From dfa2f7db9a17b6f0035f798a3f94d1ffc5334ddb Mon Sep 17 00:00:00 2001 From: Vantio Date: Wed, 30 Sep 2026 13:30:48 -0400 Subject: [PATCH 1/4] docs(optics): stage CLI 0.3.25 and Python 3.1.1 as source candidates Release notes say Gate-era enforcement was removed from Optics. These versions are CANDIDATE_ONLY. Not an npm release. Not a PyPI release. install.vantio.ai is not going live. --- docs/governance/VERSION-METADATA.json | 10 ++++---- docs/governance/canonical/ai-guide.md | 4 ++-- docs/governance/changelogs/cli.md | 6 +++++ docs/products/optics/KNOWN-LIMITATIONS.md | 2 +- .../dossiers/optics-public.json | 24 +++++++++---------- .../generated/evaluations.json | 4 ++-- .../generated/open-core-sbom.cdx.json | 8 +++---- .../generated/pin-report.json | 4 ++-- packages/vantio-agent-sdk-py/CHANGELOG.md | 6 +++++ packages/vantio-agent-sdk-py/pyproject.toml | 2 +- .../vantio-agent-sdk-py/tests/test_version.py | 4 ++-- .../vantio-agent-sdk-py/vantio/__init__.py | 2 +- packages/vantio-cli/package.json | 2 +- .../test/account-retirement.test.js | 2 +- scripts/release/test_pypi_publish_workflow.py | 4 ++-- scripts/release/ws11/ws11.test.mjs | 10 ++++---- 16 files changed, 53 insertions(+), 41 deletions(-) diff --git a/docs/governance/VERSION-METADATA.json b/docs/governance/VERSION-METADATA.json index ae4cc7a4..d6932087 100644 --- a/docs/governance/VERSION-METADATA.json +++ b/docs/governance/VERSION-METADATA.json @@ -6,10 +6,10 @@ { "id": "cli", "name": "@vantio/cli", - "version": "0.3.24", + "version": "0.3.25", "manifest": "packages/vantio-cli/package.json", "changelog": "docs/governance/changelogs/cli.md", - "changelog_heading": "## 0.3.24" + "changelog_heading": "## 0.3.25" }, { "id": "node-sdk", @@ -22,16 +22,16 @@ { "id": "python-sdk", "name": "vantio-agent-sdk", - "version": "3.1.0", + "version": "3.1.1", "manifest": "packages/vantio-agent-sdk-py/pyproject.toml", "also": [ { "file": "packages/vantio-agent-sdk-py/vantio/__init__.py", - "contains": "__version__ = \"3.1.0\"" + "contains": "__version__ = \"3.1.1\"" } ], "changelog": "packages/vantio-agent-sdk-py/CHANGELOG.md", - "changelog_heading": "## 3.1.0" + "changelog_heading": "## 3.1.1" }, { "id": "optics-mcp", diff --git a/docs/governance/canonical/ai-guide.md b/docs/governance/canonical/ai-guide.md index cbe7c602..36497cb1 100644 --- a/docs/governance/canonical/ai-guide.md +++ b/docs/governance/canonical/ai-guide.md @@ -5,9 +5,9 @@ Use this guide when editing Vantio Optics documentation in this repository. Pack ```json { "ai_guide_versions": { - "@vantio/cli": "0.3.24", + "@vantio/cli": "0.3.25", "@vantio/agent-sdk": "0.2.4", - "vantio-agent-sdk": "3.1.0", + "vantio-agent-sdk": "3.1.1", "@vantio/optics-mcp": "0.1.2", "@vantio/gate-mcp": "0.1.1", "vantio-optics": "0.1.0", diff --git a/docs/governance/changelogs/cli.md b/docs/governance/changelogs/cli.md index 02b7b3ff..12185968 100644 --- a/docs/governance/changelogs/cli.md +++ b/docs/governance/changelogs/cli.md @@ -2,6 +2,12 @@ This heading exists so a documentation release can require a changelog entry for the version already in `packages/vantio-cli/package.json`. It does not bump that version. +## 0.3.25 + +CANDIDATE_ONLY_NOT_FOR_PUBLICATION. Source version only. Not an npm release. + +Gate-era enforcement was removed from Optics. The CLI records destination, process, size, timing, and status. It does not fetch policy, block, redact, or apply a spend cap. Enforcement is provided by Phantom Engine. + ## 0.3.24 Documentation baseline at `14249ba84ff1f3d5aa8ad7a7366172f29235c76e`. The CLI reads its version from package.json. Product behavior is unchanged by this documentation record. diff --git a/docs/products/optics/KNOWN-LIMITATIONS.md b/docs/products/optics/KNOWN-LIMITATIONS.md index fac4a16c..0b545c98 100644 --- a/docs/products/optics/KNOWN-LIMITATIONS.md +++ b/docs/products/optics/KNOWN-LIMITATIONS.md @@ -1,6 +1,6 @@ # Known limitations -This page lists what Optics does not do, and the gaps that are easy to over-read. Versions: CLI 0.3.24, published Python 3.0.14, unpublished Python 3.1.0 source as labeled. +This page lists what Optics does not do, and the gaps that are easy to over-read. Versions: published CLI 0.3.24, source candidate CLI 0.3.25 (not an npm release), published Python 3.0.14, source candidate Python 3.1.1 (not a PyPI release). Gate-era enforcement was removed from the Optics source candidates. Enforcement is provided by Phantom Engine. ## Absent on purpose in the current products diff --git a/docs/programs/release-engineering/dossiers/optics-public.json b/docs/programs/release-engineering/dossiers/optics-public.json index 5bdc5757..e0ea910f 100644 --- a/docs/programs/release-engineering/dossiers/optics-public.json +++ b/docs/programs/release-engineering/dossiers/optics-public.json @@ -144,12 +144,12 @@ "selector_is_integrity": false }, "distribution": "public", - "filename": "@vantio-cli-0.3.24.source", + "filename": "@vantio-cli-0.3.25.source", "hash_status": "UNRECORDED", "role": "source-tree", "sha256": null, "source_commit": "1fd21a64468ebc6f05fdbf624dae06a2fc8e75c4", - "version": "0.3.24" + "version": "0.3.25" } ], "clean_env": { @@ -157,8 +157,8 @@ }, "distribution": "public", "docs_gate": { - "docs_version": "0.3.24", - "manifest_version": "0.3.24", + "docs_version": "0.3.25", + "manifest_version": "0.3.25", "status": "MATCH" }, "ordinary_client": { @@ -175,10 +175,10 @@ "from_version": null, "rollback_sha256": null, "to_sha256": null, - "to_version": "0.3.24", + "to_version": "0.3.25", "verified": false }, - "version": "0.3.24" + "version": "0.3.25" }, { "artifacts": [ @@ -246,7 +246,7 @@ "role": "wheel", "sha256": "dcf84cb3c4f144ece21032001657bfd9c91067faeffbefd0fb2ae19d6109dbeb", "source_commit": "764361d7adfbd7eb6c5d4baac71cf32901a7eed0", - "version": "3.1.0" + "version": "3.1.1" }, { "byte_length": 59669, @@ -264,7 +264,7 @@ "role": "sdist", "sha256": "9f991291d5e44a23e17a9b0d7db24f6e7048d4c76cf0a9c37e35ccbcfe999c4f", "source_commit": "764361d7adfbd7eb6c5d4baac71cf32901a7eed0", - "version": "3.1.0" + "version": "3.1.1" } ], "clean_env": { @@ -272,8 +272,8 @@ }, "distribution": "public", "docs_gate": { - "docs_version": "3.1.0", - "manifest_version": "3.1.0", + "docs_version": "3.1.1", + "manifest_version": "3.1.1", "status": "MATCH" }, "ordinary_client": { @@ -290,10 +290,10 @@ "from_version": "3.0.14", "rollback_sha256": null, "to_sha256": "dcf84cb3c4f144ece21032001657bfd9c91067faeffbefd0fb2ae19d6109dbeb", - "to_version": "3.1.0", + "to_version": "3.1.1", "verified": false }, - "version": "3.1.0" + "version": "3.1.1" }, { "artifacts": [ diff --git a/docs/programs/release-engineering/generated/evaluations.json b/docs/programs/release-engineering/generated/evaluations.json index 1703af1c..377b6593 100644 --- a/docs/programs/release-engineering/generated/evaluations.json +++ b/docs/programs/release-engineering/generated/evaluations.json @@ -20,12 +20,12 @@ "status": "SATISFIED" }, { - "detail": "@vantio-cli-0.3.24.source hash unrecorded; @vantio-agent-sdk-0.2.4.source hash unrecorded; @vantio-optics-mcp-0.1.2.source hash unrecorded; @vantio-gate-mcp-0.1.1.source hash unrecorded; vantio-optics-0.1.0.source hash unrecorded; @vantio-optics-evidence-contract-0.0.0-unstable-pre-1.0.source hash unrecorded", + "detail": "@vantio-cli-0.3.25.source hash unrecorded; @vantio-agent-sdk-0.2.4.source hash unrecorded; @vantio-optics-mcp-0.1.2.source hash unrecorded; @vantio-gate-mcp-0.1.1.source hash unrecorded; vantio-optics-0.1.0.source hash unrecorded; @vantio-optics-evidence-contract-0.0.0-unstable-pre-1.0.source hash unrecorded", "id": "R3", "status": "GAP" }, { - "detail": "@vantio-cli-0.3.24.source custody hash unrecorded; @vantio-agent-sdk-0.2.4.source custody hash unrecorded; @vantio-optics-mcp-0.1.2.source custody hash unrecorded; @vantio-gate-mcp-0.1.1.source custody hash unrecorded; vantio-optics-0.1.0.source custody hash unrecorded; @vantio-optics-evidence-contract-0.0.0-unstable-pre-1.0.source custody hash unrecorded", + "detail": "@vantio-cli-0.3.25.source custody hash unrecorded; @vantio-agent-sdk-0.2.4.source custody hash unrecorded; @vantio-optics-mcp-0.1.2.source custody hash unrecorded; @vantio-gate-mcp-0.1.1.source custody hash unrecorded; vantio-optics-0.1.0.source custody hash unrecorded; @vantio-optics-evidence-contract-0.0.0-unstable-pre-1.0.source custody hash unrecorded", "id": "R4", "status": "GAP" }, diff --git a/docs/programs/release-engineering/generated/open-core-sbom.cdx.json b/docs/programs/release-engineering/generated/open-core-sbom.cdx.json index 1de9760b..fbb09c1a 100644 --- a/docs/programs/release-engineering/generated/open-core-sbom.cdx.json +++ b/docs/programs/release-engineering/generated/open-core-sbom.cdx.json @@ -164,10 +164,10 @@ } ], "name": "@vantio/cli", - "purl": "pkg:npm/%40vantio/cli@0.3.24", + "purl": "pkg:npm/%40vantio/cli@0.3.25", "scope": "workspace-manifest", "type": "library", - "version": "0.3.24" + "version": "0.3.25" }, { "licenses": [ @@ -206,10 +206,10 @@ } ], "name": "vantio-agent-sdk", - "purl": "pkg:pypi/vantio-agent-sdk@3.1.0", + "purl": "pkg:pypi/vantio-agent-sdk@3.1.1", "scope": "python-manifest", "type": "library", - "version": "3.1.0" + "version": "3.1.1" }, { "hashes": [ diff --git a/docs/programs/release-engineering/generated/pin-report.json b/docs/programs/release-engineering/generated/pin-report.json index 69b684a9..28d5f442 100644 --- a/docs/programs/release-engineering/generated/pin-report.json +++ b/docs/programs/release-engineering/generated/pin-report.json @@ -341,7 +341,7 @@ "id": "cli", "manifest": "packages/vantio-cli/package.json", "name": "@vantio/cli", - "version": "0.3.24" + "version": "0.3.25" }, { "id": "node-sdk", @@ -353,7 +353,7 @@ "id": "python-sdk", "manifest": "packages/vantio-agent-sdk-py/pyproject.toml", "name": "vantio-agent-sdk", - "version": "3.1.0" + "version": "3.1.1" }, { "id": "optics-mcp", diff --git a/packages/vantio-agent-sdk-py/CHANGELOG.md b/packages/vantio-agent-sdk-py/CHANGELOG.md index 6b1b4a17..e7c5f157 100644 --- a/packages/vantio-agent-sdk-py/CHANGELOG.md +++ b/packages/vantio-agent-sdk-py/CHANGELOG.md @@ -1,5 +1,11 @@ # Changelog +## 3.1.1 + +CANDIDATE_ONLY_NOT_FOR_PUBLICATION. This heading is source. It is not a PyPI release. + +Gate-era enforcement was removed from Optics. The Python SDK records destination, process, size, timing, and status. It does not fetch policy, block hosts, redact request bodies, or rewrite curl, wget, httpie, or aria2c. Enforcement is provided by Phantom Engine. `http.client` stores status from `getresponse()` and clears pending state when that call throws. + ## 3.1.0 - HTTP 400–599 is stored with `ok` false for urllib, requests, httpx, aiohttp, and urllib3. urllib HTTP errors are application outcomes and are not labeled `network_error`. diff --git a/packages/vantio-agent-sdk-py/pyproject.toml b/packages/vantio-agent-sdk-py/pyproject.toml index ed523659..3acb89d2 100755 --- a/packages/vantio-agent-sdk-py/pyproject.toml +++ b/packages/vantio-agent-sdk-py/pyproject.toml @@ -7,7 +7,7 @@ packages = ["vantio"] [project] name = "vantio-agent-sdk" -version = "3.1.0" +version = "3.1.1" description = "Vantio Optics Python SDK — shield() for Sight Loop observe. Metadata only; no prompts." readme = "README.md" license = "MIT" diff --git a/packages/vantio-agent-sdk-py/tests/test_version.py b/packages/vantio-agent-sdk-py/tests/test_version.py index 0df10ff4..9de28ad1 100644 --- a/packages/vantio-agent-sdk-py/tests/test_version.py +++ b/packages/vantio-agent-sdk-py/tests/test_version.py @@ -10,8 +10,8 @@ class VersionTests(unittest.TestCase): def test_runtime_version_matches_pyproject(self) -> None: project = pathlib.Path(__file__).resolve().parents[1] / "pyproject.toml" text = project.read_text(encoding="utf-8") - self.assertIn('version = "3.1.0"', text) - self.assertEqual(vantio.__version__, "3.1.0") + self.assertIn('version = "3.1.1"', text) + self.assertEqual(vantio.__version__, "3.1.1") self.assertIn('license = "MIT"', text) self.assertIn('license-files = ["LICENSE"]', text) package = project.parent diff --git a/packages/vantio-agent-sdk-py/vantio/__init__.py b/packages/vantio-agent-sdk-py/vantio/__init__.py index 6c259815..87a28d93 100755 --- a/packages/vantio-agent-sdk-py/vantio/__init__.py +++ b/packages/vantio-agent-sdk-py/vantio/__init__.py @@ -23,4 +23,4 @@ "VantioPolicy", "RedactionResult", ] -__version__ = "3.1.0" +__version__ = "3.1.1" diff --git a/packages/vantio-cli/package.json b/packages/vantio-cli/package.json index 61b7e4d5..353f4d57 100644 --- a/packages/vantio-cli/package.json +++ b/packages/vantio-cli/package.json @@ -1,6 +1,6 @@ { "name": "@vantio/cli", - "version": "0.3.24", + "version": "0.3.25", "description": "Vantio Optics | Free Observability for AI Agents. Free, local-first observability for supported AI-agent traffic. Prompts and completions are never stored.", "license": "MIT", "author": "Vantio AI, Inc.", diff --git a/packages/vantio-cli/test/account-retirement.test.js b/packages/vantio-cli/test/account-retirement.test.js index f4e461d2..cc93fd86 100644 --- a/packages/vantio-cli/test/account-retirement.test.js +++ b/packages/vantio-cli/test/account-retirement.test.js @@ -97,7 +97,7 @@ describe("public surfaces do not advertise accounts", () => { test("README and package metadata do not promise accounts, billing, or the missing config route", () => { const readme = readFileSync(README_PATH, "utf8"); const pkg = JSON.parse(readFileSync(PKG_PATH, "utf8")); - assert.equal(pkg.version, "0.3.24"); + assert.equal(pkg.version, "0.3.25"); assert.equal(pkg.license, "MIT"); assert.ok(pkg.files.includes("README.md")); assert.ok(pkg.files.includes("LICENSE")); diff --git a/scripts/release/test_pypi_publish_workflow.py b/scripts/release/test_pypi_publish_workflow.py index c0abac81..03c64497 100644 --- a/scripts/release/test_pypi_publish_workflow.py +++ b/scripts/release/test_pypi_publish_workflow.py @@ -258,8 +258,8 @@ def test_other_workflows_do_not_publish_python(self) -> None: def test_python_version_pin_remains(self) -> None: pyproject = (ROOT / "packages/vantio-agent-sdk-py/pyproject.toml").read_text(encoding="utf-8") init = (ROOT / "packages/vantio-agent-sdk-py/vantio/__init__.py").read_text(encoding="utf-8") - self.assertIn('version = "3.1.0"', pyproject) - self.assertIn('__version__ = "3.1.0"', init) + self.assertIn('version = "3.1.1"', pyproject) + self.assertIn('__version__ = "3.1.1"', init) class SealedGateTests(unittest.TestCase): diff --git a/scripts/release/ws11/ws11.test.mjs b/scripts/release/ws11/ws11.test.mjs index 22079d29..745c5877 100644 --- a/scripts/release/ws11/ws11.test.mjs +++ b/scripts/release/ws11/ws11.test.mjs @@ -228,7 +228,7 @@ test("current surfaces characterize with gaps and withhold release success", () assert.equal(python.registry.this_force_refetched, false); assert.equal(python.registry.historical_register_state, "PUBLISHED_REGISTRY_BYTES_VERIFIED_CLIENT_PROVED"); const cli = optics.units.find((unit) => unit.package === "@vantio/cli"); - assert.equal(cli.version, "0.3.24"); + assert.equal(cli.version, "0.3.25"); assert.equal(cli.artifacts[0].custody.selector.kind, "git-tag"); assert.equal(cli.artifacts[0].custody.selector_is_integrity, false); const contract = optics.units.find((unit) => unit.package === "@vantio/optics-evidence-contract"); @@ -248,8 +248,8 @@ test("workspace SBOM and license scan stay bounded to what the tree shows", () = assert.equal(sbom.bomFormat, "CycloneDX"); assert.equal(sbom.specVersion, "1.5"); assert.ok(sbom.components.length > 20); - assert.ok(sbom.components.some((item) => item.name === "@vantio/cli" && item.version === "0.3.24")); - assert.ok(sbom.components.some((item) => item.purl === "pkg:pypi/vantio-agent-sdk@3.1.0")); + assert.ok(sbom.components.some((item) => item.name === "@vantio/cli" && item.version === "0.3.25")); + assert.ok(sbom.components.some((item) => item.purl === "pkg:pypi/vantio-agent-sdk@3.1.1")); assert.ok(sbom.components.some((item) => item.name === "undici" && item.hashes)); const completeness = sbom.properties.find((item) => item.name === "vantio:completeness"); assert.equal(completeness.value, "pnpm-lockfile-packages-section-plus-workspace-manifests"); @@ -332,8 +332,8 @@ test("version-matched docs gate and the customer test double agree with the tree assert.equal(assemblePeCustomerBundle({ version: "9.9.9", manualText: manual }).ok, false); const cli = JSON.parse(readFileSync(join(ROOT, "packages/vantio-cli/package.json"), "utf8")); const pyproject = readFileSync(join(ROOT, "packages/vantio-agent-sdk-py/pyproject.toml"), "utf8"); - assert.equal(cli.version, "0.3.24"); - assert.match(pyproject, /version = "3.1.0"/); + assert.equal(cli.version, "0.3.25"); + assert.match(pyproject, /version = "3.1.1"/); assert.equal(readFileSync(join(ROOT, ".github/workflows/ci.yml"), "utf8").includes("scripts/release/ws11/ws11.test.mjs"), true); }); From c12ffca57d8fd9890333f7088724128f5e1ba252 Mon Sep 17 00:00:00 2001 From: Vantio Date: Wed, 30 Sep 2026 13:56:46 -0400 Subject: [PATCH 2/4] docs(optics): keep the candidate notes honest on main The 0.3.25 and 3.1.1 headings stage source labels. They do not claim that enforcement removal or the http.client status fix is in this branch. Installer pins stay on the published CLI 0.3.24 and sealed Python 3.1.0. The live package versions are the unpublished candidates. CANDIDATE_ONLY. Not published. --- docs/governance/changelogs/cli.md | 2 +- docs/governance/llms-full.txt | 4 ++-- docs/products/optics/KNOWN-LIMITATIONS.md | 2 +- packages/vantio-agent-sdk-py/CHANGELOG.md | 2 +- packages/vantio-install/tests/test_stage_a.py | 4 ++-- 5 files changed, 7 insertions(+), 7 deletions(-) diff --git a/docs/governance/changelogs/cli.md b/docs/governance/changelogs/cli.md index 12185968..31c326a0 100644 --- a/docs/governance/changelogs/cli.md +++ b/docs/governance/changelogs/cli.md @@ -6,7 +6,7 @@ This heading exists so a documentation release can require a changelog entry for CANDIDATE_ONLY_NOT_FOR_PUBLICATION. Source version only. Not an npm release. -Gate-era enforcement was removed from Optics. The CLI records destination, process, size, timing, and status. It does not fetch policy, block, redact, or apply a spend cap. Enforcement is provided by Phantom Engine. +This heading stages the source version label and the docs checks that read it. It does not change CLI behavior. Removal of Gate-era enforcement is a separate change. ## 0.3.24 diff --git a/docs/governance/llms-full.txt b/docs/governance/llms-full.txt index 7724dee1..cbb68461 100644 --- a/docs/governance/llms-full.txt +++ b/docs/governance/llms-full.txt @@ -950,9 +950,9 @@ Use this guide when editing Vantio Optics documentation in this repository. Pack ```json { "ai_guide_versions": { - "@vantio/cli": "0.3.24", + "@vantio/cli": "0.3.25", "@vantio/agent-sdk": "0.2.4", - "vantio-agent-sdk": "3.1.0", + "vantio-agent-sdk": "3.1.1", "@vantio/optics-mcp": "0.1.2", "@vantio/gate-mcp": "0.1.1", "vantio-optics": "0.1.0", diff --git a/docs/products/optics/KNOWN-LIMITATIONS.md b/docs/products/optics/KNOWN-LIMITATIONS.md index 0b545c98..02e51018 100644 --- a/docs/products/optics/KNOWN-LIMITATIONS.md +++ b/docs/products/optics/KNOWN-LIMITATIONS.md @@ -1,6 +1,6 @@ # Known limitations -This page lists what Optics does not do, and the gaps that are easy to over-read. Versions: published CLI 0.3.24, source candidate CLI 0.3.25 (not an npm release), published Python 3.0.14, source candidate Python 3.1.1 (not a PyPI release). Gate-era enforcement was removed from the Optics source candidates. Enforcement is provided by Phantom Engine. +This page lists what Optics does not do, and the gaps that are easy to over-read. Versions: published CLI 0.3.24, source candidate CLI 0.3.25 (not an npm release), published Python 3.0.14, source candidate Python 3.1.1 (not a PyPI release). These source labels are staged here and are not a behavior change. ## Absent on purpose in the current products diff --git a/packages/vantio-agent-sdk-py/CHANGELOG.md b/packages/vantio-agent-sdk-py/CHANGELOG.md index e7c5f157..bd4b7965 100644 --- a/packages/vantio-agent-sdk-py/CHANGELOG.md +++ b/packages/vantio-agent-sdk-py/CHANGELOG.md @@ -4,7 +4,7 @@ CANDIDATE_ONLY_NOT_FOR_PUBLICATION. This heading is source. It is not a PyPI release. -Gate-era enforcement was removed from Optics. The Python SDK records destination, process, size, timing, and status. It does not fetch policy, block hosts, redact request bodies, or rewrite curl, wget, httpie, or aria2c. Enforcement is provided by Phantom Engine. `http.client` stores status from `getresponse()` and clears pending state when that call throws. +This heading stages the source version label. It does not change SDK behavior. The sealed publisher stays on 3.1.0. Enforcement removal and the http.client status fix are separate changes. ## 3.1.0 diff --git a/packages/vantio-install/tests/test_stage_a.py b/packages/vantio-install/tests/test_stage_a.py index 99e12ef5..b731f29b 100644 --- a/packages/vantio-install/tests/test_stage_a.py +++ b/packages/vantio-install/tests/test_stage_a.py @@ -141,11 +141,11 @@ def test_frozen_identities_and_cli_package_untouched(self) -> None: self.assertEqual(pins["agent_sdk_npm_version"], "0.2.4") self.assertEqual(pins["agent_sdk_py_version"], "3.1.0") cli = json.loads((REPO / "packages" / "vantio-cli" / "package.json").read_text(encoding="utf-8")) - self.assertEqual(cli["version"], "0.3.24") + self.assertEqual(cli["version"], "0.3.25") sdk = json.loads((REPO / "packages" / "vantio-agent-sdk" / "package.json").read_text(encoding="utf-8")) self.assertEqual(sdk["version"], "0.2.4") pyproject = (REPO / "packages" / "vantio-agent-sdk-py" / "pyproject.toml").read_text(encoding="utf-8") - self.assertIn('version = "3.1.0"', pyproject) + self.assertIn('version = "3.1.1"', pyproject) def test_preflight_is_read_only(self) -> None: harness = self.make() From 97d86edfd3886943af474dbe49c31a679656fb82 Mon Sep 17 00:00:00 2001 From: Vantio Date: Wed, 30 Sep 2026 14:14:19 -0400 Subject: [PATCH 3/4] test(optics): expect the source candidate version from vantio status The live package is 0.3.25. status --json reports that install version. The published registry pin in the opt-in registry check stays 0.3.24. CANDIDATE_ONLY. Not published. --- packages/vantio-cli/test/optics-cx.test.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/packages/vantio-cli/test/optics-cx.test.js b/packages/vantio-cli/test/optics-cx.test.js index 770cf3c6..00905350 100644 --- a/packages/vantio-cli/test/optics-cx.test.js +++ b/packages/vantio-cli/test/optics-cx.test.js @@ -157,7 +157,7 @@ describe("vantio status", () => { assert.equal(code, 0, stderr); const body = JSON.parse(stdout); assert.equal(body.schema_status, "unstable-pre-1.0"); - assert.equal(body.install.version, "0.3.24"); + assert.equal(body.install.version, "0.3.25"); assert.equal(body.registry.checked, false); assert.equal(body.registry.opticsStatus, "NOT_OBSERVED"); assert.equal(body.telemetry.posture, "disabled"); From 05c4d79c8356d3903f74dcec869ae342b8d25f52 Mon Sep 17 00:00:00 2001 From: Vantio Date: Wed, 30 Sep 2026 20:29:02 -0400 Subject: [PATCH 4/4] test(optics): keep the observe image on published CLI 0.3.24 The source candidate is 0.3.25. The observe example installs from npm, so its pin stays the published installer version. The exact-pin check reads that installer pin. The P1 council note records that the candidates are staged and unpublished. CANDIDATE_ONLY. Not published. --- deploy/docker/Dockerfile.observe | 3 ++- deploy/docker/test_observe_example.py | 13 ++++++++++--- .../optics-audit-p1/04-INDEPENDENT-COUNCIL.md | 2 +- 3 files changed, 13 insertions(+), 5 deletions(-) diff --git a/deploy/docker/Dockerfile.observe b/deploy/docker/Dockerfile.observe index 23da2c24..c6470a2b 100644 --- a/deploy/docker/Dockerfile.observe +++ b/deploy/docker/Dockerfile.observe @@ -1,5 +1,6 @@ # Optics observe example. Build context is this directory. -# The CLI pin is exact and matches packages/vantio-cli. It is not a range. +# The CLI pin is exact. It is the published installer version, 0.3.24. +# The source candidate in packages/vantio-cli is not what this image installs. # CANDIDATE_ONLY_NOT_FOR_PUBLICATION: this file does not publish the package. ARG BASE_IMAGE=node:22-bookworm-slim FROM ${BASE_IMAGE} diff --git a/deploy/docker/test_observe_example.py b/deploy/docker/test_observe_example.py index 904967af..8be05a50 100644 --- a/deploy/docker/test_observe_example.py +++ b/deploy/docker/test_observe_example.py @@ -38,11 +38,18 @@ class ObserveExampleTests(unittest.TestCase): - def test_cli_pin_is_exact_and_matches_the_tree(self) -> None: - cli = (DOCKER.parents[1] / "packages" / "vantio-cli" / "package.json").read_text(encoding="utf-8") + def test_cli_pin_is_exact_and_matches_the_published_installer(self) -> None: + root = DOCKER.parents[1] + cli = (root / "packages" / "vantio-cli" / "package.json").read_text(encoding="utf-8") version = re.search(r'"version":\s*"([^"]+)"', cli) self.assertIsNotNone(version) - expected = version.group(1) + source = version.group(1) + self.assertIsNotNone(_EXACT.fullmatch(source), source) + constants = (root / "packages" / "vantio-install" / "vantio_install" / "constants.py").read_text(encoding="utf-8") + published = re.search(r'"optics_cli_version":\s*"([^"]+)"', constants) + self.assertIsNotNone(published) + expected = published.group(1) + self.assertEqual(expected, "0.3.24") pins = [] for path in (DOCKERFILE, COMPOSE): for match in _PIN.finditer(path.read_text(encoding="utf-8")): diff --git a/docs/planning/optics-audit-p1/04-INDEPENDENT-COUNCIL.md b/docs/planning/optics-audit-p1/04-INDEPENDENT-COUNCIL.md index 5cc20d4f..a13f4bcd 100644 --- a/docs/planning/optics-audit-p1/04-INDEPENDENT-COUNCIL.md +++ b/docs/planning/optics-audit-p1/04-INDEPENDENT-COUNCIL.md @@ -21,7 +21,7 @@ The producer wrote this packet and the tests. The producer does not sit this cou | Observe image used `@vantio/cli@^0.3.1`, copied the repo context, and ran `vantio run npm start`, which does not attach the Node interceptor | Reproduced. Exact pin `0.3.24`, strict `.dockerignore`, `vantio run node agent.js`. | `deploy/docker/test_observe_example.py` | | `gate_get_policy` and `gate_residual_risk` accepted `api_key` and sent that value | Reproduced. The key is `VANTIO_API_KEY` only. Source version `@vantio/gate-mcp` `0.1.1` is a candidate, not a registry release. | `packages/vantio-gate-mcp/test/api_key_env.test.js` | -CLI `0.3.25` and Python `3.1.1` are not staged. Those packages were not changed. The observe example pins the CLI version already in this tree, `0.3.24`. +Source candidates `@vantio/cli` `0.3.25` and Python `vantio-agent-sdk` `3.1.1` are staged in this tree. They are not npm or PyPI releases. The observe example still installs published CLI `0.3.24`. ## Residual