0.51.0
v0.51.0-preview.0What's Changed
New Contributors
Full Changelog: google-gemini/gemini-cli@v0.50.0-preview.1...v0.51.0-preview.0
v0.51.0-nightly.20260707.g15a9429b6Compare Source
What's Changed
Full Changelog: google-gemini/gemini-cli@v0.51.0-nightly.20260706.gf7af4e518...v0.51.0-nightly.20260707.g15a9429b6
v0.51.0-nightly.20260706.gf7af4e518Compare Source
Full Changelog: google-gemini/gemini-cli@v0.51.0-nightly.20260705.gf7af4e518...v0.51.0-nightly.20260706.gf7af4e518
v0.51.0-nightly.20260705.gf7af4e518Compare Source
Full Changelog: google-gemini/gemini-cli@v0.51.0-nightly.20260704.gf7af4e518...v0.51.0-nightly.20260705.gf7af4e518
v0.51.0-nightly.20260704.gf7af4e518Compare Source
Full Changelog: google-gemini/gemini-cli@v0.51.0-nightly.20260703.gf7af4e518...v0.51.0-nightly.20260704.gf7af4e518
v0.51.0-nightly.20260703.gf7af4e518Compare Source
What's Changed
Full Changelog: google-gemini/gemini-cli@v0.51.0-nightly.20260702.gff00dacd9...v0.51.0-nightly.20260703.gf7af4e518
v0.51.0-nightly.20260702.gff00dacd9Compare Source
What's Changed
Full Changelog: google-gemini/gemini-cli@v0.51.0-nightly.20260701.g7f00c5fe5...v0.51.0-nightly.20260702.gff00dacd9
v0.51.0-nightly.20260701.g7f00c5fe5Compare Source
What's Changed
New Contributors
Full Changelog: google-gemini/gemini-cli@v0.51.0-nightly.20260630.gae0a3aa7b...v0.51.0-nightly.20260701.g7f00c5fe5
v0.51.0-nightly.20260630.gae0a3aa7bCompare Source
Full Changelog: google-gemini/gemini-cli@v0.51.0-nightly.20260629.gae0a3aa7b...v0.51.0-nightly.20260630.gae0a3aa7b
v0.51.0-nightly.20260629.gae0a3aa7bCompare Source
Full Changelog: google-gemini/gemini-cli@v0.51.0-nightly.20260628.gae0a3aa7b...v0.51.0-nightly.20260629.gae0a3aa7b
v0.51.0-nightly.20260628.gae0a3aa7bCompare Source
What's Changed
Full Changelog: google-gemini/gemini-cli@v0.51.0-nightly.20260626.gb14416447...v0.51.0-nightly.20260628.gae0a3aa7b
v0.51.0-nightly.20260626.gb14416447Compare Source
What's Changed
New Contributors
Full Changelog: google-gemini/gemini-cli@v0.49.0-nightly.20260625.gd845bc5d4...v0.51.0-nightly.20260626.gb14416447
bufbuild/buf (github.com/bufbuild/buf)
v1.72.0Compare Source
buf beta registry webhook createandbuf beta registry webhook listto emit proto JSON output.BUF_INPUT_HTTPS_USERNAMEfor the username.IMPORT_USEDlint rule silently reporting no unused imports whengoogle/protobuf/descriptor.protois in the transitive dependency graph.Configuration
📅 Schedule: (UTC)
* * * * 3)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.