Skip to content

uv: let fastapi 0.142 resolve (prerelease if-necessary, web3<8) - #149

Merged
vvillait88 merged 1 commit into
mainfrom
uv-prerelease-if-necessary
Oct 3, 2026
Merged

vvillait88 merged 1 commit into
mainfrom
uv-prerelease-if-necessary

Conversation

@vvillait88

Copy link
Copy Markdown
Contributor

Summary

prerelease = "disallow" silently held fastapi at 0.141.1. fastapi 0.142's standard extra (reached through x402[fastapi]) requires opentelemetry-sdk>=1.44, which pins opentelemetry-semantic-conventions==0.66b0, and that package has only ever published beta-tagged versions. Under disallow, uv resolved around it by keeping the older fastapi, and Dependabot failed outright on the same conflict in a consumer.

The setting existed to keep web3 off its 8.0.0 beta: cdp-sdk, pytempo and x402 all take web3 unbounded, and solana 0.41 needs a websockets only the web3 8 beta allows. This replaces the blanket ban with the two things it was standing in for:

  • prerelease = "if-necessary", which admits a prerelease only for a package with no stable release (the OpenTelemetry semantic-conventions family).
  • constraint-dependencies = ["web3<8"], which keeps web3 on 7.16.0 and solana on 0.40.1, the same versions disallow held.

Lock result: fastapi 0.142.2, plus the OpenTelemetry packages it now requires. The only prereleases in the lock are the three semantic-conventions packages.

Type of change

  • Bug fix (no breaking change)
  • New feature (no breaking change)
  • Breaking change (existing callers must update)
  • Docs, tests, or internal maintenance only

Public API

None. [tool.uv] and uv.lock are development-only; the published package's metadata is unchanged, so this needs no release.

Test plan

uv run ruff check ., uv run ruff format --check ., uv run ty check agentscore_commerce/, uv run vulture . --min-confidence 80 --exclude .venv and uv run pytest tests (1891 passed, 4 skipped) all exit 0. OSV over uv.lock (164 packages) is clean. Also checked: if-necessary alone pulls web3 8.0.0b3 back in, which is why the constraint is needed.

Checklist

  • Tests cover the new behavior, and the suite passes locally
  • Lint, format, and type checks pass
  • Docs and README examples updated if the public surface changed (no public surface changed)
  • No secrets, credentials, or personal data in the diff or the tests

vvillait88 added a commit to agentscore/python-sdk that referenced this pull request Oct 3, 2026
## Summary

Replaces `prerelease = "disallow"` with `prerelease = "if-necessary"`,
matching python-commerce (agentscore/python-commerce#149). A blanket
`disallow` also refuses packages that have never published a stable
version, and uv then silently keeps an older version of whatever needs
them; that held fastapi back in python-commerce and core's store and
failed Dependabot outright. `if-necessary` admits a prerelease only
where no stable release exists, and any package that reaches for a beta
it does not need gets its own constraint (python-commerce pins `web3<8`;
nothing in this tree needs one).

This tree relocks with no changes and no prereleases.

## Type of change

- [ ] Bug fix (no breaking change)
- [ ] New feature (no breaking change)
- [ ] Breaking change (existing callers must update)
- [x] Docs, tests, or internal maintenance only

## Public API

None. `[tool.uv]` is development-only, so no release.

## Test plan

`uv lock --upgrade` reports no changes, no `a`/`b`/`rc` version in
`uv.lock`, and `uv run pytest tests` passes (177 passed, 2 skipped).

## Checklist

- [x] Tests cover the new behavior, and the suite passes locally
- [x] Lint, format, and type checks pass
- [x] Docs and README examples updated if the public surface changed (no
public surface changed)
- [x] No secrets, credentials, or personal data in the diff or the tests
@vvillait88
vvillait88 merged commit 5d698fb into main Oct 3, 2026
12 checks passed
@vvillait88
vvillait88 deleted the uv-prerelease-if-necessary branch October 3, 2026 21:24
@vvillait88 vvillait88 mentioned this pull request Oct 4, 2026
5 of 8 tasks
vvillait88 added a commit that referenced this pull request Oct 4, 2026
## Summary

Releases 3.1.0, carrying everything merged since 3.0.0:

- the quota denial message no longer tells an agent to retry, at all six
adapters (#153)
- `to_security_requirements` exported from `identity` and the package
root (#151), which is the new public surface that makes this a minor
- A2A signing docs and supported versions corrected, README notes on UCP
`keys[]` (#150, #152)
- fastapi 0.142 resolves under the `if-necessary` prerelease rule with
the `web3<8` constraint (#149)

Also in this PR: `agentscore-py` floor raised to 2.7.1 (released today),
and the `web3<8` comment now states the real blocker. web3 8.0.0 is
stable, but it needs eth-abi 6, which pympp's `tempo` extra excludes
(`eth-abi<6`, pympp 0.11.0 is the latest), so an unconstrained re-lock
lands on the 8.0.0b3 beta and pinning 8.0.0 downgrades pympp to 0.9.1. I
tried the lift: the beta resolution passed the suite, but shipping a
beta to merchants is the thing the constraint exists to prevent.

Worked with: Varun.

Out of scope: lifting `web3<8`, which waits on pympp admitting eth-abi
6.

## Type of change

- [ ] Bug fix (no breaking change)
- [x] New feature (no breaking change)
- [ ] Breaking change (existing callers must update)
- [ ] Docs, tests, or internal maintenance only

## Public API

`to_security_requirements` is newly exported (merged in #151). Nothing
removed or changed.

## Test plan

`ruff check`, `ruff format --check`, `ty check` and `pytest` (1893
passed, 4 skipped, 95.41% coverage) pass locally on this branch.

## Checklist

- [x] Tests cover the new behavior, and the suite passes locally
- [x] Lint, format, and type checks pass
- [x] Docs and README examples updated if the public surface changed
- [x] No secrets, credentials, or personal data in the diff or the tests
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant