build(deps): bump the npm_and_yarn group across 7 directories with 9 updates - #10
build(deps): bump the npm_and_yarn group across 7 directories with 9 updates#10dependabot[bot] wants to merge 1 commit into
Conversation
…updates Bumps the npm_and_yarn group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@mariozechner/pi-coding-agent](https://github.com/badlogic/pi-mono/tree/HEAD/packages/coding-agent) | `0.57.1` | `0.73.1` | | [@whiskeysockets/baileys](https://github.com/WhiskeySockets/Baileys) | `7.0.0-rc.9` | `7.0.0-rc12` | | [hono](https://github.com/honojs/hono) | `4.12.18` | `4.12.25` | | [markdown-it](https://github.com/markdown-it/markdown-it) | `14.1.1` | `14.2.0` | | [undici](https://github.com/nodejs/undici) | `7.24.0` | `7.28.0` | | [ws](https://github.com/websockets/ws) | `8.19.0` | `8.21.0` | | [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.0.18` | `4.1.0` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.0.5` | `8.0.16` | Bumps the npm_and_yarn group with 1 update in the /extensions/matrix directory: [markdown-it](https://github.com/markdown-it/markdown-it). Bumps the npm_and_yarn group with 1 update in the /extensions/whatsapp directory: [@whiskeysockets/baileys](https://github.com/WhiskeySockets/Baileys). Bumps the npm_and_yarn group with 1 update in the /extensions/zalo directory: [undici](https://github.com/nodejs/undici). Bumps the npm_and_yarn group with 2 updates in the /ui directory: [dompurify](https://github.com/cure53/DOMPurify) and [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). Bumps the npm_and_yarn group with 1 update in the /whatsapp directory: [@whiskeysockets/baileys](https://github.com/WhiskeySockets/Baileys). Bumps the npm_and_yarn group with 1 update in the /zalo directory: [undici](https://github.com/nodejs/undici). Updates `@mariozechner/pi-coding-agent` from 0.57.1 to 0.73.1 - [Release notes](https://github.com/badlogic/pi-mono/releases) - [Changelog](https://github.com/earendil-works/pi/blob/main/packages/coding-agent/CHANGELOG.md) - [Commits](https://github.com/badlogic/pi-mono/commits/v0.73.1/packages/coding-agent) Updates `@whiskeysockets/baileys` from 7.0.0-rc.9 to 7.0.0-rc12 - [Release notes](https://github.com/WhiskeySockets/Baileys/releases) - [Changelog](https://github.com/WhiskeySockets/Baileys/blob/master/CHANGELOG.md) - [Commits](WhiskeySockets/Baileys@v7.0.0-rc.9...v7.0.0-rc12) Updates `hono` from 4.12.18 to 4.12.25 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.18...v4.12.25) Updates `markdown-it` from 14.1.1 to 14.2.0 - [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md) - [Commits](markdown-it/markdown-it@14.1.1...14.2.0) Updates `undici` from 7.24.0 to 7.28.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v7.24.0...v7.28.0) Updates `ws` from 8.19.0 to 8.21.0 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@8.19.0...8.21.0) Updates `vitest` from 4.0.18 to 4.1.0 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.0/packages/vitest) Updates `dompurify` from 3.4.0 to 3.4.11 - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@3.4.0...3.4.11) Updates `vite` from 8.0.5 to 8.0.16 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.0.16/packages/vite) Updates `markdown-it` from 14.1.1 to 14.2.0 - [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md) - [Commits](markdown-it/markdown-it@14.1.1...14.2.0) Updates `@whiskeysockets/baileys` from 7.0.0-rc.9 to 7.0.0-rc12 - [Release notes](https://github.com/WhiskeySockets/Baileys/releases) - [Changelog](https://github.com/WhiskeySockets/Baileys/blob/master/CHANGELOG.md) - [Commits](WhiskeySockets/Baileys@v7.0.0-rc.9...v7.0.0-rc12) Updates `undici` from 7.24.0 to 7.28.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v7.24.0...v7.28.0) Updates `dompurify` from 3.4.0 to 3.4.11 - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@3.4.0...3.4.11) Updates `vite` from 8.0.5 to 8.0.16 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.0.16/packages/vite) Updates `@whiskeysockets/baileys` from 7.0.0-rc.9 to 7.0.0-rc12 - [Release notes](https://github.com/WhiskeySockets/Baileys/releases) - [Changelog](https://github.com/WhiskeySockets/Baileys/blob/master/CHANGELOG.md) - [Commits](WhiskeySockets/Baileys@v7.0.0-rc.9...v7.0.0-rc12) Updates `undici` from 7.24.6 to 7.28.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v7.24.0...v7.28.0) --- updated-dependencies: - dependency-name: "@mariozechner/pi-coding-agent" dependency-version: 0.73.1 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@whiskeysockets/baileys" dependency-version: 7.0.0-rc12 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: hono dependency-version: 4.12.25 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: markdown-it dependency-version: 14.2.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: undici dependency-version: 7.28.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: ws dependency-version: 8.21.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: vitest dependency-version: 4.1.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: dompurify dependency-version: 3.4.11 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: vite dependency-version: 8.0.16 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: markdown-it dependency-version: 14.2.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@whiskeysockets/baileys" dependency-version: 7.0.0-rc12 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: undici dependency-version: 7.28.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: dompurify dependency-version: 3.4.11 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: vite dependency-version: 8.0.16 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: "@whiskeysockets/baileys" dependency-version: 7.0.0-rc12 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: undici dependency-version: 7.28.0 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
AI Code Review by LlamaPReview
🎯 TL;DR & Recommendation
Recommendation: Approve with suggestions
This PR updates multiple npm dependencies across workspaces, primarily to patch high-severity security vulnerabilities in hono, undici, ws, and @whiskeysockets/baileys. No critical issues are introduced, but some major version jumps (e.g., @mariozechner/pi-coding-agent) warrant manual verification due to breaking changes.
🌟 Strengths
- All updated packages address known security advisories, improving the application's security posture.
- The lockfile changes are consistent with the declared dependency bumps.
| Priority | File | Category | Impact Summary |
|---|---|---|---|
| P2 | package.json |
Maintainability | Major pi-coding-agent bump may break Xiaomi integration. |
| P2 | package.json |
Maintainability | Security patches may alter behavior; verify CI passes. |
| P2 | ui/package.json |
Maintainability | Minor bumps low risk; smoke test advised. |
🔍 Notable Themes
- All findings are speculative due to lack of usage context; no code references to updated packages were found in the analysis.
💡 Have feedback? We'd love to hear it in our GitHub Discussions.
✨ This review was generated by LlamaPReview Advanced, which is free for all open-source projects. Learn more.
| "@mariozechner/pi-agent-core": "0.57.1", | ||
| "@mariozechner/pi-ai": "0.57.1", | ||
| "@mariozechner/pi-coding-agent": "0.57.1", | ||
| "@mariozechner/pi-coding-agent": "0.73.1", |
There was a problem hiding this comment.
P2 | Confidence: Low
Speculative: The @mariozechner/pi-coding-agent package is upgraded from 0.57.1 to 0.73.1, a jump of 16 minor versions. The upstream release notes document breaking changes for the xiaomi provider (switching from Token Plan to API billing) and a switch from a @mariozechner/jiti fork to upstream jiti 2.7. Because no usage of this dependency was found in the related context (no import or require patterns matched), it is impossible to determine whether these breaking changes affect the host project. If the host project relies on the Xiaomi provider or on the forked jiti behavior, it could experience runtime failures or incorrect behavior after deployment. Manual verification of the integration points is strongly recommended before merging.
| "file-type": "^21.3.1", | ||
| "grammy": "^1.41.1", | ||
| "hono": "4.12.18", | ||
| "hono": "4.12.25", |
There was a problem hiding this comment.
P2 | Confidence: Low
Speculative: Several packages (hono, undici, ws, @whiskeysockets/baileys) are updated to versions that include fixes for high‑severity security advisories (GHSA‑88fw‑hqm2‑52qc, GHSA‑rv63‑4mwf‑qqc2, GHSA‑wwfh‑h76j‑fc44 for hono; multiple CVEs for undici; DoS fix for ws; GHSA‑qvv5‑jq5g‑4cgg for baileys). These are net positive changes that close exploitable vectors. However, without related‑context snippets showing how these libraries are used in the codebase, it is not possible to verify that the application's logic is unaffected by the accompanying non‑security fixes or that the patches are fully effective. For example, the hono update also modifies serve-static path normalization and AWS Lambda cookie handling, which could alter behavior if the application relies on the previous, now‑fixed patterns. CI tests that cover these surfaces should be confirmed to pass.
| "vite": "8.0.16", | ||
| "vitest": "4.1.3" |
There was a problem hiding this comment.
P2 | Confidence: Low
Speculative: The remaining dependency bumps (markdown-it, dompurify, vite, vitest, and the duplicate undici/baileys versions across workspaces) are minor or patch updates that carry low risk of breaking changes. The lockfile delta (2013 changed lines) is expected and clean. Still, because no related context exists to confirm that the application does not rely on any deprecated or removed API, a brief smoke test of each affected workspace is advisable. Grouped together as a single low‑priority maintainability note.
Bumps the npm_and_yarn group with 8 updates in the / directory:
0.57.10.73.17.0.0-rc.97.0.0-rc124.12.184.12.2514.1.114.2.07.24.07.28.08.19.08.21.04.0.184.1.08.0.58.0.16Bumps the npm_and_yarn group with 1 update in the /extensions/matrix directory: markdown-it.
Bumps the npm_and_yarn group with 1 update in the /extensions/whatsapp directory: @whiskeysockets/baileys.
Bumps the npm_and_yarn group with 1 update in the /extensions/zalo directory: undici.
Bumps the npm_and_yarn group with 2 updates in the /ui directory: dompurify and vite.
Bumps the npm_and_yarn group with 1 update in the /whatsapp directory: @whiskeysockets/baileys.
Bumps the npm_and_yarn group with 1 update in the /zalo directory: undici.
Updates
@mariozechner/pi-coding-agentfrom 0.57.1 to 0.73.1Release notes
Sourced from @mariozechner/pi-coding-agent's releases.
... (truncated)
Changelog
Sourced from @mariozechner/pi-coding-agent's changelog.
... (truncated)
Commits
781152fRelease v0.73.17fa924bdocs: audit unreleased changelog entries5e1e4c3feat(coding-agent): support renamed self-update package50993d7chore(coding-agent): switch back from fork to upstream jiti 2.7 (#4244)8861966fix(coding-agent): strip skill wrapper XML from HTML export user messages (#4...060c10bfix(coding-agent): skip X11-only native addon for /copy on Linux755da30fix(coding-agent): keep pending tool renders after thinking toggleb5755fdfeat(oauth): support interactive login selection (#4190)bb25a39feat(coding-agent): allow comments and trailing commas in models.json (#4162)bac2df3fix(coding-agent): handle frontmatter prompts in print modeUpdates
@whiskeysockets/baileysfrom 7.0.0-rc.9 to 7.0.0-rc12Release notes
Sourced from @whiskeysockets/baileys's releases.
... (truncated)
Changelog
Sourced from @whiskeysockets/baileys's changelog.
Commits
1aee6edchore(release): v7.0.0-rc123beb08efix(process-message): only drop self-only protocolMessages from non-self senders28ca087fix: guard fetch dispatcher option (#2557)988a34fchore(release): v7.0.0-rc1125bc999Fix release and move to NPM based libsignal6cb7d34feat: expose group online count in presence updates (#2545)a263cb0chore: bump whatsapp-rust-bridge@0.5.4 to support non simd (#2542)dfad98ffix release04f6d70ci: Update publishing to use Trusted Publishers42c19c7chore(release): v7.0.0-rc10Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@whiskeysockets/baileyssince your current version.Install script changes
This version adds
preinstall,preparescripts that run during installation. Review the package contents before updating.Updates
honofrom 4.12.18 to 4.12.25Release notes
Sourced from hono's releases.
... (truncated)
Commits
fce483e4.12.25751ba41Merge commit from forkf0b094dMerge commit from forkfa5f9bfMerge commit from fork3892a6cMerge commit from fork74c2cf8test(aws-lambda): update integration tests (#5012)7ae7cbaMerge commit from fork1b13848chore(ci): bump codecov-action to v7.0.0 (#5011)5fdde5a4.12.24c78932dfix(utils/ipaddr): render the unspecified address binary as "::" (#4998)Updates
markdown-itfrom 14.1.1 to 14.2.0Changelog
Sourced from markdown-it's changelog.
Commits
829797a14.2.0 released9ce2087Fix smartquotes perfomance02e73b8linkify-it bump68cfb8cfix: don't end HTML comment blocks on a blank line (#1155)1083137Readme cleanup97c7ca2Update funding infoc471b55Changelog update7769621isPunctChar => isPunctCharCodeaa2aa70fix: always reset parentType in lheading rule (#1131)59955f2Polish PRs #1072, #1074Updates
undicifrom 7.24.0 to 7.28.0Release notes
Sourced from undici's releases.
... (truncated)
Commits
f9eba0aBumped v7.28.0 (#5430)a027a4aBackport WebSocket maxPayloadSize fixes to v7.x (#5423)8cb10f9websocket: limit the number of fragments in a message04201f8fix: honor requestTls when proxy is SOCKS5fcd642ffix(socks5): preserve dispatch backpressure return value (#5166)bc98c97fix(socks5): use configured connector in Socks5ProxyAgent (#5168)9e1c743fix(socks5): encode embedded IPv4 tails in IPv6 literals correctly (#5099)376c8befix(socks5): enforce authenticated state before CONNECT (#5097)3805b8ffix(socks5-proxy-agent): use per-origin pools to prevent cross-origin routing...85a2405fix(cache): trim qualified field namesUpdates
wsfrom 8.19.0 to 8.21.0Release notes
Sourced from ws's releases.
... (truncated)
Commits
bca91ad[dist] 8.21.02b2abd4[security] Limit retained message parts78eabe2[security] Add latest vulnerability to SECURITY.md5d9b316[dist] 8.20.1c0327ec[security] Fix uninitialized memory disclosure inwebsocket.close()ce2a3d6[ci] Test on node 2658e45b8[ci] Do not test on node 255f26c24[ci] Run the lint step on node 248439255[dist] 8.20.0d3503c1[minor] Export thePerMessageDeflateclass and header utilsUpdates
vitestfrom 4.0.18 to 4.1.0Release notes
Sourced from vitest's releases.