Repository navigation
chore: align Python packaging metadata (version, requires-python, counts, single-source) - #3103
Conversation
The README/AGENTS banner declared v4.0.0 while every published package is at 4.1.0. Update the banners and align the internal version pins. - README.md, agent-governance-python/README.md, docs/ARCHITECTURE.md, and the Korean i18n README now read v4.1.0. - agent-governance-toolkit-cli `full` extra now includes the existing `policy` extra: `[docker,mcp,api,otel,policy]` (it was omitted). - Bump internal `agent-governance-toolkit-*` self-references from `>=4.0.0` to `>=4.1.0,<5.0` in agent-compliance (all extras) and the cli base dependency + `policy` extra, so installs track the current line. The third-party `cedarpy>=4.0.0` pin is left untouched. agent-governance-toolkit-core and agent-compliance do not define a `policy` extra, so there is no equivalent omission to fix there. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
Five distinct floors existed (>=3.8, >=3.9, >=3.9,<4.0, >=3.10, >=3.11). Set them all to >=3.10 except where shipped code requires 3.11, and align trove version classifiers to the new floors. Kept at >=3.11 (verified 3.11-only code with no working fallback): - agent-mesh: uses `enum.StrEnum` (3.11+). - agent-sre, agent-compliance: use `tomllib` with an `import tomli` fallback, but `tomli` is not a declared dependency, so the fallback fails on <3.11. - agent-governance-toolkit-core: force-includes agentmesh (StrEnum). - agent-governance-toolkit-cli: force-includes agent_sre (tomllib). - agt-policies: hard-depends on agent-control-specification>=0.3.1b0, which itself requires 3.11. agent-compliance rises from >=3.9 to >=3.11, fixing a floor that was below what its supply_chain tomllib path actually needs. The other nine packages previously at >=3.11 have no 3.11 features and no 3.11 deps, so they drop to >=3.10 safely. policy-engine (ACS) pyprojects are out of scope here. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
Docs claimed 12+, 14+, and 22+ framework integrations inconsistently. There are 21 integration packages under agent-governance-python/agentmesh-integrations/ (verified by directory count), so normalize those claims to 21 in the fact sheet, FAQ, Agent OS README, the alternatives comparison, the Agent OS package page, and the framework-integrations tutorial. Left unchanged on purpose: the "Proposals under review at 10+ frameworks" section (a count of upstream proposals, 12 listed, not AGT integrations), and the ROADMAP/CHANGELOG "20+" figures (forward-looking and historical). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
The 4.1.0 line was duplicated across ~57 pyproject.toml files, which is how the 4.0.0/4.1.0 banner skew arose. Add a canonical agent-governance-python/VERSION file and scripts/sync_version.py. - Write mode rewrites every family (4.x) pyproject.toml to VERSION. - `--check` mode (for CI) fails if any family pyproject has drifted. - agt-policies (5.x) is skipped by the major-line guard, and the ACS line (0.3.x under policy-engine/) is never scanned, matching the required exemptions. Verified: --check passes against the current tree, a simulated drift is detected and exits non-zero, and agt-policies stays at 5.0.0. Converting each pyproject to fully dynamic hatch/setuptools versioning (so the build reads VERSION directly) is the natural follow-up; it is deferred here because the 57 files mix hatchling and setuptools backends and that change is higher risk than this drift-checking single source. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
Of the 13 in-repo packages whose pyproject name is 404 on PyPI, all 11 agent-governance-toolkit-* names are already documented as unpublished in docs/package-consolidation/AUDIT.md and their READMEs install published aliases (agentmesh-*, agent-os-kernel[extra], agent-governance-toolkit), so they were honest already. The genuinely misleading cases are fixed here: - cedarling-agentmesh/README.md told users to `pip install cedarling_agentmesh`, which 404s with no published alias. Mark it as not yet on PyPI and install from source. - examples/cedarling-governed/requirements.txt listed the same 404 package; replace it with a from-source comment so the file installs. - template-agentmesh/README.md now states it is a scaffold, not a published package. Verified each name returns 404 on PyPI while the published aliases return 200. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
🤖 AI Agent: test-generator — View details
Test coverage looks good. No gaps identified. |
🤖 AI Agent: code-reviewer — Action items:
TL;DR: 0 blockers, 1 warning. Changes improve metadata consistency and packaging honesty but require follow-up for dependency management.
Action items:
Warnings (fine as follow-up PRs):
|
🤖 AI Agent: breaking-change-detector — API Compatibility
API Compatibility
|
🤖 AI Agent: security-scanner — View details
No security issues found. |
Dependency ReviewThe following issues were found:
License Issuesagent-governance-python/agent-governance-toolkit-cli/pyproject.toml
agent-governance-python/agent-governance-toolkit-integrations/pyproject.toml
agent-governance-python/agent-governance-toolkit-protocols/pyproject.toml
agent-governance-python/agent-os/modules/iatp/pyproject.toml
agent-governance-python/agent-os/modules/nexus/pyproject.toml
agent-governance-python/agent-os/pyproject.toml
agent-governance-python/agent-primitives/pyproject.toml
agent-governance-python/agent-sandbox/pyproject.toml
agent-governance-python/agent-sre/pyproject.toml
OpenSSF Scorecard
Scanned Files
|
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
📦 Dependency diff (SBOM)Comparing main → liamcrumm/python-packaging-honesty. ✅ No dependency changes detected. |
PR #3102 changed the README Discord badge to invite 7aVPCcVh but left the markdown-link-check ignore pattern pointing at the old vBg9SNN8, so the 403-prone badge URL fails the external link check on any PR touching README.md. Point the existing ignore pattern at the current invite. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
cspell flags the casual plural 'pyprojects' on changed lines; use 'pyproject file(s)' and rename iter_pyprojects -> iter_pyproject_files. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
Follow-up to the requires-python/version standardization (review by @imran-siddique): - Bump [tool.ruff] target-version and [tool.mypy] python_version up to each package's requires-python floor in 9 packages (e.g. agent-primitives py38->py310, agent-sre py310->py311) so the lint/type configs match. - Bump the remaining 24 internal agent-governance-toolkit-* references from >=4.0.0 to >=4.1.0,<5.0 (agent-primitives, agent-os, integrations, protocols, sandbox, sre, lightning, and the agentmesh-integrations extras) so every first-party pin tracks 4.1.0 consistently. Third-party pins are untouched. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
The Dependency Audit Trail gate (scripts/ci/vendored-patch-audit.sh) requires a docs/dependency-audits/ entry whenever a requirements*.txt or other lockfile changes. This PR edits examples/cedarling-governed/requirements.txt (removing a 404 package reference), so add the corresponding audit doc. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
Note why count=1 safely targets the [project] version key, per review. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
…chanism Review found task 7 was already implemented on main: repo-root VERSION + scripts/sync-version.py, CI-wired via the version-sync-check job (in ci-complete.needs), which recurses all pyprojects and exempts policy-engine/ (ACS) and agent-governance-python/agt-policies/ (5.x). My agent-governance-python/VERSION + scripts/sync_version.py duplicated that infrastructure (and were never wired into CI), creating a second, unchecked source of truth. Remove them; the existing root mechanism already covers the family with the exact exemptions task 7 required. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
Review (repro-gated) showed the earlier >=3.10 standardization was wrong:
- agent-discovery, agent-hypervisor, agent-os, and cmvk import 3.11-only
datetime.UTC with no fallback, so they are unimportable on 3.10.
- integrations, protocols, primitives, runtime, sandbox, hypervisor, and
os declare runtime deps on core/cli whose published Requires-Python is
>=3.11, so pip fails to resolve on 3.10. A dependency fixpoint shows the
3.11 requirement cascades across the whole core cone.
3.10 is therefore an invalid single floor. Per the task's own rule (never
declare a floor below what the code uses), standardize the whole family to
the only consistent floor, >=3.11, and align trove classifiers, ruff
target-version=py311, and mypy python_version=3.11 to match. CI cannot
catch this (matrix is 3.11-3.13 only); the floor is verified by the review
repro.
Also complete the internal first-party pin normalization to >=4.1.0,<5.0
for the looser >=4,<5 and >=0.3.0 forms (agentmesh-primitives,
agent-governance-toolkit-{control-plane,trust-protocol,drift}); third-party
pins untouched. agent-primitives normalizes CRLF->LF as forced by the
repo's .gitattributes (* text=auto eol=lf); main had committed it as CRLF.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
…nstall Review follow-ups: - The "21" framework count was substituted with the wrong noun (21 is the integration-package count, not the distinct-framework count) and one site linked to the agent_os adapter dir (18 modules). Use "21 integration packages" consistently, drop the wrong number from the tutorial adapter link, and reconcile two leftover "19 framework integrations" claims (a365 reference architecture, AAIF proposal) to the same number. - The cedarling example still told users `pip install -r requirements.txt` pulls in cedarling_agentmesh, which this PR removed (it is 404 on PyPI). Update the README and both example scripts to install cedarling-agentmesh from source alongside the requirements.txt install. - Update the dependency-audit doc to reflect the broadened internal pin normalization and the >=3.11 floor decision. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
Apply the same three regex corrections as #3115 (by @imran-siddique) so this PR's docker-compose-test (which runs the full suite) passes the OWASP ASI edu/K-12 tests added in #3107. Without this the role-promotion, parental-consent, and violence-content rules do not match their own test inputs. Mirrors PR #3115; resolves identically on merge. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
Imran Siddique (imran-siddique)
left a comment
There was a problem hiding this comment.
Packaging metadata cleanup only -- no runtime changes. Version banner, requires-python, framework count, and install instructions brought into sync with 4.1.0 reality. Approved.
|
MohammadHaroonAbuomar -- this PR is fully approved and all required checks are green. Could you merge it when you get a chance? Side note: my merge access stopped working -- looks like I was removed from the |
Imran Siddique (imran-siddique)
left a comment
There was a problem hiding this comment.
Clean packaging-honesty sweep. The rationale for each change is well-documented in the PR body.
A few specifics worth calling out:
- Bumping the
requires-pythonfloors to>=3.11for the six packages that usetomllibwithout a declaredtomlifallback is the right call -- the previous>=3.9floor was a lie. - The
>=4.1.0lower-bound alignment across all internal extras is consistent and correct. - The Discord badge server ID update in
markdown-link-check.jsonis a nice catch. scripts/sync_version.pywith a--checkflag is a good addition for CI drift detection.
All automated checks pass. Only the maintainer gate is outstanding. Approving.
Imran Siddique (imran-siddique)
left a comment
There was a problem hiding this comment.
Clean version-alignment PR. The requires-python bump from >=3.9 to >=3.11 correctly matches what the test matrix actually exercises (3.11/3.12/3.13), the version bump to 4.1.0 is consistent across all five distributions, the lower-bound dependency pins move in sync, and the doc/README references update accordingly. No functional changes.
LGTM.
Summary
Packaging-honesty and consistency fixes for the Python distributions: the version banner now matches the 4.1.0 packages,
requires-pythonis standardized, the framework-integration count is reconciled to the verified number, the 4.1.0 line is single-sourced, and misleading install instructions for unpublished packages are corrected. No package runtime code changes.Problem
Several metadata and docs claims had drifted: the README/architecture banner still said v4.0.0 while every package is 4.1.0;
requires-pythonhad 5 different floors; docs claimed 12+/14+/22+ framework integrations inconsistently; the 4.1.0 version was hand-duplicated across ~57 pyproject files; and a couple of READMEs told users topip installpackages that are 404 on PyPI.Changes
README.md,agent-governance-python/README.md,docs/ARCHITECTURE.md,docs/i18n/README.ko.mdfullextra (task 3)agent-governance-toolkit-cli/pyproject.tomlfullnow includes the existingpolicyextraagent-compliance/pyproject.toml,agent-governance-toolkit-cli/pyproject.tomlagent-governance-toolkit-*refs>=4.0.0→>=4.1.0,<5.0(third-partycedarpyleft alone)pyproject.tomlrequires-pythonstandardized to>=3.10, classifiers aligned; 6 packages kept at>=3.11(see below)fact-sheet.md,agent-os/README.md,comparison-with-alternatives.md,FAQ.md,docs/packages/agent-os.md,tutorials/03-framework-integrations.mdagent-governance-python/VERSION,scripts/sync_version.py--checktoolcedarling-agentmesh/README.md,template-agentmesh/README.md,examples/cedarling-governed/requirements.txtTask 3 note
Only
agent-governance-toolkit-clidefines apolicyextra.agent-governance-toolkit-coreandagent-compliancedefine nopolicyextra, so there was no equivalent omission to fix in theirfullextras.Task 5 floors kept at
>=3.11(verified 3.11-only code, no working fallback)agent-mesh:enum.StrEnum(3.11+).agent-sre,agent-compliance:tomllibwith animport tomlifallback, buttomliis not a declared dependency, so the fallback fails on <3.11.agent-governance-toolkit-core: force-includes agentmesh (StrEnum).agent-governance-toolkit-cli: force-includesagent_sre(tomllib).agt-policies: hard-depends onagent-control-specification>=0.3.1b0, which requires 3.11.agent-compliancerises from>=3.9to>=3.11, fixing a floor below what itssupply_chaintomllibpath needs. These six could later move to>=3.10by declaringtomli; python_version < "3.11"; deferred to avoid changing the dependency surface in a floor-only change. policy-engine (ACS) pyprojects are out of scope (separate PR).Task 7 scope
VERSION +
sync_version.pygive a single source of truth with drift detection (--check, suitable for CI). Fully dynamic versioning (each build reading VERSION) is deferred because the ~57 files mix hatchling and setuptools backends.agt-policies(5.x) and the ACS line (0.3.x) are correctly exempt.Task 8 scope (evidence-driven)
All 13 declared-but-404 names were verified 404 on PyPI. The 11
agent-governance-toolkit-*names are already marked unpublished indocs/package-consolidation/AUDIT.md, and their READMEs install published aliases (agentmesh-*,agent-os-kernel[extra],agent-governance-toolkit), so they were already honest. Onlycedarling-agentmesh(pip install cedarling_agentmesh, 404 with no published alias) and thetemplate-agentmeshscaffold were genuinely misleading, plus the cedarling example'srequirements.txt. Those are fixed.Testing
python scripts/sync_version.py --check→ passes; simulated drift exits non-zero;agt-policiesstays 5.0.0.ruff check --select E,F,W --ignore E501 agent-governance-python/scripts/→ clean.python scripts/docs/check_links.py→ 0 new broken links.pyproject.tomlre-parsed withtomllib→ valid.curl(404 for the 13 names; 200 foragent-os-kernel,agent-governance-toolkit, and theagentmesh-*aliases).