Repository navigation
chore(docs): update Discord invite link to 7aVPCcVh - #3102
Merged
Imran Siddique (imran-siddique) merged 6 commits intoJun 17, 2026
Merged
Conversation
Implements issues #3086-#3090. Uses agentrust-trace>=0.2.0 for TrustRecord model, Ed25519 signing, and validation -- no local reimplementation. - trace_sink.py: TraceConfig dataclass, session_to_trust_record() mapping function, TRACEAuditSink session-close emitter - govern.py: TraceConfig field on GovernanceConfig, policy bundle hash computation at init, TRACEAuditSink wired up, close_session() method on GovernedCallable - governance/__init__.py: export TraceConfig, TRACEAuditSink - agent-governance-toolkit-core/pyproject.toml: agentrust-trace>=0.2.0 runtime dependency - agent-mesh/pyproject.toml: agentrust-trace>=0.2.0 in dev extras - tests/governance/test_trace_sink.py: 20 tests covering mapping, emission, file output, validation, and GovernedCallable.close_session() - check_dependency_confusion.py: register agentrust-trace in allowlist - .cspell-repo-terms.txt: add agentrust, isfile, reimplementation Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Marks status accepted. Corrects wire format (signed JSON, not compact JWT), documents TraceConfig/close_session() API, notes key management delegation to agentrust-trace, and adds agentrust-trace v0.2.0 to references. Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Both terms appear in ADR-0032 (CBOR-COSE wire format deferral note). Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
condition: "true" is treated as a path lookup by the policy engine, returning False for any context. Use action.type != 'deny' instead, which evaluates to True for all normal action calls. Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Also fixes stale RcK9fHf8 link in Korean README badge. Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Imran Siddique (imran-siddique)
requested a review
from MohammadHaroonAbuomar
as a code owner
June 17, 2026 20:18
Dependency ReviewThe following issues were found:
License Issuesagent-governance-python/agent-governance-toolkit-core/pyproject.toml
OpenSSF Scorecard
Scanned Files
|
🤖 AI Agent: security-scanner — View details
No security issues found. |
🤖 AI Agent: test-generator — `agent-governance-python/agent-mesh/src/agentmesh/governance/govern.py`
|
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
liamcrumm
added a commit
that referenced
this pull request
Jun 17, 2026
PR #3102 changed the README Discord badge to invite 7aVPCcVh but left the markdown-link-check ignore pattern pointing at the old vBg9SNN8, so the 403-prone badge URL fails the external link check on any PR touching README.md. Point the existing ignore pattern at the current invite. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
MohammadHaroonAbuomar
pushed a commit
that referenced
this pull request
Jun 22, 2026
…nts, single-source) (#3103) * chore: bump version banner to 4.1.0 and add policy extra to cli full The README/AGENTS banner declared v4.0.0 while every published package is at 4.1.0. Update the banners and align the internal version pins. - README.md, agent-governance-python/README.md, docs/ARCHITECTURE.md, and the Korean i18n README now read v4.1.0. - agent-governance-toolkit-cli `full` extra now includes the existing `policy` extra: `[docker,mcp,api,otel,policy]` (it was omitted). - Bump internal `agent-governance-toolkit-*` self-references from `>=4.0.0` to `>=4.1.0,<5.0` in agent-compliance (all extras) and the cli base dependency + `policy` extra, so installs track the current line. The third-party `cedarpy>=4.0.0` pin is left untouched. agent-governance-toolkit-core and agent-compliance do not define a `policy` extra, so there is no equivalent omission to fix there. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com> * chore: standardize requires-python to >=3.10 across Python packages Five distinct floors existed (>=3.8, >=3.9, >=3.9,<4.0, >=3.10, >=3.11). Set them all to >=3.10 except where shipped code requires 3.11, and align trove version classifiers to the new floors. Kept at >=3.11 (verified 3.11-only code with no working fallback): - agent-mesh: uses `enum.StrEnum` (3.11+). - agent-sre, agent-compliance: use `tomllib` with an `import tomli` fallback, but `tomli` is not a declared dependency, so the fallback fails on <3.11. - agent-governance-toolkit-core: force-includes agentmesh (StrEnum). - agent-governance-toolkit-cli: force-includes agent_sre (tomllib). - agt-policies: hard-depends on agent-control-specification>=0.3.1b0, which itself requires 3.11. agent-compliance rises from >=3.9 to >=3.11, fixing a floor that was below what its supply_chain tomllib path actually needs. The other nine packages previously at >=3.11 have no 3.11 features and no 3.11 deps, so they drop to >=3.10 safely. policy-engine (ACS) pyprojects are out of scope here. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com> * docs: reconcile framework integration count to verified 21 Docs claimed 12+, 14+, and 22+ framework integrations inconsistently. There are 21 integration packages under agent-governance-python/agentmesh-integrations/ (verified by directory count), so normalize those claims to 21 in the fact sheet, FAQ, Agent OS README, the alternatives comparison, the Agent OS package page, and the framework-integrations tutorial. Left unchanged on purpose: the "Proposals under review at 10+ frameworks" section (a count of upstream proposals, 12 listed, not AGT integrations), and the ROADMAP/CHANGELOG "20+" figures (forward-looking and historical). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com> * build: single-source the Python package version via VERSION file The 4.1.0 line was duplicated across ~57 pyproject.toml files, which is how the 4.0.0/4.1.0 banner skew arose. Add a canonical agent-governance-python/VERSION file and scripts/sync_version.py. - Write mode rewrites every family (4.x) pyproject.toml to VERSION. - `--check` mode (for CI) fails if any family pyproject has drifted. - agt-policies (5.x) is skipped by the major-line guard, and the ACS line (0.3.x under policy-engine/) is never scanned, matching the required exemptions. Verified: --check passes against the current tree, a simulated drift is detected and exits non-zero, and agt-policies stays at 5.0.0. Converting each pyproject to fully dynamic hatch/setuptools versioning (so the build reads VERSION directly) is the natural follow-up; it is deferred here because the 57 files mix hatchling and setuptools backends and that change is higher risk than this drift-checking single source. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com> * docs: mark unpublished cedarling/template packages as unreleased Of the 13 in-repo packages whose pyproject name is 404 on PyPI, all 11 agent-governance-toolkit-* names are already documented as unpublished in docs/package-consolidation/AUDIT.md and their READMEs install published aliases (agentmesh-*, agent-os-kernel[extra], agent-governance-toolkit), so they were honest already. The genuinely misleading cases are fixed here: - cedarling-agentmesh/README.md told users to `pip install cedarling_agentmesh`, which 404s with no published alias. Mark it as not yet on PyPI and install from source. - examples/cedarling-governed/requirements.txt listed the same 404 package; replace it with a from-source comment so the file installs. - template-agentmesh/README.md now states it is a scaffold, not a published package. Verified each name returns 404 on PyPI while the published aliases return 200. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com> * ci: update dcbadge link-check ignore to current Discord invite PR #3102 changed the README Discord badge to invite 7aVPCcVh but left the markdown-link-check ignore pattern pointing at the old vBg9SNN8, so the 403-prone badge URL fails the external link check on any PR touching README.md. Point the existing ignore pattern at the current invite. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com> * chore: reword 'pyprojects' in sync_version for spell-check cspell flags the casual plural 'pyprojects' on changed lines; use 'pyproject file(s)' and rename iter_pyprojects -> iter_pyproject_files. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com> * chore: align ruff/mypy targets and remaining internal pins Follow-up to the requires-python/version standardization (review by @imran-siddique): - Bump [tool.ruff] target-version and [tool.mypy] python_version up to each package's requires-python floor in 9 packages (e.g. agent-primitives py38->py310, agent-sre py310->py311) so the lint/type configs match. - Bump the remaining 24 internal agent-governance-toolkit-* references from >=4.0.0 to >=4.1.0,<5.0 (agent-primitives, agent-os, integrations, protocols, sandbox, sre, lightning, and the agentmesh-integrations extras) so every first-party pin tracks 4.1.0 consistently. Third-party pins are untouched. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com> * docs: add dependency audit trail for packaging metadata change The Dependency Audit Trail gate (scripts/ci/vendored-patch-audit.sh) requires a docs/dependency-audits/ entry whenever a requirements*.txt or other lockfile changes. This PR edits examples/cedarling-governed/requirements.txt (removing a 404 package reference), so add the corresponding audit doc. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com> * docs: clarify sync_version version-key anchoring Note why count=1 safely targets the [project] version key, per review. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com> * chore: remove duplicate version single-source, reuse existing root mechanism Review found task 7 was already implemented on main: repo-root VERSION + scripts/sync-version.py, CI-wired via the version-sync-check job (in ci-complete.needs), which recurses all pyprojects and exempts policy-engine/ (ACS) and agent-governance-python/agt-policies/ (5.x). My agent-governance-python/VERSION + scripts/sync_version.py duplicated that infrastructure (and were never wired into CI), creating a second, unchecked source of truth. Remove them; the existing root mechanism already covers the family with the exact exemptions task 7 required. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com> * fix(packaging): standardize requires-python to >=3.11, not >=3.10 Review (repro-gated) showed the earlier >=3.10 standardization was wrong: - agent-discovery, agent-hypervisor, agent-os, and cmvk import 3.11-only datetime.UTC with no fallback, so they are unimportable on 3.10. - integrations, protocols, primitives, runtime, sandbox, hypervisor, and os declare runtime deps on core/cli whose published Requires-Python is >=3.11, so pip fails to resolve on 3.10. A dependency fixpoint shows the 3.11 requirement cascades across the whole core cone. 3.10 is therefore an invalid single floor. Per the task's own rule (never declare a floor below what the code uses), standardize the whole family to the only consistent floor, >=3.11, and align trove classifiers, ruff target-version=py311, and mypy python_version=3.11 to match. CI cannot catch this (matrix is 3.11-3.13 only); the floor is verified by the review repro. Also complete the internal first-party pin normalization to >=4.1.0,<5.0 for the looser >=4,<5 and >=0.3.0 forms (agentmesh-primitives, agent-governance-toolkit-{control-plane,trust-protocol,drift}); third-party pins untouched. agent-primitives normalizes CRLF->LF as forced by the repo's .gitattributes (* text=auto eol=lf); main had committed it as CRLF. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com> * docs: correct integration-count wording/links and cedarling example install Review follow-ups: - The "21" framework count was substituted with the wrong noun (21 is the integration-package count, not the distinct-framework count) and one site linked to the agent_os adapter dir (18 modules). Use "21 integration packages" consistently, drop the wrong number from the tutorial adapter link, and reconcile two leftover "19 framework integrations" claims (a365 reference architecture, AAIF proposal) to the same number. - The cedarling example still told users `pip install -r requirements.txt` pulls in cedarling_agentmesh, which this PR removed (it is 404 on PyPI). Update the README and both example scripts to install cedarling-agentmesh from source alongside the requirements.txt install. - Update the dependency-audit doc to reflect the broadened internal pin normalization and the >=3.11 floor decision. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com> * fix(edu-k12): correct three regex bugs in the K-12 starter pack Apply the same three regex corrections as #3115 (by @imran-siddique) so this PR's docker-compose-test (which runs the full suite) passes the OWASP ASI edu/K-12 tests added in #3107. Without this the role-promotion, parental-consent, and violence-content rules do not match their own test inputs. Mirrors PR #3115; resolves identically on merge. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com> --------- Signed-off-by: Liam Crumm <liamcrumm@gmail.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Imran Siddique <45405841+imran-siddique@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
vBg9SNN8to7aVPCcVhinREADME.mdanddocs/i18n/README.ko.mdRcK9fHf8badge link in Korean README (was already inconsistent with the footer link)Test plan
🤖 Generated with Claude Code