chore(deps): bump the container-runtime group across 5 directories with 5 updates - #64
Conversation
…th 5 updates Updates the requirements on [bedrock-agentcore](https://github.com/aws/bedrock-agentcore-sdk-python), [boto3](https://github.com/boto/boto3), [bedrock-agentcore-starter-toolkit](https://github.com/aws/bedrock-agentcore-starter-toolkit), [mcp](https://github.com/modelcontextprotocol/python-sdk) and [uvicorn](https://github.com/Kludex/uvicorn) to permit the latest version. Updates `bedrock-agentcore` to 1.19.0 - [Release notes](https://github.com/aws/bedrock-agentcore-sdk-python/releases) - [Changelog](https://github.com/aws/bedrock-agentcore-sdk-python/blob/main/CHANGELOG.md) - [Commits](aws/bedrock-agentcore-sdk-python@v0.1.0...v1.19.0) Updates `boto3` to 1.43.62 - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.34.0...1.43.62) Updates `bedrock-agentcore` from 1.18.1 to 1.19.0 - [Release notes](https://github.com/aws/bedrock-agentcore-sdk-python/releases) - [Changelog](https://github.com/aws/bedrock-agentcore-sdk-python/blob/main/CHANGELOG.md) - [Commits](aws/bedrock-agentcore-sdk-python@v0.1.0...v1.19.0) Updates `bedrock-agentcore-starter-toolkit` from 0.3.10 to 0.3.11 - [Release notes](https://github.com/aws/bedrock-agentcore-starter-toolkit/releases) - [Changelog](https://github.com/aws/bedrock-agentcore-starter-toolkit/blob/main/CHANGELOG.md) - [Commits](aws/bedrock-agentcore-starter-toolkit@v0.3.10...v0.3.11) Updates `mcp` from 1.28.1 to 1.29.0 - [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases) - [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md) - [Commits](modelcontextprotocol/python-sdk@v1.28.1...v1.29.0) Updates `uvicorn` from 0.50.2 to 0.52.1 - [Release notes](https://github.com/Kludex/uvicorn/releases) - [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md) - [Commits](Kludex/uvicorn@0.50.2...0.52.1) Updates `bedrock-agentcore` from 1.18.1 to 1.19.0 - [Release notes](https://github.com/aws/bedrock-agentcore-sdk-python/releases) - [Changelog](https://github.com/aws/bedrock-agentcore-sdk-python/blob/main/CHANGELOG.md) - [Commits](aws/bedrock-agentcore-sdk-python@v0.1.0...v1.19.0) Updates `bedrock-agentcore-starter-toolkit` from 0.3.10 to 0.3.11 - [Release notes](https://github.com/aws/bedrock-agentcore-starter-toolkit/releases) - [Changelog](https://github.com/aws/bedrock-agentcore-starter-toolkit/blob/main/CHANGELOG.md) - [Commits](aws/bedrock-agentcore-starter-toolkit@v0.3.10...v0.3.11) Updates `mcp` from 1.28.1 to 1.29.0 - [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases) - [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md) - [Commits](modelcontextprotocol/python-sdk@v1.28.1...v1.29.0) Updates `uvicorn` from 0.50.2 to 0.52.1 - [Release notes](https://github.com/Kludex/uvicorn/releases) - [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md) - [Commits](Kludex/uvicorn@0.50.2...0.52.1) Updates `bedrock-agentcore` from 1.18.1 to 1.19.0 - [Release notes](https://github.com/aws/bedrock-agentcore-sdk-python/releases) - [Changelog](https://github.com/aws/bedrock-agentcore-sdk-python/blob/main/CHANGELOG.md) - [Commits](aws/bedrock-agentcore-sdk-python@v0.1.0...v1.19.0) Updates `bedrock-agentcore-starter-toolkit` from 0.3.10 to 0.3.11 - [Release notes](https://github.com/aws/bedrock-agentcore-starter-toolkit/releases) - [Changelog](https://github.com/aws/bedrock-agentcore-starter-toolkit/blob/main/CHANGELOG.md) - [Commits](aws/bedrock-agentcore-starter-toolkit@v0.3.10...v0.3.11) Updates `mcp` from 1.28.1 to 1.29.0 - [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases) - [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md) - [Commits](modelcontextprotocol/python-sdk@v1.28.1...v1.29.0) Updates `uvicorn` from 0.50.2 to 0.52.1 - [Release notes](https://github.com/Kludex/uvicorn/releases) - [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md) - [Commits](Kludex/uvicorn@0.50.2...0.52.1) Updates `bedrock-agentcore` from 1.18.1 to 1.19.0 - [Release notes](https://github.com/aws/bedrock-agentcore-sdk-python/releases) - [Changelog](https://github.com/aws/bedrock-agentcore-sdk-python/blob/main/CHANGELOG.md) - [Commits](aws/bedrock-agentcore-sdk-python@v0.1.0...v1.19.0) Updates `bedrock-agentcore-starter-toolkit` from 0.3.10 to 0.3.11 - [Release notes](https://github.com/aws/bedrock-agentcore-starter-toolkit/releases) - [Changelog](https://github.com/aws/bedrock-agentcore-starter-toolkit/blob/main/CHANGELOG.md) - [Commits](aws/bedrock-agentcore-starter-toolkit@v0.3.10...v0.3.11) Updates `mcp` from 1.28.1 to 1.29.0 - [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases) - [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md) - [Commits](modelcontextprotocol/python-sdk@v1.28.1...v1.29.0) Updates `uvicorn` from 0.50.2 to 0.52.1 - [Release notes](https://github.com/Kludex/uvicorn/releases) - [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md) - [Commits](Kludex/uvicorn@0.50.2...0.52.1) --- updated-dependencies: - dependency-name: bedrock-agentcore dependency-version: 1.19.0 dependency-type: direct:production dependency-group: container-runtime - dependency-name: boto3 dependency-version: 1.43.62 dependency-type: direct:production dependency-group: container-runtime - dependency-name: bedrock-agentcore dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: container-runtime - dependency-name: bedrock-agentcore-starter-toolkit dependency-version: 0.3.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: container-runtime - dependency-name: mcp dependency-version: 1.29.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: container-runtime - dependency-name: uvicorn dependency-version: 0.52.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: container-runtime - dependency-name: bedrock-agentcore dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: container-runtime - dependency-name: bedrock-agentcore-starter-toolkit dependency-version: 0.3.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: container-runtime - dependency-name: mcp dependency-version: 1.29.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: container-runtime - dependency-name: uvicorn dependency-version: 0.52.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: container-runtime - dependency-name: bedrock-agentcore dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: container-runtime - dependency-name: bedrock-agentcore-starter-toolkit dependency-version: 0.3.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: container-runtime - dependency-name: mcp dependency-version: 1.29.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: container-runtime - dependency-name: uvicorn dependency-version: 0.52.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: container-runtime - dependency-name: bedrock-agentcore dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: container-runtime - dependency-name: bedrock-agentcore-starter-toolkit dependency-version: 0.3.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: container-runtime - dependency-name: mcp dependency-version: 1.29.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: container-runtime - dependency-name: uvicorn dependency-version: 0.52.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: container-runtime ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Verified before merge, per the discipline INV-SUPPLY-1/2 established — a green CI is not by itself evidence that a container dependency bump is safe, since no test installs these pins. The mcp entry proves the INV-SUPPLY-2 API surface, against the exact proposed pin set ( Both the server surface ( Vulnerability audit of the proposed set: Merging. |
…t it (INV-CONTAINER-1) (#67) docs/FIDELITY-REPORT.md claims specialists/cve-intel/ "really docker builds (multi-stage, pinned deps, non-root)" — the project's strongest deployment claim. Nothing executed it: - no workflow contains `docker build` / build-push-action / buildx - both modules named after containers (test_specialist_containers.py, test_cve_intel_container.py) are pure TEXT analysis of the Dockerfile - the latter deferred the real build to "the *verify* step", which did not exist anywhere in the repo — so a reader concluded the image was verified elsewhere when only its Dockerfile had been read The gap mattered because of what the last rounds did: INV-SUPPLY-1 moved strands-agents 1.9.1 -> 1.50.2 and fastapi -> 0.141.1 to clear 19 advisories, and PR #64 moved bedrock-agentcore -> 1.19.0, mcp -> 1.29.0, uvicorn -> 0.52.1. Each was verified by importing packages in a scratch venv — which proves the API surface survives and says NOTHING about whether the arm64 image still builds or boots. A break there surfaces at deploy time. Verified on a real arm64 build: docker build --platform linux/arm64 rc=0 versions inside the image match requirements.txt exactly, plus transitive litellm 1.91.1 / starlette 1.4.1 import agent_a2a OK (agent_card/build_agent/build_app/serve) container state Up (healthy) — exercises the HEALTHCHECK GET /ping 200 {"status":"healthy","agent":"cve-intel"} GET /.well-known/agent-card.json 200, real card id -u inside the container 10001, matching the Dockerfile So the finding is not that the image is broken — it is that nothing would notice when it breaks, on a repo that now takes container dependency bumps weekly. Env-gated (SENTINEL_CONTAINER_BUILD=1): a build needs a daemon, minutes and the network, and the suite must run where docker does not exist. The skip states exactly what is unverified, and with the gate ON a missing daemon is a FAILURE — opting in and silently doing nothing is the worst of both. Cold-cache control: 112.79s for 7 passed versus 5.81s warm, proving the build really runs rather than validating a stale cached image. CI job on a NATIVE arm64 runner (ubuntu-24.04-arm, free for public repos). AgentCore Runtime is arm64 and a QEMU cross-build on x86 would be several times 112s; the job asserts the arch, and asserts no gated test SKIPPED, so a green result cannot mean "built nothing". One assertion's SELF-DESCRIPTION was corrected by mutation testing rather than the test being patched: "declare uvicorn==0.50.2 while the image has 0.52.1" SURVIVED, because editing requirements.txt busts the COPY layer so the image installs the edited pin — declared == installed is structurally guaranteed on that path. The docstring now states what it really catches (pip resolving off-pin, a stale layer cache, a vanished package) and identifies the TRANSITIVE check as load-bearing — which mutation CAUGHT: dropping the [litellm] extra leaves every pin satisfied while litellm is absent from the shipped artifact. Mutation-tested 4/4. Suite: 4084 passed / 15 skipped. ruff clean.
Updates the requirements on bedrock-agentcore, boto3, bedrock-agentcore-starter-toolkit, mcp and uvicorn to permit the latest version.
Updates
bedrock-agentcoreto 1.19.0Release notes
Sourced from bedrock-agentcore's releases.
Changelog
Sourced from bedrock-agentcore's changelog.
... (truncated)
Commits
08a4cb7chore: bump version to 1.19.0 (#606)34e06f0fix(a2a): advertise resolved port on explicit cards (#605)59cbff3fix(memory-integ): address capacity cap and update failures in tests (#604)4a7a8c4fix: preserve generated API reference content (#595)f1a7106ci: migrate workflows to shared reusable workflows (#597)c707388fix(ci): pin Twine to 6.2.0 (#600)331f441fix(a2a): honor PORT when serving locally (#593)16f732ffeat(a2a): migrate runtime integration to a2a-sdk v1 (#591)641000dfix: convert RST admonition to ADOC (#594)3000d50Add LLM issue auto-triage: type and high-severity labelers (#584)Updates
boto3to 1.43.62Commits
f3e9c52Merge branch 'release-1.43.62'47765b7Bumping version to 1.43.622f4f5fbAdd changelog entries from botocore8cd8552Merge branch 'release-1.43.61'53d9670Merge branch 'release-1.43.61' into develop74101e1Bumping version to 1.43.617faedb5Add changelog entries from botocore785f6ffMerge branch 'release-1.43.60'550ff07Merge branch 'release-1.43.60' into develop68f5316Bumping version to 1.43.60Updates
bedrock-agentcorefrom 1.18.1 to 1.19.0Release notes
Sourced from bedrock-agentcore's releases.
Changelog
Sourced from bedrock-agentcore's changelog.
... (truncated)
Commits
08a4cb7chore: bump version to 1.19.0 (#606)34e06f0fix(a2a): advertise resolved port on explicit cards (#605)59cbff3fix(memory-integ): address capacity cap and update failures in tests (#604)4a7a8c4fix: preserve generated API reference content (#595)f1a7106ci: migrate workflows to shared reusable workflows (#597)c707388fix(ci): pin Twine to 6.2.0 (#600)331f441fix(a2a): honor PORT when serving locally (#593)16f732ffeat(a2a): migrate runtime integration to a2a-sdk v1 (#591)641000dfix: convert RST admonition to ADOC (#594)3000d50Add LLM issue auto-triage: type and high-severity labelers (#584)Updates
bedrock-agentcore-starter-toolkitfrom 0.3.10 to 0.3.11Release notes
Sourced from bedrock-agentcore-starter-toolkit's releases.
Changelog
Sourced from bedrock-agentcore-starter-toolkit's changelog.
Commits
98bf2f8fix: update execution role policies for runtime, gateway, and evaluation (#554)4f90432docs: make deprecated docs build redirect-only so deploy stops failing (#551)cb3e17fdocs: deprecate GitHub Pages site via mkdocs-redirects (#550)9b1f1c2chore(deps-dev): bump wheel from 0.45.1 to 0.46.2 (#538)bde62f0chore(deps): bump soupsieve from 2.8 to 2.8.4 (#539)0437e15chore(deps): bump mcp from 1.20.0 to 1.23.0 (#537)8e36797chore(deps): bump pyjwt from 2.10.1 to 2.13.0 (#527)7b1f8cechore(deps): bump starlette from 0.50.0 to 1.3.1 (#529)70294b5chore(deps): bump cryptography from 46.0.3 to 48.0.1 (#528)f5342f6chore(deps): bump python-multipart from 0.0.20 to 0.0.31 (#530)Updates
mcpfrom 1.28.1 to 1.29.0Release notes
Sourced from mcp's releases.
Commits
98b7159[v1.x] Move the v1.x docs to /v1/ and mark v1.x as the maintenance line (#3177)c0c5a9d[v1.x] ci: pick the docs toolchain per worktree in build-docs.sh (#3082)e828374[v1.x] fix: reject trailing newline in tool-name validation (#3086)5f0b6af[v1.x] Add Streamable HTTP request body limits (#3101)ba33472[v1.x] docs: pin mkdocs<2 (#3074)0e3a604[v1.x] docs: publish llms.txt and markdown renditions of the docs (#3029)9678a3b[v1.x] Route Context.report_progress() to the originating request stream (#2994)Updates
uvicornfrom 0.50.2 to 0.52.1Release notes
Sourced from uvicorn's releases.
Changelog
Sourced from uvicorn's changelog.
Commits
ee8e45cVersion 0.52.1 (#3056)b57926dRemove duplicate content headers from WebSocket denial responses on websocket...49de1b9chore(deps): bump pymdown-extensions from 10.21.3 to 11.0 (#3042)2f3fa3aComplete server-initiated closes in SansIO WebSocket protocols (#3053)8c59d55chore(deps): bump the github-actions group with 5 updates (#3054)e148451Handle connection loss during WebSocket write backpressure (#3050)e16a69bAdd missing write flow control towebsockets-sansio(#3048)ef1dd44Fold the zttp-only tests back into the HTTP test suite (#3046)8f1b884Version 0.52.0 (#3044)f6833dbAdd experimental zttp HTTP/1.1 protocol (#2979)Updates
bedrock-agentcorefrom 1.18.1 to 1.19.0Release notes
Sourced from bedrock-agentcore's releases.
Changelog
Sourced from bedrock-agentcore's changelog.
... (truncated)
Commits
08a4cb7chore: bump version to 1.19.0 (#606)34e06f0fix(a2a): advertise resolved port on explicit cards (#605)59cbff3fix(memory-integ): address capacity cap and update failures in tests (#604)4a7a8c4fix: preserve generated API reference content (#595)f1a7106ci: migrate workflows to shared reusable workflows (#597)c707388fix(ci): pin Twine to 6.2.0 (#600)331f441fix(a2a): honor PORT when serving locally (#593)16f732ffeat(a2a): migrate runtime integration to a2a-sdk v1 (#591)641000dfix: convert RST admonition to ADOC (#594)3000d50Add LLM issue auto-triage: type and high-severity labelers (#584)Updates
bedrock-agentcore-starter-toolkitfrom 0.3.10 to 0.3.11Release notes
Sourced from bedrock-agentcore-starter-toolkit's releases.
Changelog
Sourced from bedrock-agentcore-starter-toolkit's changelog.