Tags: agentscore/python-sdk
Tags
Sweep dependencies, move the CI uv pin to 0.12.16, and bump to 2.6.11 (… …#90) ## Summary Dependency sweep for python-sdk, plus the release bump to 2.6.11. The lock upgrade takes idna 3.20, ruff 0.16.8 and ty 0.0.82, and the lock scans clean for prereleases (`prerelease = "disallow"` stays). The uv version the three workflows pass to setup-uv as an input moves from 0.12.13 to 0.12.16; that pin is a workflow input dependabot never sees. Every action pin is at its latest tag and the osv-scanner binary is already v2.6.0. Worked with: Varun. ## Type of change - [ ] Bug fix (no breaking change) - [ ] New feature (no breaking change) - [ ] Breaking change (existing callers must update) - [x] Docs, tests, or internal maintenance only ## Public API none ## Test plan Run locally on this branch after `uv lock` (re-locked for the version bump, since uv.lock embeds it) and `uv sync --all-extras --all-groups`: `ruff check`, `ruff format --check`, `ty check agentscore/`, `vulture`, and `pytest tests/ --cov=agentscore` (183 passed, 8 skipped, 99% coverage). Nothing runtime changed, so no new tests. Release: tag v2.6.11 after merge and watch the publish run, then move the `agentscore-py` floor in python-commerce. ## Checklist - [x] Tests cover the new behavior, and the suite passes locally - [x] Lint, format, and type checks pass - [x] Docs and README examples updated if the public surface changed - [x] No secrets, credentials, or personal data in the diff or the tests
Sweep dependencies, pin uv in CI, and bump to 2.6.10 (#89) ## Summary Dependency sweep for python-sdk, plus the release bump to 2.6.10. - `uv lock --upgrade`: coverage 7.16.0 to 7.16.1 and lefthook 2.1.12 to 2.1.14 (dev tooling). No prereleases in the lock; `prerelease = "disallow"` stays. - uv itself is now pinned in CI: every `astral-sh/setup-uv` step (ci, security, publish) passes `version: "0.12.13"`, the current uv release, which is the org's CI standard for Python repos. Without it, CI installed whatever uv was newest under `required-version`. - The osv-scanner binary the Dependency Scan job downloads moves from v2.5.1 to v2.6.0. Both of these pins are workflow inputs, so dependabot never proposes them. - Version 2.6.9 to 2.6.10, with `uv.lock` re-locked so its embedded project version matches. The one runtime dependency, `httpx>=0.25.0,<1.0.0`, resolves to 0.28.1, which is httpx's latest release. Checked and found current: `astral-sh/setup-uv@v10.1.0`, `pypa/gh-action-pypi-publish@v1.14.2`, `actions/setup-python@v7` (v7.0.0), `actions/checkout@v7`, `actions/cache@v6`, `useblacksmith/checkout@v1`; dependabot config (uv and actions ecosystems); hook/CI parity (hooks run ruff check, ruff format, ty and vulture; CI adds pytest). Not changed, deliberately: CI tests on Python 3.12 and the audit job runs 3.13. That is a test-matrix choice, not a dependency pin, and `requires-python` stays `>=3.11`. ## Type of change - [ ] Bug fix (no breaking change) - [ ] New feature (no breaking change) - [ ] Breaking change (existing callers must update) - [x] Docs, tests, or internal maintenance only ## Public API None. ## Test plan Locally, from `uv sync --frozen --all-extras --all-groups`: `ruff check`, `ruff format --check`, `ty check agentscore/`, `vulture`, `pytest` (183 passed, 8 skipped, 99.85% coverage against the 95% bar) and `uv build`, all exit 0. `osv-scanner` 2.6.0 over `uv.lock`: 24 packages, no issues. `pip-audit` over the exported requirements: exit 0. The three workflow files parse, and each setup-uv step carries the version input. ## Checklist - [x] Tests cover the new behavior, and the suite passes locally - [x] Lint, format, and type checks pass - [x] Docs and README examples updated if the public surface changed - [x] No secrets, credentials, or personal data in the diff or the tests Worked with Varun. The tag follows the merge.
2.6.8: dependency sweep (anyio, ruff, ty) (#84) ## Summary Dependency sweep, 2026-09-05, and the 2.6.8 version bump so agentscore-commerce can move its floor in the same waterfall. The lock moves anyio 4.15.0, ruff 0.16.6, ty 0.0.78; `uv lock` re-run after the version bump so the lock's embedded project version matches. No prerelease resolved. Worked with Varun, who asked for the SDK-first sweep. ## Type of change - [ ] Bug fix (no breaking change) - [ ] New feature (no breaking change) - [ ] Breaking change (existing callers must update) - [x] Docs, tests, or internal maintenance only ## Public API none ## Test plan `uv sync --all-extras --all-groups`; `ruff check`, `ruff format --check`, `ty check`, and vulture with CI's exact invocation all exit 0; pytest 183 passed, 8 skipped, coverage 100%. ## Checklist - [x] Tests cover the new behavior, and the suite passes locally - [x] Lint, format, and type checks pass - [x] Docs and README examples updated if the public surface changed - [x] No secrets, credentials, or personal data in the diff or the tests
Release 2.6.7: refresh deps and lockfile (#83) ## Summary Bumps `agentscore-py` to 2.6.7. `uv lock --upgrade` refreshed dev tooling within constraints (coverage 7.16.0, ty 0.0.76) with no prereleases (the `prerelease = "disallow"` guard held), on top of the already-merged osv-scanner v2.5.1 and minor-patch group. The uv.lock own-version is synced to 2.6.7. Actions are current (setup-uv v10.0.1, pypi-publish v1.14.2 both latest). ## Type of change - [ ] Bug fix (no breaking change) - [ ] New feature (no breaking change) - [ ] Breaking change (existing callers must update) - [x] Docs, tests, or internal maintenance only ## Public API None. No exported symbols, signatures, or wire formats changed; runtime dependencies are unchanged. ## Test plan Ran `uv run ruff check`, `uv run ty check`, and `uv run pytest`: all clean, 183 passed (8 skipped), 100% coverage. No behavior change, so no new tests. ## Checklist - [x] Tests cover the new behavior, and the suite passes locally - [x] Lint, format, and type checks pass - [x] Docs and README examples updated if the public surface changed - [x] No secrets, credentials, or personal data in the diff or the tests Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Take the minor-patch group and cut 2.6.6 (#78) ## Summary Dependency sweep for this repo: idna 3.19, pygments 2.21.0, python-dotenv 1.2.3, ruff 0.16.4 and ty 0.0.73. All are dev tooling or transitives. No declared dependency range in `pyproject.toml` changed, so nothing here reaches a consumer. The version bump to 2.6.6 is deliberate rather than required: nothing in this diff obliges a caller to act. It exists so the SDK ships as tier 1 of a coordinated release across the SDKs, the commerce libraries and pay, which was Varun's call after I flagged that by the usual "bump only where a consumer must act" rule this repo did not need a release at all. `uv.lock` embeds the project's own version, so it is re-locked in the same commit rather than left naming 2.6.5. Worked with: Varun. ## Type of change - [ ] Bug fix (no breaking change) - [ ] New feature (no breaking change) - [ ] Breaking change (existing callers must update) - [x] Docs, tests, or internal maintenance only ## Public API None. No exported symbol, signature, wire format or response shape changes. The only non-lockfile edit is the `version` field. ## Test plan Ran the repo's full gate set locally on this branch: - `uv run ruff check .` clean - `uv run ruff format --check .`: 21 files already formatted - `uv run ty check agentscore/` clean - `uv run vulture . vulture_whitelist.py --min-confidence 80 --exclude .venv` clean - `uv run pytest tests/ -q`: 183 passed, 8 skipped, 100% coverage against a 95% floor - `osv-scanner` over `uv.lock`: no issues found across 24 packages No tests were added or changed, because no behavior changed. ## Checklist - [x] Tests cover the new behavior, and the suite passes locally (no new behavior; the existing suite passes unchanged) - [x] Lint, format, and type checks pass - [x] Docs and README examples updated if the public surface changed (public surface did not change, so nothing to update) - [x] No secrets, credentials, or personal data in the diff or the tests ## Deliberately not done - Consumer floors are not raised to `>=2.6.6` in python-commerce or core/store. That version does not exist on PyPI yet, so raising a floor now would make `uv lock` unresolvable. The existing ranges already accept it, so no consumer edit is needed; pinning to the exact tested combination is a follow-up after this publishes. - No tag pushed. The publish workflow fires on `v*`, and a PyPI version is permanent, so the tag is left for a deliberate step after this merges. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Bump to 2.6.5: type operator_handle on the assess response (#75) ## Summary `/v1/assess` now returns `operator_handle` on the operator-token path: a stable, pairwise handle for the account behind the presented credential. Typed here so SDK consumers can read it without casting. It is the value to key durable state on. An `opc_` lives 24h and rotates silently off a 90-day refresh, so anything keyed on the token instance is stranded every time one rotates, and revoking a leaked token would forfeit what it was holding. The handle derives from the account instead, and is pairwise per calling account so handles never correlate across merchants. Type-only change: no runtime behavior, no new request field. Against an older API the field is simply absent. ## Type of change - [ ] Bug fix (no breaking change) - [x] New feature (no breaking change) - [ ] Breaking change (existing callers must update) - [ ] Docs, tests, or internal maintenance only ## Public API Additive: one optional field on the assess response type. No migration for existing callers. ## Test plan Existing suites run clean against the change; no behavior to add tests for, since nothing but the type surface moved. Node: lint, typecheck, 166 passed / 9 skipped. Python: ruff, ty, 183 passed / 8 skipped at 100% coverage. ## Checklist - [x] Tests cover the new behavior, and the suite passes locally - [x] Lint, format, and type checks pass - [x] Docs and README examples updated if the public surface changed - [x] No secrets, credentials, or personal data in the diff or the tests
Take ty 0.0.70, bump to 2.6.4 (#74) ## Summary Routine dev-tooling sweep ahead of the commerce-side release chain: ty 0.0.69 to 0.0.70 (the only update the lock resolved). Version bumped to 2.6.4 for the patch release. ## Type of change - [ ] Bug fix (no breaking change) - [ ] New feature (no breaking change) - [ ] Breaking change (existing callers must update) - [x] Docs, tests, or internal maintenance only ## Public API Unchanged. ty is a dev-group type checker; no runtime surface is touched. ## Test plan ruff check + format, ty (clean on the new version), vulture, and the full suite (183 passing, 8 skipped) all green. ## Checklist - [x] Tests cover the new behavior, and the suite passes locally - [x] Lint, format, and type checks pass - [x] Docs and README examples updated if the public surface changed Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Refresh the dev toolchain lock, release 2.6.3 (#72) ## Summary Routine dependency pass over the whole tree. Only one package had a newer version inside its declared range: `ty` 0.0.65 to 0.0.66, a dev-group type checker. Everything else is already current. Reported so the next pass does not re-derive it: `httpx` (the single runtime dependency) is current within `>=0.25.0,<1.0.0`, and the lockfile carries no advisories under either scanner. ## Type of change - [ ] Bug fix (no breaking change) - [ ] New feature (no breaking change) - [ ] Breaking change (existing callers must update) - [x] Docs, tests, or internal maintenance only ## Public API None. `pyproject.toml` is untouched; the diff is `uv.lock` alone. `ty` is a dev-group tool that no consumer resolves, so no release is needed and no caller has to act. ## Test plan - `uv sync --all-extras --all-groups --upgrade`, then: - `uv run ruff check .` all checks passed - `uv run ruff format --check .` 21 files already formatted - `uv run ty check agentscore/` all checks passed - `uv run pytest tests/`: 183 passed, 8 skipped, 100.00% coverage (gate is 95%) - osv-scanner v2.4.0 over `uv.lock`: no issues found ## Checklist - [x] Tests cover the new behavior, and the suite passes locally - [x] Lint, format, and type checks pass - [x] Docs and README examples updated if the public surface changed - [x] No secrets, credentials, or personal data in the diff or the tests --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sweep deps and cut 2.6.2 (#71) ## Summary Dependency sweep for this repo, plus a version bump so it can be released. - `coverage` 7.15.2 to 7.15.3, the only available bump. - Version to 2.6.2. Same caveat as the node SDK, and it decides whether this is worth publishing: nothing here reaches a consumer. The only commit since v2.6.1 is a one-line `ci.yml` change and coverage is a dev dependency, so the published wheel is unchanged. `uv.lock` was re-locked after the version bump, not just after the dependency change. The lock embeds the project's own version, so a `pyproject.toml` bump leaves it stale with nothing erroring and no gate noticing: the two files simply disagree about what the package is. It was sitting at 2.6.1 and `uv lock` moved it to 2.6.2. ## Type of change - [ ] Bug fix (no breaking change) - [ ] New feature (no breaking change) - [ ] Breaking change (existing callers must update) - [x] Docs, tests, or internal maintenance only ## Public API **None.** No exported class, function signature, wire format, or response shape changed. The published wheel is unchanged; the only difference is a dev dependency. No migration for callers. Both consumers in this workspace (`core/store`, `python-commerce`) declare `agentscore-py>=2.6.1`, which already accepts 2.6.2, so no manifest edit is required downstream. ## Test plan No tests added, because no behavior changed. The existing suite was run to confirm the bump breaks nothing: - `uv run pytest`: 183 passed, 8 skipped, 100% coverage against a 95% floor - `ruff check` and `ruff format --check`: clean - `uv run ty check`: clean - `uv run vulture . vulture_whitelist.py --min-confidence 80 --exclude .venv`: clean Vulture is run through the project's exact CI invocation rather than a bare `vulture`, which reports low-confidence findings the project deliberately filters out and would read as a regression that is not there. Reproduce with `uv sync --all-extras --all-groups` followed by those four commands. ## Checklist - [x] Tests cover the new behavior, and the suite passes locally - [x] Lint, format, and type checks pass - [x] Docs and README examples updated if the public surface changed (not applicable, public surface unchanged) - [x] No secrets, credentials, or personal data in the diff or the tests
PreviousNext