Skip to content

SEARCH-3102 add semantic search to bdk (#374) - #402

Open
broHeryk wants to merge 14 commits into
finos:release/3.xfrom
broHeryk:SEARCH-3102-semantic-search-3x
Open

SEARCH-3102 add semantic search to bdk (#374)#402
broHeryk wants to merge 14 commits into
finos:release/3.xfrom
broHeryk:SEARCH-3102-semantic-search-3x

Conversation

@broHeryk

@broHeryk broHeryk commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator

Description

Closes SEARCH-3102

We've got ability to use semantic search instead alongside exact match search. This PR adds a method to handle it.

Dependencies

None

Checklist

  • Referenced an issue in the PR title or description
  • Filled properly the description and dependencies, if any
  • Unit tests updated or added
  • Docstrings added or updated
  • Updated the documentation in docsrc folder

@broHeryk
broHeryk changed the base branch from main to release/3.x September 1, 2026 14:20
catalinsymphony and others added 7 commits September 1, 2026 17:32
* Update packages for snyk

* Allow more types of licenses

* Upgrade packages flagged by safety check

* Add flag to skip checking dev deps

* Version increase

(cherry picked from commit f182642)
* Add MAINTAINERS.md file

Signed-off-by: Juan Estrella <juan.estrella@finos.org>

* Make maintainer email optional

Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.

Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>

* Update MAINTAINERS.md

* Pin GitHub Actions to commit SHAs and fix CVE/license scan findings

Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.

* Bump aiohttp, idna, PyJWT minimum versions to fix new CVE findings

Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.

* Add BSD-3-Clause to authorized licenses for liccheck

idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.

---------

Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Co-authored-by: Thibault Pensec <39826516+thibauult@users.noreply.github.com>
Co-authored-by: Thibault Pensec <thibault.pensec@symphony.com>
(cherry picked from commit 5480de1)
Adding @symphony-enrico to the list of maintainers

(cherry picked from commit 6541431)
* Add AI agent example wiring LangGraph + Vertex AI Gemini into a Symphony bot

Mirrors the Java BDK's bdk-ai-agent-example: any message addressed to the bot
is forwarded to a LangGraph ReAct agent backed by Gemini, with BDK-backed
tools for user lookup, room member listing, and sending messages.

* Add opsx commands and openspec skills used to author the AI agent example

* Pin GitHub Actions to commit SHAs and address CVE/license findings

Harden workflows against supply-chain tag mutation by pinning actions to
SHAs, bump cryptography to >=48.0.1 for a CVE fix, allow BSD-3-Clause
license, and add a documented safety-policy exception for CVE 96886
(fix requires urllib3 2.7.0 which drops Python 3.9 support).

* Pin upload-artifact SHA, fix aiohttp CVE coverage for PR checks

Semgrep flagged mutable actions/upload-artifact@v4 tag; safety flagged
aiohttp 3.13.5 CVEs because cve-scanning-python.yml was missing the -i
ignore flags already present in security.yml for py3.9-only findings.

(cherry picked from commit 21a0370)
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
(cherry picked from commit 34561a3)
* Raise cryptography ceiling to allow the patched 50.x

The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:

  48.0.1  CVE-2026-69247 and CVE-2026-69249
  49.0.0  CVE-2026-69247
  50.0.x  clean

Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.

This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.

Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.

  cryptography 48.0.1  560 passed, 3 skipped
  cryptography 50.0.0  560 passed, 3 skipped
  cryptography 50.0.1  560 passed, 3 skipped   (the locked version)

poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.

* Bump version to 2.11.4 to prepare a patch release

Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.

The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.

Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.

(cherry picked from commit 487ac1c)
@broHeryk
broHeryk force-pushed the SEARCH-3102-semantic-search-3x branch from 3ba4ebc to 3a439fd Compare September 1, 2026 14:36
@broHeryk broHeryk changed the title CAIP-99 Regenerate code using latest openapi generator (#374) SEARCH-3102 add semantic search to bdk (#374) Sep 1, 2026
…ates

Reconciles the lock file with the dependency changes cherry-picked from
finos/main (finos#381 snyk updates, finos#399 cryptography ceiling) on top of the
3.x pydantic/aiohttp-retry additions.
@broHeryk
broHeryk force-pushed the SEARCH-3102-semantic-search-3x branch from 13c3b1d to ac7a29e Compare September 2, 2026 08:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants