Skip to content

fix(pi,ci): patch Pi advisories, audit dependencies, and serialize release publication - #248

Merged
Coding-Dev-Tools merged 18 commits into
mainfrom
codex/pi-ci-audit-fix-20261001
Oct 3, 2026
Merged

Coding-Dev-Tools merged 18 commits into
mainfrom
codex/pi-ci-audit-fix-20261001

Conversation

@Coding-Dev-Tools

Copy link
Copy Markdown
Owner

Fixes locked Pi test dependency without waiving audits, patches Pi advisories, and serializes release publication queue.

Coding-Dev-Tools and others added 16 commits September 28, 2026 00:30
…ures

npm published three advisories after this stack last passed CI, failing both
Pi extension jobs introduced by the full development-tree audit:

- fast-uri <=3.1.7 and ip-address <=10.7.0 are production dependencies of
  the MCP SDK. Update the Pi lockfile to fast-uri 3.1.8 and ip-address 10.7.2.
- brace-expansion <=5.0.11 exists only inside the Pi coding agent used as the
  CI test host. That package ships its own npm-shrinkwrap.json, so npm
  overrides cannot replace it, and no Pi release (through 0.99.1) has a fixed
  lockfile yet.

Production dependencies stay strictly audited. Development advisories still
fail, except those confined to the test host's own lockfile, which are
reported as warnings until a fixed host can be adopted.

The step now runs under bash on both runners. On Windows the default pwsh
wrapper reported only the final command's exit code, so a failing npm ci,
verify or integration run was hidden whenever the audit passed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014ksPGXPZQTikJYpaGHa6R6
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@Coding-Dev-Tools
Coding-Dev-Tools merged commit cbfd720 into main Oct 3, 2026
30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants