Skip to content

chore(release): 0.4.31.2 — Teams Graph SSRF-guard hardening (#178) + NOTICE - #181

Merged
patrick-chinchill merged 1 commit into
mainfrom
chore/release-0.4.31.2
Sep 2, 2026
Merged

patrick-chinchill merged 1 commit into
mainfrom
chore/release-0.4.31.2

Conversation

@patrick-chinchill

@patrick-chinchill patrick-chinchill commented Sep 2, 2026 •

Copy link
Copy Markdown
Collaborator

Cuts 0.4.31.2: the three commits sitting unreleased on main since v0.4.31.1 — the #178 Teams Graph SSRF/token-leak guard hardening (security), the #180 test-fixture fix, and the #179 NOTICE. UPSTREAM_PARITY unchanged at 4.31.0; release-commit shape mirrors 0.4.31.1 (pyproject, README status, CLAUDE.md version list, CHANGELOG).

After merge: gh release create v0.4.31.2 → publish.yml (trusted publishing) → PyPI, then the chat-sdk==0.4.31.2 pin bump in chinchill-api.

https://claude.ai/code/session_01AxCf56kzyzW2AhTDoSc3wa

Summary by CodeRabbit

  • Bug Fixes

    • Strengthened Teams Graph request validation to block potential SSRF and token-leak scenarios, including mixed-case and scheme-relative URLs.
    • Updated authentication test coverage to remain compatible with the SDK’s renamed configuration flag.
  • Documentation

    • Updated the displayed project version to 0.4.31.2.
    • Added release notes describing the security hardening and related changes.

…NOTICE

Python-only fixes on top of 4.31.0 (UPSTREAM_PARITY unchanged): the #178
security fix, the #180 test-fixture fix and the #179 NOTICE. Mirrors the
0.4.31.1 release-commit shape (pyproject, README status line, CLAUDE.md
version list, CHANGELOG).

Claude-Session: https://claude.ai/code/session_01AxCf56kzyzW2AhTDoSc3wa
@coderabbitai

coderabbitai Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Team

Run ID: 82f9b8dc-aac6-49cf-ac70-2d8a57448003

📥 Commits

Reviewing files that changed from the base of the PR and between c55e5a4 and 76b83df.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • CLAUDE.md
  • README.md
  • pyproject.toml

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The project version changed to 0.4.31.2. The README, version mapping, and changelog now reference the release. The upstream parity target remains 4.31.0.

Changes

Release metadata

Layer / File(s) Summary
Version and release documentation
pyproject.toml, README.md, CLAUDE.md, CHANGELOG.md
The package version and project references changed to 0.4.31.2. The changelog records the Teams Graph security fix, the test-only fixture update, and the NOTICE reference.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to 76b83

This release updates the package version and related release documentation without introducing a concrete correctness, security, availability, or deployment risk; no actionable merge-blocking risk remains after normal checks and review.

Poem

A rabbit stamps the version line
The changelog shines in neat design
The README hops to match the tune
The parity target stays at noon
Release carrots now align

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the 0.4.31.2 release and its primary changes: Teams Graph SSRF-guard hardening and the NOTICE update.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (4 skipped: 4 unsupported.)


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@patrick-chinchill

Copy link
Copy Markdown
Collaborator Author

Merge gate: CI green (Lint & Type Check, Tests); local Codex review (no AI-review workflows in this repo): APPROVE.

🤖 Codex Code Review

Summary

The exact origin/main...HEAD diff contains only release metadata/documentation updates. No blocking issues found after review.

Findings

HIGH: None
MEDIUM: None
LOW: None

The requested dependency, TemplateResponse, security.yaml, NOTICE, source, and lockfile changes are not part of this PR diff. uv.lock has no delta.

Verification Performed

  • Ran both mandated git diff commands and the lockfile scan.
  • Read all four changed files with surrounding context.
  • Did not run the app, uvicorn, pytest, or dynamic checks.
  • Review guidance files referenced by the skill were absent in this checkout.

Verdict

APPROVE

@patrick-chinchill
patrick-chinchill merged commit 9459dba into main Sep 2, 2026
7 checks passed
@patrick-chinchill
patrick-chinchill deleted the chore/release-0.4.31.2 branch September 2, 2026 19:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant