Skip to content

fix(templates): refresh Python dependencies and container hygiene - #2495

Merged
aidandaly24 merged 10 commits into
aws:refactorfrom
aidandaly24:fix/python-template-security-refactor
Oct 1, 2026
Merged

aidandaly24 merged 10 commits into
aws:refactorfrom
aidandaly24:fix/python-template-security-refactor

Conversation

@aidandaly24

@aidandaly24 aidandaly24 commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Description

  • Allow patched MCP 1.x releases (>=1.28.1,<2) in FastMCP and exported Harness projects.
  • Replace SDK constraints that exclude its 1.18.1 security fix with compatible 1.x ranges.
  • Enable the SDK's declared Strands integration dependency and relax old Strands minor-version pins so SDK-compatible releases can resolve, preserving model-provider extras.
  • Add Debian package updates, disable uv caching, and remove globally installed uv after the final frozen sync in the Strands container template.
  • Guard the SDK/MCP ranges and container hygiene in one focused template test file.
  • Update the transitive Fastify lock entry from 5.12.1 to 5.12.5, resolving the required Linux audit failure without changing dependency declarations.

Frozen lockfile installs, non-root execution, Runtime ports, and direct Python startup remain unchanged. The Bedrock Managed Agents image is deliberately unchanged because it uses uv at startup.

Related Issue

Security-related dependency refresh based on already-published advisories. No public security issue was opened, following the repository's security-reporting guidance.

Public references:

Documentation PR

Not applicable. No README or documentation changes are included.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

  • Full RECORD=0 bun test after the review follow-up: 3,959 passed, zero failures.
  • Focused template-security and existing export tests: 28 passed.
  • bun install --frozen-lockfile --ignore-scripts passes.
  • bun audit: no vulnerabilities found across 784 packages.
  • Typecheck, lint, formatting, secrets scan, and build pass.
  • Fresh generated projects resolve SDK 1.24.0, MCP 1.30.0, and SDK-compatible Strands 1.57.1.
  • Built the generated Strands container with docker build --pull --no-cache --platform linux/amd64.
  • Final image inspection confirms libssl3t64 3.5.7-1~deb13u3, no uv/uvx executables, and no uv cache.
  • Default startup command returns /ping Healthy as UID 1000 with networking disabled and dummy credentials. This catches the SDK/older-Strands import incompatibility addressed by the integration extra.

This is local x86 image verification, not an ARM64 AWS deployment or Inspector rescan. No model invocation or AWS resource change was performed; live AWS E2E is not part of this template-only verification.

  • I ran bun test
  • I explained why live bun run test:e2e is not applicable to this local template verification
  • I ran bun run typecheck
  • I ran bun run lint:check
  • I ran bun run format:check
  • I ran bun run build
  • Existing project/export tests and manifest/spec snapshots pass; generated-project resolution and container checks were performed separately

Checklist

  • I have read the CONTRIBUTING document
  • I have added focused template regression coverage and kept necessary existing export assertions aligned with the updated template
  • No documentation changes are required
  • No new example is required for this template-only fix
  • My changes generate no new CLI warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@github-actions github-actions Bot added the size/m PR size: M label Oct 1, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Oct 1, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Oct 1, 2026

@agentcore-devx-automation agentcore-devx-automation Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

Scope is tight: Python template dependency bumps for the MCP and AgentCore SDK security advisories, Strands integration extra, and Dockerfile hygiene (Debian updates, UV_NO_CACHE=1, uv removal after the final frozen sync). Changes are well-matched to the stated advisories, migration guidance in docs/python-project-updates.md is clear, and the new tests exercise the real scaffolder against a temp directory rather than mocking, with coverage for every templated pyproject.toml variant and for the Dockerfile ordering (apt upgrade → UV_NO_CACHE → uv sync → pip uninstall uv → USER bedrock_agentcore).

A couple of non-blocking observations the author may want to confirm are intentional:

  • src/assets/templates/bedrock-managed-agents/pyproject.toml still lists bedrock-agentcore with no version constraint, so BMA builds can still resolve a pre-1.18.1 SDK. The PR body explains why BMA was skipped for the Dockerfile cleanup (uv at runtime), but it isn't obvious why the SDK pin was skipped. If this is deliberate (BMA pulls latest at build), fine; otherwise a >= 1.18.1, < 2.0.0 pin here would be consistent with the rest of the PR.
  • src/assets/templates/agent-python-langchain/pyproject.toml keeps bedrock-agentcore ~= 1.22.0. That already includes the fix, so no action required — just noting it was left as-is while the other templates moved to >= 1.18.1, < 2.0.0.

No telemetry concerns (template-only change) and no mocking concerns (tests use real inTempDirectory scaffolding).

@agentcore-devx-automation agentcore-devx-automation Bot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Oct 1, 2026
@github-actions github-actions Bot added size/s PR size: S and removed size/m PR size: M labels Oct 1, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added the claude-security-reviewing Claude Code /security-review in progress label Oct 1, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Oct 1, 2026
@notgitika

Copy link
Copy Markdown
Contributor

Review findings:

  1. Existing projects are not remediated by these template changes. Updating the CLI does not rewrite an existing pyproject.toml, uv.lock, or Dockerfile. This PR previously included docs/python-project-updates.md with the necessary dependency, uv lock --upgrade, Dockerfile, rebuild, and rescan steps, but that guide was removed in the final commits. Since the linked ticket concerns an already-generated customer project, please restore equivalent migration guidance or ensure it is delivered through another durable release/support channel.

  2. Please restore focused regression coverage for the security requirements. The final commit removed the assertions for bedrock-agentcore >=1.18.1, MCP >=1.28.1, apt upgrades, UV_NO_CACHE, and removing uv after the final sync. The remaining export test checks only the relaxed Strands range, so the actual security floors and container hygiene can regress while the suite remains green.

  3. The required Linux verify check is currently failing because bun audit reports Fastify 5.12.1 vulnerabilities (4 high, 1 moderate). This appears unrelated to the Python template edits, and the focused project tests, typecheck, and lint pass locally, but the required check still needs to be resolved before merge.

@github-actions github-actions Bot added size/s PR size: S and removed size/s PR size: S labels Oct 1, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added the claude-security-reviewing Claude Code /security-review in progress label Oct 1, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Oct 1, 2026
@github-actions github-actions Bot added size/s PR size: S and removed size/s PR size: S labels Oct 1, 2026
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.39%. Comparing base (b28dd21) to head (caf73bc).
⚠️ Report is 1 commits behind head on refactor.

Additional details and impacted files
@@            Coverage Diff            @@
##           refactor    #2495   +/-   ##
=========================================
  Coverage     97.39%   97.39%           
=========================================
  Files           642      642           
  Lines         46839    46839           
=========================================
  Hits          45620    45620           
  Misses         1219     1219           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@notgitika notgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, looks good!

@aidandaly24
aidandaly24 merged commit c1c88c8 into aws:refactor Oct 1, 2026
21 of 22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/s PR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants