Skip to content

Bump the sandbox-harnesses group across 1 directory with 2 updates - #847

Merged
czpython merged 1 commit into
mainfrom
dependabot/npm_and_yarn/deploy/sandbox/sandbox-harnesses-5b4e9d9462
Oct 8, 2026
Merged

czpython merged 1 commit into
mainfrom
dependabot/npm_and_yarn/deploy/sandbox/sandbox-harnesses-5b4e9d9462

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the sandbox-harnesses group with 2 updates in the /deploy/sandbox directory: @anthropic-ai/claude-code and @earendil-works/pi-coding-agent.

Updates @anthropic-ai/claude-code from 2.1.288 to 2.1.289

Release notes

Sourced from @​anthropic-ai/claude-code's releases.

v2.1.289

What's changed

  • Fixed a deny or ask rule on a nested part of a compound shell command not holding over a user-installed mod's approval on managed machines
  • Fixed the terminal freezing on short code blocks with many unclosed <script> tags or deeply nested ${ substitutions
  • Fixed Read deny rules not applying to files @-mentioned, changed, or selected in the IDE through a symlink
  • [VSCode] Reverted a 2.1.288 change to claude auth status that may have made sign-outs more frequent
  • Improved how quickly large files open in a plugin code pane by laying the highlighted view out once at its final width
  • Fixed plugin list, plugin eval and plugin update showing a stale copy of a plugin installed from a local folder marketplace, and hot reload for a symlinked --plugin-dir
  • Fixed installed mods not loading in the first session after an upgrade
  • Fixed a plugin's rows above the prompt showing a stale row while the Background tasks dialog was open in fullscreen
  • Fixed plugin panes drawing nothing when a link used a localhost address, an @ in its path, an uppercase host or a file: path
  • Fixed a user-installed plugin being able to rewrite the descriptions of an organization-managed MCP server's sign-in tools
  • Fixed a freeze or forced quit at launch when a plugin drew a Box with a border style the terminal does not know
  • Fixed supervised and background sessions ending when a plugin's on-screen handler threw asynchronously
  • Fixed sessions ending with an interface error when a plugin region with no height kept growing
  • Fixed Bash deny and ask rules missing a command behind an environment variable prefix with an expanded value (e.g. TZ="$HOME" rm -rf build) when the sandbox auto-allows commands
  • Fixed a Bash deny or ask rule being skipped under sandbox auto-allow when a bare variable assignment came before the command
  • Fixed claude plugin validate skipping the plugin when the folder also holds a marketplace manifest
  • Added agent.spawn for teammates, one agent id across plugin hook events, and idle and waiting states in $.agent.list()
  • Fixed sessions ending with "unrecoverable interface error" when a value a mod's ui.render hook wrote made a row throw while drawn; the engine now draws its own row instead
  • Fixed text with a tab, a stray escape and a C1 control, or a short text with a tab and CRLF line endings, drawing over the rows below it
  • Fixed right-aligned content in a mod's pane or band drawing under the close mark or [-], which now also keep one column in from the terminal's edge
  • Fixed a mod's Client that fails while drawn taking down everything the mod drew around it; it now fails alone and raises ui.fault
  • Fixed claude plugin validate failing an Anthropic marketplace's own plugin and listing a clean plugin.json in --json
  • Fixed a mod's band that fails to draw briefly telling the cards under it to step aside
  • Fixed a failed plugin component showing Error or nothing as its reason when the failure carried no message
  • Improved the line a mod's author sees when its band or pane fails to draw: it names the mod and says nothing was drawn
  • Fixed published artifact pages freezing or crashing the reader's browser tab on short code blocks with many unclosed <script> tags
  • Fixed a mod's Client region staying failed for the whole session after the terminal threw while drawing it
Changelog

Sourced from @​anthropic-ai/claude-code's changelog.

2.1.289

  • Fixed a deny or ask rule on a nested part of a compound shell command not holding over a user-installed mod's approval on managed machines
  • Fixed the terminal freezing on short code blocks with many unclosed <script> tags or deeply nested ${ substitutions
  • Fixed Read deny rules not applying to files @-mentioned, changed, or selected in the IDE through a symlink
  • [VSCode] Reverted a 2.1.288 change to claude auth status that may have made sign-outs more frequent
  • Improved how quickly large files open in a plugin code pane by laying the highlighted view out once at its final width
  • Fixed plugin list, plugin eval and plugin update showing a stale copy of a plugin installed from a local folder marketplace, and hot reload for a symlinked --plugin-dir
  • Fixed installed mods not loading in the first session after an upgrade
  • Fixed a plugin's rows above the prompt showing a stale row while the Background tasks dialog was open in fullscreen
  • Fixed plugin panes drawing nothing when a link used a localhost address, an @ in its path, an uppercase host or a file: path
  • Fixed a user-installed plugin being able to rewrite the descriptions of an organization-managed MCP server's sign-in tools
  • Fixed a freeze or forced quit at launch when a plugin drew a Box with a border style the terminal does not know
  • Fixed supervised and background sessions ending when a plugin's on-screen handler threw asynchronously
  • Fixed sessions ending with an interface error when a plugin region with no height kept growing
  • Fixed Bash deny and ask rules missing a command behind an environment variable prefix with an expanded value (e.g. TZ="$HOME" rm -rf build) when the sandbox auto-allows commands
  • Fixed a Bash deny or ask rule being skipped under sandbox auto-allow when a bare variable assignment came before the command
  • Fixed claude plugin validate skipping the plugin when the folder also holds a marketplace manifest
  • Added agent.spawn for teammates, one agent id across plugin hook events, and idle and waiting states in $.agent.list()
  • Fixed sessions ending with "unrecoverable interface error" when a value a mod's ui.render hook wrote made a row throw while drawn; the engine now draws its own row instead
  • Fixed text with a tab, a stray escape and a C1 control, or a short text with a tab and CRLF line endings, drawing over the rows below it
  • Fixed right-aligned content in a mod's pane or band drawing under the close mark or [-], which now also keep one column in from the terminal's edge
  • Fixed a mod's Client that fails while drawn taking down everything the mod drew around it; it now fails alone and raises ui.fault
  • Fixed claude plugin validate failing an Anthropic marketplace's own plugin and listing a clean plugin.json in --json
  • Fixed a mod's band that fails to draw briefly telling the cards under it to step aside
  • Fixed a failed plugin component showing Error or nothing as its reason when the failure carried no message
  • Improved the line a mod's author sees when its band or pane fails to draw: it names the mod and says nothing was drawn
  • Fixed published artifact pages freezing or crashing the reader's browser tab on short code blocks with many unclosed <script> tags
  • Fixed a mod's Client region staying failed for the whole session after the terminal threw while drawing it
Commits

Updates @earendil-works/pi-coding-agent from 1.0.0 to 1.0.2

Release notes

Sourced from @​earendil-works/pi-coding-agent's releases.

v1.0.2

New Features

  • Sampling by thinking level — samplingParamsByThinkingLevel in models.json sets sampling parameters such as temperature and top_p for each thinking level on OpenAI-compatible APIs. See Configure sampling by thinking level.

Added

v1.0.1

New Features

  • Nix flake — nix run github:earendil-works/pi/stable runs the latest release, and nix profile add github:earendil-works/pi/stable installs it. See Install pi.
  • Project overrides for MCP servers — .pi/mcp.json and /mcp can enable, disable, or change the exposure of a user-level server for one project. See Configure servers.
  • MCP Client ID Metadata Documents — oauth.clientRegistration: "cimd" lets authorization servers allow pi by its document URL instead of dynamic registration. See Authenticate with OAuth.
  • Tool renderers for any tool — pi.registerToolRenderer() draws calls to tools that are not registered yet, such as MCP tools in resumed sessions. See Tool rendering.
  • Cloudflare Clef classifiers — @cf/cloudflare/clef and @cf/cloudflare/clef-flash are usable from codemode scripts and extensions. See Use classifier models.

Added

  • Added a copy key (app.message.copy, default ctrl+x) to OAuth sign-in screens in /login, /mcp, and /mcp login, which copies the sign-in URL when the browser cannot be opened or the wrapped link cannot be selected.
  • Added oauth.clientRegistration: "cimd" for MCP servers, which identifies pi with its Client ID Metadata Document on pi.dev instead of dynamic client registration, so authorization servers can allow pi by URL (#10302)
  • Added project overrides for user-level MCP servers: a .pi/mcp.json entry without command or url sets only enabled, exposure, and toolExposure of the user-level server, and /mcp can enable or disable a server for the current project (#10277)
  • Added Cloudflare's Clef and Clef Flash classifier models to cloudflare-workers-ai, usable from codemode scripts and extensions (#10316 by @​ndisidore, #10322 by @​RealAlexandreAI)
  • Added pi.registerToolRenderer(), which chooses how calls to a tool are drawn, including tools that are not registered (#10285)
  • Added a Nix flake for macOS and Linux: nix run github:earendil-works/pi/stable runs the latest release, and nix profile add github:earendil-works/pi/stable installs it. See Install pi (#9137)

Changed

  • pi update on global npm installations now recommends migrating to the managed installation from the pi.dev installer, which pins all dependencies.
  • Anthropic tools added or redefined mid-conversation are now defined inline in the conversation, so redefining a tool under the same name keeps the prompt cache instead of resending the full tool list.

Fixed

  • Fixed installations resolving vulnerable brace-expansion 5.0.9 by pinning brace-expansion 5.0.12 as a direct dependency (GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p) (#10288)
  • Fixed a trailing comma in --models adding an extra model to the model cycle (#10334)
  • Fixed a codemode script that prints in a loop crashing pi by running out of memory: a script fails once its output passes 16 Mi characters or 100000 items (#10283)
  • Fixed JPEG, GIF, and WebP images rendered by extensions through Image not appearing in Kitty, Ghostty, WezTerm, and Warp (#10292)
  • Fixed MCP tool calls in resumed sessions and HTML exports rendering fully expanded until their server connected, or for good if it never did (#10285)
  • Fixed fullscreen Kitty images collapsing to a one-row strip after scrolling in WezTerm (#10319)
  • Fixed "Selected model is at capacity" provider errors ending the turn instead of being retried (#10278)
  • Fixed Cloudflare AI Gateway Claude models failing with a 404 by using dashed model IDs (claude-opus-5-5 instead of claude-opus-5.5)
  • Fixed Sign in with ChatGPT continuing when its callback port is taken by another login, which made the browser show "OAuth state mismatch"; it now fails with a port-in-use error (#10265)
  • Fixed Amazon Bedrock OpenAI models costing requests above 272k input tokens at the short-context rate; Bedrock models now include the pricing tiers listed on models.dev (#10326)
  • Fixed Amazon Bedrock Claude requests failing with "Invalid signature in thinking block" after the system prompt or tools changed (#10324)
  • Fixed Together DeepSeek V4 Pro losing its thinking level controls after Together renamed it to deepseek-ai/DeepSeek-V4-Pro-0813 (#10336 by @​cv)
  • Fixed the default NVIDIA model pointing at nvidia/nemotron-3-super-120b-a12b, which NVIDIA no longer serves; the default is now nvidia/nemotron-3-ultra-550b-a55b

Removed

... (truncated)

Changelog

Sourced from @​earendil-works/pi-coding-agent's changelog.

[1.0.2] - 2026-10-04

New Features

  • Sampling by thinking level — samplingParamsByThinkingLevel in models.json sets sampling parameters such as temperature and top_p for each thinking level on OpenAI-compatible APIs. See Configure sampling by thinking level.

Added

[1.0.1] - 2026-10-03

New Features

  • Nix flake — nix run github:earendil-works/pi/stable runs the latest release, and nix profile add github:earendil-works/pi/stable installs it. See Install pi.
  • Project overrides for MCP servers — .pi/mcp.json and /mcp can enable, disable, or change the exposure of a user-level server for one project. See Configure servers.
  • MCP Client ID Metadata Documents — oauth.clientRegistration: "cimd" lets authorization servers allow pi by its document URL instead of dynamic registration. See Authenticate with OAuth.
  • Tool renderers for any tool — pi.registerToolRenderer() draws calls to tools that are not registered yet, such as MCP tools in resumed sessions. See Tool rendering.
  • Cloudflare Clef classifiers — @cf/cloudflare/clef and @cf/cloudflare/clef-flash are usable from codemode scripts and extensions. See Use classifier models.

Added

  • Added a copy key (app.message.copy, default ctrl+x) to OAuth sign-in screens in /login, /mcp, and /mcp login, which copies the sign-in URL when the browser cannot be opened or the wrapped link cannot be selected.
  • Added oauth.clientRegistration: "cimd" for MCP servers, which identifies pi with its Client ID Metadata Document on pi.dev instead of dynamic client registration, so authorization servers can allow pi by URL (#10302)
  • Added project overrides for user-level MCP servers: a .pi/mcp.json entry without command or url sets only enabled, exposure, and toolExposure of the user-level server, and /mcp can enable or disable a server for the current project (#10277)
  • Added Cloudflare's Clef and Clef Flash classifier models to cloudflare-workers-ai, usable from codemode scripts and extensions (#10316 by @​ndisidore, #10322 by @​RealAlexandreAI)
  • Added pi.registerToolRenderer(), which chooses how calls to a tool are drawn, including tools that are not registered (#10285)
  • Added a Nix flake for macOS and Linux: nix run github:earendil-works/pi/stable runs the latest release, and nix profile add github:earendil-works/pi/stable installs it. See Install pi (#9137)

Changed

  • pi update on global npm installations now recommends migrating to the managed installation from the pi.dev installer, which pins all dependencies.
  • Anthropic tools added or redefined mid-conversation are now defined inline in the conversation, so redefining a tool under the same name keeps the prompt cache instead of resending the full tool list.

Fixed

  • Fixed installations resolving vulnerable brace-expansion 5.0.9 by pinning brace-expansion 5.0.12 as a direct dependency (GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p) (#10288)
  • Fixed a trailing comma in --models adding an extra model to the model cycle (#10334)
  • Fixed a codemode script that prints in a loop crashing pi by running out of memory: a script fails once its output passes 16 Mi characters or 100000 items (#10283)
  • Fixed JPEG, GIF, and WebP images rendered by extensions through Image not appearing in Kitty, Ghostty, WezTerm, and Warp (#10292)
  • Fixed MCP tool calls in resumed sessions and HTML exports rendering fully expanded until their server connected, or for good if it never did (#10285)
  • Fixed fullscreen Kitty images collapsing to a one-row strip after scrolling in WezTerm (#10319)
  • Fixed "Selected model is at capacity" provider errors ending the turn instead of being retried (#10278)
  • Fixed Cloudflare AI Gateway Claude models failing with a 404 by using dashed model IDs (claude-opus-5-5 instead of claude-opus-5.5)
  • Fixed Sign in with ChatGPT continuing when its callback port is taken by another login, which made the browser show "OAuth state mismatch"; it now fails with a port-in-use error (#10265)
  • Fixed Amazon Bedrock OpenAI models costing requests above 272k input tokens at the short-context rate; Bedrock models now include the pricing tiers listed on models.dev (#10326)
  • Fixed Amazon Bedrock Claude requests failing with "Invalid signature in thinking block" after the system prompt or tools changed (#10324)
  • Fixed Together DeepSeek V4 Pro losing its thinking level controls after Together renamed it to deepseek-ai/DeepSeek-V4-Pro-0813 (#10336 by @​cv)
  • Fixed the default NVIDIA model pointing at nvidia/nemotron-3-super-120b-a12b, which NVIDIA no longer serves; the default is now nvidia/nemotron-3-ultra-550b-a55b

... (truncated)

Commits
  • cd32f77 Release v1.0.2
  • 750105c docs(ai,coding-agent): move #9776 changelog entries to Unreleased
  • 76dfb88 feat(ai): add per-thinking-level sampling parameters (#9776)
  • 4c6fb7c Add [Unreleased] section for next cycle
  • a7229dd Release v1.0.1
  • 49b9df4 fix(coding-agent): default NVIDIA to Nemotron 3 Ultra
  • 4215d4d docs(ai,coding-agent): audit changelog entries since v1.0.0
  • 1144973 fix(coding-agent): render MCP tool calls before their server connects
  • a276dab fix(tui,coding-agent): convert non-PNG images for Kitty in Image
  • 1387af7 feat(coding-agent): allow project mcp.json to override enabled and exposure o...
  • Additional commits viewable in compare view

@dependabot
dependabot Bot requested a review from czpython as a code owner October 7, 2026 07:35
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 7, 2026
Bumps the sandbox-harnesses group with 2 updates in the /deploy/sandbox directory: [@anthropic-ai/claude-code](https://github.com/anthropics/claude-code) and [@earendil-works/pi-coding-agent](https://github.com/earendil-works/pi/tree/HEAD/packages/coding-agent).


Updates `@anthropic-ai/claude-code` from 2.1.288 to 2.1.289
- [Release notes](https://github.com/anthropics/claude-code/releases)
- [Changelog](https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md)
- [Commits](anthropics/claude-code@v2.1.288...v2.1.289)

Updates `@earendil-works/pi-coding-agent` from 1.0.0 to 1.0.2
- [Release notes](https://github.com/earendil-works/pi/releases)
- [Changelog](https://github.com/earendil-works/pi/blob/main/packages/coding-agent/CHANGELOG.md)
- [Commits](https://github.com/earendil-works/pi/commits/v1.0.2/packages/coding-agent)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/claude-code"
  dependency-version: 2.1.289
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: sandbox-harnesses
- dependency-name: "@earendil-works/pi-coding-agent"
  dependency-version: 1.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: sandbox-harnesses
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump the sandbox-harnesses group in /deploy/sandbox with 2 updates Bump the sandbox-harnesses group across 1 directory with 2 updates Oct 8, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/deploy/sandbox/sandbox-harnesses-5b4e9d9462 branch from 0cc46d1 to 61206f6 Compare October 8, 2026 07:34
@czpython
czpython merged commit 55ae358 into main Oct 8, 2026
7 checks passed
@czpython
czpython deleted the dependabot/npm_and_yarn/deploy/sandbox/sandbox-harnesses-5b4e9d9462 branch October 8, 2026 11:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant