deps(python): bump the opentelemetry group with 3 updates#24
Open
dependabot[bot] wants to merge 33 commits into
Open
deps(python): bump the opentelemetry group with 3 updates#24dependabot[bot] wants to merge 33 commits into
dependabot[bot] wants to merge 33 commits into
Conversation
…subscribe, queryIntelligence (#3)
…subscribe, queryIntelligence (#3)
…2+4 hybrid pivot Critical Fixes (28/28): - Fix #1: Rewrite broadcast_interactions.py with correct entry points matching Rust contracts - Fix #2: Add demo_upgrade_policy.py demonstrating v1→v2 contract upgrade on RiskPolicyManager - Fix #3: Implement real x402 flow with HTTP 402 middleware, demo_x402_subscribe.js, VaultWatchX402 class - Fix #4: AuditAgent uses record_finding entry point (was record_action) - Fix #5: MCP tools query real chain - fix ReputationEngine import, parse CLValue, fix query paths - Fix #6: Remove leaked CSPR.cloud API key from broadcast_interactions.py, server-side proxy - Fix #7: Move Groq API key server-side, remove all module-level groq_client singletons - Fix #8: SubscriberVault.open_vault and top_up now #[odra(payable)] with attached_value() - Fix #9: IntelAgent.serve_intel_with_x402 uses contract_hash=, deduct_credit entry point, query_type arg - Fix #10: SelfCorrectionAgent queries RiskPolicyManager.get_current_policy via Casper RPC - Fix #11: Add Odra events to all 8 contracts (15 events total) - Fix #12: Replace String address fields with Address type in RiskPolicyManager - Fix #13: Fix SentinelAlertLog.address_logs from comma-String to Vec<u64> capped at 256 - Fix #14: SafetyGuard fail-closed on model error - Fix #15: Remove all module-level groq_client, inject via constructor for testability - Fix #16: Add API key auth + slowapi rate limiting to FastAPI - Fix #17: Demo video script placeholder (demo_upgrade_policy.py, demo_x402_subscribe.js) - Fix #18: Replace hardcoded LIVE_FINDINGS with real API fetches in dashboard - Fix #19: Add 7 direct contract-query methods to SDK client - Fix #20: Add e2e test suite running against real Casper testnet - Fix #21: Update PROOF.md with verified markers and verification instructions - Fix #22: Complete CONTRACT_AUDIT.md with red-team security analysis - Fix #23: Landing page references added to README - Fix #24: Community engagement guidance in LAUNCH_AND_IMPACT.md - Fix #25: RBAC with OPERATOR/ADMIN roles in RiskPolicyManager - Fix #26: CSPR.click documentation added to DEPLOYMENT_GUIDE - Fix #27: Create vaultwatch-rwa-mcp domain-specific MCP server (5 tools) - Fix #28: RWA agent wired to real DeFiLlama + CoinGecko + Groq Compound data sources Practical Guidance (7/7 Recommendations): 1. Verify before submit - PROOF.md now has verification instructions 2. Demo video script - demo_upgrade_policy.py and demo_x402_subscribe.js 3. x402 flow demo-able in 60 seconds - scripted demo_x402_subscribe.js 4. Pin every claim to file:line - README now has file:line references 5. CSPR.click for agent wallets - documented in DEPLOYMENT_GUIDE 6. Domain-specific MCP server - vaultwatch_rwa_mcp with 5 tools 7. Community engagement - X/Twitter and Discord guidance in LAUNCH_AND_IMPACT.md Strategic Insights: - Track 2+4 hybrid narrative: compliance-gated RWA oracle on upgradable Casper contracts - README rewritten for VaultWatch RWA positioning - LAUNCH_AND_IMPACT.md updated with 3-phase roadmap including ZK-KYC - CONTRACT_AUDIT.md with 13-section red-team analysis - ARCHITECTURE.md corrected with real entry point names 30 files changed, 3865 insertions(+), 1645 deletions(-)
…atch, RWA MCP count, community docs Critical Fixes (from verification audit): - Fix #6 COMPLETE: Remove hardcoded CSPR_CLOUD_API_KEY from 4 additional files (broadcast_deploys.py, deploy_live.py, broadcast_transfers.py, deploy_new_account.py) All now read from CSPR_CLOUD_API_KEY environment variable - Fix #16 COMPLETE: Add @limiter.limit() decorators to ALL 9 API routes Add Depends(verify_api_key) to /api/intel, /api/findings, /api/rwa, /api/policy, /api/traces, /api/market, /api/chain Previously only 2/9 endpoints had auth; now 9/9 protected - Fix #21 COMPLETE: AuditTrail hash mismatch fixed in 7 files Wrong: ...6336a7 → Correct: ...6333a7 (matching transaction_hashes_live.json) Fixed in: sdk/client.py, mcp/server.py, e2e tests, BUILD_VERIFICATION.md, liveApi.js, mockApi.js, .env.example RWA MCP Tool Count Fix: - README.md: Updated from 8 to 5 RWA MCP tools with correct tool names (rwa_risk_assessment, compliance_check, rwa_oracle_query, subscribe_rwa_feed, agent_reputation) - ARCHITECTURE.md: Updated RWA MCP section from 8 to 5 tools - LAUNCH_AND_IMPACT.md: Updated 20+8 to 20+5 Community & Documentation: - LAUNCH_AND_IMPACT.md: Added X/Twitter strategy, Discord community channels, YouTube, and newsletter to Section 9 - DEPLOYMENT_GUIDE.md: Added Step 0 — CSPR.click wallet creation with browser and CLI instructions, agent wallet security guidelines - DEMO_SCRIPT.md: Added demo_x402_subscribe.js reference to Scene 3 Contract Fix: - risk_policy_manager.rs: Changed RiskPolicy.updated_by from String to Address type (Fix #12 now fully complete) CONTRACT_AUDIT.md: - Fixed executive summary counts: SentinelRegistry 0H→1H, total 3H→4H, 10M→11M
…ehavior_index.rs, sentinel_registry.rs, subscriber_vault.rs
Updates the requirements on [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python), [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) and [opentelemetry-instrumentation-fastapi](https://github.com/open-telemetry/opentelemetry-python-contrib) to permit the latest version. Updates `opentelemetry-api` to 1.44.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-python@v1.24.0...v1.44.0) Updates `opentelemetry-sdk` to 1.44.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-python@v1.24.0...v1.44.0) Updates `opentelemetry-instrumentation-fastapi` to 0.65b0 - [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md) - [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits) --- updated-dependencies: - dependency-name: opentelemetry-api dependency-version: 1.44.0 dependency-type: direct:production dependency-group: opentelemetry - dependency-name: opentelemetry-sdk dependency-version: 1.44.0 dependency-type: direct:production dependency-group: opentelemetry - dependency-name: opentelemetry-instrumentation-fastapi dependency-version: 0.65b0 dependency-type: direct:production dependency-group: opentelemetry ... Signed-off-by: dependabot[bot] <support@github.com>
Author
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates the requirements on opentelemetry-api, opentelemetry-sdk and opentelemetry-instrumentation-fastapi to permit the latest version.
Updates
opentelemetry-apito 1.44.0Changelog
Sourced from opentelemetry-api's changelog.
... (truncated)
Commits
53a5a40Prepare release 1.44.0/0.65b0 (#5422)d9f34e7Fixup eachdist.py handling of package names (#5417)d10f472opentelemetry-semantic-conventions: Bump to 1.43.0 (#5413)ae8feebUpdate otelbot token workflows to use client IDs (#5404)67a2abdFix Context in-place mutability bypass via inherited dict methods (#5399)87baad9Bump semconv to 1.42.0 (#5410)23dc0b2opentelemetry-sdk: add 'force_flush' method to LogRecordExporter ABC (#5294)bec55fdopentelemetry-sdk: expose SynchronousMultiLogRecordProcessor and ConcurrentMu...55d0b7aopentelemetry-sdk: Add ability to refresh process sensitive Resource attribut...6115db2opentelemetry-sdk: add log record limits environment variables (#5300)Updates
opentelemetry-sdkto 1.44.0Changelog
Sourced from opentelemetry-sdk's changelog.
... (truncated)
Commits
53a5a40Prepare release 1.44.0/0.65b0 (#5422)d9f34e7Fixup eachdist.py handling of package names (#5417)d10f472opentelemetry-semantic-conventions: Bump to 1.43.0 (#5413)ae8feebUpdate otelbot token workflows to use client IDs (#5404)67a2abdFix Context in-place mutability bypass via inherited dict methods (#5399)87baad9Bump semconv to 1.42.0 (#5410)23dc0b2opentelemetry-sdk: add 'force_flush' method to LogRecordExporter ABC (#5294)bec55fdopentelemetry-sdk: expose SynchronousMultiLogRecordProcessor and ConcurrentMu...55d0b7aopentelemetry-sdk: Add ability to refresh process sensitive Resource attribut...6115db2opentelemetry-sdk: add log record limits environment variables (#5300)Updates
opentelemetry-instrumentation-fastapito 0.65b0Changelog
Sourced from opentelemetry-instrumentation-fastapi's changelog.
... (truncated)
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions