build(deps): bump the npm_and_yarn group across 6 directories with 9 updates - #9
build(deps): bump the npm_and_yarn group across 6 directories with 9 updates#9dependabot[bot] wants to merge 1 commit into
Conversation
…updates Bumps the npm_and_yarn group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@mariozechner/pi-coding-agent](https://github.com/badlogic/pi-mono/tree/HEAD/packages/coding-agent) | `0.57.1` | `0.73.1` | | [@whiskeysockets/baileys](https://github.com/WhiskeySockets/Baileys) | `7.0.0-rc.9` | `7.0.0-rc12` | | [hono](https://github.com/honojs/hono) | `4.12.18` | `4.12.25` | | [markdown-it](https://github.com/markdown-it/markdown-it) | `14.1.1` | `14.2.0` | | [undici](https://github.com/nodejs/undici) | `7.24.0` | `7.28.0` | | [ws](https://github.com/websockets/ws) | `8.19.0` | `8.21.0` | | [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.0.18` | `4.1.0` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.0.5` | `8.0.16` | Bumps the npm_and_yarn group with 1 update in the /extensions/matrix directory: [markdown-it](https://github.com/markdown-it/markdown-it). Bumps the npm_and_yarn group with 1 update in the /extensions/whatsapp directory: [@whiskeysockets/baileys](https://github.com/WhiskeySockets/Baileys). Bumps the npm_and_yarn group with 1 update in the /extensions/zalo directory: [undici](https://github.com/nodejs/undici). Bumps the npm_and_yarn group with 2 updates in the /ui directory: [dompurify](https://github.com/cure53/DOMPurify) and [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). Bumps the npm_and_yarn group with 1 update in the /whatsapp directory: [@whiskeysockets/baileys](https://github.com/WhiskeySockets/Baileys). Updates `@mariozechner/pi-coding-agent` from 0.57.1 to 0.73.1 - [Release notes](https://github.com/badlogic/pi-mono/releases) - [Changelog](https://github.com/earendil-works/pi/blob/main/packages/coding-agent/CHANGELOG.md) - [Commits](https://github.com/badlogic/pi-mono/commits/v0.73.1/packages/coding-agent) Updates `@whiskeysockets/baileys` from 7.0.0-rc.9 to 7.0.0-rc12 - [Release notes](https://github.com/WhiskeySockets/Baileys/releases) - [Changelog](https://github.com/WhiskeySockets/Baileys/blob/master/CHANGELOG.md) - [Commits](WhiskeySockets/Baileys@v7.0.0-rc.9...v7.0.0-rc12) Updates `hono` from 4.12.18 to 4.12.25 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.18...v4.12.25) Updates `markdown-it` from 14.1.1 to 14.2.0 - [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md) - [Commits](markdown-it/markdown-it@14.1.1...14.2.0) Updates `undici` from 7.24.0 to 7.28.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v7.24.0...v7.28.0) Updates `ws` from 8.19.0 to 8.21.0 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@8.19.0...8.21.0) Updates `vitest` from 4.0.18 to 4.1.0 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.0/packages/vitest) Updates `dompurify` from 3.4.0 to 3.4.11 - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@3.4.0...3.4.11) Updates `vite` from 8.0.5 to 8.0.16 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.0.16/packages/vite) Updates `markdown-it` from 14.1.1 to 14.2.0 - [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md) - [Commits](markdown-it/markdown-it@14.1.1...14.2.0) Updates `@whiskeysockets/baileys` from 7.0.0-rc.9 to 7.0.0-rc12 - [Release notes](https://github.com/WhiskeySockets/Baileys/releases) - [Changelog](https://github.com/WhiskeySockets/Baileys/blob/master/CHANGELOG.md) - [Commits](WhiskeySockets/Baileys@v7.0.0-rc.9...v7.0.0-rc12) Updates `undici` from 7.24.0 to 7.28.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v7.24.0...v7.28.0) Updates `dompurify` from 3.4.0 to 3.4.11 - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@3.4.0...3.4.11) Updates `vite` from 8.0.5 to 8.0.16 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.0.16/packages/vite) Updates `@whiskeysockets/baileys` from 7.0.0-rc.9 to 7.0.0-rc12 - [Release notes](https://github.com/WhiskeySockets/Baileys/releases) - [Changelog](https://github.com/WhiskeySockets/Baileys/blob/master/CHANGELOG.md) - [Commits](WhiskeySockets/Baileys@v7.0.0-rc.9...v7.0.0-rc12) --- updated-dependencies: - dependency-name: "@mariozechner/pi-coding-agent" dependency-version: 0.73.1 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@whiskeysockets/baileys" dependency-version: 7.0.0-rc12 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: hono dependency-version: 4.12.25 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: markdown-it dependency-version: 14.2.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: undici dependency-version: 7.28.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: ws dependency-version: 8.21.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: vitest dependency-version: 4.1.0 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: dompurify dependency-version: 3.4.11 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: vite dependency-version: 8.0.16 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: markdown-it dependency-version: 14.2.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@whiskeysockets/baileys" dependency-version: 7.0.0-rc12 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: undici dependency-version: 7.28.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: dompurify dependency-version: 3.4.11 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: vite dependency-version: 8.0.16 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: "@whiskeysockets/baileys" dependency-version: 7.0.0-rc12 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
AI Code Review by LlamaPReview
🎯 TL;DR & Recommendation
Recommendation: Approve with suggestions
This PR updates multiple npm dependencies across the monorepo, primarily addressing security vulnerabilities and incorporating upstream bug fixes. While the changes are generally beneficial, the @mariozechner/pi-coding-agent upgrade from 0.57.1 to 0.73.1 includes breaking changes that require audit before merging.
🌟 Strengths
- Addresses multiple high-severity security advisories (Hono, undici, ws, Baileys).
- Clean dependency bumps without code changes in most packages.
| Priority | File | Category | Impact Summary (≤12 words) | Anchors |
|---|---|---|---|---|
| P2 | package.json |
Bug (Breaking Change) | Upstream breaking changes in pi-coding-agent require audit. | |
| P2 | package.json |
Security | Fixes 5 Hono security advisories (CORS, path traversal, etc.). | |
| P2 | extensions/zalo/package.json |
Security | Fixes high-severity undici CVEs (DoS, TLS bypass). | |
| P2 | extensions/whatsapp/package.json |
Security | Patches GHSA-qvv5-jq5g-4cgg in Baileys. | path:whatsapp/package.json |
| P2 | package.json |
Security (Speculative) | ws bump fixes remote memory exhaustion DoS. | |
| P2 | package.json |
Maintainability (Suggestion) | Conflicting jiti versions possible; consider aligning. |
🔍 Notable Themes
- The
@mariozechner/pi-coding-agentupgrade introduces breaking changes (extension loading, Xiaomi provider) that require adaptation; consider deferring this upgrade until the project is audited.
⚠️ **Unanchored Suggestions (Manual Review Recommended)**
The following suggestions could not be precisely anchored to a specific line in the diff. This can happen if the code is outside the changed lines, has been significantly refactored, or if the suggestion is a general observation. Please review them carefully in the context of the full file.
📁 File: package.json
The bump from Hono 4.12.18 to 4.12.25 fixes at least five distinct security advisories (GHSA-88fw-hqm2-52qc, GHSA-rv63-4mwf-qqc2, GHSA-wwfh-h76j-fc44, GHSA-j6c9-x7qj-28xf, GHSA-wgpf-jwqj-8h8p). These include CORS wildcard origin reflection, Body Limit bypass on AWS Lambda, path traversal on Windows, cookie dropping, and header dropping. All are actively exploitable and directly affect the application’s HTTP layer. Merging this PR eliminates these attack vectors.
Related Code:
- "hono": "4.12.18",
+ "hono": "4.12.25",📁 File: extensions/zalo/package.json
Undici was bumped from 7.24.0 to 7.28.0, which includes fixes for multiple high‑severity CVEs (CVE‑2026‑12151, CVE‑2026‑9697, CVE‑2026‑6734, and others). Notably: CVE‑2026‑12151 (memory exhaustion via unlimited WebSocket continuation frames), CVE‑2026‑9697 (TLS certificate validation bypass in SOCKS5 ProxyAgent), CVE‑2026‑6734 (cross-origin routing in SOCKS5 proxy agent). The Zalo extension relies on undici for HTTP networking. Without this bump, the extension is vulnerable to remote denial‑of‑service and man‑in‑the‑middle attacks.
Related Code:
- "undici": "7.24.0"
+ "undici": "7.28.0"📁 File: extensions/whatsapp/package.json
Baileys was bumped from 7.0.0-rc.9 to 7.0.0-rc12. The upstream release notes explicitly state that rc12 patches the security flaw addressed in GHSA-qvv5-jq5g-4cgg (a high‑severity advisory) and that users should “exercise extreme caution” and upgrade. The same dependency is also present in whatsapp/package.json with an identical bump. Both WhatsApp endpoints are directly exposed to the WhatsApp protocol; the vulnerability could be remotely exploited.
Related Code:
- "@whiskeysockets/baileys": "7.0.0-rc.9",
+ "@whiskeysockets/baileys": "7.0.0-rc12",📁 File: package.json
Speculative: The PR description lists a ws bump from 8.19.0 to 8.21.0, but no direct ws change appears in any of the provided package.json diffs (it may exist only in pnpm-lock.yaml, which is not shown). The upstream release notes state that ws@8.21.0 fixes a remote memory exhaustion DoS vulnerability (high severity). If the application uses WebSockets (likely given the presence of ws as a dependency), this vulnerability currently exists in the lockfile. Strongly recommend verifying that pnpm-lock.yaml correctly resolves to ws@8.21.0.
Related Code:
💡 Have feedback? We'd love to hear it in our GitHub Discussions.
✨ This review was generated by LlamaPReview Advanced, which is free for all open-source projects. Learn more.
| "@mariozechner/pi-ai": "0.57.1", | ||
| "@mariozechner/pi-coding-agent": "0.57.1", | ||
| "@mariozechner/pi-coding-agent": "0.73.1", |
There was a problem hiding this comment.
P2 | Confidence: High
- Breaking Change: Upstream changelog documents explicit breaking changes: extension loading switched to upstream jiti 2.7 (fork removed), and the Xiaomi provider changed from Token Plan AMS to API billing (env var
XIAOMI_API_KEYredefined). Any extensions depending on the fork or using the old Xiaomi provider will break. - Maintainability: The same changelog notes extension loading now uses upstream jiti 2.7, while
package.jsonalready listsjiti: ^2.6.1. This could lead to duplicate or conflicting jiti versions; consider aligning to^2.7.0or removing the direct dependency if transitive.
|
Superseded by #10. |
Bumps the npm_and_yarn group with 8 updates in the / directory:
0.57.10.73.17.0.0-rc.97.0.0-rc124.12.184.12.2514.1.114.2.07.24.07.28.08.19.08.21.04.0.184.1.08.0.58.0.16Bumps the npm_and_yarn group with 1 update in the /extensions/matrix directory: markdown-it.
Bumps the npm_and_yarn group with 1 update in the /extensions/whatsapp directory: @whiskeysockets/baileys.
Bumps the npm_and_yarn group with 1 update in the /extensions/zalo directory: undici.
Bumps the npm_and_yarn group with 2 updates in the /ui directory: dompurify and vite.
Bumps the npm_and_yarn group with 1 update in the /whatsapp directory: @whiskeysockets/baileys.
Updates
@mariozechner/pi-coding-agentfrom 0.57.1 to 0.73.1Release notes
Sourced from @mariozechner/pi-coding-agent's releases.
... (truncated)
Changelog
Sourced from @mariozechner/pi-coding-agent's changelog.
... (truncated)
Commits
781152fRelease v0.73.17fa924bdocs: audit unreleased changelog entries5e1e4c3feat(coding-agent): support renamed self-update package50993d7chore(coding-agent): switch back from fork to upstream jiti 2.7 (#4244)8861966fix(coding-agent): strip skill wrapper XML from HTML export user messages (#4...060c10bfix(coding-agent): skip X11-only native addon for /copy on Linux755da30fix(coding-agent): keep pending tool renders after thinking toggleb5755fdfeat(oauth): support interactive login selection (#4190)bb25a39feat(coding-agent): allow comments and trailing commas in models.json (#4162)bac2df3fix(coding-agent): handle frontmatter prompts in print modeUpdates
@whiskeysockets/baileysfrom 7.0.0-rc.9 to 7.0.0-rc12Release notes
Sourced from @whiskeysockets/baileys's releases.
... (truncated)
Changelog
Sourced from @whiskeysockets/baileys's changelog.
Commits
1aee6edchore(release): v7.0.0-rc123beb08efix(process-message): only drop self-only protocolMessages from non-self senders28ca087fix: guard fetch dispatcher option (#2557)988a34fchore(release): v7.0.0-rc1125bc999Fix release and move to NPM based libsignal6cb7d34feat: expose group online count in presence updates (#2545)a263cb0chore: bump whatsapp-rust-bridge@0.5.4 to support non simd (#2542)dfad98ffix release04f6d70ci: Update publishing to use Trusted Publishers42c19c7chore(release): v7.0.0-rc10Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@whiskeysockets/baileyssince your current version.Install script changes
This version adds
preinstall,preparescripts that run during installation. Review the package contents before updating.Updates
honofrom 4.12.18 to 4.12.25Release notes
Sourced from hono's releases.
... (truncated)
Commits
fce483e4.12.25751ba41Merge commit from forkf0b094dMerge commit from forkfa5f9bfMerge commit from fork3892a6cMerge commit from fork74c2cf8test(aws-lambda): update integration tests (#5012)7ae7cbaMerge commit from fork1b13848chore(ci): bump codecov-action to v7.0.0 (#5011)5fdde5a4.12.24c78932dfix(utils/ipaddr): render the unspecified address binary as "::" (#4998)Updates
markdown-itfrom 14.1.1 to 14.2.0Changelog
Sourced from markdown-it's changelog.
Commits
829797a14.2.0 released9ce2087Fix smartquotes perfomance02e73b8linkify-it bump68cfb8cfix: don't end HTML comment blocks on a blank line (#1155)1083137Readme cleanup97c7ca2Update funding infoc471b55Changelog update7769621isPunctChar => isPunctCharCodeaa2aa70fix: always reset parentType in lheading rule (#1131)59955f2Polish PRs #1072, #1074Updates
undicifrom 7.24.0 to 7.28.0Release notes
Sourced from undici's releases.
... (truncated)
Commits
f9eba0aBumped v7.28.0 (#5430)a027a4aBackport WebSocket maxPayloadSize fixes to v7.x (#5423)8cb10f9websocket: limit the number of fragments in a message04201f8fix: honor requestTls when proxy is SOCKS5fcd642ffix(socks5): preserve dispatch backpressure return value (#5166)bc98c97fix(socks5): use configured connector in Socks5ProxyAgent (#5168)9e1c743fix(socks5): encode embedded IPv4 tails in IPv6 literals correctly (#5099)376c8befix(socks5): enforce authenticated state before CONNECT (#5097)3805b8ffix(socks5-proxy-agent): use per-origin pools to prevent cross-origin routing...85a2405fix(cache): trim qualified field namesUpdates
wsfrom 8.19.0 to 8.21.0Release notes
Sourced from ws's releases.
... (truncated)
Commits
bca91ad[dist] 8.21.02b2abd4[security] Limit retained message parts78eabe2[security] Add latest vulnerability to SECURITY.md5d9b316[dist] 8.20.1c0327ec[security] Fix uninitialized memory disclosure inwebsocket.close()ce2a3d6[ci] Test on node 2658e45b8[ci] Do not test on node 255f26c24[ci] Run the lint step on node 248439255[dist] 8.20.0d3503c1[minor] Export thePerMessageDeflateclass and header utilsUpdates
vitestfrom 4.0.18 to 4.1.0Release notes
Sourced from vitest's releases.