| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
fix(agno): read the keys ContextGraph returns in the Agno graph tools (#1738) * test: run the Agno graph tools against a real ContextGraph (#1726) * fix: read ContextGraph's keys in the Agno graph tools (#1726) AgnoKGToolkit and AgnoKnowledgeGraph read node_id, node_type and edge_type from the dicts that ContextGraph.find_nodes() and get_neighbors() return. ContextGraph returns id, type and relationship, so on a real graph query_graph, find_related and infer_facts returned nothing, and the graph context lost the edge type and the target. infer_facts also read an inferred_facts attribute from the list that Reasoner.infer_facts() returns, and export_subgraph passed the ContextGraph object to RDFExporter instead of to_kg_dict(). --------- Co-authored-by: Kaif <98801504+KaifAhmad1@users.noreply.github.com> Co-authored-by: Sameer Kadam <sskadam6305@gmail.com> | 2 天前 | |
fix: drop the crewai extra to close unpatched chromadb/json-repair CVEs (#1710) * fix: drop the crewai extra to close unpatched chromadb/json-repair CVEs Removes the `semantica[crewai]` optional extra from pyproject.toml. It hard- pinned crewai>=0.80.0, which in turn hard-pins chromadb~=1.1.0 and json-repair~=0.25.2 — both carry critical advisories with no fixed release anywhere on PyPI (verified: chromadb's latest release, 1.5.9, is still inside every affected range; the json-repair fix (0.60.1) is blocked by crewai's own pin). Since nothing else in the dependency tree needs chromadb or json-repair, `uv lock` drops both (plus crewai and now-orphaned sub-dependencies) from uv.lock entirely, closing: - GHSA-f4j7-r4q5-qw2c / CVE-2026-45829 (chromadb pre-auth code injection) - GHSA-36p7-vc44-83pf / CVE-2026-45833 (chromadb authenticated code injection) - GHSA-2wm9-hf6c-p5cr / CVE-2026-45830 (chromadb cross-tenant data access) - GHSA-xph7-9rjv-w5fr / CVE-2026-45831 (chromadb RBAC tenant-scope bypass) - GHSA-xf7x-x43h-rpqh (json-repair circular $ref DoS) The integrations/crewai/ module and its tests are untouched — they already degrade gracefully when crewai isn't installed (tests/integrations/crewai/ stubs crewai for the unit tests and skips the real-package test in its own subprocess). Users who want the CrewAI integration now `pip install crewai` themselves, at their own risk assessment, rather than through a semantica extra. Docs and the now-stale osv-scanner.toml ignore entries are updated to match. * fix: pin crewai version floor in install docs, drop stale CONTRIBUTING.md mention Addresses PR review findings on #1710: - Every "pip install crewai" replacement was unconstrained, so a contributor with an older crewai already installed would silently stay below the documented crewai>=0.80.0 floor. Quoted the constraint everywhere: pip install "crewai>=0.80.0". - CONTRIBUTING.md still described the universal lock as covering "every optional extra (including crewai, which is excluded from all)" — crewai is no longer an extra at all, so that parenthetical was stale. | 8 天前 | |
fix(deps): address review feedback on import exceptions and probes (#1513) | 22 天前 | |
feat(integrations): add LangChain integration — retriever, vectorstor… (#1155) * feat(integrations): add LangChain integration — retriever, vectorstore, tools Co-authored-by: Cursor <cursoragent@cursor.com> * fix(langchain): address Qodo review on HybridSearch hits and tools Read nested HybridSearch metadata so retriever/vectorstore Documents are not empty, make the agent tools real BaseTool subclasses, and stop slicing tool JSON into invalid payloads. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com> | 1 个月前 | |
Verified RDF export: integrations/open_ontologies (#1108) (#1166) Adds `integrations/open_ontologies`, which registers a "verified" export method through Semantica's `method_registry` (#1108). Nothing in the core exporters is modified, and the verification gate is opt-in per call. The method performs standard RDF export via `RDFExporter`, then passes the written bytes to an independent Oxigraph-backed engine before the file is trusted. Validation runs in three ordered stages: 1. Strict RDF 1.1 syntax validation. 2. Closed-world vocabulary checking against declared ontologies and policed namespaces. 3. SHACL constraint validation with focus-node auditing to catch vacuous passes. Review feedback addressed in #1166: - Exception safety: Unverified files are unlinked if verification raises an exception when `raise_on_failure=True`, guaranteeing no unsound artifacts remain. - Encoding alignment: `verified_export_rdf` honors caller-specified `encoding`, preventing read-back decode errors on non-UTF-8 workflows. - Vocabulary gating: Enforced that both `ontology` and `policed_namespaces` are provided; partial configurations skip the check rather than passing against empty strings. - Version floor: Aligned integration docstrings with `open-ontologies-lite >= 0.5.0` (isolating `mcp` to prevent dependency conflicts with FastAPI). - Test fixtures: Updated `UNSOUND` fixture to test malformed IRIs against recent Turtle IRI normalization changes on `main`. Tests: - 12 unit and regression tests in `tests/integrations/open_ontologies/`, all passing. - Skips cleanly when `open-ontologies-lite` is not installed. --------- Co-authored-by: Zohaib Hassnain <109234410+ZohaibHassan16@users.noreply.github.com> | 10 天前 | |
fix: require Python >=3.10 and commit uv.lock for reproducible dev (#1506) (#1702) * fix: require Python >=3.10 and commit uv.lock for reproducible dev (#1506) `uv sync` failed from a clean checkout because requires-python allowed 3.9 while several dependencies (pyarrow>=24, open-ontologies-lite, ...) need 3.10+, so uv's universal resolution had no solution. Per maintainer decision on #1506, drop Python 3.8/3.9 and align every place that declares or tests a Python range: - pyproject.toml: requires-python >=3.10; classifiers 3.10-3.13; remove the now-dead `python_version < '3.10'` dependency branches. - explorer: replace datetime.UTC (3.11+) with timezone.utc so the package actually imports on the declared 3.10 floor. - Commit uv.lock (generated with the CI-pinned uv 0.12.1) and add a `uv lock --check` step to CI; document `uv sync --extra dev`. - Install Matrix: 3.10-3.13 (adds 3.13, which the Docker image uses). - Docs/README/badges/plugin READMEs: Python 3.10+. - osv-scanner.toml: ignore advisories that reach uv.lock only through the opt-in crewai extra (chromadb, json-repair); the extra stays out of `all` and requirements-ci.txt. requirements-ci.txt is unchanged (re-resolved for 3.11/linux: identical). Closes #1506 * fix: address #1702 review - cap Python <3.14, dev dependency group, doctor/docs - pyproject.toml: requires-python is now ">=3.10,<3.14" so the declared range matches what the Install Matrix and Docker image actually cover. - Docker: pin the runtime image back to python:3.13-slim (digest-pinned). Dependabot had bumped it to 3.14 (#1547) while the comment still said 3.13; the comment now states the current reasons, and dependabot.yml ignores python minor/major bumps for the image. - Move contributor tooling from the `dev` extra to a PEP 735 `[dependency-groups] dev` group and drop `dev` from the `all` extra, so `pip install semantica[all]` no longer ships pytest/jupyter/etc. `uv sync` installs the group by default and it is locked in uv.lock; pip users run `pip install -e . --group dev` (pip 25.1+). - requirements-ci.txt: same 410 pins and hashes; only the compile command (now `--group dev`) and the `via` annotations for dev packages change. CI's staleness check and CONTRIBUTING use the same command. - doctor: validate against MIN_PYTHON/MAX_PYTHON_EXCLUSIVE (3.10..3.13) instead of 3.8; warn on newer interpreters. - Docs: explorer/README.md and integrations/openclaw still said 3.8+; replace the removed `.[dev]` extra in README/docs. - Add tests/test_python_support_policy.py, which fails when requires-python, classifiers, the Install Matrix, the Dockerfile, doctor's constants or the dev-group layout disagree. Refs #1506 | 8 天前 | |
feat(integrations): add LangChain integration — retriever, vectorstor… (#1155) * feat(integrations): add LangChain integration — retriever, vectorstore, tools Co-authored-by: Cursor <cursoragent@cursor.com> * fix(langchain): address Qodo review on HybridSearch hits and tools Read nested HybridSearch metadata so retriever/vectorstore Documents are not empty, make the agent tools real BaseTool subclasses, and stop slicing tool JSON into invalid payloads. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com> | 1 个月前 |
| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
| 2 天前 | ||
| 8 天前 | ||
| 22 天前 | ||
| 1 个月前 | ||
| 10 天前 | ||
| 8 天前 | ||
| 1 个月前 |