Repository navigation
OpenHands: owner delta review of draft PR 535 at head 7c0df369 (lock 83293867: urllib3 2.8.0, PyJWT 2.15.0), artifact-only record - #558
Merged
Conversation
…3293867, urllib3 2.8.0 and PyJWT 2.15.0): artifact-only record Adds evidence/artifacts/openhands-oauthlib-review-535-head7c0df3-20260930/ (README, receipt.json with claims D1-D11, findings and residuals, 15 check outputs, 3 scanner JSON files without advisory prose, the scripts as run). The lock is byte-identical to an independent prediction (the previously reviewed lock with only the urllib3 and pyjwt entries substituted from PyPI hashes); the closure differs from the reviewed lock in exactly those two entries; hashed installs, the OAuthlib sweep, the pinned OSV-Scanner and the workflow's own scan step at the head, the receipt's 62 artifact and 53 command bindings and the repository's own checks all pass. Two P2 findings (a stale workflow binding in the requested receipt; the category of four excluded compile-input captures) need no change to the lock. No code, workflow, config or lock changes; approves no merge, exception, pin or promotion. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
4 of 7 tasks
seathatflowsinourveins
deleted the
res-ohrev-535-head7c0df3-20260930
branch
September 30, 2026 20:28
5 of 7 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope
evidence/artifacts/openhands-oauthlib-review-535-head7c0df3-20260930/, of the owner delta review of draft PR Qualify native runtime recipes and repair Sol routing and grader FTP dependency #535 at its head7c0df369(lock sha25683293867..., Linux x86_64 CPython 3.13.15): the OpenHands SDK 1.50.0 lock relocked onto urllib3 2.8.0 and PyJWT 2.15.0, reviewed against the lock of the earlier record (6a7b16, OpenHands: independent OAuthlib reachability review of draft PR 535 at its corrected head 6a7b1646 (candidate lock 383ccc5b), artifacts only #537). No code, workflow, config or lock changes.8fc86119eacfd5be9b8a139e1ed167d85748091blane:foundationevidence/artifacts/openhands-oauthlib-review-535-head7c0df3-20260930/(new, 32 files),manifests/evidence.json(registration only).SOTA sources
evidence/artifacts/openhands-oauthlib-review-535-head6a7b16-20260930/, merged in OpenHands: independent OAuthlib reachability review of draft PR 535 at its corrected head 6a7b1646 (candidate lock 383ccc5b), artifacts only #537) plus checks of this delta: the pinned OSV-Scanner 2.6.0 (https://github.com/google/osv-scanner/releases/tag/v2.6.0, binary sha256ca69b3d3...), uv 0.12.17 hashed installs, the PyPI release metadata of urllib3 2.8.0 and PyJWT 2.15.0 (https://pypi.org/project/urllib3/2.8.0/, https://pypi.org/project/PyJWT/2.15.0/), the PyJWT 2.15.0 sdist and tag (https://github.com/jpadilla/pyjwt/releases/tag/2.15.0), and the OpenHands software-agent-sdk archive at commitdcf401af7a9a302ef92cb7d092e1df9bb659daa5(https://github.com/OpenHands/software-agent-sdk/tree/dcf401af7a9a302ef92cb7d092e1df9bb659daa5), whose sha256 and uv.lock hash are recomputed in the record.Evidence-class table
source_review,our_integration_checkchecks/pr535-identity.txt,checks/prediction.txt(claims D1, D2)our_integration_checkchecks/closure-diff-*.txt(D2)uv pip checkand the SDK import check pass in a fresh CPython 3.13.15 venvour_integration_checkchecks/install-log.txt(D3)our_integration_check(static)checks/independent-scan.txt,checks/pyjwt-surface.txt(D4, D5)our_integration_checkchecks/osv-*.txt,checks/osv-*.json(D6, D7)our_integration_checkchecks/receipt-bindings.txt,checks/external-hashes.txt(D8, D9)validate.py,evidence_manifest.py --check)our_integration_checkchecks/repo-checks-at-head.txt(D10)Findings recorded (no change to the lock needed): P2-1 the receipt's
bound_filesentry forsecurity-scan.ymlrecords the pre-#546 workflow; P2-2 four frozen compile-input captures are listed underexcludedalthough the inventory rule names only deliberately vulnerable test fixtures. Not covered: the other workers' locks and their nltk allowances, hosted CI of the head, image, trusted observer and task quality (the record approves none of them).Local commands run
Decision record
None needed: an artifact-only record. The decision paragraph "urllib3 and PyJWT relock and a frozen macOS lock (2026-09-30)" of
docs/decisions/2026-09-22-github-automation-closure.md(merged in #546) covers the lock lane.Checklist
detailsprose is removed from the scanner JSON.🤖 Generated with Claude Code