Repository navigation
OpenHands: independent OAuthlib reachability review of draft PR 535 (head bb3d00dc, candidate lock 8d257833), artifacts only - #536
Merged
Conversation
…head bb3d00d, candidate lock 8d257833), artifacts only Publishes the already-run review as sanitized artifacts, at Codex's request: identity of the head and the lock, the hashed installs reproduced in a fresh CPython 3.13.15 environment, an independent metadata and raw-text OAuthlib sweep (no server-side or advisory class outside oauthlib; requests-oauthlib the only consumer), the advisory files against the candidate's recorded hashes, OSV-Scanner 2.6.0 in CI form (exit 0), the empty-config control (exit 1, exactly the two oauthlib ids) and the closure difference against the PR base's lock (159 macOS packages removed; click, pypdf, soupsieve lowered without a forcing dependency). A historical scoped proof for that exact head and lock, Linux x86_64 and CPython 3.13.15 only; it approves no merge, exception, pin or promotion. Only manifests/evidence.json is touched outside the new directory (registration). Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
seathatflowsinourveins
deleted the
res-oh-oauthlib-review-535-20260930
branch
September 30, 2026 09:37
This was referenced Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope
bb3d00dc1ed493726481d0d3d746f6b0b46ed8bd(basef03f41c7f3601532b8635f8f112a3d2731454375) for its candidate lock, sha2568d257833a90ad4096858d108a427e908a54850dee24d1036d37bd7b5e5d86676(OpenHands SDK 1.50.0, Linux x86_64, CPython 3.13.15). It was requested and accepted by the Codex coordinator ("Codex will cite exact paths and hashes from your PR"). Contents: head and lock identity, the reproduced hashed installs, an independent metadata and raw-text sweep, the advisory files against the candidate's recorded hashes, OSV-Scanner 2.6.0 in CI form and the empty-config control, the closure difference against the PR base's lock, what constrains the three lowered packages, the commands as typed, the scripts as run,receipt.json(claims, findings, controls, residuals).f03f41c7f3601532b8635f8f112a3d2731454375(main).lane:foundation. The only file outside the new directory ismanifests/evidence.json(registration through the hot-file protocol,docs/lanes.md); no shared file's text changes.evidence/artifacts/openhands-oauthlib-review-535-20260930/,manifests/evidence.json.SOTA sources
ca69b3d3cd08f889a49dc0a383122f71cc528b83803671df5fd874d97485b108(the pin in.github/workflows/security-scan.yml), advisories GHSA-hj66-6f7g-4r5v and GHSA-xpv3-w29h-x7cv (oauthlib 3.3.1, fixed in 4.0.0).oauth2/rfc6749/endpoints/revocation.pyandoauth2/rfc6749/grant_types/authorization_code.py, compared byte for byte with the hashes in the candidate's own callers output.uv pip install --require-hashes, uv 0.12.17) and the maintained callers-scan method it adapts,blueprints/runtime-workers/openhands/evidence/relock-2026-09-30.jwt-callers.py.txt(PyJWT relock record: redis decode search (D1), timing range from the outputs (D2), honest output labels #529).Evidence-class table
pins.json, the exact-lock test entry and the evidence file agree; the OSV config gains only comment linessource_reviewchecks/pr535-identity.txtlocal_integrationchecks/install-log.txtlocal_integration(static; not a runtime trace)checks/independent-scan.txtlocal_integrationchecks/advisory-files-and-helper.txtlocal_integrationchecks/osv-*local_integrationandsource_reviewchecks/closure-diff-base-vs-head.txt,checks/pin-sources.txtLocal commands run
The full
unittestdiscovery runs in CI'svalidatecheck.Decision record
None: this is a review record. Its findings (A: the candidate receipt's before-hash is not main's lock and the delta against main is unrecorded; B: the review covers the Linux x86_64 CPython 3.13.15 closure only) are in
receipt.json.Host evidence
This PR adds an artifact directory under
evidence/artifacts/, notevidence/hosts/.scripts/validate.py(exit 0 above) validates the registered artifacts.platform_statuschange.Checklist
🤖 Generated with Claude Code