# Reviewed, exact-version constraints for a reproducible release install.
#
# Codex#15 (round 8, 2026-09-12), reproduced exactly as reported: pyproject.toml
# declares only lower bounds (>=), not a reviewed lock or hash-pinned set - two
# clean installations at different times can resolve different dependency
# graphs, and preflight.py (and pip-audit) only ever audit whichever graph
# happened to be installed, not a specific reviewed one.
#
# Regenerate after intentionally upgrading a dependency:
#   pip install -e ".[llm,api,dev]" --upgrade
#   pip list --format=freeze | grep -v '^security-knowledge-os==' | sort > constraints.txt
# then re-run the full test suite, ruff, mypy, and pip-audit before committing.
#
# Release/CI installs should pin against this file:
#   pip install -e ".[llm,api,dev]" -c constraints.txt --build-constraint constraints.txt
#
# Codex#7 (round 12, 2026-09-13), reproduced exactly as reported: `-c` alone
# does not reach pip's ISOLATED build environment (where the `hatchling`
# build backend itself installs) - only the main install environment. This
# file already lists every dependency of the full installed environment,
# hatchling included, so passing it again as `--build-constraint` pins that
# separate environment too, with no second file to maintain.
#
# This is a reviewed, working combination as of commit generation time - not a
# hash-pinned/supply-chain-attested lock (see PyPA's pylock.toml specification
# for that stronger guarantee, out of scope for this MVP release process).
#
# Codex#9 (round 15, 2026-09-14), reproduced exactly as reported: version
# pinning alone does not authenticate package artifacts - the same
# version string can still come from an unintended index or a replaced
# artifact; `-c constraints.txt` verifies resolved VERSIONS, not hashes.
# Re-flagged, same accepted scope decision as above - no new action
# taken here beyond confirming it is still the intended, documented
# trade-off for this MVP.

annotated-doc==0.0.5
annotated-types==0.8.0
anthropic==1.5.0
anyio==4.15.1
ast_serialize==0.11.1
boolean.py==5.0
CacheControl==0.14.4
certifi==2026.7.22
charset-normalizer==3.5.1
click==8.5.0
cyclonedx-python-lib==11.12.0
defusedxml==0.7.1
docstring_parser==0.18.0
fastapi==0.141.1
filelock==3.32.6
h11==0.16.0
hatchling==1.32.0
httpcore==1.0.9
httpcore2==2.12.0
httpx==0.28.1
httpx2==2.12.0
idna==3.19
iniconfig==2.3.0
jiter==0.16.0
librt==0.15.0
license-expression==30.4.4
markdown-it-py==4.2.0
mdurl==0.1.2
msgpack==1.2.2
mypy==2.3.1
mypy_extensions==1.1.0
packageurl-python==0.17.6
packaging==26.3
pathspec==1.1.1
pip==26.2.1
pip_api==0.0.35
pip_audit==2.10.1
pip-requirements-parser==32.0.1
platformdirs==4.11.8
pluggy==1.6.0
pydantic==2.13.5
pydantic_core==2.46.5
Pygments==2.21.0
pyparsing==3.3.2
py-serializable==2.1.0
pytest==9.1.1
PyYAML==6.0.3
requests==2.34.2
rich==15.0.0
ruff==0.16.6
sniffio==1.3.1
sortedcontainers==2.4.0
starlette==1.6.0
tomli==2.4.1
tomli_w==1.2.0
tomlkit==0.15.1
trove-classifiers==2026.6.1.19
truststore==0.10.4
types-PyYAML==6.0.12.20260906
typing_extensions==4.16.0
typing-inspection==0.4.4
urllib3==2.7.0
uvicorn==0.52.4
