Skip to content

Export to_security_requirements from identity and the package root - #151

Merged
vvillait88 merged 1 commit into
mainfrom
export-to-security-requirements
Oct 3, 2026
Merged

vvillait88 merged 1 commit into
mainfrom
export-to-security-requirements

Conversation

@vvillait88

Copy link
Copy Markdown
Contributor

Summary

to_security_requirements shipped in 3.0.0 only inside agentscore_commerce.identity.a2a, while node-commerce exports toSecurityRequirements from the package root. This re-exports it from agentscore_commerce.identity and the package root, beside build_a2a_agent_card, so the two libraries match. Found in a review pass over the 3.0.0 release notes.

Type of change

  • Bug fix (no breaking change)
  • New feature (no breaking change)
  • Breaking change (existing callers must update)
  • Docs, tests, or internal maintenance only

Public API

Adds to_security_requirements to agentscore_commerce and agentscore_commerce.identity (same function). Nothing removed. No version bump here: it ships with the next release rather than as its own.

Test plan

New test asserts both import paths resolve to the same function and that it maps [{"bearer": []}] to the A2A 1.0 shape. uv run ruff check ., uv run ruff format --check ., uv run ty check agentscore_commerce/, vulture, and uv run pytest tests (1892 passed, 95.41% coverage) all pass.

Checklist

  • Tests cover the new behavior, and the suite passes locally
  • Lint, format, and type checks pass
  • Docs and README examples updated if the public surface changed (no README change needed)
  • No secrets, credentials, or personal data in the diff or the tests

Comment thread tests/test_a2a.py


def test_to_security_requirements_is_public_where_the_card_builder_is():
import agentscore_commerce
@vvillait88
vvillait88 merged commit a6d0cb4 into main Oct 3, 2026
12 checks passed
@vvillait88
vvillait88 deleted the export-to-security-requirements branch October 3, 2026 22:20
@vvillait88 vvillait88 mentioned this pull request Oct 4, 2026
5 of 8 tasks
vvillait88 added a commit that referenced this pull request Oct 4, 2026
## Summary

Releases 3.1.0, carrying everything merged since 3.0.0:

- the quota denial message no longer tells an agent to retry, at all six
adapters (#153)
- `to_security_requirements` exported from `identity` and the package
root (#151), which is the new public surface that makes this a minor
- A2A signing docs and supported versions corrected, README notes on UCP
`keys[]` (#150, #152)
- fastapi 0.142 resolves under the `if-necessary` prerelease rule with
the `web3<8` constraint (#149)

Also in this PR: `agentscore-py` floor raised to 2.7.1 (released today),
and the `web3<8` comment now states the real blocker. web3 8.0.0 is
stable, but it needs eth-abi 6, which pympp's `tempo` extra excludes
(`eth-abi<6`, pympp 0.11.0 is the latest), so an unconstrained re-lock
lands on the 8.0.0b3 beta and pinning 8.0.0 downgrades pympp to 0.9.1. I
tried the lift: the beta resolution passed the suite, but shipping a
beta to merchants is the thing the constraint exists to prevent.

Worked with: Varun.

Out of scope: lifting `web3<8`, which waits on pympp admitting eth-abi
6.

## Type of change

- [ ] Bug fix (no breaking change)
- [x] New feature (no breaking change)
- [ ] Breaking change (existing callers must update)
- [ ] Docs, tests, or internal maintenance only

## Public API

`to_security_requirements` is newly exported (merged in #151). Nothing
removed or changed.

## Test plan

`ruff check`, `ruff format --check`, `ty check` and `pytest` (1893
passed, 4 skipped, 95.41% coverage) pass locally on this branch.

## Checklist

- [x] Tests cover the new behavior, and the suite passes locally
- [x] Lint, format, and type checks pass
- [x] Docs and README examples updated if the public surface changed
- [x] No secrets, credentials, or personal data in the diff or the tests
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant