Forward-merge release/0.4 into main - #346
Merged
Merged
Conversation
#### Overview Updates `@earendil-works/pi-ai` and `@earendil-works/pi-coding-agent` from `0.84.2` to `0.86.0`. Pi `0.86.0` resolves the high-severity npm audit failure by using `undici@8.10.2`. This is the smallest published Pi upgrade that resolves the advisory. Upgrading to `0.99.1`, as suggested by `npm audit fix --force`, would introduce a larger breaking-version change. Pi remains a caller-installed harness and is not added as a production dependency of the adapter package. The lockfile and Node attribution file were regenerated. Added dependencies use MIT or Unlicense terms. No unknown, proprietary, copyleft, or network-copyleft licenses were introduced. Dependency approval is requested from Saloni Jain. #### Details - Updates the optional Pi peer dependency ranges to `^0.86.0`. - Updates exact development and test pins to `0.86.0`. - Updates installation diagnostics, package checks, tests, and documentation. - Regenerates `adapters/typescript/package-lock.json`. - Regenerates `ATTRIBUTIONS-Node.md`. - Removes the vulnerable `undici@8.9.0` resolution. - Does not change the caller-installed harness model. - Does not introduce a breaking change to NeMo Fabric. #### Validation - `npm ci --prefix adapters/typescript --ignore-scripts --no-audit --no-fund` - `npm test --prefix adapters/typescript --workspace nemo-fabric-adapters-pi` - `npx --yes --package=bun@1.4.2 -- npm test --prefix adapters/typescript` - `npm audit --prefix adapters/typescript --audit-level=high` - `.venv/bin/python scripts/licensing/license_diff.py node --base-ref upstream/main` - `.venv/bin/python scripts/licensing/license_diff.py node --base-ref upstream/main` - `git diff --check` The focused Pi tests, full TypeScript adapter suite, dependency checks, temporary consumer-install checks, and high-severity audit gate pass. Existing low- and moderate-severity OpenCode findings remain below the configured audit threshold. #### Dependency and license review The complete output from: ```bash .venv/bin/python scripts/licensing/license_diff.py node --base-ref upstream/main ``` is included below. The command completed successfully with exit code 0. <details> <summary>Complete license-diff output</summary> ```text [license-diff] selected languages: node [license-diff] generating current inventory [license-diff] current: generating Node inventory [license-diff] current: Node inventory complete (613 packages) [license-diff] current inventory complete [license-diff] checking out base ref upstream/main into a temporary worktree [license-diff] base: generating Node inventory [license-diff] base: Node inventory complete (602 packages) [license-diff] base inventory complete [license-diff] removing temporary base worktree [license-diff] comparing inventories [license-diff] rendering Markdown output [license-diff] done # Lockfile License Changes ## Node ### Added - `@earendil-works/chord` 0.86.0 (MIT) - `@esbuild/aix-ppc64` 0.28.2 (MIT) - `@esbuild/android-arm` 0.28.2 (MIT) - `@esbuild/android-arm64` 0.28.2 (MIT) - `@esbuild/android-x64` 0.28.2 (MIT) - `@esbuild/darwin-arm64` 0.28.2 (MIT) - `@esbuild/darwin-x64` 0.28.2 (MIT) - `@esbuild/freebsd-arm64` 0.28.2 (MIT) - `@esbuild/freebsd-x64` 0.28.2 (MIT) - `@esbuild/linux-arm` 0.28.2 (MIT) - `@esbuild/linux-arm64` 0.28.2 (MIT) - `@esbuild/linux-ia32` 0.28.2 (MIT) - `@esbuild/linux-loong64` 0.28.2 (MIT) - `@esbuild/linux-mips64el` 0.28.2 (MIT) - `@esbuild/linux-ppc64` 0.28.2 (MIT) - `@esbuild/linux-riscv64` 0.28.2 (MIT) - `@esbuild/linux-s390x` 0.28.2 (MIT) - `@esbuild/linux-x64` 0.28.2 (MIT) - `@esbuild/netbsd-arm64` 0.28.2 (MIT) - `@esbuild/netbsd-x64` 0.28.2 (MIT) - `@esbuild/openbsd-arm64` 0.28.2 (MIT) - `@esbuild/openbsd-x64` 0.28.2 (MIT) - `@esbuild/openharmony-arm64` 0.28.2 (MIT) - `@esbuild/sunos-x64` 0.28.2 (MIT) - `@esbuild/win32-arm64` 0.28.2 (MIT) - `@esbuild/win32-ia32` 0.28.2 (MIT) - `@esbuild/win32-x64` 0.28.2 (MIT) - `@stablelib/base64` 1.0.1 (MIT) - `esbuild` 0.28.2 (MIT) - `fast-sha256` 1.3.0 (Unlicense) - `proxy-agent-negotiate` 1.1.0 (MIT) - `standardwebhooks` 1.1.1 (MIT) ### Removed - `@earendil-works/pi-client` 0.84.2 (MIT) - `@earendil-works/pi-protocol` 0.84.2 (MIT) - `@mariozechner/clipboard` 0.3.9 (MIT) - `@mariozechner/clipboard-darwin-arm64` 0.3.9 (MIT) - `@mariozechner/clipboard-darwin-universal` 0.3.9 (MIT) - `@mariozechner/clipboard-darwin-x64` 0.3.9 (MIT) - `@mariozechner/clipboard-linux-arm64-gnu` 0.3.9 (MIT) - `@mariozechner/clipboard-linux-arm64-musl` 0.3.9 (MIT) - `@mariozechner/clipboard-linux-riscv64-gnu` 0.3.9 (MIT) - `@mariozechner/clipboard-linux-x64-gnu` 0.3.9 (MIT) - `@mariozechner/clipboard-linux-x64-musl` 0.3.9 (MIT) - `@mariozechner/clipboard-win32-arm64-msvc` 0.3.9 (MIT) - `@mariozechner/clipboard-win32-x64-msvc` 0.3.9 (MIT) - `@nodable/entities` 2.1.0 (MIT) - `fast-xml-builder` 1.2.0 (MIT) - `fast-xml-parser` 5.7.3 (MIT) - `path-expression-matcher` 1.5.0 (MIT) - `strnum` 2.3.0 (MIT) - `xml-naming` 0.1.0 (MIT) ### Updated/Changed #### `@anthropic-ai/sdk` Before: - `@anthropic-ai/sdk` 0.71.2 (MIT) - `@anthropic-ai/sdk` 0.91.1 (MIT) After: - `@anthropic-ai/sdk` 0.124.0 (MIT) - `@anthropic-ai/sdk` 0.71.2 (MIT) #### `@aws-sdk/client-bedrock-runtime` Before: - `@aws-sdk/client-bedrock-runtime` 3.1048.0 (Apache-2.0) After: - `@aws-sdk/client-bedrock-runtime` 3.1127.0 (Apache-2.0) #### `@aws-sdk/core` Before: - `@aws-sdk/core` 3.974.11 (Apache-2.0) - `@aws-sdk/core` 3.978.0 (Apache-2.0) After: - `@aws-sdk/core` 3.977.9 (Apache-2.0) - `@aws-sdk/core` 3.978.1 (Apache-2.0) #### `@aws-sdk/credential-provider-env` Before: - `@aws-sdk/credential-provider-env` 3.972.37 (Apache-2.0) - `@aws-sdk/credential-provider-env` 3.972.69 (Apache-2.0) After: - `@aws-sdk/credential-provider-env` 3.972.70 (Apache-2.0) - `@aws-sdk/credential-provider-env` 3.972.72 (Apache-2.0) #### `@aws-sdk/credential-provider-http` Before: - `@aws-sdk/credential-provider-http` 3.972.39 (Apache-2.0) - `@aws-sdk/credential-provider-http` 3.972.71 (Apache-2.0) After: - `@aws-sdk/credential-provider-http` 3.972.72 (Apache-2.0) - `@aws-sdk/credential-provider-http` 3.972.74 (Apache-2.0) #### `@aws-sdk/credential-provider-ini` Before: - `@aws-sdk/credential-provider-ini` 3.972.41 (Apache-2.0) - `@aws-sdk/credential-provider-ini` 3.973.14 (Apache-2.0) After: - `@aws-sdk/credential-provider-ini` 3.973.15 (Apache-2.0) - `@aws-sdk/credential-provider-ini` 3.973.17 (Apache-2.0) #### `@aws-sdk/credential-provider-login` Before: - `@aws-sdk/credential-provider-login` 3.972.41 (Apache-2.0) - `@aws-sdk/credential-provider-login` 3.972.76 (Apache-2.0) After: - `@aws-sdk/credential-provider-login` 3.972.77 (Apache-2.0) - `@aws-sdk/credential-provider-login` 3.972.79 (Apache-2.0) #### `@aws-sdk/credential-provider-node` Before: - `@aws-sdk/credential-provider-node` 3.972.42 (Apache-2.0) - `@aws-sdk/credential-provider-node` 3.972.80 (Apache-2.0) After: - `@aws-sdk/credential-provider-node` 3.972.82 (Apache-2.0) - `@aws-sdk/credential-provider-node` 3.972.84 (Apache-2.0) #### `@aws-sdk/credential-provider-process` Before: - `@aws-sdk/credential-provider-process` 3.972.37 (Apache-2.0) - `@aws-sdk/credential-provider-process` 3.972.69 (Apache-2.0) After: - `@aws-sdk/credential-provider-process` 3.972.70 (Apache-2.0) - `@aws-sdk/credential-provider-process` 3.972.72 (Apache-2.0) #### `@aws-sdk/credential-provider-sso` Before: - `@aws-sdk/credential-provider-sso` 3.972.41 (Apache-2.0) - `@aws-sdk/credential-provider-sso` 3.973.13 (Apache-2.0) After: - `@aws-sdk/credential-provider-sso` 3.973.14 (Apache-2.0) - `@aws-sdk/credential-provider-sso` 3.973.16 (Apache-2.0) #### `@aws-sdk/credential-provider-web-identity` Before: - `@aws-sdk/credential-provider-web-identity` 3.972.41 (Apache-2.0) - `@aws-sdk/credential-provider-web-identity` 3.972.75 (Apache-2.0) After: - `@aws-sdk/credential-provider-web-identity` 3.972.76 (Apache-2.0) - `@aws-sdk/credential-provider-web-identity` 3.972.78 (Apache-2.0) #### `@aws-sdk/eventstream-handler-node` Before: - `@aws-sdk/eventstream-handler-node` 3.972.16 (Apache-2.0) - `@aws-sdk/eventstream-handler-node` 3.972.33 (Apache-2.0) After: - `@aws-sdk/eventstream-handler-node` 3.972.34 (Apache-2.0) - `@aws-sdk/eventstream-handler-node` 3.972.35 (Apache-2.0) #### `@aws-sdk/middleware-eventstream` Before: - `@aws-sdk/middleware-eventstream` 3.972.12 (Apache-2.0) - `@aws-sdk/middleware-eventstream` 3.972.28 (Apache-2.0) After: - `@aws-sdk/middleware-eventstream` 3.972.29 (Apache-2.0) - `@aws-sdk/middleware-eventstream` 3.972.30 (Apache-2.0) #### `@aws-sdk/middleware-websocket` Before: - `@aws-sdk/middleware-websocket` 3.972.19 (Apache-2.0) - `@aws-sdk/middleware-websocket` 3.972.51 (Apache-2.0) After: - `@aws-sdk/middleware-websocket` 3.972.52 (Apache-2.0) - `@aws-sdk/middleware-websocket` 3.972.54 (Apache-2.0) #### `@aws-sdk/nested-clients` Before: - `@aws-sdk/nested-clients` 3.997.45 (Apache-2.0) - `@aws-sdk/nested-clients` 3.997.9 (Apache-2.0) After: - `@aws-sdk/nested-clients` 3.997.44 (Apache-2.0) - `@aws-sdk/nested-clients` 3.997.46 (Apache-2.0) #### `@aws-sdk/signature-v4-multi-region` Before: - `@aws-sdk/signature-v4-multi-region` 3.996.27 (Apache-2.0) - `@aws-sdk/signature-v4-multi-region` 3.996.46 (Apache-2.0) After: - `@aws-sdk/signature-v4-multi-region` 3.996.46 (Apache-2.0) - `@aws-sdk/signature-v4-multi-region` 3.996.47 (Apache-2.0) #### `@aws-sdk/token-providers` Before: - `@aws-sdk/token-providers` 3.1048.0 (Apache-2.0) - `@aws-sdk/token-providers` 3.1111.0 (Apache-2.0) After: - `@aws-sdk/token-providers` 3.1116.0 (Apache-2.0) - `@aws-sdk/token-providers` 3.1127.0 (Apache-2.0) - `@aws-sdk/token-providers` 3.1138.0 (Apache-2.0) #### `@aws-sdk/types` Before: - `@aws-sdk/types` 3.973.8 (Apache-2.0) - `@aws-sdk/types` 3.974.5 (Apache-2.0) After: - `@aws-sdk/types` 3.974.5 (Apache-2.0) - `@aws-sdk/types` 3.974.6 (Apache-2.0) #### `@aws-sdk/util-locate-window` Before: - `@aws-sdk/util-locate-window` 3.965.10 (Apache-2.0) - `@aws-sdk/util-locate-window` 3.965.5 (Apache-2.0) After: - `@aws-sdk/util-locate-window` 3.965.10 (Apache-2.0) #### `@aws-sdk/xml-builder` Before: - `@aws-sdk/xml-builder` 3.972.24 (Apache-2.0) - `@aws-sdk/xml-builder` 3.972.40 (Apache-2.0) After: - `@aws-sdk/xml-builder` 3.972.40 (Apache-2.0) - `@aws-sdk/xml-builder` 3.972.41 (Apache-2.0) #### `@aws/lambda-invoke-store` Before: - `@aws/lambda-invoke-store` 0.2.4 (Apache-2.0) - `@aws/lambda-invoke-store` 0.3.0 (Apache-2.0) After: - `@aws/lambda-invoke-store` 0.3.0 (Apache-2.0) #### `@earendil-works/pi-agent-core` Before: - `@earendil-works/pi-agent-core` 0.84.2 (MIT) After: - `@earendil-works/pi-agent-core` 0.86.0 (MIT) #### `@earendil-works/pi-ai` Before: - `@earendil-works/pi-ai` 0.84.2 (MIT) After: - `@earendil-works/pi-ai` 0.86.0 (MIT) #### `@earendil-works/pi-coding-agent` Before: - `@earendil-works/pi-coding-agent` 0.84.2 (MIT) After: - `@earendil-works/pi-coding-agent` 0.86.0 (MIT) #### `@earendil-works/pi-telemetry` Before: - `@earendil-works/pi-telemetry` 0.84.2 (MIT) After: - `@earendil-works/pi-telemetry` 0.86.0 (MIT) - `@earendil-works/pi-telemetry` 0.86.1 (MIT) #### `@earendil-works/pi-tui` Before: - `@earendil-works/pi-tui` 0.84.2 (MIT) After: - `@earendil-works/pi-tui` 0.86.0 (MIT) #### `@google/genai` Before: - `@google/genai` 1.52.0 (Apache-2.0) After: - `@google/genai` 2.21.0 (Apache-2.0) #### `@smithy/core` Before: - `@smithy/core` 3.24.3 (Apache-2.0) - `@smithy/core` 3.33.3 (Apache-2.0) After: - `@smithy/core` 3.33.3 (Apache-2.0) - `@smithy/core` 3.35.0 (Apache-2.0) #### `@smithy/credential-provider-imds` Before: - `@smithy/credential-provider-imds` 4.3.3 (Apache-2.0) - `@smithy/credential-provider-imds` 4.5.2 (Apache-2.0) After: - `@smithy/credential-provider-imds` 4.5.2 (Apache-2.0) #### `@smithy/fetch-http-handler` Before: - `@smithy/fetch-http-handler` 5.4.3 (Apache-2.0) - `@smithy/fetch-http-handler` 5.7.2 (Apache-2.0) After: - `@smithy/fetch-http-handler` 5.8.0 (Apache-2.0) #### `@smithy/node-http-handler` Before: - `@smithy/node-http-handler` 4.11.3 (Apache-2.0) - `@smithy/node-http-handler` 4.12.1 (Apache-2.0) - `@smithy/node-http-handler` 4.7.3 (Apache-2.0) After: - `@smithy/node-http-handler` 4.12.1 (Apache-2.0) #### `@smithy/signature-v4` Before: - `@smithy/signature-v4` 5.4.3 (Apache-2.0) - `@smithy/signature-v4` 5.7.3 (Apache-2.0) After: - `@smithy/signature-v4` 5.7.3 (Apache-2.0) #### `@smithy/types` Before: - `@smithy/types` 4.14.2 (Apache-2.0) - `@smithy/types` 4.18.0 (Apache-2.0) After: - `@smithy/types` 4.18.0 (Apache-2.0) - `@smithy/types` 4.19.0 (Apache-2.0) #### `agent-base` Before: - `agent-base` 7.1.4 (MIT) After: - `agent-base` 7.1.4 (MIT) - `agent-base` 9.0.0 (MIT) #### `chalk` Before: - `chalk` 5.6.2 (MIT) After: - `chalk` 6.0.0 (MIT) #### `glob` Before: - `glob` 13.0.5 (BlueOak-1.0.0) - `glob` 13.0.6 (BlueOak-1.0.0) After: - `glob` 13.0.5 (BlueOak-1.0.0) #### `grok-mermaid` Before: - `grok-mermaid` 0.2.2 (Apache-2.0) After: - `grok-mermaid` 0.2.3 (Apache-2.0) #### `http-proxy-agent` Before: - `http-proxy-agent` 7.0.2 (MIT) After: - `http-proxy-agent` 7.0.2 (MIT) - `http-proxy-agent` 9.1.0 (MIT) #### `https-proxy-agent` Before: - `https-proxy-agent` 7.0.6 (MIT) After: - `https-proxy-agent` 7.0.6 (MIT) - `https-proxy-agent` 9.1.0 (MIT) #### `ignore` Before: - `ignore` 7.0.5 (MIT) After: - `ignore` 7.0.5 (MIT) - `ignore` 7.0.8 (MIT) #### `marked` Before: - `marked` 17.0.1 (MIT) - `marked` 18.0.5 (MIT) After: - `marked` 17.0.1 (MIT) - `marked` 18.0.11 (MIT) #### `minimatch` Before: - `minimatch` 10.2.5 (BlueOak-1.0.0) After: - `minimatch` 10.2.5 (BlueOak-1.0.0) - `minimatch` 10.2.6 (BlueOak-1.0.0) #### `protobufjs` Before: - `protobufjs` 7.6.5 (BSD-3-Clause) After: - `protobufjs` 7.6.5 (BSD-3-Clause) - `protobufjs` 7.6.6 (BSD-3-Clause) #### `semver` Before: - `semver` 7.8.0 (ISC) - `semver` 7.8.5 (ISC) After: - `semver` 7.8.5 (ISC) #### `typebox` Before: - `typebox` 1.3.7 (MIT) After: - `typebox` 1.3.27 (MIT) #### `undici` Before: - `undici` 6.28.1 (MIT) - `undici` 8.10.2 (MIT) - `undici` 8.9.0 (MIT) After: - `undici` 6.28.1 (MIT) - `undici` 8.10.2 (MIT) ``` </details> All newly added packages use MIT or Unlicense terms. No `UNKNOWN`, proprietary, copyleft, or network-copyleft licenses were introduced. This report is evidence for dependency review; final compatibility approval is requested from Saloni Jain. #### Where should the reviewer start? Start with `adapters/typescript/pi/package.json` for the supported Pi version change, followed by `adapters/typescript/package-lock.json` for the resolved dependency graph and removal of `undici@8.9.0`. #### Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to) - Relates to: none - [x] I confirm this contribution is my own work, or I have the right to submit it under this project's license. - [x] I searched existing issues and open pull requests, and this does not duplicate existing work. Authors: - Soumili Nandi (https://github.com/soumilinandi) Approvers: - Anuradha Karuppiah (https://github.com/AnuradhaKaruppiah) - https://github.com/Salonijain27 URL: #337
Author
|
SUCCESS - forward-merge complete. |
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: NVIDIA/NeMo-Fabric/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Forward-merge triggered by push to release/0.4 that creates a PR to keep main up-to-date. If this PR is unable to be immediately merged due to conflicts, it will remain open for the team to manually merge. See forward-merger docs for more info.