Skip to content

build(deps): bump cmcp-runtime from 0.5.0 to 0.7.0 in /demos - #262

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/demos/cmcp-runtime-0.6.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/demos/cmcp-runtime-0.6.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Bumps cmcp-runtime from 0.5.0 to 0.7.0.

Release notes

Sourced from cmcp-runtime's releases.

cmcp v0.7.0

Security

  • TPM 2.0: verify_tpm_measurement listed a qualifying_data mismatch as unverified but still returned verified, so a genuine quote could be attached to a claim signed by any key. It also never compared the quote's pcrDigest with the claim's measurement, though docs/spec/tpm-security-model.md said it did. Both now fail the check.

Changed

  • verify_trace_claim takes expected_launch_measurements, and cmcp verify takes a repeatable --launch-measurement. A hardware claim whose measurement is outside the set fails. With no set, a hardware claim is partially_verified with launch_measurement unverified: genuine hardware says what ran, not that it was approved, and a report from any guest image used to come out verified.

v0.6.0

cmcp-runtime 0.6.0. Full detail is in CHANGELOG.md.

Kill switch

  • Blocks survive a restart and live in the audit database. The close that trips the switch returns its signed claim, and later calls get 403 KILL_SWITCH_TRIPPED (#665).
  • A session stops at the call that trips the switch, not at session close (#666).
  • Claims carry a gateway.kill_switch block, each refused call returns a signed receipt, and cmcp_verify.verify_kill_switch_refusal checks one against the other. kill_switch.enabled with no Agent Manifest now stops startup (#667).
  • A compromised policy signing key can be revoked without a restart through CMCP_POLICY_SUCCESSOR_SIGNING_KEY and signing-key-revocations.json (#668).
  • agent_manifest.revocation_list_path makes startup refuse a revoked Agent Manifest; a missing or malformed list stops startup instead of reading as empty (#689).

Also in this release

  • Verifier-owned SNP platform policy in native, Azure and TRACE verification (#656).
  • Opt-in exact-output disclosure bound to scoped owner signatures (#672).
  • Monotonic session boundary, and session close and reset release stdio children and upstream caches (#629, #634).
  • Two tool names that derive the same Cedar action are refused at catalog load (#671).
  • Operator sensitivity ceilings at tool and response sinks.
  • Linux agent confinement reference (#663).
  • Paginated tools/list is read to the end before drift and provenance checks (#633).
  • session_state_path is accepted and wired at startup, so the session sensitivity value can live in a shared SQLite store. An unopenable path stops startup with SESSION_STATE_STORE_UNAVAILABLE (#661).
  • verify_audit_bundle requires a recorded session_reset at every session change, and code_digest refuses an installed file whose bytes differ from its RECORD entry (#689).

Behaviour changes

  • A tools/call carrying _cmcp.execution_id is refused with execution_correlation_unavailable until execution correlation ships (#606).
  • Session reset and catalog exception take CMCP_OPERATOR_TOKEN, required outside dev mode. Where it is unset they still accept the bearer token.
Changelog

Sourced from cmcp-runtime's changelog.

[0.7.0] - 2026-09-30

Security

  • TPM 2.0: verify_tpm_measurement listed a qualifying_data mismatch as unverified but still returned verified, so a genuine quote could be attached to a claim signed by any key. It also never compared the quote's pcrDigest with the claim's measurement, though docs/spec/tpm-security-model.md said it did. Both now fail the check.
  • Agent Manifest v0.2: the SDK appraised the COSE envelope, but the binding fields were read from the decoded dict the caller passed, and nothing checked that the two were the same document. A valid envelope paired with a dict carrying another policy or catalog hash bound. The dict must now equal the signed payload, and issuer_key_id is the key that verified the envelope instead of an empty string.

Added

  • build_server(ctx, trace_gate=...): an optional pre-transport hook for verifier-issued TRACE tokens (cmcp_runtime.trace_gate.TraceGate). With a gate, POST /trace/challenge and POST /trace/admit are registered behind bearer auth, every tools/call needs a holder proof bound to its exact action, and the gate is rechecked and a receipt committed before any byte goes upstream. A gate requires enforcing mode. With no gate, the routes do not exist and the call path is unchanged.
  • cmcp_runtime.manifest_catalog.manifest_catalog_binding: the Agent Manifest tool Merkle root (spec 3.2.3) computed from the catalog being served, kept separate from cMCP's sealed catalog digest.
  • Experimental evidence-requirements-experimental-v1 manifest profile: the tool binding is checked against that Merkle projection, and the signed evidence requirements must also name the sealed catalog digest.

Changed

  • verify_trace_claim takes expected_launch_measurements, and cmcp verify takes a repeatable --launch-measurement. A hardware claim whose measurement is outside the set fails. With no set, a hardware claim is partially_verified with launch_measurement unverified: genuine hardware says what ran, not that it was approved, and a report from any guest image used to come out verified.

Fixed

  • An Agent Manifest that lists its tools in tool_manifest.tools could never bind: cMCP handed the SDK its sealed catalog digest, and from agent-manifest 0.13 the SDK compares catalog_hash with the Merkle root of that list. Such a manifest now binds when its list and root equal the projection of the catalog being served (cmcp_runtime.manifest_catalog). A manifest that omits tools is still compared with the sealed digest. verify_agent_manifest_binding takes runtime_catalog for this; without it a manifest with tools does not bind, which includes cmcp verify, since it has no catalog to project.

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 2, 2026
@dependabot dependabot Bot changed the title build(deps): bump cmcp-runtime from 0.5.0 to 0.6.0 in /demos build(deps): bump cmcp-runtime from 0.5.0 to 0.7.0 in /demos Oct 4, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/demos/cmcp-runtime-0.6.0 branch from f16929f to 6c5966e Compare October 4, 2026 18:19
Bumps [cmcp-runtime](https://github.com/agentrust-io/cmcp) from 0.5.0 to 0.7.0.
- [Release notes](https://github.com/agentrust-io/cmcp/releases)
- [Changelog](https://github.com/agentrust-io/cmcp/blob/main/CHANGELOG.md)
- [Commits](agentrust-io/cmcp@v0.5.0...v0.7.0)

---
updated-dependencies:
- dependency-name: cmcp-runtime
  dependency-version: 0.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/demos/cmcp-runtime-0.6.0 branch from 6c5966e to 674a514 Compare October 4, 2026 19:10
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #281.

@dependabot dependabot Bot closed this Oct 5, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/demos/cmcp-runtime-0.6.0 branch October 5, 2026 04:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants