Skip to content

Bump the sandbox-harnesses group across 1 directory with 4 updates - #747

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/deploy/sandbox/sandbox-harnesses-41d06a4adc
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/deploy/sandbox/sandbox-harnesses-41d06a4adc

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the sandbox-harnesses group with 4 updates in the /deploy/sandbox directory: @anthropic-ai/claude-code, @earendil-works/pi-coding-agent, @openai/codex and pi-mcp-adapter.

Updates @anthropic-ai/claude-code from 2.1.278 to 2.1.283

Release notes

Sourced from @​anthropic-ai/claude-code's releases.

v2.1.283

What's changed

  • Added x-claude-code-prompt-id to the gateway hint headers so LLM gateways can group the requests that serve one user prompt; opt in with CLAUDE_CODE_GATEWAY_HINT_HEADERS=1
  • Added availableModelsMatch managed setting: with "exact", an availableModels entry allows only the model version it names, so new releases stay blocked until listed
  • Added deniedModels managed setting to block specific models, even when availableModels allows them
  • Added MCP tool, WebFetch and WebSearch outputs to the tool.output OpenTelemetry span event when OTEL_LOG_TOOL_CONTENT=1
  • Added /doctor prompt-audit (also /checkup prompt-audit) to audit your CLAUDE.md files, skills, agents and commands for prompting patterns written for older models
  • Added click-to-expand for truncated messages from your other sessions in fullscreen mode
  • Added path to --plugin-dir load-failure entries in the stream-json system/init plugin_errors, naming the directory that did not load
  • Added an opt-in load_test_mode block to the Claude apps gateway config: requests are built and signed but not sent upstream, and clients get a canned reply, so a deployment can be load tested
  • Added a mantle upstream provider to the Claude apps gateway for Amazon Bedrock's Mantle endpoint
  • Fixed SDK sessions losing a deferred tool call or finished tool result when a turn ended early, a held approval prompt after a worker restart, and a non-streaming fallback's result.usage
  • Fixed MCP progress notifications being discarded once a long-running tool call moved to the background; the background task now shows the latest progress
  • Fixed stdio MCP servers being left running when the session ended while they were still starting
  • Fixed a brief HTTP 404 from a stateless remote MCP server (for example a proxy mid-redeploy) leaving that server unusable for the rest of the session while still shown as connected
  • Fixed MCP sign-in for a server with no valid URL failing with an opaque SDK error; /mcp no longer offers Authenticate for such servers
  • Fixed the weekly Fable limit not appearing in /usage and the VS Code usage meters when telemetry is disabled
  • Fixed /model accepting Sonnet 4.6 or Sonnet 5 with [1m] when the id carried a date or -v1:0 suffix, in the cases where the plain id was refused
  • Fixed /model picker showing a hardcoded Haiku version and price when ANTHROPIC_DEFAULT_HAIKU_MODEL pins a different model
  • Fixed dynamic workflows started during a model fallback running every agent on the fallback model instead of retrying the configured model
  • Fixed DISABLE_PROMPT_CACHING_HAIKU having no effect when Haiku is the session's main model
  • Fixed claude plugin validate saying Claude Code accepts a plugin or marketplace name it cannot install; such names in marketplace.json now fail validation
  • Fixed claude plugin validate passing plugins whose outputStyles, themes, monitors, or lspServers paths are missing or point outside the plugin directory
  • Fixed claude plugin details showing 0 MCP servers for plugins that declare their servers in plugin.json
  • Fixed claude plugin marketplace remove not saying which installed plugins it uninstalled with the marketplace; it now lists them
  • Fixed claude plugin uninstall removing the other of two installed plugins whose ids differ only in case, with its options and secrets, when the one named had no enabledPlugins entry at that scope
  • Fixed plugins that declare no version being silently restored at their source's newest commit, not the installed one, when their cached files were missing
  • Fixed user-installed plugins and marketplaces failing to load with "cache-miss" after the home or config directory was moved, for example in bind-mounted devcontainers
  • Fixed installed_plugins.json showing no plugins when it holds a record under an invalid plugin id; such a file loads again
  • Fixed installed_plugins.json being rewritten, losing records, when it holds a record this version cannot read; claude plugin commands now name the record and say how to recover
  • Fixed permission dialogs in screen-reader mode reading quoted commands and paths as if they were the dialog's own text
  • Fixed /context not counting MCP server instructions: they now appear as their own row and count toward the total
  • Fixed markdown links in the Warp terminal rendering as plain text instead of clickable hyperlinks
  • Fixed claude mcp add, add-json, and remove reporting success when the user or local config file could not be written, for example inside a sandbox
  • Fixed the first words of a reply in a cloud session sometimes appearing late instead of streaming as Claude writes them
  • Fixed Claude's built-in keybindings guide saying chords time out after 1 second instead of 3, and calling cmd an alias of meta, which could produce cmd+ shortcuts most terminals never send
  • Fixed keybindings.json silently accepting a misspelled modifier such as ctl+k; it now warns in the debug log and suggests the fix
  • Fixed footer hints still saying "Enter to view" after footer:openSelected was rebound or unbound in keybindings.json
  • Fixed keys typed quickly together (type-ahead, key repeat, bursts over ssh or tmux) sometimes being handled against stale state
  • Fixed worktree checkouts failing certificate verification (for example on Git LFS downloads) when the CA certificate is passed to git as GIT_CONFIG_COUNT environment pairs
  • Fixed sandboxed git asking credential helpers to store the sandbox proxy's login, which printed "failed to store"
  • Fixed managed sandbox settings being ignored entirely when one nested value was invalid; the invalid value now fails closed and the rest of the block still applies
  • Fixed Claude's edits to its own auto-memory notes being blocked as sensitive-file writes when Claude Code was started in a subdirectory of a git repository
  • Fixed Remote Control being unavailable on paid plans when telemetry is turned off with DISABLE_TELEMETRY or DO_NOT_TRACK
  • Fixed the /remote-control menu cutting its QR-code hint mid-word in narrow terminals
  • Fixed vim mode . dropping a Shift+Enter newline, leaving the cursor inside an accented letter, and repeating an older change after 3J or Visual-mode J on the last line
  • Fixed vim mode cursor placement: recalling a prompt over 10,000 characters in normal mode no longer leaves the cursor past the end, and V then p now lands on the first non-blank
  • Fixed vim mode J joining lines with different spacing than Vim (such as a space before ) or after a tab), and 3J or Visual-mode J on the last line not moving the cursor as Vim does
  • Windows: Fixed the PowerShell tool letting cmd /c rd, rmdir, del or erase delete drive roots, the home folder and other folders that Remove-Item refuses

... (truncated)

Changelog

Sourced from @​anthropic-ai/claude-code's changelog.

2.1.283

  • Added x-claude-code-prompt-id to the gateway hint headers so LLM gateways can group the requests that serve one user prompt; opt in with CLAUDE_CODE_GATEWAY_HINT_HEADERS=1
  • Added availableModelsMatch managed setting: with "exact", an availableModels entry allows only the model version it names, so new releases stay blocked until listed
  • Added deniedModels managed setting to block specific models, even when availableModels allows them
  • Added MCP tool, WebFetch and WebSearch outputs to the tool.output OpenTelemetry span event when OTEL_LOG_TOOL_CONTENT=1
  • Added /doctor prompt-audit (also /checkup prompt-audit) to audit your CLAUDE.md files, skills, agents and commands for prompting patterns written for older models
  • Added click-to-expand for truncated messages from your other sessions in fullscreen mode
  • Added path to --plugin-dir load-failure entries in the stream-json system/init plugin_errors, naming the directory that did not load
  • Added an opt-in load_test_mode block to the Claude apps gateway config: requests are built and signed but not sent upstream, and clients get a canned reply, so a deployment can be load tested
  • Added a mantle upstream provider to the Claude apps gateway for Amazon Bedrock's Mantle endpoint
  • Fixed SDK sessions losing a deferred tool call or finished tool result when a turn ended early, a held approval prompt after a worker restart, and a non-streaming fallback's result.usage
  • Fixed MCP progress notifications being discarded once a long-running tool call moved to the background; the background task now shows the latest progress
  • Fixed stdio MCP servers being left running when the session ended while they were still starting
  • Fixed a brief HTTP 404 from a stateless remote MCP server (for example a proxy mid-redeploy) leaving that server unusable for the rest of the session while still shown as connected
  • Fixed MCP sign-in for a server with no valid URL failing with an opaque SDK error; /mcp no longer offers Authenticate for such servers
  • Fixed the weekly Fable limit not appearing in /usage and the VS Code usage meters when telemetry is disabled
  • Fixed /model accepting Sonnet 4.6 or Sonnet 5 with [1m] when the id carried a date or -v1:0 suffix, in the cases where the plain id was refused
  • Fixed /model picker showing a hardcoded Haiku version and price when ANTHROPIC_DEFAULT_HAIKU_MODEL pins a different model
  • Fixed dynamic workflows started during a model fallback running every agent on the fallback model instead of retrying the configured model
  • Fixed DISABLE_PROMPT_CACHING_HAIKU having no effect when Haiku is the session's main model
  • Fixed claude plugin validate saying Claude Code accepts a plugin or marketplace name it cannot install; such names in marketplace.json now fail validation
  • Fixed claude plugin validate passing plugins whose outputStyles, themes, monitors, or lspServers paths are missing or point outside the plugin directory
  • Fixed claude plugin details showing 0 MCP servers for plugins that declare their servers in plugin.json
  • Fixed claude plugin marketplace remove not saying which installed plugins it uninstalled with the marketplace; it now lists them
  • Fixed claude plugin uninstall removing the other of two installed plugins whose ids differ only in case, with its options and secrets, when the one named had no enabledPlugins entry at that scope
  • Fixed plugins that declare no version being silently restored at their source's newest commit, not the installed one, when their cached files were missing
  • Fixed user-installed plugins and marketplaces failing to load with "cache-miss" after the home or config directory was moved, for example in bind-mounted devcontainers
  • Fixed installed_plugins.json showing no plugins when it holds a record under an invalid plugin id; such a file loads again
  • Fixed installed_plugins.json being rewritten, losing records, when it holds a record this version cannot read; claude plugin commands now name the record and say how to recover
  • Fixed permission dialogs in screen-reader mode reading quoted commands and paths as if they were the dialog's own text
  • Fixed /context not counting MCP server instructions: they now appear as their own row and count toward the total
  • Fixed markdown links in the Warp terminal rendering as plain text instead of clickable hyperlinks
  • Fixed claude mcp add, add-json, and remove reporting success when the user or local config file could not be written, for example inside a sandbox
  • Fixed the first words of a reply in a cloud session sometimes appearing late instead of streaming as Claude writes them
  • Fixed Claude's built-in keybindings guide saying chords time out after 1 second instead of 3, and calling cmd an alias of meta, which could produce cmd+ shortcuts most terminals never send
  • Fixed keybindings.json silently accepting a misspelled modifier such as ctl+k; it now warns in the debug log and suggests the fix
  • Fixed footer hints still saying "Enter to view" after footer:openSelected was rebound or unbound in keybindings.json
  • Fixed keys typed quickly together (type-ahead, key repeat, bursts over ssh or tmux) sometimes being handled against stale state
  • Fixed worktree checkouts failing certificate verification (for example on Git LFS downloads) when the CA certificate is passed to git as GIT_CONFIG_COUNT environment pairs
  • Fixed sandboxed git asking credential helpers to store the sandbox proxy's login, which printed "failed to store"
  • Fixed managed sandbox settings being ignored entirely when one nested value was invalid; the invalid value now fails closed and the rest of the block still applies
  • Fixed Claude's edits to its own auto-memory notes being blocked as sensitive-file writes when Claude Code was started in a subdirectory of a git repository
  • Fixed Remote Control being unavailable on paid plans when telemetry is turned off with DISABLE_TELEMETRY or DO_NOT_TRACK
  • Fixed the /remote-control menu cutting its QR-code hint mid-word in narrow terminals
  • Fixed vim mode . dropping a Shift+Enter newline, leaving the cursor inside an accented letter, and repeating an older change after 3J or Visual-mode J on the last line
  • Fixed vim mode cursor placement: recalling a prompt over 10,000 characters in normal mode no longer leaves the cursor past the end, and V then p now lands on the first non-blank
  • Fixed vim mode J joining lines with different spacing than Vim (such as a space before ) or after a tab), and 3J or Visual-mode J on the last line not moving the cursor as Vim does
  • Windows: Fixed the PowerShell tool letting cmd /c rd, rmdir, del or erase delete drive roots, the home folder and other folders that Remove-Item refuses
  • Improved the /mcp tool list: it shows more tools at once, scrolls with the page keys and mouse, and marks tools your organization blocked with a warning icon

... (truncated)

Commits
  • 7779afb chore: Update CHANGELOG.md and feed.xml
  • c948155 diff: the focus hook answers to either name the engine stamps on its elements...
  • e1bb7b0 telemetry, agents-md: the test plugins hook and call the collector stream by ...
  • 163ae3a chore: Update CHANGELOG.md and feed.xml
  • 6557bbe telemetry: log and mark are what the mod's hooks do, the noun added only wher...
  • 684ffc4 agents-md: the truncated-read tests laid out as the formatter lays them
  • 653d32f fix(agents-md): retain instructions after truncated reads
  • ddcb43a chore: Update CHANGELOG.md and feed.xml
  • 32251d1 diff: the shared diff arguments' doc says what --no-color pins
  • 4536209 fix(diff): preserve hunks when Git forces colored output
  • Additional commits viewable in compare view

Updates @earendil-works/pi-coding-agent from 0.87.0 to 0.87.1

Release notes

Sourced from @​earendil-works/pi-coding-agent's releases.

v0.87.1

New Features

  • Latest frontier models — Use Claude Opus 5.5, GPT-6 Sol, and GPT-6 Luna through supported providers, including GitHub Copilot. See Choose a Model.
  • Grok 4.7 by default for xAI — New xAI sessions now default to Grok 4.7. See Provider Authentication.

Added

  • Added inherited Claude Opus 5.5, GPT-6 Sol, and GPT-6 Luna support for GitHub Copilot.
  • Added inherited GPT-6 Sol and GPT-6 Luna support for OpenAI API keys and OpenAI Codex subscriptions.
  • Added inherited Claude Opus 5.5 support for Anthropic with adaptive thinking and a 1M context window.

Changed

  • Changed the default xAI model to Grok 4.7.

Fixed

  • Fixed split-turn compaction summaries being refused by Claude Fable 5.1 by clearly separating the conversation and using continuation-oriented instructions (#9908 by @​davidbrai).
  • Fixed missing or invalid --mode values being silently ignored instead of reporting an error and exiting with a nonzero status (#9045).
  • Fixed inherited image-only user messages being rejected by some OpenAI-compatible providers because they included an empty text part (#9797).
  • Fixed inherited Anthropic OAuth requests reporting an outdated Claude Code version.
Changelog

Sourced from @​earendil-works/pi-coding-agent's changelog.

[0.87.1] - 2026-09-22

New Features

  • Latest frontier models — Use Claude Opus 5.5, GPT-6 Sol, and GPT-6 Luna through supported providers, including GitHub Copilot. See Choose a Model.
  • Grok 4.7 by default for xAI — New xAI sessions now default to Grok 4.7. See Provider Authentication.

Added

  • Added inherited Claude Opus 5.5, GPT-6 Sol, and GPT-6 Luna support for GitHub Copilot.
  • Added inherited GPT-6 Sol and GPT-6 Luna support for OpenAI API keys and OpenAI Codex subscriptions.
  • Added inherited Claude Opus 5.5 support for Anthropic with adaptive thinking and a 1M context window.

Changed

  • Changed the default xAI model to Grok 4.7.

Fixed

  • Fixed split-turn compaction summaries being refused by Claude Fable 5.1 by clearly separating the conversation and using continuation-oriented instructions (#9908 by @​davidbrai).
  • Fixed missing or invalid --mode values being silently ignored instead of reporting an error and exiting with a nonzero status (#9045).
  • Fixed inherited image-only user messages being rejected by some OpenAI-compatible providers because they included an empty text part (#9797).
  • Fixed inherited Anthropic OAuth requests reporting an outdated Claude Code version.
Commits
  • f07218c Release v0.87.1
  • 3a4c777 docs(coding-agent): complete unreleased changelog
  • 27c072e feat(ai,coding-agent): add new Copilot models
  • db91e03 feat(ai,coding-agent): add GPT-6 Sol and Luna support
  • b4588f2 feat(ai,coding-agent): add Claude Opus 5.5 support
  • d192bd6 fix(coding-agent): avoid Fable split-turn summary refusals (#9908)
  • 25cc5c7 docs(coding-agent): refresh documentation (#9898)
  • 95fbc04 docs(coding-agent): update changelog with --mode validation fix (#9877)
  • e40126f fix(coding-agent): reject invalid --mode values
  • 1a584a7 feat(ai,coding-agent): add Grok 4.7 support
  • Additional commits viewable in compare view

Updates @openai/codex from 0.155.1 to 0.157.1
Updates pi-mcp-adapter from 2.36.0 to 3.0.0

Release notes

Sourced from pi-mcp-adapter's releases.

v3.0.0

pi-mcp-adapter 3.0.0 gets the adapter ready for Pi's upcoming built-in MCP support and closes two security gaps. The adapter now keeps its settings in its own mcp-adapter.json file and uses the /mcp-adapter command, so it can run next to Pi's built-in MCP without starting the same servers twice. Opening a repository no longer starts that repository's MCP servers on its own: you trust the project and approve each server first. mcpScript code now runs in a separate sandbox that scripts cannot escape. If you kept adapter settings in mcp.json, rename the file once; Pi shows you the exact command.

Highlights

  • Its own config file. The adapter reads mcp-adapter.json and leaves mcp.json to Pi, so the two never start the same servers.
  • Project servers wait for approval. Servers defined by a repository stay off until the project is trusted and you approve each one. Pi asks again if the server definition changes.
  • A safer mcpScript. Scripts run in a memory-limited QuickJS sandbox with no way to reach your files or processes.
  • Traceable tool calls. MCP servers can match each request to the Pi tool call that made it.

Need to know

If you… Do this
kept adapter config in ~/.pi/agent/mcp.json or .pi/mcp.json Rename it to mcp-adapter.json in the same folder (mv is enough; merge if the target already exists). Until then Pi warns you at startup with the exact command.
type /mcp Use /mcp-adapter. /mcp still works only when Pi's built-in MCP extension is not installed.
rely on MCP servers in a project's .mcp.json or .pi/mcp-adapter.json Trust the project and approve each server the first time Pi asks. For headless runs, set settings.projectServers to "allow" in your user-global mcp-adapter.json.
use .mcp.json, ~/.config/mcp/mcp.json, or --mcp-config Nothing changes.

Changelog

Highlights

  • The adapter now has its own config file, mcp-adapter.json, so it can run alongside Pi's upcoming built-in MCP support without starting the same servers twice. If you used mcp.json with the adapter, rename it (see Breaking).
  • Opening a repository no longer starts its MCP servers on its own. Project servers wait until you trust the project and approve each server.
  • mcpScript code now runs in a QuickJS sandbox that scripts cannot escape to reach your files or processes.
  • MCP servers can now match each request to the Pi tool call that made it.

Breaking

  • The adapter no longer reads <Pi agent dir>/mcp.json or .pi/mcp.json. Those files now belong to Pi's built-in MCP support. Rename yours to mcp-adapter.json in the same folder. The format is the same, so mv is enough; if mcp-adapter.json already exists, merge the two. Until you do, Pi shows a warning with the exact command. .mcp.json, ~/.config/mcp/mcp.json, and --mcp-config work as before.
  • The interactive command is now /mcp-adapter. /mcp still works as a shortcut when Pi's built-in MCP extension is not installed.

Security

  • mcpScript now runs scripts in a memory-limited QuickJS/WASM sandbox instead of Node's vm module, which scripts could escape to reach process, the filesystem, or child processes (#676). Each script can emit up to 16 MiB of output, and error messages are capped at 64 KiB. Values pass between the script and Pi as JSON, so values that are not plain JSON still show up but may be formatted differently than before.
  • MCP servers defined by a project no longer start until the project is trusted and you approve the server. This covers .mcp.json, .pi/mcp-adapter.json, and servers a project brings in through imports, plugins, repo-local host configs, or Pi packages in its settings. In an untrusted project they stay blocked. In a trusted interactive session, Pi shows the server's command or URL and asks once; the approval is saved, and Pi asks again if the server definition changes. Headless sessions skip unapproved servers unless your user-global config sets settings.projectServers to "allow". /mcp-adapter status shows why a server is blocked. Fixes #675.

Added

  • MCP tool calls now include the id of the Pi tool call that made them, under _meta["pi-mcp-adapter/toolCallId"], so servers can match requests to Pi's tool calls in their logs and traces. Direct tools, the mcp tool, and mcp__<server> tools send it. mcpScript calls do not, because a script is not a single tool call. Thanks to @​sebavalaris for [PR #673](nicobailon/pi-mcp-adapter#673).

v2.38.0

pi-mcp-adapter 2.38.0 makes lazy and runtime-registered MCP tools more dependable. Search-mode tools can promote themselves to full direct tools after a successful call, while keep-alive servers registered later now work even when Pi starts with no enabled servers. Compact mcpScript results are easier to understand, and configuration compatibility is broader across stdio paths, OpenCode v2, and Rust MCP schemas. OAuth and MCP UI behavior are also less fragile.

Highlights

  • Search-mode tools become full direct tools after a successful proxy call.
  • Runtime-registered keep-alive servers work from an empty MCP startup.
  • Compact mcpScript results show called tools, repeat counts, and failures.

... (truncated)

Changelog

Sourced from pi-mcp-adapter's changelog.

[3.0.0] - 2026-09-26

Highlights

  • The adapter now has its own config file, mcp-adapter.json, so it can run alongside Pi's upcoming built-in MCP support without starting the same servers twice. If you used mcp.json with the adapter, rename it (see Breaking).
  • Opening a repository no longer starts its MCP servers on its own. Project servers wait until you trust the project and approve each server.
  • mcpScript code now runs in a QuickJS sandbox that scripts cannot escape to reach your files or processes.
  • MCP servers can now match each request to the Pi tool call that made it.

Breaking

  • The adapter no longer reads <Pi agent dir>/mcp.json or .pi/mcp.json. Those files now belong to Pi's built-in MCP support. Rename yours to mcp-adapter.json in the same folder. The format is the same, so mv is enough; if mcp-adapter.json already exists, merge the two. Until you do, Pi shows a warning with the exact command. .mcp.json, ~/.config/mcp/mcp.json, and --mcp-config work as before.
  • The interactive command is now /mcp-adapter. /mcp still works as a shortcut when Pi's built-in MCP extension is not installed.

Security

  • mcpScript now runs scripts in a memory-limited QuickJS/WASM sandbox instead of Node's vm module, which scripts could escape to reach process, the filesystem, or child processes (#676). Each script can emit up to 16 MiB of output, and error messages are capped at 64 KiB. Values pass between the script and Pi as JSON, so values that are not plain JSON still show up but may be formatted differently than before.
  • MCP servers defined by a project no longer start until the project is trusted and you approve the server. This covers .mcp.json, .pi/mcp-adapter.json, and servers a project brings in through imports, plugins, repo-local host configs, or Pi packages in its settings. In an untrusted project they stay blocked. In a trusted interactive session, Pi shows the server's command or URL and asks once; the approval is saved, and Pi asks again if the server definition changes. Headless sessions skip unapproved servers unless your user-global config sets settings.projectServers to "allow". /mcp-adapter status shows why a server is blocked. Fixes #675.

Added

  • MCP tool calls now include the id of the Pi tool call that made them, under _meta["pi-mcp-adapter/toolCallId"], so servers can match requests to Pi's tool calls in their logs and traces. Direct tools, the mcp tool, and mcp__<server> tools send it. mcpScript calls do not, because a script is not a single tool call. Thanks to @​sebavalaris for [PR #673](nicobailon/pi-mcp-adapter#673).

[2.38.0] - 2026-09-26

Highlights

  • Search-mode tools become full direct tools after a successful proxy call, without requiring a separate search first.
  • Runtime-registered keep-alive servers now publish their tools even when Pi starts with no enabled MCP servers.
  • Compact mcpScript results show which tools ran, how often they ran, and how many calls failed.
  • Stdio configurations support home-relative paths, and MCP UI windows can open in Orca.
  • OpenCode v2 imports, OAuth credential access, and Rust MCP schemas are more reliable.

Added

Fixed

  • Keep-alive servers registered at runtime now connect and publish their tools even when no configured servers are enabled at startup. Thanks to @​ahodges22 for [issue #671](nicobailon/pi-mcp-adapter#671).
  • Valid ancestorConfigRoots entries that do not contain the current working directory are ignored without warnings. Invalid entries still warn. Thanks to @​TheEdgeOfRage for [issue #668](nicobailon/pi-mcp-adapter#668) and [PR #669](nicobailon/pi-mcp-adapter#669).
  • Collapsed mcpScript results now show the tools called, repeat counts, and a visible failure count instead of only the first output line. Unsafe or ambiguous tool names are quoted and escaped, and script code remains hidden. Thanks to @​sargismarkosyan for [PR #666](nicobailon/pi-mcp-adapter#666).
  • Metadata refreshes no longer reactivate an mcp gateway tool removed by the host. On hosts without unregisterTool, the adapter can still hide the gateway when direct tools cover the server and restore it when needed. Thanks to @​xulongwu4 for [PR #665](nicobailon/pi-mcp-adapter#665).
  • mcpScript no longer asks models to load its intentionally hidden manual skill. Thanks to @​k03mad for #659.
  • OAuth credential reads now reuse a healthy keyring Entry without retaining secret values, avoiding repeated native sessions while still observing external updates. Thanks to @​mmarabel for #657.
  • Suppressing MCP UI windows with MCP_UI_VIEWER=none / off / disabled no longer prints raw output into the TUI. Thanks to @​andreafspeziale for #656.
  • The published package now includes the OAuth guide linked from the README. Thanks to @​dajiaohuang for [PR #653](nicobailon/pi-mcp-adapter#653).
  • OpenCode v2 configs now import. Servers under mcp.servers are picked up, disabled: true servers are skipped, and the snake_case OAuth fields client_id, client_secret, and auth_server_metadata_url are mapped. OpenCode v1 configs keep working. Thanks to @​sleroq for [PR #650](nicobailon/pi-mcp-adapter#650).

... (truncated)

Commits
  • 3a13257 chore(release): v3.0.0
  • f763ada refactor: trim unreleased trust, sandbox, and tool-call-id changes (#682)
  • d5e952a feat!: move adapter config to mcp-adapter.json and avoid Pi built-in MCP coll...
  • 5d645df fix: gate project MCP servers on trust and approval (#681)
  • 5f7ce89 fix: run mcpScript in a QuickJS sandbox (#679)
  • 4b7e310 feat: forward Pi tool call IDs to MCP requests (#674)
  • 817357d chore(release): update generated artifacts
  • 16c1e46 chore(release): 2.38.0
  • 7dcc52c fix: finalize lifecycle with no enabled MCP servers (#672)
  • 021528b Avoid warnings for non-matching ancestor roots (#669)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
@dependabot
dependabot Bot requested a review from czpython as a code owner September 28, 2026 07:38
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
@dependabot dependabot Bot changed the title Bump the sandbox-harnesses group in /deploy/sandbox with 4 updates Bump the sandbox-harnesses group across 1 directory with 4 updates Sep 29, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/deploy/sandbox/sandbox-harnesses-41d06a4adc branch from a3b4e1b to 6ce6f55 Compare September 29, 2026 07:35
---
updated-dependencies:
- dependency-name: "@anthropic-ai/claude-code"
  dependency-version: 2.1.282
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: sandbox-harnesses
- dependency-name: "@earendil-works/pi-coding-agent"
  dependency-version: 0.87.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: sandbox-harnesses
- dependency-name: "@openai/codex"
  dependency-version: 0.157.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: sandbox-harnesses
- dependency-name: pi-mcp-adapter
  dependency-version: 2.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: sandbox-harnesses
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/deploy/sandbox/sandbox-harnesses-41d06a4adc branch from 6ce6f55 to 04f5866 Compare September 30, 2026 07:35

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants