f0ff4bce69
CI / benchmark-publish (pull_request) Has been skipped
CI / build (pull_request) Successful in 17s
CI / lint (pull_request) Failing after 20s
CI / helm (pull_request) Successful in 23s
CI / typecheck (pull_request) Failing after 50s
CI / security (pull_request) Failing after 50s
CI / coverage (pull_request) Has been skipped
CI / benchmark-regression (pull_request) Has been skipped
CI / unit_tests (pull_request) Failing after 1m48s
CI / docker (pull_request) Has been skipped
CI / quality (pull_request) Successful in 3m41s
CI / e2e_tests (pull_request) Failing after 15m4s
CI / integration_tests (pull_request) Failing after 20m55s
CI / status-check (pull_request) Failing after 1s
Add explicit aiohttp>=3.13.4 dependency constraint to pyproject.toml to remediate CVE-2026-34515, a high-severity open redirect vulnerability in aiohttp that affects the A2A server HTTP transport, MCP tool source fetching, and agent communication layers. The uv.lock already resolves aiohttp to 3.13.5 which satisfies the >=3.13.4 constraint. Adding the explicit constraint ensures vulnerable versions (<3.13.4) cannot be installed even if upstream transitive dependency constraints are loosened. ISSUES CLOSED: #1544
233 lines
6.1 KiB
TOML
233 lines
6.1 KiB
TOML
[build-system]
|
|
requires = ["hatchling>=1.21.0"]
|
|
build-backend = "hatchling.build"
|
|
|
|
[project]
|
|
name = "cleveragents"
|
|
version = "1.0.0"
|
|
description = "CleverAgents CLI and runtime toolkit"
|
|
readme = "README.md"
|
|
requires-python = ">=3.13"
|
|
license = {text = "MIT"}
|
|
authors = [
|
|
{name = "CleverThis Engineering", email = "engineering@cleverthis.com"},
|
|
]
|
|
keywords = ["cleveragents", "ai", "cli", "automation"]
|
|
classifiers = [
|
|
"Development Status :: 4 - Beta",
|
|
"Intended Audience :: Developers",
|
|
"License :: OSI Approved :: MIT License",
|
|
"Programming Language :: Python",
|
|
"Programming Language :: Python :: 3",
|
|
"Programming Language :: Python :: 3.13",
|
|
]
|
|
|
|
dependencies = [
|
|
# CLI Framework (ADR-009)
|
|
"typer>=0.9.0",
|
|
"uvicorn>=0.30.1",
|
|
"watchdog>=4.0.0",
|
|
"faiss-cpu>=1.7.4", # Vector store backend
|
|
"rx>=3.2.0", # Reactive streams for routing
|
|
"dependency-injector>=4.41.0", # DI container
|
|
"pydantic>=2.7.0",
|
|
"pydantic-settings>=2.11.0",
|
|
"structlog>=24.4.0",
|
|
"langchain>=0.2.14",
|
|
"langchain-anthropic>=0.2.0",
|
|
"langchain-community>=0.2.14",
|
|
"langchain-anthropic>=0.2.0",
|
|
"langchain-openai>=0.2.0",
|
|
"langchain-google-genai>=0.2.0",
|
|
"jinja2>=3.1.0",
|
|
"alembic>=1.13.1",
|
|
"numpy>=2.1.0",
|
|
"python-ulid>=2.7.0", # ULID generation for plan/action IDs
|
|
"RestrictedPython>=7.0", # Secure sandbox for user-supplied code
|
|
"jsonschema>=4.20.0", # JSON Schema validation for tool inputs/outputs
|
|
"tomlkit>=0.13.0", # TOML writing with comment preservation for config CLI
|
|
"tenacity>=8.2.0", # Retry framework for service layer resilience
|
|
"aiohttp>=3.13.4", # CVE-2026-34515 mitigation: open redirect vulnerability
|
|
]
|
|
|
|
[project.optional-dependencies]
|
|
tui = [
|
|
"textual>=1.0.0,<2.0.0",
|
|
]
|
|
dev = [
|
|
# Code formatting and linting
|
|
"ruff>=0.15.0,<0.16.0",
|
|
# Type checking
|
|
"pyright>=1.1.350",
|
|
"types-pyyaml>=6.0.0",
|
|
"types-aiofiles>=23.0.0",
|
|
# Testing
|
|
"behave==1.3.3",
|
|
"pytest>=8.0.0",
|
|
"pytest-asyncio>=0.23.0",
|
|
"pytest-cov>=4.1.0",
|
|
# Pre-commit hooks
|
|
"pre-commit>=3.6.0",
|
|
# Security scanning
|
|
"bandit[toml]>=1.7.5",
|
|
"semgrep>=1.60.0",
|
|
# Dead code detection
|
|
"vulture>=2.10",
|
|
# Complexity metrics
|
|
"radon>=6.0.1",
|
|
]
|
|
tests = [
|
|
"behave==1.3.3",
|
|
"slipcover>=1.0.17",
|
|
"asv>=0.6.5",
|
|
"robotframework>=7.3.2",
|
|
"robotframework-pabot>=4.0.0",
|
|
]
|
|
docs = [
|
|
"mkdocs>=1.6.1",
|
|
"mkdocs-material>=9.6.0",
|
|
"mkdocstrings[python]>=0.24.0",
|
|
"mkdocs-kroki-plugin>=1.2.0",
|
|
"mkdocs-gen-files>=0.5.0",
|
|
"mkdocs-literate-nav>=0.6.0",
|
|
"griffe-pydantic>=1.0.0",
|
|
"mkdocs-click>=0.8.0",
|
|
"ruff>=0.4.0",
|
|
]
|
|
|
|
[project.urls]
|
|
Homepage = "https://cleverthis.com/cleveragents"
|
|
Documentation = "https://docs.cleverthis.com/cleveragents"
|
|
Repository = "https://git.cleverthis.com/cleveragents/core"
|
|
Issues = "https://git.cleverthis.com/cleveragents/core/issues"
|
|
|
|
[project.scripts]
|
|
cleveragents = "cleveragents.cli:main"
|
|
agents = "cleveragents.cli:main"
|
|
|
|
[tool.hatch.build.targets.wheel]
|
|
packages = ["src/cleveragents"]
|
|
include = ["src/cleveragents/py.typed"]
|
|
|
|
[tool.ruff]
|
|
line-length = 88
|
|
target-version = "py313" # Target Python 3.13
|
|
src = ["src", "tests", "benchmarks"]
|
|
extend-exclude = ["docs/reference/contracts/stubs/*.py", "scripts/*.sh"]
|
|
|
|
[tool.ruff.lint]
|
|
select = ["E", "F", "W", "B", "UP", "I", "SIM", "RUF"]
|
|
ignore = []
|
|
|
|
[tool.ruff.lint.per-file-ignores]
|
|
"__init__.py" = ["F401"]
|
|
# Behave step files: F811 = redefined step_impl (Behave pattern), E501 = long step decorator strings
|
|
"features/steps/*.py" = ["F811", "E501"]
|
|
"features/mocks/*.py" = ["E501"]
|
|
"features/environment.py" = ["E501"]
|
|
# retry_patterns.py re-exports symbols from retry_service_patterns at module bottom
|
|
"src/cleveragents/core/retry_patterns.py" = ["E402"]
|
|
|
|
[tool.ruff.format]
|
|
# Use double quotes for strings
|
|
quote-style = "double"
|
|
# Indent with 4 spaces
|
|
indent-style = "space"
|
|
# Unix line endings
|
|
line-ending = "auto"
|
|
|
|
[tool.pyright]
|
|
include = ["src"]
|
|
exclude = ["**/.nox", "**/__pycache__", "**/site-packages", "src/cleveragents/discovery"]
|
|
pythonVersion = "3.13" # Target Python 3.13
|
|
typeCheckingMode = "strict"
|
|
strictListInference = true
|
|
strictDictionaryInference = true
|
|
strictSetInference = true
|
|
reportMissingImports = true
|
|
reportMissingTypeStubs = false
|
|
reportMissingTypeArgument = true
|
|
reportIncompatibleMethodOverride = true
|
|
reportIncompatibleVariableOverride = true
|
|
reportUnusedImport = true
|
|
reportUnusedClass = true
|
|
reportUnusedFunction = true
|
|
reportUnusedVariable = true
|
|
reportDuplicateImport = true
|
|
reportOptionalMemberAccess = true
|
|
reportOptionalCall = true
|
|
reportOptionalIterable = true
|
|
reportOptionalContextManager = true
|
|
reportOptionalOperand = true
|
|
reportTypedDictNotRequiredAccess = true
|
|
reportUnnecessaryIsInstance = true
|
|
reportUnnecessaryCast = true
|
|
reportUnnecessaryComparison = true
|
|
reportImplicitStringConcatenation = false
|
|
reportUnusedCallResult = false
|
|
reportUnknownMemberType = false
|
|
reportUnknownVariableType = false
|
|
reportUnknownParameterType = false
|
|
|
|
[tool.coverage]
|
|
# Coverage configuration
|
|
|
|
[tool.coverage.run]
|
|
source = ["src", "scripts"]
|
|
branch = true
|
|
parallel = false
|
|
omit = [
|
|
"*/tests/*",
|
|
"*/test_*",
|
|
"features/*",
|
|
"*/features/*",
|
|
"*/__pycache__/*",
|
|
"*/site-packages/*",
|
|
"*/dependency_injector/*",
|
|
"*/venv/*",
|
|
"*/.venv/*",
|
|
"*/.nox/*",
|
|
"src/cleveragents/discovery/*",
|
|
]
|
|
data_file = "build/.coverage"
|
|
|
|
[tool.coverage.html]
|
|
directory = "build/htmlcov"
|
|
|
|
[tool.coverage.xml]
|
|
output = "build/coverage.xml"
|
|
|
|
[tool.bandit]
|
|
targets = ["src/cleveragents"]
|
|
exclude_dirs = [
|
|
"tests",
|
|
"features",
|
|
".nox",
|
|
"build",
|
|
"dist",
|
|
"docs",
|
|
"src/cleveragents/discovery",
|
|
]
|
|
# Severity level: LOW, MEDIUM, HIGH
|
|
severity = "MEDIUM"
|
|
# Confidence level: LOW, MEDIUM, HIGH
|
|
confidence = "MEDIUM"
|
|
# Skip specific tests if needed
|
|
skips = []
|
|
|
|
[tool.vulture]
|
|
min_confidence = 80
|
|
paths = ["src/cleveragents"]
|
|
exclude = ["src/cleveragents/discovery"]
|
|
|
|
[tool.hatch]
|
|
# Hatch build configuration
|
|
|
|
[tool.commitizen]
|
|
name = "cz_conventional_commits"
|
|
tag_format = "$version"
|
|
version_scheme = "pep440"
|
|
version_provider = "pep621"
|
|
update_changelog_on_bump = true
|
|
major_version_zero = true
|