Skip to content

Tags: agentscore/python-sdk

Tags

v2.6.11

Toggle v2.6.11's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
Sweep dependencies, move the CI uv pin to 0.12.16, and bump to 2.6.11 (…

…#90)

## Summary

Dependency sweep for python-sdk, plus the release bump to 2.6.11. The
lock upgrade takes idna 3.20, ruff 0.16.8 and ty 0.0.82, and the lock
scans clean for prereleases (`prerelease = "disallow"` stays). The uv
version the three workflows pass to setup-uv as an input moves from
0.12.13 to 0.12.16; that pin is a workflow input dependabot never sees.
Every action pin is at its latest tag and the osv-scanner binary is
already v2.6.0.

Worked with: Varun.

## Type of change

- [ ] Bug fix (no breaking change)
- [ ] New feature (no breaking change)
- [ ] Breaking change (existing callers must update)
- [x] Docs, tests, or internal maintenance only

## Public API

none

## Test plan

Run locally on this branch after `uv lock` (re-locked for the version
bump, since uv.lock embeds it) and `uv sync --all-extras --all-groups`:
`ruff check`, `ruff format --check`, `ty check agentscore/`, `vulture`,
and `pytest tests/ --cov=agentscore` (183 passed, 8 skipped, 99%
coverage). Nothing runtime changed, so no new tests. Release: tag
v2.6.11 after merge and watch the publish run, then move the
`agentscore-py` floor in python-commerce.

## Checklist

- [x] Tests cover the new behavior, and the suite passes locally
- [x] Lint, format, and type checks pass
- [x] Docs and README examples updated if the public surface changed
- [x] No secrets, credentials, or personal data in the diff or the tests

v2.6.10

Toggle v2.6.10's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
Sweep dependencies, pin uv in CI, and bump to 2.6.10 (#89)

## Summary

Dependency sweep for python-sdk, plus the release bump to 2.6.10.

- `uv lock --upgrade`: coverage 7.16.0 to 7.16.1 and lefthook 2.1.12 to
2.1.14 (dev tooling). No prereleases in the lock; `prerelease =
"disallow"` stays.
- uv itself is now pinned in CI: every `astral-sh/setup-uv` step (ci,
security, publish) passes `version: "0.12.13"`, the current uv release,
which is the org's CI standard for Python repos. Without it, CI
installed whatever uv was newest under `required-version`.
- The osv-scanner binary the Dependency Scan job downloads moves from
v2.5.1 to v2.6.0. Both of these pins are workflow inputs, so dependabot
never proposes them.
- Version 2.6.9 to 2.6.10, with `uv.lock` re-locked so its embedded
project version matches.

The one runtime dependency, `httpx>=0.25.0,<1.0.0`, resolves to 0.28.1,
which is httpx's latest release.

Checked and found current: `astral-sh/setup-uv@v10.1.0`,
`pypa/gh-action-pypi-publish@v1.14.2`, `actions/setup-python@v7`
(v7.0.0), `actions/checkout@v7`, `actions/cache@v6`,
`useblacksmith/checkout@v1`; dependabot config (uv and actions
ecosystems); hook/CI parity (hooks run ruff check, ruff format, ty and
vulture; CI adds pytest).

Not changed, deliberately: CI tests on Python 3.12 and the audit job
runs 3.13. That is a test-matrix choice, not a dependency pin, and
`requires-python` stays `>=3.11`.

## Type of change

- [ ] Bug fix (no breaking change)
- [ ] New feature (no breaking change)
- [ ] Breaking change (existing callers must update)
- [x] Docs, tests, or internal maintenance only

## Public API

None.

## Test plan

Locally, from `uv sync --frozen --all-extras --all-groups`: `ruff
check`, `ruff format --check`, `ty check agentscore/`, `vulture`,
`pytest` (183 passed, 8 skipped, 99.85% coverage against the 95% bar)
and `uv build`, all exit 0. `osv-scanner` 2.6.0 over `uv.lock`: 24
packages, no issues. `pip-audit` over the exported requirements: exit 0.
The three workflow files parse, and each setup-uv step carries the
version input.

## Checklist

- [x] Tests cover the new behavior, and the suite passes locally
- [x] Lint, format, and type checks pass
- [x] Docs and README examples updated if the public surface changed
- [x] No secrets, credentials, or personal data in the diff or the tests

Worked with Varun. The tag follows the merge.

v2.6.9

Toggle v2.6.9's commit message
v2.6.9: create_session gains the kind option (kyc | sign_in)

v2.6.8

Toggle v2.6.8's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
2.6.8: dependency sweep (anyio, ruff, ty) (#84)

## Summary

Dependency sweep, 2026-09-05, and the 2.6.8 version bump so
agentscore-commerce can move its floor in the same waterfall. The lock
moves anyio 4.15.0, ruff 0.16.6, ty 0.0.78; `uv lock` re-run after the
version bump so the lock's embedded project version matches. No
prerelease resolved.

Worked with Varun, who asked for the SDK-first sweep.

## Type of change

- [ ] Bug fix (no breaking change)
- [ ] New feature (no breaking change)
- [ ] Breaking change (existing callers must update)
- [x] Docs, tests, or internal maintenance only

## Public API

none

## Test plan

`uv sync --all-extras --all-groups`; `ruff check`, `ruff format
--check`, `ty check`, and vulture with CI's exact invocation all exit 0;
pytest 183 passed, 8 skipped, coverage 100%.

## Checklist

- [x] Tests cover the new behavior, and the suite passes locally
- [x] Lint, format, and type checks pass
- [x] Docs and README examples updated if the public surface changed
- [x] No secrets, credentials, or personal data in the diff or the tests

v2.6.7

Toggle v2.6.7's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
Release 2.6.7: refresh deps and lockfile (#83)

## Summary

Bumps `agentscore-py` to 2.6.7. `uv lock --upgrade` refreshed dev
tooling within constraints (coverage 7.16.0, ty 0.0.76) with no
prereleases (the `prerelease = "disallow"` guard held), on top of the
already-merged osv-scanner v2.5.1 and minor-patch group. The uv.lock
own-version is synced to 2.6.7. Actions are current (setup-uv v10.0.1,
pypi-publish v1.14.2 both latest).

## Type of change

- [ ] Bug fix (no breaking change)
- [ ] New feature (no breaking change)
- [ ] Breaking change (existing callers must update)
- [x] Docs, tests, or internal maintenance only

## Public API

None. No exported symbols, signatures, or wire formats changed; runtime
dependencies are unchanged.

## Test plan

Ran `uv run ruff check`, `uv run ty check`, and `uv run pytest`: all
clean, 183 passed (8 skipped), 100% coverage. No behavior change, so no
new tests.

## Checklist

- [x] Tests cover the new behavior, and the suite passes locally
- [x] Lint, format, and type checks pass
- [x] Docs and README examples updated if the public surface changed
- [x] No secrets, credentials, or personal data in the diff or the tests

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

v2.6.6

Toggle v2.6.6's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
Take the minor-patch group and cut 2.6.6 (#78)

## Summary

Dependency sweep for this repo: idna 3.19, pygments 2.21.0,
python-dotenv 1.2.3,
ruff 0.16.4 and ty 0.0.73. All are dev tooling or transitives. No
declared
dependency range in `pyproject.toml` changed, so nothing here reaches a
consumer.

The version bump to 2.6.6 is deliberate rather than required: nothing in
this diff
obliges a caller to act. It exists so the SDK ships as tier 1 of a
coordinated
release across the SDKs, the commerce libraries and pay, which was
Varun's call
after I flagged that by the usual "bump only where a consumer must act"
rule this
repo did not need a release at all.

`uv.lock` embeds the project's own version, so it is re-locked in the
same commit
rather than left naming 2.6.5.

Worked with: Varun.

## Type of change

- [ ] Bug fix (no breaking change)
- [ ] New feature (no breaking change)
- [ ] Breaking change (existing callers must update)
- [x] Docs, tests, or internal maintenance only

## Public API

None. No exported symbol, signature, wire format or response shape
changes. The
only non-lockfile edit is the `version` field.

## Test plan

Ran the repo's full gate set locally on this branch:

- `uv run ruff check .` clean
- `uv run ruff format --check .`: 21 files already formatted
- `uv run ty check agentscore/` clean
- `uv run vulture . vulture_whitelist.py --min-confidence 80 --exclude
.venv` clean
- `uv run pytest tests/ -q`: 183 passed, 8 skipped, 100% coverage
against a 95% floor
- `osv-scanner` over `uv.lock`: no issues found across 24 packages

No tests were added or changed, because no behavior changed.

## Checklist

- [x] Tests cover the new behavior, and the suite passes locally
      (no new behavior; the existing suite passes unchanged)
- [x] Lint, format, and type checks pass
- [x] Docs and README examples updated if the public surface changed
      (public surface did not change, so nothing to update)
- [x] No secrets, credentials, or personal data in the diff or the tests

## Deliberately not done

- Consumer floors are not raised to `>=2.6.6` in python-commerce or
core/store.
That version does not exist on PyPI yet, so raising a floor now would
make
`uv lock` unresolvable. The existing ranges already accept it, so no
consumer
edit is needed; pinning to the exact tested combination is a follow-up
after
  this publishes.
- No tag pushed. The publish workflow fires on `v*`, and a PyPI version
is
  permanent, so the tag is left for a deliberate step after this merges.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>

v2.6.5

Toggle v2.6.5's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
Bump to 2.6.5: type operator_handle on the assess response (#75)

## Summary

`/v1/assess` now returns `operator_handle` on the operator-token path: a
stable, pairwise handle for the account behind the presented credential.
Typed here so SDK consumers can read it without casting.

It is the value to key durable state on. An `opc_` lives 24h and rotates
silently off a 90-day refresh, so anything keyed on the token instance
is stranded every time one rotates, and revoking a leaked token would
forfeit what it was holding. The handle derives from the account
instead, and is pairwise per calling account so handles never correlate
across merchants.

Type-only change: no runtime behavior, no new request field. Against an
older API the field is simply absent.

## Type of change

- [ ] Bug fix (no breaking change)
- [x] New feature (no breaking change)
- [ ] Breaking change (existing callers must update)
- [ ] Docs, tests, or internal maintenance only

## Public API

Additive: one optional field on the assess response type. No migration
for existing callers.

## Test plan

Existing suites run clean against the change; no behavior to add tests
for, since nothing but the type surface moved. Node: lint, typecheck,
166 passed / 9 skipped. Python: ruff, ty, 183 passed / 8 skipped at 100%
coverage.

## Checklist

- [x] Tests cover the new behavior, and the suite passes locally
- [x] Lint, format, and type checks pass
- [x] Docs and README examples updated if the public surface changed
- [x] No secrets, credentials, or personal data in the diff or the tests

v2.6.4

Toggle v2.6.4's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
Take ty 0.0.70, bump to 2.6.4 (#74)

## Summary

Routine dev-tooling sweep ahead of the commerce-side release chain: ty
0.0.69 to 0.0.70 (the only update the lock resolved). Version bumped to
2.6.4 for the patch release.

## Type of change

- [ ] Bug fix (no breaking change)
- [ ] New feature (no breaking change)
- [ ] Breaking change (existing callers must update)
- [x] Docs, tests, or internal maintenance only

## Public API

Unchanged. ty is a dev-group type checker; no runtime surface is
touched.

## Test plan

ruff check + format, ty (clean on the new version), vulture, and the
full suite (183 passing, 8 skipped) all green.

## Checklist

- [x] Tests cover the new behavior, and the suite passes locally
- [x] Lint, format, and type checks pass
- [x] Docs and README examples updated if the public surface changed

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

v2.6.3

Toggle v2.6.3's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
Refresh the dev toolchain lock, release 2.6.3 (#72)

## Summary

Routine dependency pass over the whole tree. Only one package had a
newer version inside its declared range: `ty` 0.0.65 to 0.0.66, a
dev-group type checker. Everything else is already current.

Reported so the next pass does not re-derive it: `httpx` (the single
runtime dependency) is current within `>=0.25.0,<1.0.0`, and the
lockfile carries no advisories under either scanner.

## Type of change

- [ ] Bug fix (no breaking change)
- [ ] New feature (no breaking change)
- [ ] Breaking change (existing callers must update)
- [x] Docs, tests, or internal maintenance only

## Public API

None. `pyproject.toml` is untouched; the diff is `uv.lock` alone. `ty`
is a dev-group tool that no consumer resolves, so no release is needed
and no caller has to act.

## Test plan

- `uv sync --all-extras --all-groups --upgrade`, then:
- `uv run ruff check .` all checks passed
- `uv run ruff format --check .` 21 files already formatted
- `uv run ty check agentscore/` all checks passed
- `uv run pytest tests/`: 183 passed, 8 skipped, 100.00% coverage (gate
is 95%)
- osv-scanner v2.4.0 over `uv.lock`: no issues found

## Checklist

- [x] Tests cover the new behavior, and the suite passes locally
- [x] Lint, format, and type checks pass
- [x] Docs and README examples updated if the public surface changed
- [x] No secrets, credentials, or personal data in the diff or the tests

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>

v2.6.2

Toggle v2.6.2's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
Sweep deps and cut 2.6.2 (#71)

## Summary

Dependency sweep for this repo, plus a version bump so it can be
released.

- `coverage` 7.15.2 to 7.15.3, the only available bump.
- Version to 2.6.2.

Same caveat as the node SDK, and it decides whether this is worth
publishing: nothing here reaches a consumer. The only commit since
v2.6.1 is a one-line `ci.yml` change and coverage is a dev dependency,
so the published wheel is unchanged.

`uv.lock` was re-locked after the version bump, not just after the
dependency change. The lock embeds the project's own version, so a
`pyproject.toml` bump leaves it stale with nothing erroring and no gate
noticing: the two files simply disagree about what the package is. It
was sitting at 2.6.1 and `uv lock` moved it to 2.6.2.

## Type of change

- [ ] Bug fix (no breaking change)
- [ ] New feature (no breaking change)
- [ ] Breaking change (existing callers must update)
- [x] Docs, tests, or internal maintenance only

## Public API

**None.** No exported class, function signature, wire format, or
response shape changed. The published wheel is unchanged; the only
difference is a dev dependency.

No migration for callers. Both consumers in this workspace
(`core/store`, `python-commerce`) declare `agentscore-py>=2.6.1`, which
already accepts 2.6.2, so no manifest edit is required downstream.

## Test plan

No tests added, because no behavior changed. The existing suite was run
to confirm the bump breaks nothing:

- `uv run pytest`: 183 passed, 8 skipped, 100% coverage against a 95%
floor
- `ruff check` and `ruff format --check`: clean
- `uv run ty check`: clean
- `uv run vulture . vulture_whitelist.py --min-confidence 80 --exclude
.venv`: clean

Vulture is run through the project's exact CI invocation rather than a
bare `vulture`, which reports low-confidence findings the project
deliberately filters out and would read as a regression that is not
there.

Reproduce with `uv sync --all-extras --all-groups` followed by those
four commands.

## Checklist

- [x] Tests cover the new behavior, and the suite passes locally
- [x] Lint, format, and type checks pass
- [x] Docs and README examples updated if the public surface changed
(not applicable, public surface unchanged)
- [x] No secrets, credentials, or personal data in the diff or the tests