Repository navigation
Export to_security_requirements from identity and the package root - #151
Merged
Merged
Conversation
…atching node-commerce
|
|
||
|
|
||
| def test_to_security_requirements_is_public_where_the_card_builder_is(): | ||
| import agentscore_commerce |
vvillait88
added a commit
that referenced
this pull request
Oct 4, 2026
## Summary Releases 3.1.0, carrying everything merged since 3.0.0: - the quota denial message no longer tells an agent to retry, at all six adapters (#153) - `to_security_requirements` exported from `identity` and the package root (#151), which is the new public surface that makes this a minor - A2A signing docs and supported versions corrected, README notes on UCP `keys[]` (#150, #152) - fastapi 0.142 resolves under the `if-necessary` prerelease rule with the `web3<8` constraint (#149) Also in this PR: `agentscore-py` floor raised to 2.7.1 (released today), and the `web3<8` comment now states the real blocker. web3 8.0.0 is stable, but it needs eth-abi 6, which pympp's `tempo` extra excludes (`eth-abi<6`, pympp 0.11.0 is the latest), so an unconstrained re-lock lands on the 8.0.0b3 beta and pinning 8.0.0 downgrades pympp to 0.9.1. I tried the lift: the beta resolution passed the suite, but shipping a beta to merchants is the thing the constraint exists to prevent. Worked with: Varun. Out of scope: lifting `web3<8`, which waits on pympp admitting eth-abi 6. ## Type of change - [ ] Bug fix (no breaking change) - [x] New feature (no breaking change) - [ ] Breaking change (existing callers must update) - [ ] Docs, tests, or internal maintenance only ## Public API `to_security_requirements` is newly exported (merged in #151). Nothing removed or changed. ## Test plan `ruff check`, `ruff format --check`, `ty check` and `pytest` (1893 passed, 4 skipped, 95.41% coverage) pass locally on this branch. ## Checklist - [x] Tests cover the new behavior, and the suite passes locally - [x] Lint, format, and type checks pass - [x] Docs and README examples updated if the public surface changed - [x] No secrets, credentials, or personal data in the diff or the tests
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
to_security_requirementsshipped in 3.0.0 only insideagentscore_commerce.identity.a2a, while node-commerce exportstoSecurityRequirementsfrom the package root. This re-exports it fromagentscore_commerce.identityand the package root, besidebuild_a2a_agent_card, so the two libraries match. Found in a review pass over the 3.0.0 release notes.Type of change
Public API
Adds
to_security_requirementstoagentscore_commerceandagentscore_commerce.identity(same function). Nothing removed. No version bump here: it ships with the next release rather than as its own.Test plan
New test asserts both import paths resolve to the same function and that it maps
[{"bearer": []}]to the A2A 1.0 shape.uv run ruff check .,uv run ruff format --check .,uv run ty check agentscore_commerce/, vulture, anduv run pytest tests(1892 passed, 95.41% coverage) all pass.Checklist