Skip to content

fix(release): update stable SDK 8 to AdCP 3.2.3 #1427

Description

@bokelley

The stable SDK 8 line on release/8.x embeds AdCP 3.2.1. Update it to the signed AdCP 3.2.3 maintenance release after that protocol release publishes.

The audited-release pin checker currently accepts only the upstream main certificate identity, so it rejects stable 3.2 bundles signed by release.yml@refs/heads/3.2.x. Permit that exact identity only for stable 3.2 pins, retain exact audited URLs/digests and Sigstore transparency verification, and add tests rejecting unrelated branches and mismatched release lines.

After publication, audit the protocol tag and signed tuple, add the reviewed 3.2.3 release pin, regenerate the schema/model/compliance assets, validate wheel/sdist inclusion and compatibility, and use the existing stable Release Please/PyPI flow. Keep Python 9 on its separate beta line.

Work is already in progress; no-triage avoids a duplicate implementation.

Activity

  1. added
    no-triageSkip the Claude triage bot — human or designated agent will handle this issue
    claude-triagingTriage routine is actively working on this issue (1-3 min)
    on Oct 6, 2026
  2. bokelley commented on Oct 6, 2026

    @bokelley
    ContributorAuthor

    Triage

    Classification: Bug / maintenance release
    Bucket(s): signing, validation
    Status: deferred

    My take: PR #1429 ("fix(release): verify audited stable 3.2 maintenance bundles") by @bokelley already references this issue and covers the described work — pin checker identity expansion for stable 3.2 bundles, audited URL/digest/Sigstore verification, and the 3.2.3 schema/model regeneration. The no-triage label was set at creation to prevent duplicate implementation.

    Blocked-on: #1429 — resurfaces on merge


    Triaged by Claude Code. Session: https://claude.ai/code/session_01SFPAFXNWUZZbQnaBv1GcKN


    Generated by Claude Code

  3. added and removed
    claude-triagingTriage routine is actively working on this issue (1-3 min)
    on Oct 6, 2026
  4. bokelley commented on Oct 8, 2026

    @bokelley
    ContributorAuthor

    Implemented in #1429 and published in Python SDK 8.1.1. The stable 8.x line now adopts the signed AdCP 3.2.3 maintenance bundle, its exact 3.2.x workflow identity, and all 33 operation-resolution vectors.

    Closing as completed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    claude-triagedno-triageSkip the Claude triage bot — human or designated agent will handle this issue

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions