Skip to content

build: coordinate dependency updates and MCP 2.1 smoke - #66

Merged
veil-chow-fyaic merged 1 commit into
mainfrom
agent/dependency-governance-2026-09
Sep 2, 2026
Merged

veil-chow-fyaic merged 1 commit into
mainfrom
agent/dependency-governance-2026-09

Conversation

@veil-chow-fyaic

Copy link
Copy Markdown
Collaborator

Outcome

Consolidates the broken one-file Dependabot updates into one verified maintenance change and removes the wildcard review rule that automatically requested a personal review on every repository change.

Changes

Python 3.14 from #63 is intentionally not included: it is a runtime major migration, not a patch update, and its Compose acceptance currently fails the repository's supported Python 3.13.14 contract.

Verification

  • ./scripts/check.sh: 2,088 tests, 100% statement/branch coverage, package/docs/OpenAPI/secret/dependency checks pass; no known vulnerabilities.
  • ./scripts/test_compose.sh: full PostgreSQL 18.4 reference deployment passes with zero project residue.
  • ./scripts/test_official_screening_live.sh: current four-source refresh/replay and CLI/REST/CRM/MCP parity pass with zero residue (EU FSF 6,234; Annex I 384; OFAC SDN 19,321; Consolidated 481).
  • Stale-source and invalid-input MCP paths remain fail closed; no mutating/clearance tool is exposed.

Evidence: docs/evidence/dependency-and-mcp-smoke-2026-09-02.md.

Relates to #47. Supersedes #61, #64 and #65 after merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant