Skip to content

build(deps-dev): bump agentrust-trace-tests from 0.5.1 to 0.6.1 in /integrations/ramen-ai-cmcp - #256

Merged
imran-siddique merged 2 commits into
mainfrom
dependabot/pip/integrations/ramen-ai-cmcp/agentrust-trace-tests-0.6.1
Oct 6, 2026
Merged

imran-siddique merged 2 commits into
mainfrom
dependabot/pip/integrations/ramen-ai-cmcp/agentrust-trace-tests-0.6.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Bumps agentrust-trace-tests from 0.5.1 to 0.6.1.

Release notes

Sourced from agentrust-trace-tests's releases.

TRACE SDK 0.6.0

Fixed

  • __version__ reported the wrong number for four releases. It was a literal that drifted from pyproject.toml at #36 and was never corrected, so v0.3.0, v0.4.0, v0.5.0 and v0.5.1 each shipped a wheel reporting 0.2.0 at runtime. Anyone pinning or logging on agentrust_trace.__version__ got the wrong answer, and nothing failed. It now derives from installed package metadata, which makes the two unable to disagree, and tests/test_version.py pins the source tree against pyproject.toml and requires the changelog to carry a section for the declared version before a tag is cut.

  • The package description advertised TRACE v0.1. The PyPI summary still named the superseded profile.

Added

  • TraceSandboxAdapter: Trust Records from a sandboxed agent runtime. A kernel sandbox confines one agent on one machine. It does not answer, on its own, which agent on which of two hundred machines took an action, what actually ran rather than what the policy said, or how to say either on a host with no secure hardware. The adapter builds a record from what such a runtime already has at session close: sandbox identity, image digest, the effective policy bundle bytes, and the decision log. No change to the runtime is required.

    Unlike TraceAGTAdapter, one code path spans Level 0 and Level 1. Passing a SandboxAttestation moves the record from software-only to the attested platform and nothing else about the call changes, because a sandbox runs wherever the customer runs it and the deployments that most need evidence often have the least hardware.

    A caller cannot claim hardware it does not have: platform is only ever set from a supplied attestation, an attestation may not name software-only, the platform is validated against the enum on RuntimeInfo rather than a copy of it, and the measurement must be a sha256:/sha384: digest. Sandbox identity and image ride the existing subject and build_provenance.digest, so no schema change was needed.

    Two defaults differ from the AGT adapter, deliberately. appraisal.status is "none", because building a record does not appraise it and affirming would put a verdict in the field a consumer reads to find out whether anybody checked. transparency is None and omitted, which is what an unanchored record should say.

    tool_transcript.hash is taken over the RFC 8785 canonical form of the decision log rather than json.dumps(sort_keys=True). The two agree on ASCII and diverge on non-ASCII strings and number formatting; a decision log carries paths and hostnames, and the signature pre-image already uses JCS. See docs/integration/sandbox-runtime.md and examples/sandbox-runtime.json.

  • verify_record(..., revocation=...) enforces key revocation at verification time (#76). §3.2.1 has always required that "Verifiers MUST consult current revocation status at verification time", but verify_record() checked only signature and freshness, so a record signed by a revoked or compromised key kept verifying. The new revocation parameter accepts either a container of revoked key identifiers or a callable performing a live CRL, status-endpoint, or SCITT lookup. A listed key is rejected, and a store that cannot answer is also rejected: an unavailable revocation source is not evidence that a key is unrevoked.

    Keys are identified by RFC 7638 JWK Thumbprint or kid. The check reads the trusted key rather than record["cnf"]["jwk"], which is attacker-controlled until the signature verifies.

    Additive and backward compatible: revocation defaults to None, which leaves verification purely offline and unchanged. That mode cannot prove non-revocation, now stated in LIMITATIONS.md and docs/verification.md. No normative text, schema, or record field changed.

  • jwk_thumbprint(jwk): RFC 7638 JWK Thumbprint (RFC 8037 §2 for OKP), exported so callers can key a revocation list on the same identifier the verifier derives.

Changelog

Sourced from agentrust-trace-tests's changelog.

Changelog

All notable changes to the TRACE specification will be documented here.

Format: Semantic Versioning. Spec versions follow MAJOR.MINOR.PATCH:

  • MAJOR: breaking changes to wire format or required Trust Record fields
  • MINOR: new optional fields, new platform profiles, new conformance levels
  • PATCH: editorial fixes, clarifications, non-normative additions

[Unreleased]

  • verify_record reports what a caller-supplied appraiser found about runtime.measurement, per layer (#279 platform-measurement row, #431). A matching composite measurement says nothing about which layers were measured, which were appraised, or whether the evidence describes one boot, and verify_record never sees the quote, log or reference values to decide it. The new platform_appraiser argument, modelled on citation_resolver, is called last with a copy of runtime; the result's new platform_measurement field carries its report as appraised with a LayerCheck per layer (established, or not_established with layer_not_measured, measured_not_appraised or evidence_spans_multiple_boots), appraisal_rejected when the appraiser raised, returned another shape or appraised another measurement, or not_attempted without one. The names are not accepted normative text. No outcome moves revocation, the thumbprint, citations or appraisal.status, and not_attempted is never a pass. Sixteen signed vectors in examples/platform-measurement/: each cause with a twin that differs only in the condition producing it, and two carrying measurements from published quotes on a board with a discrete TPM. No schema or wire-format change.

  • A surrogate code point in an object key is refused as rfc8785.CanonicalizationError (found by fuzzing #452). rfc8785 refuses one in a value itself, but in an object key the UTF-16 key sort reaches it first and raised UnicodeEncodeError. The three places that catch CanonicalizationError to raise their own error, the intent bridge's _jcs and provenance.sign_record and verify_record, let it through: sign_bridge and verify_bridge (a key in tool_call.arguments, say) raised it instead of IntentBridgeError, and the two provenance functions instead of ProvenanceError. The canonicalizer now reports it as a CanonicalizationError subclass, as it already does for nesting too deep to walk. No schema or wire-format change.

  • verify_successor_artifact binds the observer's name to the observer key (#451, following #432). It now takes trusted_observer, the identity trusted_observer_jwk belongs to, and refuses a successor whose signed observer is anything else. Before this, any key the verifier accepted for observers could sign under another observer's name, and evaluate_successor_observation, which decides trust and independence on that name, could reach established with independence required on evidence from the executor alone. trusted_observer is a required keyword argument, so existing callers must pass it; the function is on main only and in no release. New tests cover the four refusals in the function that had none: a key other than the trusted one, a kid mismatch, a signed observer or observed_at that differs from the envelope, and a wrong profile. No schema or wire-format change.

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 2, 2026
@dependabot
dependabot Bot requested review from a team, carloshvp and imran-siddique as code owners October 2, 2026 19:50
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 2, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/integrations/ramen-ai-cmcp/agentrust-trace-tests-0.6.1 branch from 93c6684 to 6e34402 Compare October 5, 2026 22:04
@imran-siddique

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [agentrust-trace-tests](https://github.com/agentrust-io/trace-spec) from 0.5.1 to 0.6.1.
- [Release notes](https://github.com/agentrust-io/trace-spec/releases)
- [Changelog](https://github.com/agentrust-io/trace-spec/blob/main/CHANGELOG.md)
- [Commits](https://github.com/agentrust-io/trace-spec/commits)

---
updated-dependencies:
- dependency-name: agentrust-trace-tests
  dependency-version: 0.6.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/integrations/ramen-ai-cmcp/agentrust-trace-tests-0.6.1 branch from 6e34402 to 834cfb8 Compare October 5, 2026 22:15
0.6.1 adds three checks that SKIP at Level 0 here (TR-POL-003, TR-APR-003, TR-APR-005) and adds TR-APR-005 to the Level 1 failures, since this record's appraisal.status is 'none'. The assertions stay exact. tested_against now names the pins this job runs: agentrust-trace 0.11.0, agentrust-trace-tests 0.6.1.

Signed-off-by: Imran Siddique <45405841+imran-siddique@users.noreply.github.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@imran-siddique
imran-siddique force-pushed the dependabot/pip/integrations/ramen-ai-cmcp/agentrust-trace-tests-0.6.1 branch from e59d96d to 386468a Compare October 5, 2026 23:29

@imran-siddique imran-siddique left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependabot bump. Every check is green apart from the maintainer hold.

@imran-siddique
imran-siddique merged commit ff2fe87 into main Oct 6, 2026
35 of 36 checks passed
@imran-siddique
imran-siddique deleted the dependabot/pip/integrations/ramen-ai-cmcp/agentrust-trace-tests-0.6.1 branch October 6, 2026 22:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant