fix(templates): refresh Python dependencies and container hygiene - #2495
aidandaly24 merged 10 commits into
Conversation
|
Claude Security Review: no high-confidence findings. (run) |
There was a problem hiding this comment.
AgentCore Harness Review
Verdict: Looks good
Scope is tight: Python template dependency bumps for the MCP and AgentCore SDK security advisories, Strands integration extra, and Dockerfile hygiene (Debian updates, UV_NO_CACHE=1, uv removal after the final frozen sync). Changes are well-matched to the stated advisories, migration guidance in docs/python-project-updates.md is clear, and the new tests exercise the real scaffolder against a temp directory rather than mocking, with coverage for every templated pyproject.toml variant and for the Dockerfile ordering (apt upgrade → UV_NO_CACHE → uv sync → pip uninstall uv → USER bedrock_agentcore).
A couple of non-blocking observations the author may want to confirm are intentional:
src/assets/templates/bedrock-managed-agents/pyproject.tomlstill listsbedrock-agentcorewith no version constraint, so BMA builds can still resolve a pre-1.18.1 SDK. The PR body explains why BMA was skipped for the Dockerfile cleanup (uv at runtime), but it isn't obvious why the SDK pin was skipped. If this is deliberate (BMA pulls latest at build), fine; otherwise a>= 1.18.1, < 2.0.0pin here would be consistent with the rest of the PR.src/assets/templates/agent-python-langchain/pyproject.tomlkeepsbedrock-agentcore ~= 1.22.0. That already includes the fix, so no action required — just noting it was left as-is while the other templates moved to>= 1.18.1, < 2.0.0.
No telemetry concerns (template-only change) and no mocking concerns (tests use real inTempDirectory scaffolding).
|
Claude Security Review: no high-confidence findings. (run) |
|
Review findings:
|
|
Claude Security Review: no high-confidence findings. (run) |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## refactor #2495 +/- ##
=========================================
Coverage 97.39% 97.39%
=========================================
Files 642 642
Lines 46839 46839
=========================================
Hits 45620 45620
Misses 1219 1219 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Description
>=1.28.1,<2) in FastMCP and exported Harness projects.1.18.1security fix with compatible 1.x ranges.5.12.1to5.12.5, resolving the required Linux audit failure without changing dependency declarations.Frozen lockfile installs, non-root execution, Runtime ports, and direct Python startup remain unchanged. The Bedrock Managed Agents image is deliberately unchanged because it uses uv at startup.
Related Issue
Security-related dependency refresh based on already-published advisories. No public security issue was opened, following the repository's security-reporting guidance.
Public references:
Documentation PR
Not applicable. No README or documentation changes are included.
Type of Change
Testing
RECORD=0 bun testafter the review follow-up: 3,959 passed, zero failures.bun install --frozen-lockfile --ignore-scriptspasses.bun audit: no vulnerabilities found across 784 packages.1.24.0, MCP1.30.0, and SDK-compatible Strands1.57.1.docker build --pull --no-cache --platform linux/amd64.libssl3t64 3.5.7-1~deb13u3, no uv/uvx executables, and no uv cache./pingHealthy as UID 1000 with networking disabled and dummy credentials. This catches the SDK/older-Strands import incompatibility addressed by the integration extra.This is local x86 image verification, not an ARM64 AWS deployment or Inspector rescan. No model invocation or AWS resource change was performed; live AWS E2E is not part of this template-only verification.
bun testbun run test:e2eis not applicable to this local template verificationbun run typecheckbun run lint:checkbun run format:checkbun run buildChecklist
By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.