Skip to content

chore(deps): uv: bump the all-python group across 1 directory with 9 updates - #828

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/agent/all-python-c138f6a181
Open

chore(deps): uv: bump the all-python group across 1 directory with 9 updates#828
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/agent/all-python-c138f6a181

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 29, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-python group with 9 updates in the /agent directory:

Package From To
bedrock-agentcore 1.18.1 1.22.0
claude-agent-sdk 0.2.110 0.2.144
fastapi 0.139.0 0.141.1
uvicorn 0.50.0 0.52.4
aws-opentelemetry-distro 0.18.0 0.19.0
mcp 1.28.1 2.0.0
ruff 0.15.20 0.16.4
ty 0.0.56 0.0.73
pygments 2.20.0 2.21.0

Updates bedrock-agentcore from 1.18.1 to 1.22.0

Release notes

Sourced from bedrock-agentcore's releases.

Bedrock AgentCore SDK v1.22.0

Installation

pip install bedrock-agentcore==1.22.0

What's Changed

See CHANGELOG.md for details.

What's Changed

Full Changelog: aws/bedrock-agentcore-sdk-python@v1.21.0...v1.22.0

Bedrock AgentCore SDK v1.21.0

Installation

pip install bedrock-agentcore==1.21.0

What's Changed

See CHANGELOG.md for details.

What's Changed

New Contributors

Full Changelog: aws/bedrock-agentcore-sdk-python@v1.20.0...v1.21.0

Bedrock AgentCore SDK v1.20.0

Installation

pip install bedrock-agentcore==1.20.0

What's Changed

See CHANGELOG.md for details.

What's Changed

... (truncated)

Changelog

Sourced from bedrock-agentcore's changelog.

[1.22.0] - 2026-08-18

Other Changes

  • feat(payments): add MPP, x402 upto, and Quick Create support (#643) (66a68e3)

[1.21.0] - 2026-08-06

Other Changes

  • feat(memory): add AgentCoreMemoryStore Strands integration (#588) (439d788)
  • feat(runtime): propagate X-Amz-Bedrock-AgentCore-Identity-WAT on outbound calls (#607) (01d3800)

[1.20.0] - 2026-08-04

Added

  • feat: third-party eval metrics adapter (DeepEval + Autoevals) with strands-evals mappers (#568) (9b7d38e)

Fixed

  • fix: validate sample agent inputs (#612) (528471e)

Other Changes

  • fix(test): pin autoevals judge to the OpenAI API (#617) (703ccfd)
  • fix(a2a): bind the A2A contract port, ignore generic PORT (#615) (207adb7)
  • fix(test): repair eval adapter integ fixture and wire LLM judge key (#614) (9d8cc26)
  • fix(test): repair four unit tests drifting behind source and upstream APIs (#610) (53b0b48)
  • ci: install deepeval and autoevals for evaluation integ tests (#608) (5d23292)
  • fix(ci): add pinned deepeval and autoevals to dev group (#609) (70165d9)
  • ci: wire shared composite actions (#601) (a3382a4)

[1.19.0] - 2026-07-28

Fixed

  • fix: preserve generated API reference content (#595) (4a7a8c4)
  • fix: convert RST admonition to ADOC (#594) (641000d)

Other Changes

  • fix(a2a): advertise resolved port on explicit cards (#605) (34e06f0)
  • fix(memory-integ): address capacity cap and update failures in tests (#604) (59cbff3)
  • ci: migrate workflows to shared reusable workflows (#597) (f1a7106)
  • fix(ci): pin Twine to 6.2.0 (#600) (c707388)
  • fix(a2a): honor PORT when serving locally (#593) (331f441)
  • feat(a2a): migrate runtime integration to a2a-sdk v1 (#591) (16f732f)
  • Add LLM issue auto-triage: type and high-severity labelers (#584) (3000d50)
Commits
  • b981f7e chore: bump version to 1.22.0 (#644)
  • 66a68e3 feat(payments): add MPP, x402 upto, and Quick Create support (#643)
  • 5d4ca0d chore: bump version to 1.21.0 (#623)
  • 439d788 feat(memory): add AgentCoreMemoryStore Strands integration (#588)
  • 01d3800 feat(runtime): propagate X-Amz-Bedrock-AgentCore-Identity-WAT on outbound cal...
  • 9195576 chore: bump version to 1.20.0 (#619)
  • 703ccfd fix(test): pin autoevals judge to the OpenAI API (#617)
  • 207adb7 fix(a2a): bind the A2A contract port, ignore generic PORT (#615)
  • 9d8cc26 fix(test): repair eval adapter integ fixture and wire LLM judge key (#614)
  • 528471e fix: validate sample agent inputs (#612)
  • Additional commits viewable in compare view

Updates claude-agent-sdk from 0.2.110 to 0.2.144

Release notes

Sourced from claude-agent-sdk's releases.

v0.2.144

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.246

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.144/

pip install claude-agent-sdk==0.2.144

v0.2.143

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.238

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.143/

pip install claude-agent-sdk==0.2.143

v0.2.142

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.237

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.142/

pip install claude-agent-sdk==0.2.142

v0.2.141

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.236

... (truncated)

Changelog

Sourced from claude-agent-sdk's changelog.

0.2.144

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.246

0.2.143

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.238

0.2.142

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.237

0.2.141

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.236

0.2.140

New Features

  • MCP 2.x support for in-process SDK MCP servers: The SDK now supports mcp 2.x alongside 1.x (dependency widened to mcp>=1.23.0,<3.0.0). In-process servers are served over mcp's own in-memory transport instead of hand-rolled JSON-RPC dispatch, so hand-built mcp.server.Server instances now work at full fidelity — resources, prompts, and all result content types reach the CLI verbatim. Tool cancellation on interrupt is supported on mcp 2.x. claude_agent_sdk.ToolAnnotations accepts both camelCase and snake_case hint names on every mcp version (#1218)
  • forward_subagent_text option: New forward_subagent_text boolean on ClaudeAgentOptions forwards a subagent's text and thinking blocks as messages in the stream, so consumers can render the full nested transcript. Matches the TypeScript SDK's forwardSubagentText (#1206)
  • ResultError exception with structured error payload: When the CLI exits after a terminal error result, the SDK now raises ResultError (a subclass of ProcessError) instead of a bare "exit code 1" error. Carries subtype, errors, result, api_error_status, terminal_reason, session_id, and the raw data dict so callers can branch on failure reason without string matching. New exported types: ResultError (#1205)
  • can_use_tool callback support for query() and string prompts: The can_use_tool permission callback now works with string prompts (not just ClaudeSDKClient), and stdin is kept open so the CLI can send permission requests over the control protocol (#1204)

Bug Fixes

  • Recover parent_tool_use_id when reading subagent transcripts: get_subagent_messages() and get_subagent_messages_from_store() now recover the parent_tool_use_id from the subagent's metadata, linking each subagent's messages to the Agent tool_use block in the parent session. SessionMessage also gains a parent_agent_id field for the spawning agent's id (#1207)

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.235

0.2.139

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.233

0.2.138

Internal/Other Changes

... (truncated)

Commits
  • 24956bb docs: update changelog for v0.2.144
  • f8d0152 chore: release v0.2.144
  • a4c72e4 chore: bump bundled CLI version to 2.1.246
  • 15af77c chore: bump bundled CLI version to 2.1.245
  • 21b93c1 chore: bump bundled CLI version to 2.1.241
  • d867f48 chore: bump bundled CLI version to 2.1.243
  • 542fefb chore: bump bundled CLI version to 2.1.241
  • e8bde60 chore: bump bundled CLI version to 2.1.240
  • bc0c9af chore: bump bundled CLI version to 2.1.239
  • 22795fe docs: update changelog for v0.2.143
  • Additional commits viewable in compare view

Updates fastapi from 0.139.0 to 0.141.1

Release notes

Sourced from fastapi's releases.

0.141.1

Fixes

  • 🐛 Fix support for background tasks and headers from dependencies in app.frontend(). PR #16105 by @​tiangolo.

Docs

0.141.0

Features

  • ✨ Add app.frontend(check_dir="auto"), to make local development more convenient with fastapi dev. PR #16102 by @​tiangolo.

0.140.13

Fixes

Docs

0.140.12

Fixes

0.140.11

Fixes

  • 🐛 Fix response_model_* params ignored for non-generator endpoints with Iterable[..] return type. PR #15093 by @​YuriiMotov.

0.140.10

Fixes

Internal

0.140.9

Fixes

  • 🐛 Fix exclude_defaults not propagated to dict keys and values in jsonable_encoder. PR #16043 by @​MBGrao.

... (truncated)

Commits
  • 95f8322 🔖 Release version 0.141.1 (#16106)
  • f137944 📝 Update release notes
  • d623544 🐛 Fix support for background tasks and headers from dependencies in `app.fron...
  • 1d211b9 📝 Update release notes
  • 8a1f876 📝 Document FASTAPI_ENV in FastAPI CLI guide (#16104)
  • c7e7b65 🔖 Release version 0.141.0 (#16103)
  • 6bceb84 📝 Update release notes
  • 5429fed ✨ Add app.frontend(check_dir="auto"), to make local development more conven...
  • 628663f 🔖 Release version 0.140.13 (#16096)
  • 0b54fd0 📝 Update release notes
  • Additional commits viewable in compare view

Updates uvicorn from 0.50.0 to 0.52.4

Release notes

Sourced from uvicorn's releases.

Version 0.52.4

Fixed

  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#3078)

Full Changelog: Kludex/uvicorn@0.52.3...0.52.4

Version 0.52.3

Changed

  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#3067)

Full Changelog: Kludex/uvicorn@0.52.2...0.52.3

Version 0.52.2

Fixed

  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#3063)

Full Changelog: Kludex/uvicorn@0.52.1...0.52.2

Version 0.52.1

Fixed

  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#3050)
  • Remove duplicate Content-Type and Content-Length headers from WebSocket denial responses on the websockets-sansio implementation, and deliver non-UTF-8 denial bodies intact (#3041)

Full Changelog: Kludex/uvicorn@0.52.0...0.52.1

Version 0.52.0

This release adds an experimental HTTP/1.1 implementation backed by zttp, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.

It is still experimental, so don't put it in front of production traffic yet. Try it with --http zttp, and please send any feedback to the issue tracker.

Added

  • Add an experimental zttp HTTP/1.1 implementation, selectable with --http zttp (#2979)

Fixed

  • Keep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (#3036)

Full Changelog: Kludex/uvicorn@0.51.0...0.52.0

Version 0.51.0

What's Changed

... (truncated)

Changelog

Sourced from uvicorn's changelog.

0.52.4 (August 18, 2026)

Fixed

  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#3078)

0.52.3 (August 13, 2026)

Changed

  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#3067)

0.52.2 (August 13, 2026)

Fixed

  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#3063)

0.52.1 (August 1, 2026)

Fixed

  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#3050)
  • Remove duplicate Content-Type and Content-Length headers from WebSocket denial responses on the websockets-sansio implementation, and deliver non-UTF-8 denial bodies intact (#3041)

0.52.0 (July 29, 2026)

This release adds an experimental HTTP/1.1 implementation backed by zttp, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.

It is still experimental, so don't put it in front of production traffic yet. Try it with --http zttp, and please send any feedback to the issue tracker.

Added

  • Add an experimental zttp HTTP/1.1 implementation, selectable with --http zttp (#2979)

Fixed

  • Keep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (#3036)

0.51.0 (July 8, 2026)

Added

  • Restart workers one at a time on SIGHUP, bringing each replacement up before retiring the old worker, so reloads no longer drop requests (#3025)

Removed

  • Remove colorama from the standard extra (#3027)

... (truncated)

Commits

Updates aws-opentelemetry-distro from 0.18.0 to 0.19.0

Release notes

Sourced from aws-opentelemetry-distro's releases.

Release v0.19.0

What's Changed

  • fix(mcp): fall back to HTTP headers for server-side trace context when params._meta is absent (#829)
  • fix(mcp-instrumentation): always inject W3C trace context into outbound HTTP request headers so MCP servers that read context only from HTTP (API Gateways, service meshes, non-Python MCP servers) can join the caller's trace, even with OTEL_MCP_SUPPRESS_HTTP_INSTRUMENTATION enabled (#827)
  • Nightly dependency update: OpenTelemetry 1.44.0/0.65b0 (#799)
  • feat(genai): capture user input and agent output on llama_index invoke_agent spans (#824)
  • fix(crewai): use native per-call token usage when crewai provides it (#822)
  • fix(crewai): normalize tool description across crewai versions (#821)
  • fix(serviceevents): key the incident-snapshot dedup hash on operation + bounded throw-site origin (module/path.function) (#825)
  • fix(crewai): report per-call LLM token usage instead of cumulative total (#806)
  • fix(genai): serialize tool call arguments/results and blob bytes to match OTel util-genai (primitives kept native, bytes base64-encoded) (#817)
  • feat(genai): capture user input and agent output on invoke_agent spans (#815)
  • refactor(serviceevents): make the endpoint span processor framework-agnostic
  • fix(serviceevents): gate incident trace correlation on the SAMPLED flag and harden incident dedup/rate-limiting
  • fix(genai): serialize list-valued message content into typed parts so multimodal/reasoning content is no longer stringified to a Python repr in gen_ai.input/output.messages across langchain, llama_index, and crewai (#805)
  • feat: add OTel lite SDK for Lambda cold start optimization (#789)

Upstream Components

  • opentelemetry-api - 1.44.0
  • opentelemetry-sdk - 1.44.0
  • opentelemetry-exporter-otlp-proto-grpc - 1.44.0
  • opentelemetry-exporter-otlp-proto-http - 1.44.0
  • opentelemetry-propagator-b3 - 1.44.0
  • opentelemetry-propagator-jaeger - 1.44.0
  • opentelemetry-exporter-otlp-proto-common - 1.44.0
  • opentelemetry-sdk-extension-aws - 2.1.0
  • opentelemetry-propagator-aws-xray - 1.0.2
  • opentelemetry-distro - 0.65b0
  • opentelemetry-processor-baggage - 0.65b0
  • opentelemetry-propagator-ot-trace - 0.65b0
  • opentelemetry-instrumentation - 0.65b0
  • opentelemetry-instrumentation-aws-lambda - 0.65b0
  • opentelemetry-instrumentation-aio-pika - 0.65b0
  • opentelemetry-instrumentation-aiohttp-client - 0.65b0
  • opentelemetry-instrumentation-aiokafka - 0.65b0
  • opentelemetry-instrumentation-aiopg - 0.65b0
  • opentelemetry-instrumentation-asgi - 0.65b0
  • opentelemetry-instrumentation-asyncpg - 0.65b0
  • opentelemetry-instrumentation-boto3sqs - 0.65b0
  • opentelemetry-instrumentation-botocore - 0.65b0
  • opentelemetry-instrumentation-celery - 0.65b0
  • opentelemetry-instrumentation-confluent-kafka - 0.65b0
  • opentelemetry-instrumentation-dbapi - 0.65b0
  • opentelemetry-instrumentation-django - 0.65b0
  • opentelemetry-instrumentation-falcon - 0.65b0
  • opentelemetry-instrumentation-fastapi - 0.65b0
  • opentelemetry-instrumentation-flask - 0.65b0
  • opentelemetry-instrumentation-grpc - 0.65b0
  • opentelemetry-instrumentation-httpx - 0.65b0

... (truncated)

Changelog

Sourced from aws-opentelemetry-distro's changelog.

v0.19.0 - 2026-07-22

  • fix(mcp): fall back to HTTP headers for server-side trace context when params._meta is absent (#829)
  • fix(mcp-instrumentation): always inject W3C trace context into outbound HTTP request headers so MCP servers that read context only from HTTP (API Gateways, service meshes, non-Python MCP servers) can join the caller's trace, even with OTEL_MCP_SUPPRESS_HTTP_INSTRUMENTATION enabled (#827)
  • Nightly dependency update: OpenTelemetry 1.44.0/0.65b0 (#799)
  • feat(genai): capture user input and agent output on llama_index invoke_agent spans (#824)
  • fix(crewai): use native per-call token usage when crewai provides it (#822)
  • fix(crewai): normalize tool description across crewai versions (#821)
  • fix(serviceevents): key the incident-snapshot dedup hash on operation + bounded throw-site origin (module/path.function) (#825)
  • fix(crewai): report per-call LLM token usage instead of cumulative total (#806)
  • fix(genai): serialize tool call arguments/results and blob bytes to match OTel util-genai (primitives kept native, bytes base64-encoded) (#817)
  • feat(genai): capture user input and agent output on invoke_agent spans (#815)
  • refactor(serviceevents): make the endpoint span processor framework-agnostic
  • fix(serviceevents): gate incident trace correlation on the SAMPLED flag and harden incident dedup/rate-limiting
  • fix(genai): serialize list-valued message content into typed parts so multimodal/reasoning content is no longer stringified to a Python repr in gen_ai.input/output.messages across langchain, llama_index, and crewai (#805)
  • feat: add OTel lite SDK for Lambda cold start optimization (#789)
Commits
  • 821465a Pre-release: Update version to 0.19.0 (#834)
  • ed8782f Backport #797 to release/v0.19.x: add Python 3.14 Lambda runtime (#835)
  • 4dcbf60 test(e2e): wire Python Lambda Lite SDK test into Application Signals E2E (#833)
  • 315bddd fix(mcp): extract server-side trace context from HTTP headers when _meta is a...
  • 76f8f2d Nightly dependency update: OpenTelemetry 1.44.0/0.65b0 (#799)
  • ffa8c72 fix(mcp-instrumentation): inject W3C trace context into outbound HTTP headers...
  • d7e49b5 Revert "feat(genai): extract gen_ai.tool.call.arguments/result as LLO content...
  • f9bb4f5 feat(genai): capture user input and agent output on llama_index invoke_agent ...
  • 2b43f03 Add best-effort public ECR image signing to release workflow (#828)
  • 9356e72 Key incident-snapshot dedup hash on operation + throw-site origin (#825)
  • Additional commits viewable in compare view

Updates mcp from 1.28.1 to 2.0.0

Release notes

Sourced from mcp's releases.

v2.0.0

MCP Python SDK v2 Stable Release

This is v2.0.0, the stable v2 release of the MCP Python SDK. It supports the 2026-07-28 revision of the Model Context Protocol and serves every earlier revision from the same server. pip install mcp now installs 2.x.

pip install "mcp[cli]"
# or
uv add "mcp[cli]"

Documentation Rewrite

The documentation has the full tutorial and API reference. Coming from v1? What's new in v2 is the tour of what changed and why, and the migration guide lists every breaking change with before-and-after code.

V1 Maintenance mode

v1.x is in maintenance mode and will only receive security fixes from now on The 1.x line lives on the v1.x branch, continues to receive critical bug fixes and security patches, and is documented at https://py.sdk.modelcontextprotocol.io/v1/. If your project is not ready to migrate, keep a <2 upper bound on your requirement (for example mcp>=1.28,<2).

Highlights

One SDK, both protocol eras

v2 speaks the 2026-07-28 revision (stateless requests with no handshake, server/discover, subscriptions/listen, multi-round-trip requests) and still serves every 2025-era client from the same MCPServer, over Streamable HTTP and stdio, with nothing to configure. Client(target) negotiates the version automatically.

FastMCP is now MCPServer, and there is a first-class Client

The decorator API is unchanged; the low-level Server is rebuilt around a shared dispatcher engine, and one Client object replaces v1's transport-plus-ClientSession-plus-initialize() layering. It connects to a URL, a stdio subprocess, a custom transport, or straight to a server object in memory for tests.

Multi-round-trip requests and resolver dependency injection

At 2026-07-28 the server can no longer call the client, so tools return the question instead. A Resolve(fn) parameter is filled by your function invisibly to the model and can put a question to the user; one tool body serves both eras.

Extension APIs, OpenTelemetry, and a standalone types package

Servers and clients compose protocol extensions through pluggable extension APIs (MCP Apps built in); OpenTelemetry tracing ships on by default; every protocol type is its own package, mcp-types (imported as mcp_types), published in lock-step with mcp.

Hardened stdio and auth

stdio servers keep handler subprocesses and stray prints off the wire, and stdout is diverted to stderr while serving. OAuth adds RFC 9207 issuer validation, the SEP-990 identity-assertion flow, and the client-credentials extension.

Coming from a v2 pre-release

Since the last release candidate: the per-version wire packages are private (mcp_types._v*), mcp.types is a permanent alias for mcp_types, the auth registration request model is split from the registered-client record, cancelled requests are no longer answered, and log notifications are gated on the per-request log-level opt-in at 2026-07-28. Since the betas: Client(cache=False) is now cache=None with CacheConfig() the default; Context.client_id, RFC7523OAuthClientProvider, and OAuthClientProvider(timeout=) are removed; the client-credentials providers take scope=; message_handler receives notifications and exceptions only; FileResource(is_binary=) becomes encoding; MCP_* env vars are gone with pydantic-settings; Streamable HTTP servers reject bodies over 4 MiB with HTTP 413. The migration guide covers all of it.

Known gaps

The tasks extension (SEP-2663) is not part of this release. On the client, the DPoP proof binding (SEP-1932) and the workload-identity jwt-bearer grant are not implemented; both are additive and can land in 2.x.

Feedback

... (truncated)

Commits
  • 6f69a37 Present v2 as the stable release across the README, docs, and policies (#3178)
  • 78e6fbb Serve v2 docs at the site root, with permanent per-major paths (#3176)
  • af06330 Remove unused StreamableHTTPTransport.get_session_id() (#3205)
  • 68ca87e Document the two-line release process for stable v2 (#3179)
  • c9c431b Expose the middleware chain on MCPServer and stop sending unrequested change ...
  • 528e366 Fail fast on server-to-client requests in JSON-response mode instead of hangi...
  • 27f5cc7 Remove unused mcpserver.exceptions.ValidationError (#3199)
  • 89c5e70 Gate log notifications on the per-request log-level opt-in at 2026-07-28 (#3198)
  • b61ce38 docs: fix off-by-one hl_lines in apps.md (#3196)
  • b7c9a91 Add mcp.types as a permanent alias for mcp_types (#3190)
  • Additional commits viewable in compare view

Updates ruff from 0.15.20 to 0.16.4

Release notes

Sourced from ruff's releases.

0.16.4

Release Notes

Released on 2026-08-20.

Preview features

  • [flake8-use-pathlib] Add autofix for PTH116 (#26460)
  • [refurb] Restrict delete-full-slice to lists (FURB131) (#27711)
  • [refurb] Skip FURB101 and FURB103 when the open argument is a file descriptor (#27643)

Bug fixes

  • Fix InvalidInstruction on Windows CPUs that do not support POPCNT (#27803)
  • [pyflakes] Emit semantic syntax errors in string type definitions as F722 (#27835)
  • [pylint] Allow os._exit imports in import-private-name (PLC2701) (#27738)

Rule changes

  • [syntax-errors] Align mixed t-string/bytes error message with CPython 3.14 (#27766)
  • [ruff] Add ctypes.LittleEndianStructure and related types to existing exception (RUF012) (#27753)
  • [syntax-errors] Detect duplicate keyword arguments (#17804)
  • [syntax-errors] Detect parameters declared nonlocal (#27628)

Server

  • Offer display-only fixes and mark safe fixes preferred (#27807)
  • Support pull diagnostics for notebook cells (#27779)

Documentation

  • Add default indicator to rules table (#27724)
  • Fix broken link to Python docs (#27757)

Other changes

  • Fix s390x stacker assembly in release builds (#27776)
  • Guarantee minimum stack size when parsing a module, standalone expression, and suites (#25464)
  • Reduce configuration deserialization code size (#27924)
  • Check packed AST index bounds (#27849)

Contributors

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.4

Released on 2026-08-20.

Preview features

  • [flake8-use-pathlib] Add autofix for PTH116 (#26460)
  • [refurb] Restrict delete-full-slice to lists (FURB131) (#27711)
  • [refurb] Skip FURB101 and FURB103 when the open argument is a file descriptor (#27643)

Bug fixes

  • Fix InvalidInstruction on Windows CPUs that do not support POPCNT (#27803)
  • [pyflakes] Emit semantic syntax errors in string type definitions as F722 (#27835)
  • [pylint] Allow os._exit imports in import-private-name (PLC2701) (#27738)

Rule changes

  • [syntax-errors] Align mixed t-string/bytes error message with CPython 3.14 (#27766)
  • [ruff] Add ctypes.LittleEndianStructure and related types to existing exception (RUF012) (#27753)
  • [syntax-errors] Detect duplicate keyword arguments (#17804)
  • [syntax-errors] Detect parameters declared nonlocal (#27628)

Server

  • Offer display-only fixes and mark safe fixes preferred (#27807)
  • Support pull diagnostics for notebook cells (#27779)

Documentation

  • Add default indicator to rules table (#27724)
  • Fix broken link to Python docs (#27757)

Other changes

  • Fix s390x stacker assembly in release builds (#27776)
  • Guarantee minimum stack size when parsing a module, standalone expression, and suites (#25464)
  • Reduce configuration deserialization code size (#27924)
  • Check packed AST index bounds (#27849)

Contributors

... (truncated)

Commits

…updates

Bumps the all-python group with 9 updates in the /agent directory:

| Package | From | To |
| --- | --- | --- |
| [bedrock-agentcore](https://github.com/aws/bedrock-agentcore-sdk-python) | `1.18.1` | `1.22.0` |
| [claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-python) | `0.2.110` | `0.2.144` |
| [fastapi](https://github.com/fastapi/fastapi) | `0.139.0` | `0.141.1` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.50.0` | `0.52.4` |
| [aws-opentelemetry-distro](https://github.com/aws-observability/aws-otel-python-instrumentation) | `0.18.0` | `0.19.0` |
| [mcp](https://github.com/modelcontextprotocol/python-sdk) | `1.28.1` | `2.0.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.15.20` | `0.16.4` |
| [ty](https://github.com/astral-sh/ty) | `0.0.56` | `0.0.73` |
| [pygments](https://github.com/pygments/pygments) | `2.20.0` | `2.21.0` |



Updates `bedrock-agentcore` from 1.18.1 to 1.22.0
- [Release notes](https://github.com/aws/bedrock-agentcore-sdk-python/releases)
- [Changelog](https://github.com/aws/bedrock-agentcore-sdk-python/blob/main/CHANGELOG.md)
- [Commits](aws/bedrock-agentcore-sdk-python@v1.18.1...v1.22.0)

Updates `claude-agent-sdk` from 0.2.110 to 0.2.144
- [Release notes](https://github.com/anthropics/claude-agent-sdk-python/releases)
- [Changelog](https://github.com/anthropics/claude-agent-sdk-python/blob/main/CHANGELOG.md)
- [Commits](anthropics/claude-agent-sdk-python@v0.2.110...v0.2.144)

Updates `fastapi` from 0.139.0 to 0.141.1
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.139.0...0.141.1)

Updates `uvicorn` from 0.50.0 to 0.52.4
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.50.0...0.52.4)

Updates `aws-opentelemetry-distro` from 0.18.0 to 0.19.0
- [Release notes](https://github.com/aws-observability/aws-otel-python-instrumentation/releases)
- [Changelog](https://github.com/aws-observability/aws-otel-python-instrumentation/blob/main/CHANGELOG.md)
- [Commits](aws-observability/aws-otel-python-instrumentation@v0.18.0...v0.19.0)

Updates `mcp` from 1.28.1 to 2.0.0
- [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md)
- [Commits](modelcontextprotocol/python-sdk@v1.28.1...v2.0.0)

Updates `ruff` from 0.15.20 to 0.16.4
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.15.20...0.16.4)

Updates `ty` from 0.0.56 to 0.0.73
- [Release notes](https://github.com/astral-sh/ty/releases)
- [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ty@0.0.56...0.0.73)

Updates `pygments` from 2.20.0 to 2.21.0
- [Release notes](https://github.com/pygments/pygments/releases)
- [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES)
- [Commits](pygments/pygments@2.20.0...2.21.0)

---
updated-dependencies:
- dependency-name: bedrock-agentcore
  dependency-version: 1.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-python
- dependency-name: claude-agent-sdk
  dependency-version: 0.2.144
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-python
- dependency-name: fastapi
  dependency-version: 0.141.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-python
- dependency-name: uvicorn
  dependency-version: 0.52.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-python
- dependency-name: aws-opentelemetry-distro
  dependency-version: 0.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-python
- dependency-name: mcp
  dependency-version: 2.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-python
- dependency-name: ruff
  dependency-version: 0.16.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-python
- dependency-name: ty
  dependency-version: 0.0.73
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-python
- dependency-name: pygments
  dependency-version: 2.21.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-python
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Aug 29, 2026
@dependabot
dependabot Bot requested review from a team as code owners August 29, 2026 06:14
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Aug 29, 2026

@scottschreckengaust scottschreckengaust left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1. Verdict — Request changes

Request changes. Three of the nine bumps are load-bearing and unsafe as shipped: mcp 1.28.1 → 2.0.0 is a major release that renames or deletes every symbol agent/src/gateway_tools.py uses (and swaps httpx for httpx2, so import httpx no longer resolves at all); claude-agent-sdk 0.2.110 → 0.2.144 breaks the #215 SDK↔CLI lockstep the repo explicitly documents; and ty 0.0.56 → 0.0.73 re-runs the exact regression that killed #626 and #590. build (agentcore) is RED with 14 ty diagnostics — this is not a flake, it is the diff.

The other six bumps (bedrock-agentcore, fastapi, uvicorn, aws-opentelemetry-distro, pygments, ruff) look clean and I would take them today.


2. Vision alignment

Keeping the runtime patched serves bounded blast radius — stale transports and CVE-bearing pins are exactly the drift ABCA's own dogfooding is supposed to catch. But as assembled this PR works against the tenet: it lands a silent, total loss of the AgentCore Gateway tool bridge (repo_config) behind a broad except Exception that converts the breakage into a per-call log_error_cw line and an isError tool result. The agent keeps running, tells the model "Error calling repo_config: ModuleNotFoundError…", and the operator gets a CloudWatch error on every invocation. That is the plausible-default / silent-degradation failure mode docs/design/VISION.md and the AI004 heuristic exist to prevent. No ADR covers trading the Gateway bridge away, and none should — the fix is code, not a tenet trade.

Correctly, cedarpy did not move: .github/dependabot.yml:47-54 ignores it for all update types, so the Cedar parity contract (cedarpy 4.8.4 / @cedar-policy/cedar-wasm 4.8.2) is intact. No cedar finding. That ignore-list pattern is also the template for fixing findings B1 and B2 below.


3. Blocking issues

B1 — mcp==2.0.0 breaks the AgentCore Gateway bridge in four independent ways (agent/pyproject.toml:24)

agent/src/gateway_tools.py is the only consumer of mcp, and every symbol it touches changed in 2.0.0. I read the upstream v2.0.0 tag to confirm each one:

gateway_tools.py mcp 1.28.1 mcp 2.0.0 (verified at tag v2.0.0)
:161 from mcp.client.streamable_http import streamablehttp_client exists renamed streamable_http_client (src/mcp/client/streamable_http.py:640)
:163 streamablehttp_client(url=…, auth=…, timeout=…) accepts auth, timeout signature is (url, *, http_client: httpx2.AsyncClient | None = None, terminate_on_close: bool = True)auth and timeout are gone; auth/timeout must ride on a caller-supplied httpx2.AsyncClient
:164-168 unpack as (read, write, _get_session_id) 3-tuple yields TransportStreams = tuple[ReadStream, WriteStream] (src/mcp/client/_transport.py:13) — 2-tuple; the 3-way unpack raises ValueError
:178 read_timeout_seconds=timedelta(seconds=…) timedelta float | None (ty flagged this directly)
:212 from mcp.shared.exceptions import McpError exists renamed MCPError (src/mcp/shared/exceptions.py:20)
:46, :85, :206 import httpx present transitively via mcp mcp 2.0.0 depends on httpx2 (module name httpx2); the httpx entry is deleted from agent/uv.lock entirely

Risk, concretely. With enableToolGateway=true, every mcp__abca_gateway__repo_config call now:

  1. raises ImportError at gateway_tools.py:161 before the transport is ever opened;
  2. falls through except _expected_gateway_errors() — because _expected_gateway_errors() at :196-217 also silently loses both httpx.HTTPError and McpError to its bare except ImportError: pass, collapsing the expected-error tuple to (OSError, TimeoutError);
  3. lands in except Exceptionlog_error_cw(...) → an operator-visible APPLICATION_LOGS error per tool call, plus a bogus isError result telling the model the Gateway is down.

So the feature is 100% dead and the diagnostics are actively misleading: a routine HTTP hiccup and a total import failure now produce the same loud line, and genuine MCP protocol errors that used to be classified as expected also go loud. This is the silent-failure pattern the module's own docstrings claim to defend against.

Suggested fix — do it in a dedicated, reviewed PR, not a grouped bump:

# agent/src/gateway_tools.py
import httpx2                                             # and declare httpx2 in pyproject
from mcp.client.streamable_http import streamable_http_client
...
auth = _sigv4_auth(region)          # returns httpx2.Auth
async with (
    httpx2.AsyncClient(auth=auth, timeout=_GATEWAY_TIMEOUT_S) as http_client,
    streamable_http_client(url, http_client=http_client) as (read, write),
    ClientSession(read, write) as session,
):
    ...
    return await session.call_tool(remote_name, arguments,
                                   read_timeout_seconds=_GATEWAY_TIMEOUT_S)  # float, not timedelta

and rename McpErrorMCPError at :212.

Related root cause, worth fixing in the same change: httpx is used in src/gateway_tools.py (3 sites) and tests/test_gateway_tools.py:270 but is not declared in agent/pyproject.toml — it free-rode on mcp's transitive pin, which is precisely the trap the file's own comment at agent/pyproject.toml:44-48 says was fixed for pyyaml/jsonschema ("previously only transitively present; declared directly so the workflow loader does not depend on another package's transitive pin"). Declare httpx2 explicitly so the next transport shuffle is a resolver error, not a runtime one.

Also: .github/dependabot.yml:44-46 groups patterns: ["*"] with no update-types split, so a runtime-transport major rides in the same PR as a pygments patch. Either add mcp to the existing ignore: block for version-update:semver-major (mirroring the cedarpy precedent at :47-54), or split majors into their own group, so a breaking transport change gets its own reviewable PR.

B2 — claude-agent-sdk==0.2.144 breaks the #215 SDK↔CLI lockstep; comment and docs are now false (agent/pyproject.toml:19)

I read the upstream _cli_version.py at both tags:

  • v0.2.110__cli_version__ = "2.1.191"
  • v0.2.144__cli_version__ = "2.1.246"

agent/Dockerfile:90 still installs @anthropic-ai/claude-code@2.1.191. The image therefore ships an SDK that expects CLI 2.1.246 next to an on-PATH CLI at 2.1.191 — and agent/Dockerfile:76-80 states the invariant in its own words: "the SDK and the on-PATH CLI must agree on the control protocol." A control-protocol mismatch surfaces as opaque subprocess/transport failures deep in a long-running task, i.e. the worst possible place.

Three stale-comment/doc sites make this worse than a bare version skew, because they now assert something untrue:

  1. agent/pyproject.toml:19 — comment still links the v0.2.110 release tag and claims "(bundles claude CLI 2.1.191; kept in lockstep with the npm CLI pin in the Dockerfile, #215)". Both clauses are now false, and the comment is the primary documentation of the invariant this PR broke. (comment-analyzer dimension)
  2. agent/Dockerfile:76 — "Pinned 2.1.191 to match the CLI bundled by claude-agent-sdk 0.2.110".
  3. docs/design/BEDROCK_COST_ATTRIBUTION.md:89 (+ generated mirror docs/src/content/docs/architecture/Bedrock-cost-attribution.md:93) — "Both are pinned in lockstep — claude-agent-sdk==0.2.110 (bundles CLI 2.1.191) and npm @anthropic-ai/claude-code@2.1.191."

Suggested fix: bump agent/Dockerfile to @anthropic-ai/claude-code@2.1.246, re-verify the install.cjs/claude --version shim guard at :88-94 still passes on that build, update all three prose sites, and re-run mise //docs:sync for the mirror. Then close the loop structurally: claude-agent-sdk belongs in the .github/dependabot.yml ignore: list alongside cedarpy (dependabot's uv ecosystem cannot see the npm pin in the Dockerfile, so it cannot keep this lockstep — the config is guaranteed to reopen this PR), or add a check:claude-cli-lockstep guard to mise run drift-prevention that diffs the installed claude_agent_sdk._cli_version.__cli_version__ against the Dockerfile pin. #215 has now drifted twice; the third time should be caught by a script, not a reviewer.

B3 — ty 0.0.73 regresses the typecheck gate on 7 deliberate frozen-model negative tests (agent/pyproject.toml:88)

build (agentcore) failed with 14 diagnostics (job 99062295464). Seven are the #626/#590 pattern, verbatim:

error[invalid-assignment]: Property `filename` defined in `PreparedAttachment` is read-only
  --> tests/test_attachments.py:46:13
error[invalid-assignment]: Property `author` defined in `IssueComment` is read-only
  --> tests/test_models.py:30:13
... also test_models.py:63, :140, :170, :431, :462

Every one of those lines is inside with pytest.raises(ValidationError): — the tests are asserting runtime immutability of frozen Pydantic models and are correct as written. ty 0.0.73 has simply started reporting statically what the tests deliberately do at runtime. Deleting or weakening the assertions would trade real coverage for a green tool; the right move is a targeted # ty: ignore[invalid-assignment] on each of the 7 lines (or a scoped [tool.ty.rules] override for tests/), landed as its own reviewed change with a comment explaining why — exactly the shape of the existing deprecated = "ignore" entry at agent/pyproject.toml:180-181.

This is the third time a 0.0.x ty bump has flipped this build red (#590, #626, now #828). Given ty is pre-1.0 and its gate is uv run ty check (agent/mise.toml:45), it is worth deciding as a team whether ty should be pinned-and-bumped deliberately (dependabot ignore, like cedarpy) rather than weekly. That is a judgement call for the maintainer, not a blocker on its own — but B3 as it stands is a blocker because the gate is red.


4. Non-blocking suggestions / nits

  • ruff 0.15.20 → 0.16.4 is cosmetic in the lock. agent/mise.toml:29/33/37/41 runs uvx ruff …, which resolves the latest ruff from PyPI at task time, not the [dev] pin. The CI log confirms it ("Downloading ruff (9.8MiB)" → "All checks passed!"), so the lint gate was already effectively on a floating ruff before this PR. Worth either pinning the uvx invocation (uvx ruff@0.16.4 …) or dropping ruff from [dev] so the pin isn't misleading. Same applies to bandit at :59.
  • Six bumps are genuinely clean. bedrock-agentcore 1.22.0, fastapi 0.141.1, uvicorn 0.52.4, aws-opentelemetry-distro 0.19.0, pygments 2.21.0, ruff 0.16.4 produced zero diagnostics. If you split this PR, those can merge immediately.
  • Dropped transitives are safe. pydantic-settings, python-dotenv, httpx-sse, httpcore, and opentelemetry-instrumentation-elasticsearch all disappear from agent/uv.lock; I grepped agent/src and agent/tests for each and found no importers.
  • truststore 0.10.4 (new transitive via httpx2/httpcore2) is fine here. httpx2 replaces certifi with the OS trust store; agent/Dockerfile:52 already installs ca-certificates, so TLS verification will resolve. Flagging only so it isn't a surprise later.
  • Branch name dependabot/uv/agent/all-python-c138f6a181 does not match (feat|fix|chore|docs)/<issue>-…. Waived — automated PR.

Supply chain (I checked, since three of the new distributions look alarming)

httpx2, httpcore2, httpx2-jsfetch, mcp-types, truststore are all new names in agent/uv.lock. I queried PyPI metadata for each: httpx2/httpcore2github.com/pydantic/httpx2 (the next-gen httpx line), httpx2-jsfetch → its Emscripten/Pyodide transport, mcp-typesgithub.com/modelcontextprotocol/python-sdk (official), truststoregithub.com/sethmlarson/truststore. All are pulled in by mcp==2.0.0's own declared metadata, not injected by dependabot, and all sdist/wheel URLs are files.pythonhosted.org with plausible upload timestamps. No evidence of typosquatting or a hijacked release — the version jumps are surprising but legitimate. Secrets, deps, and workflow scan is green.


5. Documentation

  • Required and missing: docs/design/BEDROCK_COST_ATTRIBUTION.md:89 pins the SDK↔CLI lockstep in prose as 0.2.110/2.1.191. This PR falsifies it. The generated mirror docs/src/content/docs/architecture/Bedrock-cost-attribution.md:93 carries the same sentence and must be regenerated via mise //docs:sync — never hand-edited.
  • Also stale: agent/pyproject.toml:19 and agent/Dockerfile:76 (see B2).
  • Mirror sync status: currently consistent (neither source nor mirror was touched), so docs:sync is not failing — but fixing B2 will require the regen.
  • Issue tracking: no backing issue, which is correct for a dependabot PR — ADR-003 governs contributor work and the repo has explicit automation for dependency PRs (dependencies / python:uv labels, .github/workflows/auto-approve.yml). No governance finding. That said, B1 and B3 each deserve a tracked issue with a priority label, since neither is a one-line pin edit: "migrate gateway_tools.py to the mcp 2.x transport API" and "ty ≥0.0.73 flags frozen-Pydantic negative tests" (a follow-up to the closed #626).

6. Tests & CI

  • build (agentcore): FAILURE. 14 ty diagnostics; mise aborted at //agent:typecheck, so //agent:test never ran. There is no pytest evidence for any of these nine bumps.
  • Statically (unverified — I did not run pytest; see the honesty note in §7), agent:test would also fail once typecheck is satisfied: tests/test_gateway_tools.py:271 does monkeypatch.setattr("mcp.client.streamable_http.streamablehttp_client", _fake_transport), and monkeypatch.setattr raises AttributeError on a missing attribute by default — that symbol no longer exists in mcp 2.0.0. tests/test_gateway_tools.py:270's import httpx would raise ModuleNotFoundError. So at least two test classes (TestCallGateway, TestSigV4Auth) are broken, and the --cov-fail-under=72 floor at agent/mise.toml:53 is at risk.
  • Credit where due: the test suite would have caught B1 even without ty, precisely because it monkeypatches by string path rather than accepting whatever the module exposes. That is the AI001 "verify against real API behavior" discipline working as intended.
  • No new tests are needed for a pin bump, but the migration in B1 must land with the TestCallGateway transport double updated to the 2-tuple TransportStreams shape and the http_client= kwarg — otherwise the mock will keep asserting the old contract (AI005).
  • Bootstrap synth-coverage: not applicable. No CDK constructs, stacks, handlers, or CFN resource types changed; cdk/src/bootstrap/** and BOOTSTRAP_VERSION are correctly untouched.
  • Dead-code detection (advisory), Validate PR title, Secrets, deps, and workflow scan green; CodeQL neutral.

Base freshness: the PR is behind origin/main (merge-base 780161b9, tip 4da0a1fa, 31 files changed on main since). I diffed agent/pyproject.toml and agent/Dockerfile across that range — untouched on main, so nothing main-side invalidates the analysis above, and none of the three blockers is a stale-base artifact.


7. Review agents run

Nested agent dispatch was unavailable in this run — this review executed as a subagent inside a batch fan-out, which cannot spawn the pr-review-toolkit agents that Stage 3 names. I therefore applied each rubric dimension inline, by hand, one at a time. Everything below is rubric-applied-inline, not agent-dispatched. I did not run mise run build, pytest, ty, jest, tsc, or cdk synth — the worktree has no agent/.venv. All execution evidence cited is from the CI job log (job 99062295464) plus read-only queries against upstream repos/PyPI; anything I could not execute is labelled unverified above.

Dimension Applied inline Result
code-reviewer (guidelines/style/conventions) Yes B2 (repo's own documented #215 lockstep violated); nit on the uvx ruff pin fiction; dependabot grouping/ignore conventions vs the cedarpy precedent
silent-failure-hunter (error handling, swallowed exceptions, plausible defaults) Yes Primary finding. gateway_tools.py:196-217 except ImportError: pass silently drops both httpx.HTTPError and McpError from the expected-error tuple; :243-264's broad except Exception converts a total feature outage into a per-call log_error_cw + isError result. Feature dead, no build/deploy signal.
comment-analyzer (comment accuracy vs code) Yes agent/pyproject.toml:19 asserts sdk 0.2.110 / CLI 2.1.191 next to a 0.2.144 pin and links the wrong release tag; agent/Dockerfile:76; BEDROCK_COST_ATTRIBUTION.md:89 + mirror. Four false statements.
pr-test-analyzer (failure-path coverage) Yes agent:test never ran (build aborted at typecheck); statically ≥2 test classes in tests/test_gateway_tools.py break under mcp 2.0.0; coverage floor at risk. See §6.
type-design-analyzer (new types: encapsulation, invariants) Out of scope The diff introduces no new types — it is two dependency-manifest files. The consumers of changed upstream types are covered under B1.
security-review skill Out of scope as a code review, replaced by a targeted manual supply-chain check No IAM, Cedar, network, secrets, or input-validation code changed. The security-relevant surface here is provenance of the five new distributions and the certifi → truststore TLS-trust shift, which I verified by hand against PyPI metadata and agent/Dockerfile:52 — see the Supply chain subsection in §4.

8. Human heuristics

  • Proportionality — concern. A single grouped PR carrying one major runtime-transport break, one control-protocol lockstep break, and one pre-1.0 type-checker regression is disproportionate to its reviewability. .github/dependabot.yml:44-46 (patterns: ["*"], no update-types split) is the mechanism; the cedarpy ignore: block at :47-54 is the proven fix pattern.
  • Coherence — concern. The repo has a well-articulated "these two pins move together" doctrine (Cedar parity banner at agent/pyproject.toml:25-42, cdk/package.json:7, #215 at agent/Dockerfile:76) and enforces it for Cedar via dependabot ignore + parity fixtures. The same doctrine is stated for claude-agent-sdk ↔ the npm CLI pin but is enforced by nothing — so it drifts. Same concept, unequal enforcement.
  • Clarity — concern. agent/pyproject.toml:19 now says the opposite of what the code does (B2), and gateway_tools.py's error-classification docstrings promise a distinction between "routine hiccup" and "loud bug" that mcp 2.0.0 quietly erases (B1). Both are cases of comments/architecture describing an invariant that the pins no longer satisfy.
  • Appropriateness — pass, with one note. The bumps are the right kind of maintenance and the six clean ones are ready. The note: tests/test_gateway_tools.py monkeypatches by string path, which is exactly why the mocked test would surface an upstream rename instead of hiding it (AI001) — good existing practice that must be preserved when B1's migration updates the transport double to the new 2-tuple shape.

Recommended path forward

  1. Split this PR. Keep bedrock-agentcore, fastapi, uvicorn, aws-opentelemetry-distro, pygments, ruff → green, merge.
  2. mcp 2.x → its own issue + PR, migrating gateway_tools.py to streamable_http_client / httpx2 / MCPError / float timeout / 2-tuple unpack, declaring httpx2 directly, and updating tests/test_gateway_tools.py.
  3. claude-agent-sdk → its own PR paired with agent/Dockerfile at CLI 2.1.246, all four prose sites corrected, mise //docs:sync re-run, plus a drift-prevention guard so #215 cannot drift a fourth time.
  4. ty 0.0.73 → its own PR adding the 7 targeted # ty: ignore[invalid-assignment] suppressions with a rationale comment; consider a dependabot ignore for ty while it is pre-1.0.
  5. Add mcp (major) and claude-agent-sdk to the .github/dependabot.yml ignore: block so the grouped weekly PR stops re-proposing coordinated changes it structurally cannot make.

Comment thread agent/pyproject.toml
"fastapi==0.141.1", #https://pypi.org/project/fastapi/
"uvicorn==0.52.4", #https://pypi.org/project/uvicorn/
"aws-opentelemetry-distro==0.19.0", #https://pypi.org/project/aws-opentelemetry-distro/
"mcp==2.0.0", #https://pypi.org/project/mcp/

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

BLOCKING (B1)mcp 1.28.1 → 2.0.0 is a major release that renames or deletes every symbol agent/src/gateway_tools.py uses. Verified against upstream tag v2.0.0:

  • streamablehttp_clientstreamable_http_client (src/mcp/client/streamable_http.py:640)
  • that function no longer accepts auth= or timeout= — signature is (url, *, http_client: httpx2.AsyncClient | None = None, terminate_on_close: bool = True); SigV4 auth and the timeout must now ride on a caller-supplied httpx2.AsyncClient
  • it yields TransportStreams = tuple[ReadStream, WriteStream] (src/mcp/client/_transport.py:13) — a 2-tuple, so gateway_tools.py:164-168's as (read, write, _get_session_id) raises ValueError
  • ClientSession.call_tool(read_timeout_seconds=…) is now float | None, not timedelta (gateway_tools.py:178)
  • mcp.shared.exceptions.McpErrorMCPError (gateway_tools.py:212)
  • mcp 2.0.0 depends on httpx2 (module httpx2), and the httpx entry is deleted from agent/uv.lock — so import httpx at gateway_tools.py:46/85/206 no longer resolves

Net effect: with enableToolGateway=true, every repo_config call raises ImportError at line 161, _expected_gateway_errors() silently loses both httpx.HTTPError and McpError to its except ImportError: pass, and the failure lands in the broad except Exception → a log_error_cw operator error per tool call plus a bogus isError result to the model. Feature 100% dead, diagnostics actively misleading.

Also: httpx is used in src/gateway_tools.py and tests/test_gateway_tools.py:270 but never declared here — it free-rode on mcp's transitive pin, the exact trap the comment at lines 44-48 says was fixed for pyyaml/jsonschema. Declare httpx2 explicitly.

Suggested: split mcp 2.x into its own issue + PR with the migration, and add mcp version-update:semver-major to the .github/dependabot.yml ignore: block (mirroring the cedarpy precedent at :47-54) so a breaking transport change gets its own reviewable PR.

Comment thread agent/pyproject.toml
"bedrock-agentcore==1.18.1", #https://pypi.org/project/bedrock-agentcore/
"claude-agent-sdk==0.2.110", #https://github.com/anthropics/claude-agent-sdk-python/releases/tag/v0.2.110 (bundles claude CLI 2.1.191; kept in lockstep with the npm CLI pin in the Dockerfile, #215)
"bedrock-agentcore==1.22.0", #https://pypi.org/project/bedrock-agentcore/
"claude-agent-sdk==0.2.144", #https://github.com/anthropics/claude-agent-sdk-python/releases/tag/v0.2.110 (bundles claude CLI 2.1.191; kept in lockstep with the npm CLI pin in the Dockerfile, #215)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

BLOCKING (B2) — this bump breaks the #215 SDK↔CLI lockstep, and the trailing comment now asserts the opposite of the pin.

I read _cli_version.py at both upstream tags:

  • v0.2.110__cli_version__ = "2.1.191"
  • v0.2.144__cli_version__ = "2.1.246"

agent/Dockerfile:90 still installs @anthropic-ai/claude-code@2.1.191, so the image ships an SDK expecting CLI 2.1.246 beside an on-PATH CLI at 2.1.191 — against the invariant agent/Dockerfile:76-80 states in its own words ("the SDK and the on-PATH CLI must agree on the control protocol"). A control-protocol mismatch surfaces as opaque subprocess failures deep in a long-running task.

The comment on this line is now doubly false: it links the v0.2.110 release tag and claims "(bundles claude CLI 2.1.191; kept in lockstep with the npm CLI pin in the Dockerfile, #215)". Two more sites repeat it: agent/Dockerfile:76 and docs/design/BEDROCK_COST_ATTRIBUTION.md:89 (+ generated mirror docs/src/content/docs/architecture/Bedrock-cost-attribution.md:93).

Fix: bump the Dockerfile to 2.1.246, re-verify the install.cjs / claude --version shim guard at Dockerfile:88-94, correct all four prose sites, re-run mise //docs:sync. Then close the loop structurally — dependabot's uv ecosystem cannot see the npm pin in the Dockerfile, so it structurally cannot keep this lockstep and will reopen this PR forever. Either add claude-agent-sdk to the ignore: list alongside cedarpy, or add a check:claude-cli-lockstep guard to mise run drift-prevention that diffs claude_agent_sdk._cli_version.__cli_version__ against the Dockerfile pin. #215 has drifted twice now; the third time should be caught by a script, not a reviewer.

Comment thread agent/pyproject.toml
@@ -87,7 +87,7 @@ dev = [
"ruff",
"ty",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

BLOCKING (B3) — the lock moves ty 0.0.56 → 0.0.73, which re-runs the exact regression that killed #626 and #590. build (agentcore) is RED with 14 diagnostics (job 99062295464); 7 are the frozen-Pydantic pattern:

error[invalid-assignment]: Property `filename` defined in `PreparedAttachment` is read-only
  --> tests/test_attachments.py:46:13
error[invalid-assignment]: Property `author` defined in `IssueComment` is read-only
  --> tests/test_models.py:30:13
... also test_models.py:63, :140, :170, :431, :462

Every one of those lines sits inside with pytest.raises(ValidationError): — the tests assert runtime immutability of frozen models and are correct as written. ty 0.0.73 has simply started reporting statically what the tests deliberately do at runtime. Weakening the assertions would trade real coverage for a green tool.

Fix: targeted # ty: ignore[invalid-assignment] on each of the 7 lines (or a scoped [tool.ty.rules] override for tests/), landed as its own reviewed change with a rationale comment — the same shape as the existing deprecated = "ignore" entry at line 180-181.

Standing suggestion: this is the third 0.0.x ty bump to flip the build red. Since the gate is uv run ty check (agent/mise.toml:45) and ty is pre-1.0, consider a dependabot ignore for ty so it is bumped deliberately rather than weekly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant