-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathpyproject.toml
More file actions
105 lines (93 loc) · 2.91 KB
/
Copy pathpyproject.toml
File metadata and controls
105 lines (93 loc) · 2.91 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
[build-system]
requires = ["hatchling"]
build-backend = "hatchling.build"
[project]
name = "costbomb"
version = "0.2.0"
description = "Denial-of-wallet fuzzing for agent systems — find the inputs that make your agent spend $500 to answer a $0.05 question, and gate CI on spend regressions."
readme = "README.md"
requires-python = ">=3.11"
license = "Apache-2.0"
license-files = ["LICENSE"]
authors = [{ name = "Swarm Proof" }]
keywords = [
"agents", "llm", "reliability", "fuzzing", "denial-of-wallet",
"cost", "finops", "security", "ci", "opentelemetry",
]
classifiers = [
"Development Status :: 3 - Alpha",
"Intended Audience :: Developers",
"License :: OSI Approved :: Apache Software License",
"Programming Language :: Python :: 3.11",
"Programming Language :: Python :: 3.12",
"Programming Language :: Python :: 3.13",
"Topic :: Software Development :: Testing",
"Topic :: Software Development :: Quality Assurance",
]
# Core stays intentionally light so `pip install costbomb` + `--dry-run` works
# with zero network/LLM (NFR-6, NFR-10). The search loop is pure Python; heavy
# integrations live in extras. Matches stampede's dependency posture.
dependencies = [
"pydantic>=2.6",
"typer>=0.12",
"rich>=13.7",
]
[project.optional-dependencies]
# Live (paid) targets — provider-agnostic (NFR-3). Pricing stays table-driven;
# no provider is hardcoded in logic.
providers = ["anthropic>=0.40", "openai>=1.40"]
# HTTPTarget against a real agent endpoint.
http = ["httpx>=0.27"]
# Real exactly-once cross-check for duplicate side-effects (REQ-RP-4).
exactly-once = ["exactly-once>=0.2"]
# Validate the downstream/blast-radius slice against Stripe test-mode.
stripe = ["stripe>=9.0"]
# OTLP export of findings to any OTel GenAI backend (REQ-RP-5, NFR-9).
otel = [
"opentelemetry-api>=1.27",
"opentelemetry-sdk>=1.27",
"opentelemetry-exporter-otlp-proto-http>=1.27",
]
dev = [
"pytest>=8.0",
"pytest-cov>=5.0",
"ruff>=0.6",
"mypy>=1.11",
"httpx>=0.27",
]
[project.scripts]
costbomb = "costbomb.cli:app"
[project.urls]
Homepage = "https://github.com/swarmproof/costbomb"
Repository = "https://github.com/swarmproof/costbomb"
Issues = "https://github.com/swarmproof/costbomb/issues"
[tool.hatch.build.targets.wheel]
packages = ["src/costbomb"]
[tool.pytest.ini_options]
testpaths = ["tests"]
addopts = "-ra"
[tool.coverage.run]
source = ["costbomb"]
branch = true
[tool.coverage.report]
exclude_also = [
"if TYPE_CHECKING:",
"raise NotImplementedError",
"@(abc\\.)?abstractmethod",
"\\.\\.\\.",
]
[tool.ruff]
line-length = 100
target-version = "py311"
src = ["src", "tests"]
[tool.ruff.lint]
select = ["E", "F", "I", "UP", "B", "SIM", "C4"]
ignore = ["E501"]
[tool.mypy]
python_version = "3.11"
packages = ["costbomb"]
plugins = ["pydantic.mypy"]
warn_unused_ignores = true
warn_redundant_casts = true
disallow_untyped_defs = false
ignore_missing_imports = true