Repository navigation
chore: bump monorepo version 4.1.0 -> 5.0.0 - #3191
Conversation
Aligns the released version line with the documentation, which already describes Agent Control Specification (ACS) as the "AGT 5.0 policy layer" (ACS landed in #2747) while the artifacts were still on 4.1.0. - Bumped self-version to 5.0.0 across all first-party packages: 57 pyproject.toml, 4 __init__.py __version__, 17 package.json, the Rust workspace Cargo.toml, the .NET Directory.Build.props, the top-level VERSION file, and the Claude Code plugin/marketplace manifests. - Widened internal cross-package caps from <5.0 to <6.0 (57 pins) so the 5.0.0 packages resolve against each other. Third-party caps (jsonschema, anyio, redis, pytest-cov, etc.) are untouched. - Updated the docs/ARCHITECTURE.md version banner and added a CHANGELOG [5.0.0] section. Out of scope / intentionally unchanged: the independently-versioned policy-engine/ ACS engine (0.3.1-beta), the separately-tagged Go module, historical README "as of v4.1.0" consolidation narrative, and all lockfiles (package-lock.json/uv.lock/Cargo.lock regenerate at publish; CI does not enforce --locked). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
Dependency ReviewThe following issues were found:
License Issuesagent-governance-python/agent-governance-toolkit-cli/pyproject.toml
agent-governance-python/agent-governance-toolkit-integrations/pyproject.toml
agent-governance-python/agent-governance-toolkit-protocols/pyproject.toml
agent-governance-python/agent-hypervisor/pyproject.toml
agent-governance-python/agent-mcp-governance/pyproject.toml
agent-governance-python/agent-mesh/pyproject.toml
agent-governance-python/agent-os/modules/iatp/pyproject.toml
agent-governance-python/agent-os/modules/nexus/pyproject.toml
agent-governance-python/agent-os/pyproject.toml
agent-governance-python/agent-primitives/pyproject.toml
agent-governance-python/agent-runtime/pyproject.toml
agent-governance-python/agent-sandbox/pyproject.toml
agent-governance-python/agent-sre/pyproject.toml
OpenSSF ScorecardScorecard details
Scanned Files
|
📦 Dependency diff (SBOM)Comparing main → liamcrumm/bump-v5.0.0. ✅ No dependency changes detected. |
The monorepo v5 bump set the Rust workspace version to 5.0.0 (via
[workspace.package].version), but the internal path dependency
`agentmesh-mcp = { path = "agentmesh-mcp", version = "4.0.0" }` kept its
`^4.0.0` requirement, which excludes the now-5.0.0 member. `agentmesh`
depends on `agentmesh-mcp` (agentmesh-mcp.workspace = true), so cargo
resolution failed:
error: failed to select a version for the requirement
`agentmesh-mcp = "^4.0.0"`
Mirror the prior convention (the requirement tracked the major line:
^4.0.0 for the 4.x workspace) and bump it to ^5.0.0. cargo metadata now
resolves cleanly. The canonical scripts/sync-version.py syncs
[workspace.package].version but not [workspace.dependencies] path-dep
requirements, so this needs the manual follow-up on a major bump.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
… for mcp-server
The v5 bump touches the TS SDK and mcp-server package.json, which triggers
the path-filtered build-npm CI job. That job surfaced pre-existing failures
(they fail identically on main; build-npm only runs when these packages
change, so they went unnoticed):
- agent-governance-typescript: 5 tests asserted the pre-hardening DID
scheme. Per the mesh security model (DIDs MUST be derived from
SHA-256(public_key), never client-supplied), MeshClient now canonicalizes
the self DID to `did:mesh:<sha256(pubkey)>` (computeCanonicalDid honors a
did:mesh:-prefixed value as-is) and RegistryClient.register() uses the POP
wire shape (public_key + proof) returning the canonical `{ did }` (AGT
#2533). Updated the stale tests to the hardened behavior: self/peer/AAD
DIDs use did:mesh:, register() 409 resolves to `{ did }`, and the
auto-register POST asserts the POP shape. Full suite: 560/560 pass.
- agentos-mcp-server: has no test files, so bare `vitest` exits 1 with
"No test files found". Use `vitest run --passWithNoTests`.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Liam Crumm <liamcrumm@gmail.com>
🤖 AI Agent: docs-sync-checker — Docs Sync
Docs SyncDocumentation is in sync. |
🤖 AI Agent: code-reviewer — View details
TL;DR: 0 blockers, 1 warning. Version bump aligns with documentation but requires careful testing for compatibility.
Action items:
Warnings:
No other issues found. |
🤖 AI Agent: test-generator — View details
Test coverage looks good. No gaps identified. |
Summary
Bump the monorepo version from
4.1.0to5.0.0. The documentation already describes Agent Control Specification (ACS) as the "AGT 5.0 policy layer" in multiple places (introduced with ACS in #2747), but the shipped artifacts were still on the4.1.0line. This aligns the version with the docs and marks the ACS-era major.Problem
ACSis referenced as the "AGT 5.0 policy layer" acrossdocs/packages/agent-control-specification.md,docs/GLOSSARY.md,docs/tutorials/55-agent-control-specification.md,policy-engine/README.md,policy-engine/sdk/python/README.md, and theagt-policiespackage description but other packages are still versioned4.1.0.Changes
pyproject.tomlself-versions and 4__init__.py__version__→5.0.0package.jsonself-versions →5.0.0agent-governance-rust/Cargo.tomlandagent-governance-dotnet/Directory.Build.props→5.0.0VERSIONfile and Claude Codeplugin.json/marketplace.jsonmanifests →5.0.0,<5.0→,<6.0so the 5.0.0 packages resolve against each otherdocs/ARCHITECTURE.mdversion banner →v5.0.0; newCHANGELOG.md[5.0.0]sectionIntentionally NOT changed
policy-engine/(ACS engine) — independently versioned at0.3.1-beta, not part of the monorepo line.agent-governance-golang/v3.1.0); no monorepo version constant.jsonschema,anyio,redis,pytest-cov,beautifulsoup4,langfuse,helicone,ddtrace,cedarpykeep their own<5.0bounds.agent-governance-pythonREADMEs say "as of v4.1.0 … consolidated", which describes when consolidation happened; left as history.package-lock.json/uv.lock/Cargo.lockregenerate at publish time (per the repo's documented version-bump process); CI does not enforce--locked, and theuv.lock4.1.0entries are resolved-from-PyPI dependency versions that stay correct until5.0.0actually publishes. Hand-editing them risks transitive-version corruption.Notes for reviewers
[4.1.0]section (the post-4.0.0 delta sat under[Unreleased]); that delta is now promoted under[5.0.0]with aBREAKINGalignment note. The pre-existing missing[4.1.0]section was left as-is rather than retroactively reconstructed.Testing
pyproject.tomland 19 changed.jsonfiles validated to parse.agentmesh.__version__imports as5.0.0;agent-meshpyproject reports5.0.0.,<6.0cap is on an AGT-internal package (no third-party pin touched), andpolicy-engine/, Go, lockfiles, andnode_modulesare untouched.python scripts/docs/check_links.py: 0 new broken links.Follow-up fixes (cross-language resolution + pre-existing test debt surfaced by the bump)
Bumping the workspace/package versions triggered two CI jobs that don't normally run, exposing issues that needed fixing for this PR to go green:
e5c054b0[workspace.package].versionto 5.0.0, but the internalagentmesh-mcppath-dependency kept its^4.0.0requirement, which excludes the now-5.0.0 member, socargofailed to resolve. Bumped the requirement to5.0.0to track the major line. (scripts/sync-version.pysyncs the workspace version but not[workspace.dependencies]path-dep requirements, so this needs the manual follow-up on a major bump.)13186e13agent-governance-typescriptand the mcp-serverpackage.jsontriggered the path-filteredbuild-npmjob, which surfaced failures that already existed onmain. The TS SDK had 5 stale tests asserting the old client-supplieddid:agentmesh:DID scheme; per the mesh security model the SDK now derivesdid:mesh:<sha256(public_key)>andregister()uses the POP wire shape (#2533). Updated the tests to the hardened behavior (did:mesh:self/peer/AAD DIDs, POP-shape registration, canonical{ did }return) — full suite 560/560. mcp-server has no test files, so barevitestexited 1; switched tovitest run --passWithNoTests.These are not behavior changes to shipped code; the Rust fix restores resolution, and the TS changes align tests with the existing DID/POP hardening rather than weakening it.