deps(python): update fastmcp requirement from >=0.1.0 to >=3.4.4#27
Open
dependabot[bot] wants to merge 33 commits into
Open
deps(python): update fastmcp requirement from >=0.1.0 to >=3.4.4#27dependabot[bot] wants to merge 33 commits into
dependabot[bot] wants to merge 33 commits into
Conversation
…subscribe, queryIntelligence (#3)
…subscribe, queryIntelligence (#3)
…2+4 hybrid pivot Critical Fixes (28/28): - Fix #1: Rewrite broadcast_interactions.py with correct entry points matching Rust contracts - Fix #2: Add demo_upgrade_policy.py demonstrating v1→v2 contract upgrade on RiskPolicyManager - Fix #3: Implement real x402 flow with HTTP 402 middleware, demo_x402_subscribe.js, VaultWatchX402 class - Fix #4: AuditAgent uses record_finding entry point (was record_action) - Fix #5: MCP tools query real chain - fix ReputationEngine import, parse CLValue, fix query paths - Fix #6: Remove leaked CSPR.cloud API key from broadcast_interactions.py, server-side proxy - Fix #7: Move Groq API key server-side, remove all module-level groq_client singletons - Fix #8: SubscriberVault.open_vault and top_up now #[odra(payable)] with attached_value() - Fix #9: IntelAgent.serve_intel_with_x402 uses contract_hash=, deduct_credit entry point, query_type arg - Fix #10: SelfCorrectionAgent queries RiskPolicyManager.get_current_policy via Casper RPC - Fix #11: Add Odra events to all 8 contracts (15 events total) - Fix #12: Replace String address fields with Address type in RiskPolicyManager - Fix #13: Fix SentinelAlertLog.address_logs from comma-String to Vec<u64> capped at 256 - Fix #14: SafetyGuard fail-closed on model error - Fix #15: Remove all module-level groq_client, inject via constructor for testability - Fix #16: Add API key auth + slowapi rate limiting to FastAPI - Fix #17: Demo video script placeholder (demo_upgrade_policy.py, demo_x402_subscribe.js) - Fix #18: Replace hardcoded LIVE_FINDINGS with real API fetches in dashboard - Fix #19: Add 7 direct contract-query methods to SDK client - Fix #20: Add e2e test suite running against real Casper testnet - Fix #21: Update PROOF.md with verified markers and verification instructions - Fix #22: Complete CONTRACT_AUDIT.md with red-team security analysis - Fix #23: Landing page references added to README - Fix #24: Community engagement guidance in LAUNCH_AND_IMPACT.md - Fix #25: RBAC with OPERATOR/ADMIN roles in RiskPolicyManager - Fix #26: CSPR.click documentation added to DEPLOYMENT_GUIDE - Fix #27: Create vaultwatch-rwa-mcp domain-specific MCP server (5 tools) - Fix #28: RWA agent wired to real DeFiLlama + CoinGecko + Groq Compound data sources Practical Guidance (7/7 Recommendations): 1. Verify before submit - PROOF.md now has verification instructions 2. Demo video script - demo_upgrade_policy.py and demo_x402_subscribe.js 3. x402 flow demo-able in 60 seconds - scripted demo_x402_subscribe.js 4. Pin every claim to file:line - README now has file:line references 5. CSPR.click for agent wallets - documented in DEPLOYMENT_GUIDE 6. Domain-specific MCP server - vaultwatch_rwa_mcp with 5 tools 7. Community engagement - X/Twitter and Discord guidance in LAUNCH_AND_IMPACT.md Strategic Insights: - Track 2+4 hybrid narrative: compliance-gated RWA oracle on upgradable Casper contracts - README rewritten for VaultWatch RWA positioning - LAUNCH_AND_IMPACT.md updated with 3-phase roadmap including ZK-KYC - CONTRACT_AUDIT.md with 13-section red-team analysis - ARCHITECTURE.md corrected with real entry point names 30 files changed, 3865 insertions(+), 1645 deletions(-)
…atch, RWA MCP count, community docs Critical Fixes (from verification audit): - Fix #6 COMPLETE: Remove hardcoded CSPR_CLOUD_API_KEY from 4 additional files (broadcast_deploys.py, deploy_live.py, broadcast_transfers.py, deploy_new_account.py) All now read from CSPR_CLOUD_API_KEY environment variable - Fix #16 COMPLETE: Add @limiter.limit() decorators to ALL 9 API routes Add Depends(verify_api_key) to /api/intel, /api/findings, /api/rwa, /api/policy, /api/traces, /api/market, /api/chain Previously only 2/9 endpoints had auth; now 9/9 protected - Fix #21 COMPLETE: AuditTrail hash mismatch fixed in 7 files Wrong: ...6336a7 → Correct: ...6333a7 (matching transaction_hashes_live.json) Fixed in: sdk/client.py, mcp/server.py, e2e tests, BUILD_VERIFICATION.md, liveApi.js, mockApi.js, .env.example RWA MCP Tool Count Fix: - README.md: Updated from 8 to 5 RWA MCP tools with correct tool names (rwa_risk_assessment, compliance_check, rwa_oracle_query, subscribe_rwa_feed, agent_reputation) - ARCHITECTURE.md: Updated RWA MCP section from 8 to 5 tools - LAUNCH_AND_IMPACT.md: Updated 20+8 to 20+5 Community & Documentation: - LAUNCH_AND_IMPACT.md: Added X/Twitter strategy, Discord community channels, YouTube, and newsletter to Section 9 - DEPLOYMENT_GUIDE.md: Added Step 0 — CSPR.click wallet creation with browser and CLI instructions, agent wallet security guidelines - DEMO_SCRIPT.md: Added demo_x402_subscribe.js reference to Scene 3 Contract Fix: - risk_policy_manager.rs: Changed RiskPolicy.updated_by from String to Address type (Fix #12 now fully complete) CONTRACT_AUDIT.md: - Fixed executive summary counts: SentinelRegistry 0H→1H, total 3H→4H, 10M→11M
…ehavior_index.rs, sentinel_registry.rs, subscriber_vault.rs
Updates the requirements on [fastmcp](https://github.com/PrefectHQ/fastmcp) to permit the latest version. - [Release notes](https://github.com/PrefectHQ/fastmcp/releases) - [Changelog](https://github.com/PrefectHQ/fastmcp/blob/main/docs/changelog.mdx) - [Commits](PrefectHQ/fastmcp@v0.1.0...v3.4.4) --- updated-dependencies: - dependency-name: fastmcp dependency-version: 3.4.4 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Author
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates the requirements on fastmcp to permit the latest version.
Release notes
Sourced from fastmcp's releases.
Changelog
Sourced from fastmcp's changelog.
... (truncated)
Commits
9138d40Docs: add v3.4.4 changelog entries (#4473)d929882Hugging Face Auth Integration (#4385)5fe4faeRestore HTTP host guard compatibility (#4472)400db61Relax host origin guard defaults (#4439)1eedd1fDocs: add v3.4.2 and v3.4.3 changelog entries (#4430)3b1afe6chore(deps): bump joserfc from 1.6.7 to 1.6.8 in the uv group across 1 direct...874425achore: Update SDK documentation (#4427)691766b[codex] Fix OpenAPI resource template requests (#4407)47907e0Fix ty 0.0.55 diagnostics and prefab-ui protocol version drift (#4428)c1b0396Block IPv6 transition SSRF bypasses (#4426)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)