Skip to content

build(deps): update cmcp-runtime requirement from >=0.5.0 to >=0.7.0 in /examples - #265

Merged
imran-siddique merged 1 commit into
mainfrom
dependabot/pip/examples/cmcp-runtime-gte-0.6.0
Oct 4, 2026
Merged

imran-siddique merged 1 commit into
mainfrom
dependabot/pip/examples/cmcp-runtime-gte-0.6.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on cmcp-runtime to permit the latest version.

Release notes

Sourced from cmcp-runtime's releases.

cmcp v0.7.0

Security

  • TPM 2.0: verify_tpm_measurement listed a qualifying_data mismatch as unverified but still returned verified, so a genuine quote could be attached to a claim signed by any key. It also never compared the quote's pcrDigest with the claim's measurement, though docs/spec/tpm-security-model.md said it did. Both now fail the check.

Changed

  • verify_trace_claim takes expected_launch_measurements, and cmcp verify takes a repeatable --launch-measurement. A hardware claim whose measurement is outside the set fails. With no set, a hardware claim is partially_verified with launch_measurement unverified: genuine hardware says what ran, not that it was approved, and a report from any guest image used to come out verified.
Changelog

Sourced from cmcp-runtime's changelog.

[0.7.0] - 2026-09-30

Security

  • TPM 2.0: verify_tpm_measurement listed a qualifying_data mismatch as unverified but still returned verified, so a genuine quote could be attached to a claim signed by any key. It also never compared the quote's pcrDigest with the claim's measurement, though docs/spec/tpm-security-model.md said it did. Both now fail the check.
  • Agent Manifest v0.2: the SDK appraised the COSE envelope, but the binding fields were read from the decoded dict the caller passed, and nothing checked that the two were the same document. A valid envelope paired with a dict carrying another policy or catalog hash bound. The dict must now equal the signed payload, and issuer_key_id is the key that verified the envelope instead of an empty string.

Added

  • build_server(ctx, trace_gate=...): an optional pre-transport hook for verifier-issued TRACE tokens (cmcp_runtime.trace_gate.TraceGate). With a gate, POST /trace/challenge and POST /trace/admit are registered behind bearer auth, every tools/call needs a holder proof bound to its exact action, and the gate is rechecked and a receipt committed before any byte goes upstream. A gate requires enforcing mode. With no gate, the routes do not exist and the call path is unchanged.
  • cmcp_runtime.manifest_catalog.manifest_catalog_binding: the Agent Manifest tool Merkle root (spec 3.2.3) computed from the catalog being served, kept separate from cMCP's sealed catalog digest.
  • Experimental evidence-requirements-experimental-v1 manifest profile: the tool binding is checked against that Merkle projection, and the signed evidence requirements must also name the sealed catalog digest.

Changed

  • verify_trace_claim takes expected_launch_measurements, and cmcp verify takes a repeatable --launch-measurement. A hardware claim whose measurement is outside the set fails. With no set, a hardware claim is partially_verified with launch_measurement unverified: genuine hardware says what ran, not that it was approved, and a report from any guest image used to come out verified.

Fixed

  • An Agent Manifest that lists its tools in tool_manifest.tools could never bind: cMCP handed the SDK its sealed catalog digest, and from agent-manifest 0.13 the SDK compares catalog_hash with the Merkle root of that list. Such a manifest now binds when its list and root equal the projection of the catalog being served (cmcp_runtime.manifest_catalog). A manifest that omits tools is still compared with the sealed digest. verify_agent_manifest_binding takes runtime_catalog for this; without it a manifest with tools does not bind, which includes cmcp verify, since it has no catalog to project.

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 2, 2026
@dependabot
dependabot Bot requested review from a team, carloshvp and imran-siddique as code owners October 2, 2026 19:50
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 2, 2026
imran-siddique
imran-siddique previously approved these changes Oct 4, 2026
Updates the requirements on [cmcp-runtime](https://github.com/agentrust-io/cmcp) to permit the latest version.
- [Release notes](https://github.com/agentrust-io/cmcp/releases)
- [Changelog](https://github.com/agentrust-io/cmcp/blob/main/CHANGELOG.md)
- [Commits](agentrust-io/cmcp@v0.5.0...v0.7.0)

---
updated-dependencies:
- dependency-name: cmcp-runtime
  dependency-version: 0.6.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps): update cmcp-runtime requirement from >=0.5.0 to >=0.6.0 in /examples build(deps): update cmcp-runtime requirement from >=0.5.0 to >=0.7.0 in /examples Oct 4, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/examples/cmcp-runtime-gte-0.6.0 branch from 87b51a8 to 28dd1a4 Compare October 4, 2026 18:19
@imran-siddique
imran-siddique merged commit 80abbd1 into main Oct 4, 2026
55 of 57 checks passed
@imran-siddique
imran-siddique deleted the dependabot/pip/examples/cmcp-runtime-gte-0.6.0 branch October 4, 2026 19:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant