From 834cfb8b78a4582dcff16a95b4f97ff4ef8ff551 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 5 Oct 2026 22:15:46 +0000 Subject: [PATCH 1/2] build(deps-dev): bump agentrust-trace-tests Bumps [agentrust-trace-tests](https://github.com/agentrust-io/trace-spec) from 0.5.1 to 0.6.1. - [Release notes](https://github.com/agentrust-io/trace-spec/releases) - [Changelog](https://github.com/agentrust-io/trace-spec/blob/main/CHANGELOG.md) - [Commits](https://github.com/agentrust-io/trace-spec/commits) --- updated-dependencies: - dependency-name: agentrust-trace-tests dependency-version: 0.6.1 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- integrations/ramen-ai-cmcp/pyproject.toml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/integrations/ramen-ai-cmcp/pyproject.toml b/integrations/ramen-ai-cmcp/pyproject.toml index 6df486a..6ee0150 100644 --- a/integrations/ramen-ai-cmcp/pyproject.toml +++ b/integrations/ramen-ai-cmcp/pyproject.toml @@ -15,7 +15,7 @@ dependencies = [ [project.optional-dependencies] test = [ - "agentrust-trace-tests==0.5.1", + "agentrust-trace-tests==0.6.1", "pytest==9.1.1", ] From 386468a69be088fdfcff117885829b2501ce0846 Mon Sep 17 00:00:00 2001 From: Imran Siddique <45405841+imran-siddique@users.noreply.github.com> Date: Mon, 5 Oct 2026 16:29:10 -0700 Subject: [PATCH 2/2] test(ramen-ai-cmcp): expect agentrust-trace-tests 0.6.1 findings 0.6.1 adds three checks that SKIP at Level 0 here (TR-POL-003, TR-APR-003, TR-APR-005) and adds TR-APR-005 to the Level 1 failures, since this record's appraisal.status is 'none'. The assertions stay exact. tested_against now names the pins this job runs: agentrust-trace 0.11.0, agentrust-trace-tests 0.6.1. Signed-off-by: Imran Siddique <45405841+imran-siddique@users.noreply.github.com> Co-Authored-By: Claude Opus 5.5 --- integrations/ramen-ai-cmcp/integration.yaml | 4 +-- .../ramen-ai-cmcp/tests/test_mapping.py | 27 ++++++++++++++----- 2 files changed, 23 insertions(+), 8 deletions(-) diff --git a/integrations/ramen-ai-cmcp/integration.yaml b/integrations/ramen-ai-cmcp/integration.yaml index 13ae757..c26d75b 100644 --- a/integrations/ramen-ai-cmcp/integration.yaml +++ b/integrations/ramen-ai-cmcp/integration.yaml @@ -21,5 +21,5 @@ trace_conformance_level: 0 trace_roles: - record-producer tested_against: - agentrust-trace: "0.10.0" - agentrust-trace-tests: "0.5.1" + agentrust-trace: "0.11.0" + agentrust-trace-tests: "0.6.1" diff --git a/integrations/ramen-ai-cmcp/tests/test_mapping.py b/integrations/ramen-ai-cmcp/tests/test_mapping.py index ef19f78..5d4466a 100644 --- a/integrations/ramen-ai-cmcp/tests/test_mapping.py +++ b/integrations/ramen-ai-cmcp/tests/test_mapping.py @@ -251,8 +251,17 @@ def test_signed_software_record_passes_level_0(self, trace_key): record = _build(_load("vector1_allowed.json"), iat=int(time.time())) results = run_trace_tests(record, "trace", level=0) findings = [finding for group in results.values() for finding in group] - assert len(findings) == 8 - assert all(finding.status is Status.PASS for finding in findings) + assert len(findings) == 15 + # agentrust-trace-tests 0.6 adds three checks that do not apply to this + # record at Level 0 and report SKIP; everything else passes. + assert sorted( + finding.code for finding in findings if finding.status is not Status.PASS + ) == ["TR-APR-003", "TR-APR-005", "TR-POL-003"] + assert all( + finding.status is Status.SKIP + for finding in findings + if finding.status is not Status.PASS + ) assert [ finding.status for finding in findings if finding.code == "TR-SIG-005" ] == [Status.PASS] @@ -260,10 +269,12 @@ def test_signed_software_record_passes_level_0(self, trace_key): def test_signed_software_record_fails_level_1_runtime_rules(self, trace_key): """A software-only record fails Level 1 on runtime rules only. - Two of them as of agentrust-trace-tests 0.5.1. TR-RTE-001 is the platform - rule and has always fired here. TR-RTE-004 was added in 0.5.1 and fires - because no verifier nonce is supplied: this harness does not issue one, and - the record carries no ``runtime.nonce`` to match it if it did. The assertion + Three of them as of agentrust-trace-tests 0.6.1. TR-APR-005 was added in + 0.6 and fires because the record's appraisal.status is 'none', not + 'affirming'. TR-RTE-001 is the platform rule and has always fired here. + TR-RTE-004 was added in 0.5.1 and fires because no verifier nonce is + supplied: this harness does not issue one, and the record carries no + ``runtime.nonce`` to match it if it did. The assertion stays an exact comparison on purpose, so that a future change to the Level 1 finding set fails this test rather than passing silently. """ @@ -276,6 +287,10 @@ def test_signed_software_record_fails_level_1_runtime_rules(self, trace_key): if finding.status is Status.FAIL ] assert [(finding.code, finding.message) for finding in failures] == [ + ( + "TR-APR-005", + "TR-APR-005: Level 1 requires appraisal.status 'affirming', got 'none'", + ), ( "TR-RTE-001", "TR-RTE-001: runtime.platform 'software-only' is development-mode "