Take sdk 2.8.0 and the coupled set, release 2.15.0 - #140
Merged
Merged
Conversation
…15.0 mppx 0.12.0 defaults an unconfigured Tempo offer to OUSD first; the rail passes an explicit USDC currency, and a test now pins that the challenge offers USDC alone. The sdk move drops getReputation from the api re-export, since /v1/reputation was retired.
Stripe's 2026-09-30.preview API rejects payment_method_types on PaymentIntent create; allowed_payment_method_types is accepted there and on the 2026-03-04.preview the storefronts pin today (both checked in test mode).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Dependency sweep and the reputation cleanup, released as 2.15.0.
@agent-score/sdk^2.8.0. The SDK droppedgetReputation()becauseGET /v1/reputationwas retired on 2026-09-30.@agent-score/commerce/apire-exports the SDK'sAgentScoreclient, so that method leaves this package's surface too.The coupled settle set's verifier side: mppx 0.12.0, viem 2.57.2, and
@x402/core,@x402/evm,@x402/extensions2.28.0, all exact.mppx 0.12.0 changes Tempo's defaults. An unconfigured
tempo.chargenow offers OUSD first, then USDC. We always pass an explicitcurrency, and mppx turns the singular option into a one-item list, so we still offer USDC only. A new test pins that, because nothing else would notice the default leaking in.mppx 0.12.0 also rejects a malformed Tempo currency address when the server is built. One test was passing a placeholder string and now passes a well-formed address.
The crypto deposit PaymentIntent is restricted with
allowed_payment_method_types: ['crypto']instead ofpayment_method_types. Stripe's2026-09-30.previewAPI rejectspayment_method_typeson PaymentIntent create ("no longer supported"). I checked both fields in test mode with the same crypto deposit body:payment_method_typesallowed_payment_method_types2026-03-04.preview(what the storefronts pin)2026-09-30.previewThe GA
2026-09-30.endiverejects crypto deposit mode itself, so a store must keep pinning a preview version either way. A new test pins the field.The
axiosoverride floor goes to^1.20.0.^1.18.0admitted 1.19.0, which carries advisories fixed in 1.20.0. The lock already resolved 1.20.0 here; the floor now guarantees it.Minors and patches:
@solana/kit8.4.0, hono 4.13.12,@a2a-js/sdk1.3.0, vitest and coverage 5.0.3, typescript-eslint 8.71.0, knip 6.39.0, lefthook 2.1.16, dotenv 18.0.5.Comments and keywords: the
chainoption comments no longer say "scoring", theapimodule comment no longer lists reputation, and the package keyword is dropped.Type of change
Public API
AgentScore.getReputation()disappears from the@agent-score/commerce/apire-export, by way of SDK 2.8.0. Migration: drop the call. The endpoint has returned 404 since it was retired, so no working call changes. This is versioned as a minor for that reason. Nothing else exported changes.Test plan
issues a single Tempo challenge priced in USDCbuilds a server throughcreateMppxServer, issues a real 402 throughcomposeMppxRequest, decodes the challenge, and asserts exactly one Tempo offer in USDC. With the explicit currency stripped from the source, it fails with two offers, OUSD and USDC. The source was restored before committing.bun run lint,typecheck(including examples),knip,test(1845 passed, 4 skipped, coverage thresholds met) andbuildpass locally. The OSV scan ofbun.lockis clean.Worked with Varun.
Checklist