From 6708bf8ae7e83dc4dceaa2a7960d975455704a47 Mon Sep 17 00:00:00 2001 From: Tom Softreck Date: Wed, 7 Oct 2026 00:32:40 +0200 Subject: [PATCH] chore(api): verify and upgrade 3 runtime dependency pins --- api/requirements.txt | 6 +-- project/TICKETS.md | 1 + project/ticket-004/README.md | 14 ++++++ project/ticket-004/intent.json | 81 ++++++++++++++++++++++++++++++++++ 4 files changed, 99 insertions(+), 3 deletions(-) create mode 100644 project/ticket-004/README.md create mode 100644 project/ticket-004/intent.json diff --git a/api/requirements.txt b/api/requirements.txt index 157ffe7..914ae60 100644 --- a/api/requirements.txt +++ b/api/requirements.txt @@ -1,10 +1,10 @@ fastapi==0.141.1 -uvicorn[standard]==0.52.4 +uvicorn[standard]==0.53.0 pydantic==2.13.5 httpx==0.28.1 -pyjwt==2.13.0 +pyjwt==2.15.0 passlib[bcrypt]==1.7.4 -jsonschema==4.23.0 +jsonschema==4.26.0 pyyaml==6.0.3 jinja2==3.1.4 python-multipart==0.0.12 diff --git a/project/TICKETS.md b/project/TICKETS.md index d7dc418..2c53bc7 100644 --- a/project/TICKETS.md +++ b/project/TICKETS.md @@ -6,4 +6,5 @@ | **ticket-001** | [`README.md`](./ticket-001/README.md) | - | - | - | - | - | | **ticket-002** | [`README.md`](./ticket-002/README.md) | - | - | - | - | - | | **ticket-003** | [`README.md`](./ticket-003/README.md) | - | - | - | - | - | +| **ticket-004** | [`README.md`](./ticket-004/README.md) | - | - | - | - | - | diff --git a/project/ticket-004/README.md b/project/ticket-004/README.md new file mode 100644 index 0000000..4f1c1d9 --- /dev/null +++ b/project/ticket-004/README.md @@ -0,0 +1,14 @@ +# Ticket 004: Verify and consolidate 3 pending API dependency upgrades + +- **ID**: ticket-004 +- **Owner**: agent:codex +- **Status**: IN_PROGRESS +- **Workflow state**: PUBLICATION +- **Created**: 2026-10-07 + +SESSION_EXECUTION_AUTHORIZATION: User requested continuing repairs, tests and protected publication of pending PRs. Consolidates Codot PR #12 (uvicorn), #13 (PyJWT) and #14 (jsonschema) after adding independently approved hosted API CI. + +## Acceptance criteria + +- [x] AC-01: Only the three requested version pins change; both Python versions pass existing tests and actual dependency binding smoke checks. +- [ ] AC-02: Native governance, all four hosted checks and independent exact-head protected publication pass. diff --git a/project/ticket-004/intent.json b/project/ticket-004/intent.json new file mode 100644 index 0000000..224e426 --- /dev/null +++ b/project/ticket-004/intent.json @@ -0,0 +1,81 @@ +{ + "schema": "new-project.intent/v3", + "ticket": "ticket-004", + "summary": "Verify and consolidate 3 pending API dependency upgrades", + "workstream": "interfaces", + "classification": { + "kind": "BUG", + "priority": "P1", + "origin": "requested" + }, + "allowedPaths": [ + "api/requirements.txt" + ], + "forbiddenPaths": [ + "project/ticket-*/user-*.md" + ], + "stacks": [], + "dependsOn": [], + "conflictsWith": [], + "integrationTicket": null, + "delivery": { + "acceptedBaseSha": "963b706b69341192968d0039066ea78eb14e7a76", + "targetBranch": "main", + "outcome": "Publish the verified uvicorn 0.53.0, PyJWT 2.15.0 and jsonschema 4.26.0 updates requested by Codot PRs 12, 13 and 14.", + "nonGoals": [ + "Add dependencies or change application behavior", + "Change workflow, publication actors or required checks", + "Discard unmerged bot history" + ], + "complexity": "L", + "estimatedMinutes": 30, + "budgets": { + "maxImplementationFiles": 1, + "maxAffectedComponents": 1, + "maxPublicInterfaceChanges": 1, + "maxRuntimeDependencies": 3 + }, + "architecture": { + "status": "accepted", + "decision": "Consolidate three existing dependency version pins under one native interfaces ticket; retain hosted API and governance gates and validate actual JWT/schema/ASGI bindings locally on both Python versions.", + "components": [ + { + "name": "api", + "paths": [ + "api/requirements.txt" + ] + } + ], + "responsibilityChanges": false, + "interfaceChanges": [], + "dataChanges": [], + "ui": { + "impact": "none", + "states": [], + "evidence": [] + }, + "rollback": "Revert the three version pins to the accepted base versions." + }, + "runtimeDependencies": [ + "uvicorn[standard]==0.53.0", + "PyJWT==2.15.0", + "jsonschema==4.26.0" + ], + "validation": [ + { + "criterion": "AC-01", + "commands": [ + "python -m pytest -q -p no:cacheprovider tests/test_policy.py tests/test_protocols.py" + ], + "evidence": "All ten existing API tests pass on Python 3.10 and 3.12 with the combined updates; actual JWT valid/expired/wrong-signature, inline schema valid/invalid and uvicorn ASGI loading smoke checks pass." + }, + { + "criterion": "AC-02", + "commands": [ + "bash project/governance-check.sh" + ], + "evidence": "Native governance, both hosted API matrix checks and both hosted governance checks pass before independent exact-head protected publication." + } + ] + } +}