Repository navigation
Expand file tree
/
Copy pathpyproject.toml
More file actions
168 lines (158 loc) · 7.34 KB
/
Copy pathpyproject.toml
File metadata and controls
168 lines (158 loc) · 7.34 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
# Copyright 2026 Visa, Inc.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
[build-system]
requires = ["setuptools>=84.0.0,<85"]
build-backend = "setuptools.build_meta"
[project]
name = "vvaharness"
version = "1.5.0"
description = "Visa's open-source harness for autonomous vulnerability discovery and validation, using large language models"
readme = "README.md"
requires-python = ">=3.11"
license = "Apache-2.0"
dependencies = [
"pydantic>=2.13.5,<3",
"pydantic-settings>=2.15.0,<3",
"PyYAML>=6.0.3,<7",
# anthropic 1.0 removed temperature/top_p/top_k from messages.create/stream's
# typed kwargs (client-side TypeError if passed top-level) -- the HTTP API
# itself still honours them via extra_body, which is the officially
# documented path. backends/llm/sdk.py routes temperature through
# extra_body for this reason; its reactive 400-handler (a model rejecting
# the value server-side) only ever saw a live request once that fix landed.
"anthropic>=1.11.0,<2.0",
"openai>=3.22.1,<4",
"httpx>=0.28.1,<1",
# Declared explicitly because anthropic>=1 and openai>=3 are backed by
# httpx2; also imported directly by backends/llm/sdk.py and
# deepagents/options/model_building.py for create_ssl_context.
"httpx2>=2.13.1,<3",
"urllib3>=2.8.0,<3",
"python-dotenv>=1.2.4,<2",
# util/logs.py: one processor chain, key-value to a terminal and JSON to --log-file.
"structlog>=25.1.0,<27",
# cli/_app.py: command dispatch and help; handlers keep their own parsers.
"typer>=0.15.0,<1",
# util/console.py: the product's status tables and banners.
"rich>=13.9.0,<15",
"typing_extensions>=4.16.0,<5",
"claude-agent-sdk>=0.2.163,<0.3",
# Pinned to what context-graph-sdk conformance-tested its bundled queries
# against. The vendored SDK (vendor/context_graph_sdk) is packaged into
# this wheel rather than installed as a separate distribution, so its
# runtime dependencies -- including these two grammar packages -- are
# restated here; tests/test_packaging.py keeps every restated pin equal
# to vendor/context_graph_sdk/pyproject.toml, one source of truth.
"tree-sitter==0.25.2",
"tree-sitter-language-pack==1.15.8",
"arcadedb-embedded==26.10.1",
"tree-sitter-go==0.25.0",
"tree-sitter-python==0.25.0",
"tree-sitter-javascript==0.25.0",
"tree-sitter-typescript==0.23.2",
"tree-sitter-java==0.23.5",
"tree-sitter-c-sharp==0.23.5",
"tree-sitter-scala==0.26.2",
"tree-sitter-c==0.24.2",
"tree-sitter-cpp==0.23.4",
"tree-sitter-rust==0.24.2",
"tree-sitter-ruby==0.23.1",
"tree-sitter-php==0.24.1",
"tree-sitter-swift==0.7.3",
"tree-sitter-dart==0.1.0",
"tree-sitter-solidity==1.2.13",
# Keep the marker aligned with DeepAgents' own floor. The project-level
# requires-python >=3.11 means supported installs always include it.
"deepagents>=0.7.21,<0.8; python_version >= '3.11'",
"langchain>=1.4.3,<2",
# Floor is load-bearing twice: pre-1.7.0 releases conflict with the anthropic
# pin above, and every allowed version has the tool_result cache_control hoist
# (upstream since 1.3.4) that our deepagents tool-result markers depend on.
"langchain-anthropic>=1.7.5,<2",
"langchain-openai>=1.6.7,<2",
"langgraph>=1.2.12,<2",
]
[project.optional-dependencies]
# Dev tooling: `pip install '.[dev]'` to run the test suite + the static
# undefined-name gate (pyflakes).
dev = ["pytest>=9.1.1,<10", "pyflakes>=4.0.1,<5", "ruff>=0.16.9,<0.17", "pyright>=1.1.414,<2",
"jsonschema>=4.26.0,<5"] # SARIF 2.1.0 schema-compliance test
[project.scripts]
vvaharness = "vvaharness.cli:main"
[tool.setuptools.packages.find]
where = [".", "vendor/context_graph_sdk/src"]
include = ["vvaharness*", "context_graph_sdk*"]
[tool.setuptools.package-data]
context_graph_sdk = ["py.typed", "extractors/queries/*.scm"]
vvaharness = [
"py.typed",
"config/profiles/*.yaml",
"exploit_verification/payloads/templates/*.yaml",
# Explicit allowlist — do NOT use a broad rules/*.yaml glob. Org-specific
# overlays (e.g. *.kb.yaml harvested from internal reviews) must live
# OUTSIDE the package and be referenced by path, never packaged. See
# vvaharness/rules/__init__.py and rules/README.md.
"rules/generic.kb.yaml",
"rules/README.md",
"sdk/README.md",
"validation/hints/*.yaml",
"validation/prompts/*.md",
"validation/subagents/*.md",
"validation/claude_config/**/*",
# The detection lenses. Absent from this allowlist, EVERY installed build
# shipped an empty `skills/` holding only its `__init__.py`, so
# `skills.skill_names()` returned `()` and skill injection was a silent
# no-op -- while `s4/prompts.py` still told the model all 17 lenses were
# readable at `.vvaharness/skills/<name>/SKILL.md`. Only a run from a source
# checkout had them. Enumerated by file rather than as `skills/**/*` so
# `__pycache__` stays out; `test_packaging.py` fails if a new skill asset
# extension appears without a pattern here.
"skills/*/SKILL.md",
"skills/*/probe.sh",
]
# These files intentionally remain canonical under the repository-level
# ``inputs/`` directory. Install them into a stable shared-data location so a
# non-editable wheel does not lose the fail-closed remediation rules.
[tool.setuptools.data-files]
"share/vvaharness/rules" = [
"inputs/remediation_policy.yaml",
"inputs/remediation_playbook.yaml",
]
# vvaharness ships production modules named test_*.py (fact tools the agent calls);
# without this pytest scrapes them from the repo root and errors on them.
[tool.pytest.ini_options]
testpaths = ["tests"]
# Lint gate: per-package ``ruff.toml`` files, one per package held to the standard
# (``vvaharness/validation/ruff.toml`` was the first, ``vvaharness/backends/harness/``
# the second). Deliberately NOT configured here: a root ``[tool.ruff]`` would become the
# nearest config for every legacy package too, and those report ~219 findings that no
# single change should be sweeping.
# Typing gate. Scoped to the packages held to this standard; the rest of the
# tree predates it. venvPath/venv are load-bearing -- without them pyright
# resolves no langchain/langgraph/deepagents and reports 17 phantom
# reportMissingImports for packages that are in fact installed.
[tool.pyright]
include = ["vvaharness/validation", "vvaharness/backends/harness", "vvaharness/models",
"vvaharness/remediation_agent", "vvaharness/detect", "vvaharness/codegraph",
"vvaharness/api.py",
"vvaharness/orchestrator/artifacts.py", "vvaharness/orchestrator/case_ids.py",
"vvaharness/orchestrator/findings_json.py",
"vvaharness/util/pricing.py", "vvaharness/util/stage_telemetry.py"]
venvPath = "."
venv = ".venv"
pythonVersion = "3.11"
typeCheckingMode = "standard"
reportMissingImports = true
reportMissingTypeStubs = false
reportPrivateUsage = false