Skip to content

chore: bump monorepo version 4.1.0 -> 5.0.0 - #3191

Merged
MohammadHaroonAbuomar merged 3 commits into
mainfrom
liamcrumm/bump-v5.0.0
Jun 26, 2026
Merged

MohammadHaroonAbuomar merged 3 commits into
mainfrom
liamcrumm/bump-v5.0.0

Conversation

@liamcrumm

@liamcrumm liamcrumm commented Jun 25, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Bump the monorepo version from 4.1.0 to 5.0.0. The documentation already describes Agent Control Specification (ACS) as the "AGT 5.0 policy layer" in multiple places (introduced with ACS in #2747), but the shipped artifacts were still on the 4.1.0 line. This aligns the version with the docs and marks the ACS-era major.

Problem

ACS is referenced as the "AGT 5.0 policy layer" across docs/packages/agent-control-specification.md, docs/GLOSSARY.md, docs/tutorials/55-agent-control-specification.md, policy-engine/README.md, policy-engine/sdk/python/README.md, and the agt-policies package description but other packages are still versioned 4.1.0.

Changes

Area What changed
Python 57 pyproject.toml self-versions and 4 __init__.py __version__ → 5.0.0
JS/TS 17 package.json self-versions → 5.0.0
Rust / .NET agent-governance-rust/Cargo.toml and agent-governance-dotnet/Directory.Build.props → 5.0.0
Top-level VERSION file and Claude Code plugin.json / marketplace.json manifests → 5.0.0
Internal caps 57 internal cross-package pins widened ,<5.0 → ,<6.0 so the 5.0.0 packages resolve against each other
Docs docs/ARCHITECTURE.md version banner → v5.0.0; new CHANGELOG.md [5.0.0] section

Intentionally NOT changed

  • policy-engine/ (ACS engine) — independently versioned at 0.3.1-beta, not part of the monorepo line.
  • Go module — separately tagged (agent-governance-golang/v3.1.0); no monorepo version constant.
  • Third-party dependency caps — jsonschema, anyio, redis, pytest-cov, beautifulsoup4, langfuse, helicone, ddtrace, cedarpy keep their own <5.0 bounds.
  • Historical narrative — the root and agent-governance-python READMEs say "as of v4.1.0 … consolidated", which describes when consolidation happened; left as history.
  • Lockfiles — package-lock.json / uv.lock / Cargo.lock regenerate at publish time (per the repo's documented version-bump process); CI does not enforce --locked, and the uv.lock 4.1.0 entries are resolved-from-PyPI dependency versions that stay correct until 5.0.0 actually publishes. Hand-editing them risks transitive-version corruption.

Notes for reviewers

  • This is a version-alignment bump only; no code behavior changes.
  • The CHANGELOG had no [4.1.0] section (the post-4.0.0 delta sat under [Unreleased]); that delta is now promoted under [5.0.0] with a BREAKING alignment note. The pre-existing missing [4.1.0] section was left as-is rather than retroactively reconstructed.

Testing

  • All 58 changed pyproject.toml and 19 changed .json files validated to parse.
  • agentmesh.__version__ imports as 5.0.0; agent-mesh pyproject reports 5.0.0.
  • Verified every ,<6.0 cap is on an AGT-internal package (no third-party pin touched), and policy-engine/, Go, lockfiles, and node_modules are untouched.
  • python scripts/docs/check_links.py: 0 new broken links.

Follow-up fixes (cross-language resolution + pre-existing test debt surfaced by the bump)

Bumping the workspace/package versions triggered two CI jobs that don't normally run, exposing issues that needed fixing for this PR to go green:

Commit Fix
e5c054b0 Rust workspace resolution. The bump set [workspace.package].version to 5.0.0, but the internal agentmesh-mcp path-dependency kept its ^4.0.0 requirement, which excludes the now-5.0.0 member, so cargo failed to resolve. Bumped the requirement to 5.0.0 to track the major line. (scripts/sync-version.py syncs the workspace version but not [workspace.dependencies] path-dep requirements, so this needs the manual follow-up on a major bump.)
13186e13 TS SDK + mcp-server test debt (pre-existing). Touching agent-governance-typescript and the mcp-server package.json triggered the path-filtered build-npm job, which surfaced failures that already existed on main. The TS SDK had 5 stale tests asserting the old client-supplied did:agentmesh: DID scheme; per the mesh security model the SDK now derives did:mesh:<sha256(public_key)> and register() uses the POP wire shape (#2533). Updated the tests to the hardened behavior (did:mesh: self/peer/AAD DIDs, POP-shape registration, canonical { did } return) — full suite 560/560. mcp-server has no test files, so bare vitest exited 1; switched to vitest run --passWithNoTests.

These are not behavior changes to shipped code; the Rust fix restores resolution, and the TS changes align tests with the existing DID/POP hardening rather than weakening it.

Aligns the released version line with the documentation, which already
describes Agent Control Specification (ACS) as the "AGT 5.0 policy layer"
(ACS landed in #2747) while the artifacts were still on 4.1.0.

- Bumped self-version to 5.0.0 across all first-party packages: 57
  pyproject.toml, 4 __init__.py __version__, 17 package.json, the Rust
  workspace Cargo.toml, the .NET Directory.Build.props, the top-level
  VERSION file, and the Claude Code plugin/marketplace manifests.
- Widened internal cross-package caps from <5.0 to <6.0 (57 pins) so the
  5.0.0 packages resolve against each other. Third-party caps
  (jsonschema, anyio, redis, pytest-cov, etc.) are untouched.
- Updated the docs/ARCHITECTURE.md version banner and added a CHANGELOG
  [5.0.0] section.

Out of scope / intentionally unchanged: the independently-versioned
policy-engine/ ACS engine (0.3.1-beta), the separately-tagged Go module,
historical README "as of v4.1.0" consolidation narrative, and all
lockfiles (package-lock.json/uv.lock/Cargo.lock regenerate at publish;
CI does not enforce --locked).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
@github-actions

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@github-actions

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 13 package(s) with unknown licenses.
See the Details below.

License Issues

agent-governance-python/agent-governance-toolkit-cli/pyproject.toml

PackageVersionLicenseIssue Type
agent-governance-toolkit-core>= 4.1.0,< 6.0NullUnknown License

agent-governance-python/agent-governance-toolkit-integrations/pyproject.toml

PackageVersionLicenseIssue Type
agent-governance-toolkit-core>= 4.1.0,< 6.0NullUnknown License

agent-governance-python/agent-governance-toolkit-protocols/pyproject.toml

PackageVersionLicenseIssue Type
agent-governance-toolkit-core>= 4.1.0,< 6.0NullUnknown License

agent-governance-python/agent-hypervisor/pyproject.toml

PackageVersionLicenseIssue Type
agent-governance-toolkit-core>= 4.1.0,< 6.0NullUnknown License

agent-governance-python/agent-mcp-governance/pyproject.toml

PackageVersionLicenseIssue Type
agent-governance-toolkit-protocols>= 4.1.0,< 6.0NullUnknown License

agent-governance-python/agent-mesh/pyproject.toml

PackageVersionLicenseIssue Type
agent-governance-toolkit-core>= 4.1.0,< 6.0NullUnknown License

agent-governance-python/agent-os/modules/iatp/pyproject.toml

PackageVersionLicenseIssue Type
agentmesh-primitives>= 4.1.0,< 6.0NullUnknown License

agent-governance-python/agent-os/modules/nexus/pyproject.toml

PackageVersionLicenseIssue Type
agent-governance-toolkit-trust-protocol>= 4.1.0,< 6.0NullUnknown License

agent-governance-python/agent-os/pyproject.toml

PackageVersionLicenseIssue Type
agent-governance-toolkit-core>= 4.1.0,< 6.0NullUnknown License

agent-governance-python/agent-primitives/pyproject.toml

PackageVersionLicenseIssue Type
agent-governance-toolkit-core>= 4.1.0,< 6.0NullUnknown License

agent-governance-python/agent-runtime/pyproject.toml

PackageVersionLicenseIssue Type
agent-governance-toolkit-core>= 4.1.0,< 6.0NullUnknown License

agent-governance-python/agent-sandbox/pyproject.toml

PackageVersionLicenseIssue Type
agent-governance-toolkit-cli>= 4.1.0,< 6.0NullUnknown License

agent-governance-python/agent-sre/pyproject.toml

PackageVersionLicenseIssue Type
agent-governance-toolkit-cli>= 4.1.0,< 6.0NullUnknown License
Allowed Licenses: MIT, Apache-2.0, Apache-2.0 WITH LLVM-exception, BSD-2-Clause, BSD-3-Clause, ISC, PSF-2.0, Python-2.0, 0BSD, Unlicense, CC0-1.0, CC-BY-4.0, Zlib, BSL-1.0, MPL-2.0, JSON, Unicode-3.0, CDLA-Permissive-2.0
Excluded from license check: pkg:cargo/futures-timer

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
pip/agent-governance-toolkit-core >= 4.1.0,< 6.0 UnknownUnknown
pip/agent-governance-toolkit-core >= 4.1.0,< 6.0 UnknownUnknown
pip/agent-governance-toolkit-core >= 4.1.0,< 6.0 UnknownUnknown
pip/agent-governance-toolkit-core >= 4.1.0,< 6.0 UnknownUnknown
pip/agent-governance-toolkit-protocols >= 4.1.0,< 6.0 UnknownUnknown
pip/agent-governance-toolkit-core >= 4.1.0,< 6.0 UnknownUnknown
pip/agentmesh-primitives >= 4.1.0,< 6.0 UnknownUnknown
pip/agent-governance-toolkit-trust-protocol >= 4.1.0,< 6.0 UnknownUnknown
pip/agent-governance-toolkit-core >= 4.1.0,< 6.0 UnknownUnknown
pip/agent-governance-toolkit-core >= 4.1.0,< 6.0 UnknownUnknown
pip/agent-governance-toolkit-core >= 4.1.0,< 6.0 UnknownUnknown
pip/agent-governance-toolkit-cli >= 4.1.0,< 6.0 UnknownUnknown
pip/agent-governance-toolkit-cli >= 4.1.0,< 6.0 UnknownUnknown

Scanned Files

  • agent-governance-python/agent-governance-toolkit-cli/pyproject.toml
  • agent-governance-python/agent-governance-toolkit-integrations/pyproject.toml
  • agent-governance-python/agent-governance-toolkit-protocols/pyproject.toml
  • agent-governance-python/agent-hypervisor/pyproject.toml
  • agent-governance-python/agent-mcp-governance/pyproject.toml
  • agent-governance-python/agent-mesh/pyproject.toml
  • agent-governance-python/agent-os/modules/iatp/pyproject.toml
  • agent-governance-python/agent-os/modules/nexus/pyproject.toml
  • agent-governance-python/agent-os/pyproject.toml
  • agent-governance-python/agent-primitives/pyproject.toml
  • agent-governance-python/agent-runtime/pyproject.toml
  • agent-governance-python/agent-sandbox/pyproject.toml
  • agent-governance-python/agent-sre/pyproject.toml

@github-actions

Copy link
Copy Markdown

📦 Dependency diff (SBOM)

Comparing main → liamcrumm/bump-v5.0.0.

✅ No dependency changes detected.

The monorepo v5 bump set the Rust workspace version to 5.0.0 (via
[workspace.package].version), but the internal path dependency
`agentmesh-mcp = { path = "agentmesh-mcp", version = "4.0.0" }` kept its
`^4.0.0` requirement, which excludes the now-5.0.0 member. `agentmesh`
depends on `agentmesh-mcp` (agentmesh-mcp.workspace = true), so cargo
resolution failed:

    error: failed to select a version for the requirement
    `agentmesh-mcp = "^4.0.0"`

Mirror the prior convention (the requirement tracked the major line:
^4.0.0 for the 4.x workspace) and bump it to ^5.0.0. cargo metadata now
resolves cleanly. The canonical scripts/sync-version.py syncs
[workspace.package].version but not [workspace.dependencies] path-dep
requirements, so this needs the manual follow-up on a major bump.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
@liamcrumm
liamcrumm marked this pull request as ready for review June 25, 2026 23:52
… for mcp-server

The v5 bump touches the TS SDK and mcp-server package.json, which triggers
the path-filtered build-npm CI job. That job surfaced pre-existing failures
(they fail identically on main; build-npm only runs when these packages
change, so they went unnoticed):

- agent-governance-typescript: 5 tests asserted the pre-hardening DID
  scheme. Per the mesh security model (DIDs MUST be derived from
  SHA-256(public_key), never client-supplied), MeshClient now canonicalizes
  the self DID to `did:mesh:<sha256(pubkey)>` (computeCanonicalDid honors a
  did:mesh:-prefixed value as-is) and RegistryClient.register() uses the POP
  wire shape (public_key + proof) returning the canonical `{ did }` (AGT
  #2533). Updated the stale tests to the hardened behavior: self/peer/AAD
  DIDs use did:mesh:, register() 409 resolves to `{ did }`, and the
  auto-register POST asserts the POP shape. Full suite: 560/560 pass.

- agentos-mcp-server: has no test files, so bare `vitest` exits 1 with
  "No test files found". Use `vitest run --passWithNoTests`.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
@github-actions github-actions Bot added the tests label Jun 26, 2026
@github-actions

Copy link
Copy Markdown
🤖 AI Agent: docs-sync-checker — Docs Sync

AI-generated review output. Treat it as untrusted analysis and verify before acting.

Docs Sync

Documentation is in sync.

@github-actions

Copy link
Copy Markdown
🤖 AI Agent: code-reviewer — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

TL;DR: 0 blockers, 1 warning. Version bump aligns with documentation but requires careful testing for compatibility.

# Sev Issue Where
1 Warn Potential for missed dependency issues due to widened version caps Internal package dependencies

Action items:

  1. Ensure comprehensive testing of all internal dependencies with the widened &lt;6.0 version caps to confirm compatibility.

Warnings:

# Issue Where Follow-up
1 Potential for missed dependency issues due to widened version caps Internal package dependencies Fine as follow-up PRs

No other issues found.

@github-actions

Copy link
Copy Markdown
🤖 AI Agent: test-generator — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

Test coverage looks good. No gaps identified.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment