This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/requirements.txt

24 lines
1 KiB
Text
Raw Permalink Normal View History

langgraph==1.2.9
Prove P1 exit criteria against the real LangGraph graph; fix question_id stability Reworks the P1 sim so the four §7.1 exit criteria are demonstrated against the ACTUAL mechanic, not a model (resolves the verifier's "sim models the ledger, not the LangGraph integration" finding). - New tests/sim/test_p1_graph_integration.py drives the real agent_team.graph StateGraph (interrupt/Command(resume)) + the real langgraph SqliteSaver checkpointer + the committed pending_questions compare-and-set, proving: (a) suspend survives a simulated restart (drop saver/conn, rebuild over the same checkpoint DB) and resumes; (b) duplicate answer loses the CAS and the graph never double-advances; (c) a post-deadline answer loses to expire and the task is not resumed; (d) two concurrent tasks resume to the correct thread, with a turn-guarded no-double-apply check. - graph.py: derive a STABLE question_id from uuid5(thread_id, turn). The clarifier node replays on resume, so the prior fresh-uuid id changed between the delivered/ledgered question and the qa_history entry — breaking the §3.3.1 identity contract. Now the delivered id == ledger key == history entry (unit-tested in test_graph.py). - harness._connect() now uses the committed schema.connect() (WAL + busy_timeout) instead of a raw sqlite3.connect, so concurrent responders genuinely serialize; the criterion-(d) concurrency test no longer swallows OperationalError (it asserts zero errors + exactly one CAS winner). - requirements.txt: pin langgraph-checkpoint-sqlite==3.1.0 (design D9 durable checkpointer), now exercised by the integration test. Full suite: 564 passed; ruff + format clean.
2026-06-17 14:47:54 -04:00
# Durable SQLite checkpointer for the R720 agent-team Plane-2 pipeline (design D9).
langgraph-checkpoint-sqlite==3.1.0
langchain-anthropic==1.4.8
langchain-openai==1.3.4
langchain-google-genai==4.2.7
build(deps): bump the minor-and-patch group across 1 directory with 6 updates (#11) Bumps the minor-and-patch group with 6 updates in the / directory: | Package | From | To | | --- | --- | --- | | [langgraph](https://github.com/langchain-ai/langgraph) | `1.1.10` | `1.2.5` | | [langchain-anthropic](https://github.com/langchain-ai/langchain) | `1.4.3` | `1.4.6` | | [langchain-openai](https://github.com/langchain-ai/langchain) | `1.2.1` | `1.3.2` | | [langchain-google-genai](https://github.com/langchain-ai/langchain-google) | `4.2.2` | `4.2.5` | | [langchain-community](https://github.com/langchain-ai/langchain-community) | `0.4.1` | `0.4.2` | | [composio-langgraph](https://github.com/ComposioHQ/composio) | `0.13.0` | `0.15.0` | Updates `langgraph` from 1.1.10 to 1.2.5 - [Release notes](https://github.com/langchain-ai/langgraph/releases) - [Commits](https://github.com/langchain-ai/langgraph/compare/1.1.10...1.2.5) Updates `langchain-anthropic` from 1.4.3 to 1.4.6 - [Release notes](https://github.com/langchain-ai/langchain/releases) - [Commits](https://github.com/langchain-ai/langchain/compare/langchain-anthropic==1.4.3...langchain-anthropic==1.4.6) Updates `langchain-openai` from 1.2.1 to 1.3.2 - [Release notes](https://github.com/langchain-ai/langchain/releases) - [Commits](https://github.com/langchain-ai/langchain/compare/langchain-openai==1.2.1...langchain-openai==1.3.2) Updates `langchain-google-genai` from 4.2.2 to 4.2.5 - [Release notes](https://github.com/langchain-ai/langchain-google/releases) - [Commits](https://github.com/langchain-ai/langchain-google/compare/libs/genai/v4.2.2...libs/genai/v4.2.5) Updates `langchain-community` from 0.4.1 to 0.4.2 - [Release notes](https://github.com/langchain-ai/langchain-community/releases) - [Commits](https://github.com/langchain-ai/langchain-community/compare/libs/community/v0.4.1...libs/community/v0.4.2) Updates `composio-langgraph` from 0.13.0 to 0.15.0 - [Release notes](https://github.com/ComposioHQ/composio/releases) - [Commits](https://github.com/ComposioHQ/composio/compare/py@0.13.0...py@0.15.0) --- updated-dependencies: - dependency-name: composio-langgraph dependency-version: 0.13.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: langchain-anthropic dependency-version: 1.4.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: langchain-community dependency-version: 0.4.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: langchain-google-genai dependency-version: 4.2.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: langchain-openai dependency-version: 1.3.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: langgraph dependency-version: 1.2.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:44:46 -04:00
langchain-community==0.4.2
composio-langgraph==0.17.1
python-dotenv==1.2.2
# WS1 agent-team HTTP API (agent_team/api.py): FastAPI app + uvicorn ASGI server.
fastapi==0.139.0
uvicorn==0.51.0
fix(agent-team): dispatch via GitHub App so P3 reaches CI (run_id resolves) The P3 dispatcher's default seams shell out to gh/git, but the R720 box has no gh and a read-only PAT with no Actions scope — so dispatch_apply_verify returned no run_id and every task parked at verify ("dispatch unresolved"). Add a GitHub-App auth path: the box mints short-lived (~1h) installation access tokens from the App private key and uses them for the three dispatch seams, removing the gh dependency. - agent_team/github_app.py (new): mint_installation_token (RS256 App JWT, iss=app_id, iat backdated 60s, exp 9 min; POST /access_tokens) + a lazy TokenProvider that caches and re-mints near expiry. Secret-safe: the JWT and token are never logged, never in an exception message, never persisted. - dispatcher.py: app_branch_pusher / app_workflow_dispatcher / app_run_locator (additive; gh/git _default_* left untouched). Push auth rides a host-scoped http.extraHeader via GIT_CONFIG_* env (token never in argv/ps); the REST run locator maps id->databaseId / created_at->createdAt into select_run_id and surfaces 4xx promptly instead of silently exhausting the poll window. - coordinator.py: default_dispatch_node_factory binds the App seams when AGENT_TEAM_GH_APP_ID / _INSTALLATION_ID / _PRIVATE_KEY are all set; partial or unreadable config logs one warning and falls back to gh-default (never raises at serve-start). - requirements.txt: pin PyJWT, cryptography, requests (App seams + CI fetcher). - DEPLOY-R720.md / README.md: App dispatch config, permission/scope audit, env-precedence check, key rotation/revocation + incident response. Tests: +18 (test_github_app.py new; dispatcher/coordinator additions) covering JWT claims, cache/re-mint, token-scrub-on-error, REST field mapping + run-name correlation, and the partial-env inert fallback. Full suite 1523 passing.
2026-06-24 17:07:01 -04:00
# GitHub App installation-token minting for the agent-team P3 dispatcher
# (agent_team/github_app.py): RS256 JWT (PyJWT) signed with the App private key,
# exchanged for a short-lived installation token. cryptography backs RS256.
PyJWT==2.13.0
# >=48.0.1: earlier wheels statically link a vulnerable OpenSSL (GHSA-537c-gmf6-5ccf).
cryptography==48.0.1
fix(agent-team): dispatch via GitHub App so P3 reaches CI (run_id resolves) The P3 dispatcher's default seams shell out to gh/git, but the R720 box has no gh and a read-only PAT with no Actions scope — so dispatch_apply_verify returned no run_id and every task parked at verify ("dispatch unresolved"). Add a GitHub-App auth path: the box mints short-lived (~1h) installation access tokens from the App private key and uses them for the three dispatch seams, removing the gh dependency. - agent_team/github_app.py (new): mint_installation_token (RS256 App JWT, iss=app_id, iat backdated 60s, exp 9 min; POST /access_tokens) + a lazy TokenProvider that caches and re-mints near expiry. Secret-safe: the JWT and token are never logged, never in an exception message, never persisted. - dispatcher.py: app_branch_pusher / app_workflow_dispatcher / app_run_locator (additive; gh/git _default_* left untouched). Push auth rides a host-scoped http.extraHeader via GIT_CONFIG_* env (token never in argv/ps); the REST run locator maps id->databaseId / created_at->createdAt into select_run_id and surfaces 4xx promptly instead of silently exhausting the poll window. - coordinator.py: default_dispatch_node_factory binds the App seams when AGENT_TEAM_GH_APP_ID / _INSTALLATION_ID / _PRIVATE_KEY are all set; partial or unreadable config logs one warning and falls back to gh-default (never raises at serve-start). - requirements.txt: pin PyJWT, cryptography, requests (App seams + CI fetcher). - DEPLOY-R720.md / README.md: App dispatch config, permission/scope audit, env-precedence check, key rotation/revocation + incident response. Tests: +18 (test_github_app.py new; dispatcher/coordinator additions) covering JWT claims, cache/re-mint, token-scrub-on-error, REST field mapping + run-name correlation, and the partial-env inert fallback. Full suite 1523 passing.
2026-06-24 17:07:01 -04:00
# Runtime HTTP client for the agent-team P3 App-dispatch seams
# (github_app.mint_installation_token, dispatcher.app_workflow_dispatcher,
# dispatcher.app_run_locator) and the CI fetcher/transport. Pinned first-class
# (was previously relied on only as a transitive dep of langchain-community).
requests==2.34.2