Fixed
- Patched non-bundled transitive dependencies reachable via
@earendil-works/pi-ai→@google/genaiusing npmoverrides - Bumped
protobufjsto7.6.4andwsto8.21.0in the non-bundled dependency tree
Security
- Mitigated Dependabot advisories for
protobufjs(GHSA-wcpc-wj8m-hjx6, GHSA-f38q-mgvj-vph7, GHSA-jggg-4jg4-v7c6) andws(GHSA-96hv-2xvq-fx4p, GHSA-58qx-3vcg-4xpx) where reachable - Bundled copies inside
@earendil-works/pi-coding-agent@0.79.6(undici,protobufjs,ws) remain and require an upstream bump from the@earendil-workspublisher
Full Changelog: v1.0.1...v1.0.2