Build(deps): Update claude-agent-sdk requirement from <0.3,>=0.2.136 to >=0.2.152,<0.3 - #706
dependabot[bot] wants to merge 1 commit into
Conversation
pengfei-threemoonslab
left a comment
There was a problem hiding this comment.
Independent coding-agent review — round 1, exact head b935ffdefa8d3ce85b3a79fdda4122644ddd1a2c. This is not human approval or merge authority.
[P2] The harness-specific upgrade qualification is missing. harness/requirements.txt:7-8 explicitly says the lower bound is bumped only after a smoke and paid Sonnet cell against the new version, because SDK event/cost changes affect paid-run behavior. This PR contains only the requirement change and no such evidence. Upstream 0.2.152 changes the bundled CLI to 2.1.259 (https://github.com/anthropics/claude-agent-sdk-python/releases/tag/v0.2.152), so a green Shipgate core suite/mock harness is not verification of that path. Attach the required candidate/version-bound evidence, or explicitly defer this optional paid-harness upgrade under the owner's repository-only v1.0 scope rather than treating it as readiness work. I did not initiate paid execution.
This requirement belongs to the external evaluation harness, not the published default scanner or locked CI closure. The existing range already permits this release, so the lower-bound change alone is not reproducible harness pinning. verify_dependency_lock.py passes but does not cover this requirements file. Official package metadata (https://pypi.org/pypi/claude-agent-sdk/0.2.152/json) retains Python >=3.10 and mcp>=1.23,<3.
All nine required GitHub checks were SUCCESS when inspected. I reviewed the actual diff and authoritative upstream metadata, ran the repository lock-coherence check, and did not repeat the hosted full suite. No repository edits or merge performed.
22f23e8 to
cb9c063
Compare
|
Reviewed. This only changes The harness drives real provider sessions, and those do not run in CI, so the 9/9 green is not evidence about Assessment: low risk, off the shipped surface. Merges are serial under the up-to-date rule, so this goes after the v1.0 PRs (#704, #710, #678, #642), once it is updated to |
Review: holding, not mergingThe requirement file sets its own precondition for this change:
What I ran on this head (
What that does not cover. The smoke uses the mock driver, so the Claude driver's parsing of real SDK events ( Why hold rather than close. The current range, To land it, run one paid Sonnet cell against 0.2.152 and merge if its events parse cleanly. |
2f33064 to
7ca433c
Compare
Updates the requirements on [claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-python) to permit the latest version. - [Release notes](https://github.com/anthropics/claude-agent-sdk-python/releases) - [Changelog](https://github.com/anthropics/claude-agent-sdk-python/blob/main/CHANGELOG.md) - [Commits](anthropics/claude-agent-sdk-python@v0.2.136...v0.2.152) --- updated-dependencies: - dependency-name: claude-agent-sdk dependency-version: 0.2.152 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
7ca433c to
709b187
Compare
|
Superseded by #844. |
Updates the requirements on claude-agent-sdk to permit the latest version.
Release notes
Sourced from claude-agent-sdk's releases.
Changelog
Sourced from claude-agent-sdk's changelog.
... (truncated)
Commits
a8b1e28docs: update changelog for v0.2.1520b41fb4chore: release v0.2.152ed1718fchore: bump bundled CLI version to 2.1.25916606a3docs: update changelog for v0.2.151dbe3998chore: release v0.2.151637906echore: bump bundled CLI version to 2.1.2581539d2adocs: update changelog for v0.2.15023ca647chore: release v0.2.150036a35achore: bump bundled CLI version to 2.1.2579597fc9docs: update changelog for v0.2.149