Skip to content

Build(deps): Update claude-agent-sdk requirement from <0.3,>=0.2.136 to >=0.2.152,<0.3 - #706

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/claude-agent-sdk-gte-0.2.152-and-lt-0.3
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/claude-agent-sdk-gte-0.2.152-and-lt-0.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 12, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on claude-agent-sdk to permit the latest version.

Release notes

Sourced from claude-agent-sdk's releases.

v0.2.152

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.259

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.152/

pip install claude-agent-sdk==0.2.152
Changelog

Sourced from claude-agent-sdk's changelog.

0.2.152

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.259

0.2.151

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.258

0.2.150

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.257

0.2.149

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.252

0.2.148

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.251

0.2.147

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.250

0.2.146

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.248

0.2.145

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.247

0.2.144

... (truncated)

Commits
  • a8b1e28 docs: update changelog for v0.2.152
  • 0b41fb4 chore: release v0.2.152
  • ed1718f chore: bump bundled CLI version to 2.1.259
  • 16606a3 docs: update changelog for v0.2.151
  • dbe3998 chore: release v0.2.151
  • 637906e chore: bump bundled CLI version to 2.1.258
  • 1539d2a docs: update changelog for v0.2.150
  • 23ca647 chore: release v0.2.150
  • 036a35a chore: bump bundled CLI version to 2.1.257
  • 9597fc9 docs: update changelog for v0.2.149
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 12, 2026

@pengfei-threemoonslab pengfei-threemoonslab left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent coding-agent review — round 1, exact head b935ffdefa8d3ce85b3a79fdda4122644ddd1a2c. This is not human approval or merge authority.

[P2] The harness-specific upgrade qualification is missing. harness/requirements.txt:7-8 explicitly says the lower bound is bumped only after a smoke and paid Sonnet cell against the new version, because SDK event/cost changes affect paid-run behavior. This PR contains only the requirement change and no such evidence. Upstream 0.2.152 changes the bundled CLI to 2.1.259 (https://github.com/anthropics/claude-agent-sdk-python/releases/tag/v0.2.152), so a green Shipgate core suite/mock harness is not verification of that path. Attach the required candidate/version-bound evidence, or explicitly defer this optional paid-harness upgrade under the owner's repository-only v1.0 scope rather than treating it as readiness work. I did not initiate paid execution.

This requirement belongs to the external evaluation harness, not the published default scanner or locked CI closure. The existing range already permits this release, so the lower-bound change alone is not reproducible harness pinning. verify_dependency_lock.py passes but does not cover this requirements file. Official package metadata (https://pypi.org/pypi/claude-agent-sdk/0.2.152/json) retains Python >=3.10 and mcp>=1.23,<3.

All nine required GitHub checks were SUCCESS when inspected. I reviewed the actual diff and authoritative upstream metadata, ran the repository lock-coherence check, and did not repeat the hosted full suite. No repository edits or merge performed.

@dependabot
dependabot Bot force-pushed the dependabot/pip/claude-agent-sdk-gte-0.2.152-and-lt-0.3 branch 2 times, most recently from 22f23e8 to cb9c063 Compare September 12, 2026 21:17
@pengfei-threemoonslab

Copy link
Copy Markdown
Contributor

Reviewed. This only changes harness/requirements.txt, and harness/ is not part of what users install: the wheel builds with only-include, and the sdist excludes /harness and /harness/** (pyproject.toml). So it cannot change the shipped package.

The harness drives real provider sessions, and those do not run in CI, so the 9/9 green is not evidence about claude-agent-sdk 0.2.152. The bump stays within 0.2.x and only raises the floor.

Assessment: low risk, off the shipped surface. Merges are serial under the up-to-date rule, so this goes after the v1.0 PRs (#704, #710, #678, #642), once it is updated to main and green.

@pengfei-threemoonslab

Copy link
Copy Markdown
Contributor

Review: holding, not merging

The requirement file sets its own precondition for this change:

Bump the lower bound only after you've re-run the smoke + a paid Sonnet cell against the new release.

What I ran on this head (cb9c063f), in a fresh Python 3.13 venv installed from harness/requirements.txt:

  • The resolved claude-agent-sdk was 0.2.152.
  • The mock-driver smoke (python -m harness.adoption smoke) exited 0.
    • 10-agents-md scored 90 with headline_pass=True.
    • 00-no-hints scored 20 with headline_pass=False. That is the expected control cell.
  • tests/harness passed, 169 tests.

What that does not cover. The smoke uses the mock driver, so the Claude driver's parsing of real SDK events (ToolUseBlock, usage reporting) is never exercised. That parsing is exactly what the comment protects. The paid Sonnet cell has not been run, and running it needs API spend and an owner decision.

Why hold rather than close. The current range, >=0.2.136,<0.3, already admits 0.2.152, so nothing is blocked by leaving the floor where it is. This change only forbids older SDKs. It is not on the v1.0 path.

To land it, run one paid Sonnet cell against 0.2.152 and merge if its events parse cleanly.

@dependabot
dependabot Bot force-pushed the dependabot/pip/claude-agent-sdk-gte-0.2.152-and-lt-0.3 branch 3 times, most recently from 2f33064 to 7ca433c Compare September 14, 2026 21:22
Updates the requirements on [claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-python) to permit the latest version.
- [Release notes](https://github.com/anthropics/claude-agent-sdk-python/releases)
- [Changelog](https://github.com/anthropics/claude-agent-sdk-python/blob/main/CHANGELOG.md)
- [Commits](anthropics/claude-agent-sdk-python@v0.2.136...v0.2.152)

---
updated-dependencies:
- dependency-name: claude-agent-sdk
  dependency-version: 0.2.152
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/claude-agent-sdk-gte-0.2.152-and-lt-0.3 branch from 7ca433c to 709b187 Compare September 17, 2026 09:07
@dependabot @github

dependabot Bot commented on behalf of github Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #844.

@dependabot dependabot Bot closed this Sep 19, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/claude-agent-sdk-gte-0.2.152-and-lt-0.3 branch September 19, 2026 07:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant