Skip to content

Take sdk 2.8.0 and the coupled set, release 2.15.0 - #140

Merged
vvillait88 merged 2 commits into
mainfrom
sweep/2026-10-02
Oct 2, 2026
Merged

vvillait88 merged 2 commits into
mainfrom
sweep/2026-10-02

Conversation

@vvillait88

@vvillait88 vvillait88 commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Dependency sweep and the reputation cleanup, released as 2.15.0.

  • @agent-score/sdk ^2.8.0. The SDK dropped getReputation() because GET /v1/reputation was retired on 2026-09-30. @agent-score/commerce/api re-exports the SDK's AgentScore client, so that method leaves this package's surface too.

  • The coupled settle set's verifier side: mppx 0.12.0, viem 2.57.2, and @x402/core, @x402/evm, @x402/extensions 2.28.0, all exact.

    • The Tempo proof domain stays at version 3.
    • x402 2.28.0's core dist is byte-identical to 2.27.0. Its evm change only adds Monad testnet and Arc USDC entries; Base is untouched.
  • mppx 0.12.0 changes Tempo's defaults. An unconfigured tempo.charge now offers OUSD first, then USDC. We always pass an explicit currency, and mppx turns the singular option into a one-item list, so we still offer USDC only. A new test pins that, because nothing else would notice the default leaking in.

  • mppx 0.12.0 also rejects a malformed Tempo currency address when the server is built. One test was passing a placeholder string and now passes a well-formed address.

  • The crypto deposit PaymentIntent is restricted with allowed_payment_method_types: ['crypto'] instead of payment_method_types. Stripe's 2026-09-30.preview API rejects payment_method_types on PaymentIntent create ("no longer supported"). I checked both fields in test mode with the same crypto deposit body:

    API version payment_method_types allowed_payment_method_types
    2026-03-04.preview (what the storefronts pin) accepted accepted
    2026-09-30.preview rejected accepted

    The GA 2026-09-30.endive rejects crypto deposit mode itself, so a store must keep pinning a preview version either way. A new test pins the field.

  • The axios override floor goes to ^1.20.0. ^1.18.0 admitted 1.19.0, which carries advisories fixed in 1.20.0. The lock already resolved 1.20.0 here; the floor now guarantees it.

  • Minors and patches: @solana/kit 8.4.0, hono 4.13.12, @a2a-js/sdk 1.3.0, vitest and coverage 5.0.3, typescript-eslint 8.71.0, knip 6.39.0, lefthook 2.1.16, dotenv 18.0.5.

  • Comments and keywords: the chain option comments no longer say "scoring", the api module comment no longer lists reputation, and the package keyword is dropped.

Type of change

  • Bug fix (no breaking change)
  • New feature (no breaking change)
  • Breaking change (existing callers must update)
  • Docs, tests, or internal maintenance only

Public API

AgentScore.getReputation() disappears from the @agent-score/commerce/api re-export, by way of SDK 2.8.0. Migration: drop the call. The endpoint has returned 404 since it was retired, so no working call changes. This is versioned as a minor for that reason. Nothing else exported changes.

Test plan

  • New: issues a single Tempo challenge priced in USDC builds a server through createMppxServer, issues a real 402 through composeMppxRequest, decodes the challenge, and asserts exactly one Tempo offer in USDC. With the explicit currency stripped from the source, it fails with two offers, OUSD and USDC. The source was restored before committing.
  • bun run lint, typecheck (including examples), knip, test (1845 passed, 4 skipped, coverage thresholds met) and build pass locally. The OSV scan of bun.lock is clean.
  • The live settle on Tempo, Solana and Base, gated and ungated, runs against a storefront once the storefronts take this release and the matching pay release.

Worked with Varun.

Checklist

  • Tests cover the new behavior, and the suite passes locally
  • Lint, format, and type checks pass
  • Docs and README examples updated if the public surface changed
  • No secrets, credentials, or personal data in the diff or the tests

…15.0

mppx 0.12.0 defaults an unconfigured Tempo offer to OUSD first; the
rail passes an explicit USDC currency, and a test now pins that the
challenge offers USDC alone. The sdk move drops getReputation from the
api re-export, since /v1/reputation was retired.
Stripe's 2026-09-30.preview API rejects payment_method_types on
PaymentIntent create; allowed_payment_method_types is accepted there and
on the 2026-03-04.preview the storefronts pin today (both checked in
test mode).
@vvillait88
vvillait88 merged commit 1aa0e21 into main Oct 2, 2026
6 checks passed
@vvillait88
vvillait88 deleted the sweep/2026-10-02 branch October 2, 2026 18:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant