Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion deploy/docker/Dockerfile.observe
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# Optics observe example. Build context is this directory.
# The CLI pin is exact and matches packages/vantio-cli. It is not a range.
# The CLI pin is exact. It is the published installer version, 0.3.24.
# The source candidate in packages/vantio-cli is not what this image installs.
# CANDIDATE_ONLY_NOT_FOR_PUBLICATION: this file does not publish the package.
ARG BASE_IMAGE=node:22-bookworm-slim
FROM ${BASE_IMAGE}
Expand Down
13 changes: 10 additions & 3 deletions deploy/docker/test_observe_example.py
Original file line number Diff line number Diff line change
Expand Up @@ -38,11 +38,18 @@


class ObserveExampleTests(unittest.TestCase):
def test_cli_pin_is_exact_and_matches_the_tree(self) -> None:
cli = (DOCKER.parents[1] / "packages" / "vantio-cli" / "package.json").read_text(encoding="utf-8")
def test_cli_pin_is_exact_and_matches_the_published_installer(self) -> None:
root = DOCKER.parents[1]
cli = (root / "packages" / "vantio-cli" / "package.json").read_text(encoding="utf-8")
version = re.search(r'"version":\s*"([^"]+)"', cli)
self.assertIsNotNone(version)
expected = version.group(1)
source = version.group(1)
self.assertIsNotNone(_EXACT.fullmatch(source), source)
constants = (root / "packages" / "vantio-install" / "vantio_install" / "constants.py").read_text(encoding="utf-8")
published = re.search(r'"optics_cli_version":\s*"([^"]+)"', constants)
self.assertIsNotNone(published)
expected = published.group(1)
self.assertEqual(expected, "0.3.24")
pins = []
for path in (DOCKERFILE, COMPOSE):
for match in _PIN.finditer(path.read_text(encoding="utf-8")):
Expand Down
10 changes: 5 additions & 5 deletions docs/governance/VERSION-METADATA.json
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,10 @@
{
"id": "cli",
"name": "@vantio/cli",
"version": "0.3.24",
"version": "0.3.25",
"manifest": "packages/vantio-cli/package.json",
"changelog": "docs/governance/changelogs/cli.md",
"changelog_heading": "## 0.3.24"
"changelog_heading": "## 0.3.25"
},
{
"id": "node-sdk",
Expand All @@ -22,16 +22,16 @@
{
"id": "python-sdk",
"name": "vantio-agent-sdk",
"version": "3.1.0",
"version": "3.1.1",
"manifest": "packages/vantio-agent-sdk-py/pyproject.toml",
"also": [
{
"file": "packages/vantio-agent-sdk-py/vantio/__init__.py",
"contains": "__version__ = \"3.1.0\""
"contains": "__version__ = \"3.1.1\""
}
],
"changelog": "packages/vantio-agent-sdk-py/CHANGELOG.md",
"changelog_heading": "## 3.1.0"
"changelog_heading": "## 3.1.1"
},
{
"id": "optics-mcp",
Expand Down
4 changes: 2 additions & 2 deletions docs/governance/canonical/ai-guide.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,9 @@ Use this guide when editing Vantio Optics documentation in this repository. Pack
```json
{
"ai_guide_versions": {
"@vantio/cli": "0.3.24",
"@vantio/cli": "0.3.25",
"@vantio/agent-sdk": "0.2.4",
"vantio-agent-sdk": "3.1.0",
"vantio-agent-sdk": "3.1.1",
"@vantio/optics-mcp": "0.1.2",
"@vantio/gate-mcp": "0.1.1",
"vantio-optics": "0.1.0",
Expand Down
6 changes: 6 additions & 0 deletions docs/governance/changelogs/cli.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,12 @@

This heading exists so a documentation release can require a changelog entry for the version already in `packages/vantio-cli/package.json`. It does not bump that version.

## 0.3.25

CANDIDATE_ONLY_NOT_FOR_PUBLICATION. Source version only. Not an npm release.

This heading stages the source version label and the docs checks that read it. It does not change CLI behavior. Removal of Gate-era enforcement is a separate change.

## 0.3.24

Documentation baseline at `14249ba84ff1f3d5aa8ad7a7366172f29235c76e`. The CLI reads its version from package.json. Product behavior is unchanged by this documentation record.
4 changes: 2 additions & 2 deletions docs/governance/llms-full.txt
Original file line number Diff line number Diff line change
Expand Up @@ -950,9 +950,9 @@ Use this guide when editing Vantio Optics documentation in this repository. Pack
```json
{
"ai_guide_versions": {
"@vantio/cli": "0.3.24",
"@vantio/cli": "0.3.25",
"@vantio/agent-sdk": "0.2.4",
"vantio-agent-sdk": "3.1.0",
"vantio-agent-sdk": "3.1.1",
"@vantio/optics-mcp": "0.1.2",
"@vantio/gate-mcp": "0.1.1",
"vantio-optics": "0.1.0",
Expand Down
2 changes: 1 addition & 1 deletion docs/planning/optics-audit-p1/04-INDEPENDENT-COUNCIL.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ The producer wrote this packet and the tests. The producer does not sit this cou
| Observe image used `@vantio/cli@^0.3.1`, copied the repo context, and ran `vantio run npm start`, which does not attach the Node interceptor | Reproduced. Exact pin `0.3.24`, strict `.dockerignore`, `vantio run node agent.js`. | `deploy/docker/test_observe_example.py` |
| `gate_get_policy` and `gate_residual_risk` accepted `api_key` and sent that value | Reproduced. The key is `VANTIO_API_KEY` only. Source version `@vantio/gate-mcp` `0.1.1` is a candidate, not a registry release. | `packages/vantio-gate-mcp/test/api_key_env.test.js` |

CLI `0.3.25` and Python `3.1.1` are not staged. Those packages were not changed. The observe example pins the CLI version already in this tree, `0.3.24`.
Source candidates `@vantio/cli` `0.3.25` and Python `vantio-agent-sdk` `3.1.1` are staged in this tree. They are not npm or PyPI releases. The observe example still installs published CLI `0.3.24`.

## Residual

Expand Down
2 changes: 1 addition & 1 deletion docs/products/optics/KNOWN-LIMITATIONS.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Known limitations

This page lists what Optics does not do, and the gaps that are easy to over-read. Versions: CLI 0.3.24, published Python 3.0.14, unpublished Python 3.1.0 source as labeled.
This page lists what Optics does not do, and the gaps that are easy to over-read. Versions: published CLI 0.3.24, source candidate CLI 0.3.25 (not an npm release), published Python 3.0.14, source candidate Python 3.1.1 (not a PyPI release). These source labels are staged here and are not a behavior change.

## Absent on purpose in the current products

Expand Down
24 changes: 12 additions & 12 deletions docs/programs/release-engineering/dossiers/optics-public.json
Original file line number Diff line number Diff line change
Expand Up @@ -144,21 +144,21 @@
"selector_is_integrity": false
},
"distribution": "public",
"filename": "@vantio-cli-0.3.24.source",
"filename": "@vantio-cli-0.3.25.source",
"hash_status": "UNRECORDED",
"role": "source-tree",
"sha256": null,
"source_commit": "1fd21a64468ebc6f05fdbf624dae06a2fc8e75c4",
"version": "0.3.24"
"version": "0.3.25"
}
],
"clean_env": {
"status": "NOT_RUN"
},
"distribution": "public",
"docs_gate": {
"docs_version": "0.3.24",
"manifest_version": "0.3.24",
"docs_version": "0.3.25",
"manifest_version": "0.3.25",
"status": "MATCH"
},
"ordinary_client": {
Expand All @@ -175,10 +175,10 @@
"from_version": null,
"rollback_sha256": null,
"to_sha256": null,
"to_version": "0.3.24",
"to_version": "0.3.25",
"verified": false
},
"version": "0.3.24"
"version": "0.3.25"
},
{
"artifacts": [
Expand Down Expand Up @@ -246,7 +246,7 @@
"role": "wheel",
"sha256": "dcf84cb3c4f144ece21032001657bfd9c91067faeffbefd0fb2ae19d6109dbeb",
"source_commit": "764361d7adfbd7eb6c5d4baac71cf32901a7eed0",
"version": "3.1.0"
"version": "3.1.1"
},
{
"byte_length": 59669,
Expand All @@ -264,16 +264,16 @@
"role": "sdist",
"sha256": "9f991291d5e44a23e17a9b0d7db24f6e7048d4c76cf0a9c37e35ccbcfe999c4f",
"source_commit": "764361d7adfbd7eb6c5d4baac71cf32901a7eed0",
"version": "3.1.0"
"version": "3.1.1"
}
],
"clean_env": {
"status": "NOT_RUN"
},
"distribution": "public",
"docs_gate": {
"docs_version": "3.1.0",
"manifest_version": "3.1.0",
"docs_version": "3.1.1",
"manifest_version": "3.1.1",
"status": "MATCH"
},
"ordinary_client": {
Expand All @@ -290,10 +290,10 @@
"from_version": "3.0.14",
"rollback_sha256": null,
"to_sha256": "dcf84cb3c4f144ece21032001657bfd9c91067faeffbefd0fb2ae19d6109dbeb",
"to_version": "3.1.0",
"to_version": "3.1.1",
"verified": false
},
"version": "3.1.0"
"version": "3.1.1"
},
{
"artifacts": [
Expand Down
4 changes: 2 additions & 2 deletions docs/programs/release-engineering/generated/evaluations.json
Original file line number Diff line number Diff line change
Expand Up @@ -20,12 +20,12 @@
"status": "SATISFIED"
},
{
"detail": "@vantio-cli-0.3.24.source hash unrecorded; @vantio-agent-sdk-0.2.4.source hash unrecorded; @vantio-optics-mcp-0.1.2.source hash unrecorded; @vantio-gate-mcp-0.1.1.source hash unrecorded; vantio-optics-0.1.0.source hash unrecorded; @vantio-optics-evidence-contract-0.0.0-unstable-pre-1.0.source hash unrecorded",
"detail": "@vantio-cli-0.3.25.source hash unrecorded; @vantio-agent-sdk-0.2.4.source hash unrecorded; @vantio-optics-mcp-0.1.2.source hash unrecorded; @vantio-gate-mcp-0.1.1.source hash unrecorded; vantio-optics-0.1.0.source hash unrecorded; @vantio-optics-evidence-contract-0.0.0-unstable-pre-1.0.source hash unrecorded",
"id": "R3",
"status": "GAP"
},
{
"detail": "@vantio-cli-0.3.24.source custody hash unrecorded; @vantio-agent-sdk-0.2.4.source custody hash unrecorded; @vantio-optics-mcp-0.1.2.source custody hash unrecorded; @vantio-gate-mcp-0.1.1.source custody hash unrecorded; vantio-optics-0.1.0.source custody hash unrecorded; @vantio-optics-evidence-contract-0.0.0-unstable-pre-1.0.source custody hash unrecorded",
"detail": "@vantio-cli-0.3.25.source custody hash unrecorded; @vantio-agent-sdk-0.2.4.source custody hash unrecorded; @vantio-optics-mcp-0.1.2.source custody hash unrecorded; @vantio-gate-mcp-0.1.1.source custody hash unrecorded; vantio-optics-0.1.0.source custody hash unrecorded; @vantio-optics-evidence-contract-0.0.0-unstable-pre-1.0.source custody hash unrecorded",
"id": "R4",
"status": "GAP"
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -164,10 +164,10 @@
}
],
"name": "@vantio/cli",
"purl": "pkg:npm/%40vantio/cli@0.3.24",
"purl": "pkg:npm/%40vantio/cli@0.3.25",
"scope": "workspace-manifest",
"type": "library",
"version": "0.3.24"
"version": "0.3.25"
},
{
"licenses": [
Expand Down Expand Up @@ -206,10 +206,10 @@
}
],
"name": "vantio-agent-sdk",
"purl": "pkg:pypi/vantio-agent-sdk@3.1.0",
"purl": "pkg:pypi/vantio-agent-sdk@3.1.1",
"scope": "python-manifest",
"type": "library",
"version": "3.1.0"
"version": "3.1.1"
},
{
"hashes": [
Expand Down
4 changes: 2 additions & 2 deletions docs/programs/release-engineering/generated/pin-report.json
Original file line number Diff line number Diff line change
Expand Up @@ -341,7 +341,7 @@
"id": "cli",
"manifest": "packages/vantio-cli/package.json",
"name": "@vantio/cli",
"version": "0.3.24"
"version": "0.3.25"
},
{
"id": "node-sdk",
Expand All @@ -353,7 +353,7 @@
"id": "python-sdk",
"manifest": "packages/vantio-agent-sdk-py/pyproject.toml",
"name": "vantio-agent-sdk",
"version": "3.1.0"
"version": "3.1.1"
},
{
"id": "optics-mcp",
Expand Down
6 changes: 6 additions & 0 deletions packages/vantio-agent-sdk-py/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,11 @@
# Changelog

## 3.1.1

CANDIDATE_ONLY_NOT_FOR_PUBLICATION. This heading is source. It is not a PyPI release.

This heading stages the source version label. It does not change SDK behavior. The sealed publisher stays on 3.1.0. Enforcement removal and the http.client status fix are separate changes.

## 3.1.0

- HTTP 400–599 is stored with `ok` false for urllib, requests, httpx, aiohttp, and urllib3. urllib HTTP errors are application outcomes and are not labeled `network_error`.
Expand Down
2 changes: 1 addition & 1 deletion packages/vantio-agent-sdk-py/pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ packages = ["vantio"]

[project]
name = "vantio-agent-sdk"
version = "3.1.0"
version = "3.1.1"
description = "Vantio Optics Python SDK — shield() for Sight Loop observe. Metadata only; no prompts."
readme = "README.md"
license = "MIT"
Expand Down
4 changes: 2 additions & 2 deletions packages/vantio-agent-sdk-py/tests/test_version.py
Original file line number Diff line number Diff line change
Expand Up @@ -10,8 +10,8 @@ class VersionTests(unittest.TestCase):
def test_runtime_version_matches_pyproject(self) -> None:
project = pathlib.Path(__file__).resolve().parents[1] / "pyproject.toml"
text = project.read_text(encoding="utf-8")
self.assertIn('version = "3.1.0"', text)
self.assertEqual(vantio.__version__, "3.1.0")
self.assertIn('version = "3.1.1"', text)
self.assertEqual(vantio.__version__, "3.1.1")
self.assertIn('license = "MIT"', text)
self.assertIn('license-files = ["LICENSE"]', text)
package = project.parent
Expand Down
2 changes: 1 addition & 1 deletion packages/vantio-agent-sdk-py/vantio/__init__.py
Original file line number Diff line number Diff line change
Expand Up @@ -23,4 +23,4 @@
"VantioPolicy",
"RedactionResult",
]
__version__ = "3.1.0"
__version__ = "3.1.1"
2 changes: 1 addition & 1 deletion packages/vantio-cli/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@vantio/cli",
"version": "0.3.24",
"version": "0.3.25",
"description": "Vantio Optics | Free Observability for AI Agents. Free, local-first observability for supported AI-agent traffic. Prompts and completions are never stored.",
"license": "MIT",
"author": "Vantio AI, Inc.",
Expand Down
2 changes: 1 addition & 1 deletion packages/vantio-cli/test/account-retirement.test.js
Original file line number Diff line number Diff line change
Expand Up @@ -97,7 +97,7 @@ describe("public surfaces do not advertise accounts", () => {
test("README and package metadata do not promise accounts, billing, or the missing config route", () => {
const readme = readFileSync(README_PATH, "utf8");
const pkg = JSON.parse(readFileSync(PKG_PATH, "utf8"));
assert.equal(pkg.version, "0.3.24");
assert.equal(pkg.version, "0.3.25");
assert.equal(pkg.license, "MIT");
assert.ok(pkg.files.includes("README.md"));
assert.ok(pkg.files.includes("LICENSE"));
Expand Down
2 changes: 1 addition & 1 deletion packages/vantio-cli/test/optics-cx.test.js
Original file line number Diff line number Diff line change
Expand Up @@ -157,7 +157,7 @@ describe("vantio status", () => {
assert.equal(code, 0, stderr);
const body = JSON.parse(stdout);
assert.equal(body.schema_status, "unstable-pre-1.0");
assert.equal(body.install.version, "0.3.24");
assert.equal(body.install.version, "0.3.25");
assert.equal(body.registry.checked, false);
assert.equal(body.registry.opticsStatus, "NOT_OBSERVED");
assert.equal(body.telemetry.posture, "disabled");
Expand Down
4 changes: 2 additions & 2 deletions packages/vantio-install/tests/test_stage_a.py
Original file line number Diff line number Diff line change
Expand Up @@ -141,11 +141,11 @@ def test_frozen_identities_and_cli_package_untouched(self) -> None:
self.assertEqual(pins["agent_sdk_npm_version"], "0.2.4")
self.assertEqual(pins["agent_sdk_py_version"], "3.1.0")
cli = json.loads((REPO / "packages" / "vantio-cli" / "package.json").read_text(encoding="utf-8"))
self.assertEqual(cli["version"], "0.3.24")
self.assertEqual(cli["version"], "0.3.25")
sdk = json.loads((REPO / "packages" / "vantio-agent-sdk" / "package.json").read_text(encoding="utf-8"))
self.assertEqual(sdk["version"], "0.2.4")
pyproject = (REPO / "packages" / "vantio-agent-sdk-py" / "pyproject.toml").read_text(encoding="utf-8")
self.assertIn('version = "3.1.0"', pyproject)
self.assertIn('version = "3.1.1"', pyproject)

def test_preflight_is_read_only(self) -> None:
harness = self.make()
Expand Down
4 changes: 2 additions & 2 deletions scripts/release/test_pypi_publish_workflow.py
Original file line number Diff line number Diff line change
Expand Up @@ -258,8 +258,8 @@ def test_other_workflows_do_not_publish_python(self) -> None:
def test_python_version_pin_remains(self) -> None:
pyproject = (ROOT / "packages/vantio-agent-sdk-py/pyproject.toml").read_text(encoding="utf-8")
init = (ROOT / "packages/vantio-agent-sdk-py/vantio/__init__.py").read_text(encoding="utf-8")
self.assertIn('version = "3.1.0"', pyproject)
self.assertIn('__version__ = "3.1.0"', init)
self.assertIn('version = "3.1.1"', pyproject)
self.assertIn('__version__ = "3.1.1"', init)


class SealedGateTests(unittest.TestCase):
Expand Down
10 changes: 5 additions & 5 deletions scripts/release/ws11/ws11.test.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -228,7 +228,7 @@ test("current surfaces characterize with gaps and withhold release success", ()
assert.equal(python.registry.this_force_refetched, false);
assert.equal(python.registry.historical_register_state, "PUBLISHED_REGISTRY_BYTES_VERIFIED_CLIENT_PROVED");
const cli = optics.units.find((unit) => unit.package === "@vantio/cli");
assert.equal(cli.version, "0.3.24");
assert.equal(cli.version, "0.3.25");
assert.equal(cli.artifacts[0].custody.selector.kind, "git-tag");
assert.equal(cli.artifacts[0].custody.selector_is_integrity, false);
const contract = optics.units.find((unit) => unit.package === "@vantio/optics-evidence-contract");
Expand All @@ -248,8 +248,8 @@ test("workspace SBOM and license scan stay bounded to what the tree shows", () =
assert.equal(sbom.bomFormat, "CycloneDX");
assert.equal(sbom.specVersion, "1.5");
assert.ok(sbom.components.length > 20);
assert.ok(sbom.components.some((item) => item.name === "@vantio/cli" && item.version === "0.3.24"));
assert.ok(sbom.components.some((item) => item.purl === "pkg:pypi/vantio-agent-sdk@3.1.0"));
assert.ok(sbom.components.some((item) => item.name === "@vantio/cli" && item.version === "0.3.25"));
assert.ok(sbom.components.some((item) => item.purl === "pkg:pypi/vantio-agent-sdk@3.1.1"));
assert.ok(sbom.components.some((item) => item.name === "undici" && item.hashes));
const completeness = sbom.properties.find((item) => item.name === "vantio:completeness");
assert.equal(completeness.value, "pnpm-lockfile-packages-section-plus-workspace-manifests");
Expand Down Expand Up @@ -332,8 +332,8 @@ test("version-matched docs gate and the customer test double agree with the tree
assert.equal(assemblePeCustomerBundle({ version: "9.9.9", manualText: manual }).ok, false);
const cli = JSON.parse(readFileSync(join(ROOT, "packages/vantio-cli/package.json"), "utf8"));
const pyproject = readFileSync(join(ROOT, "packages/vantio-agent-sdk-py/pyproject.toml"), "utf8");
assert.equal(cli.version, "0.3.24");
assert.match(pyproject, /version = "3.1.0"/);
assert.equal(cli.version, "0.3.25");
assert.match(pyproject, /version = "3.1.1"/);
assert.equal(readFileSync(join(ROOT, ".github/workflows/ci.yml"), "utf8").includes("scripts/release/ws11/ws11.test.mjs"), true);
});

Expand Down
Loading