Repository navigation
styxx 7.49.0 — security repair: capsule verify compares the whole certificate (GHSA-3g8h-qcfm-25xw); the diff gate withholds verdicts its known defects can make wrong
Latestpip install -U styxx==7.49.0Security release. Advisory: GHSA-3g8h-qcfm-25xw (moderate). Upgrade if you check OATH capsules someone else made with python -m styxx.capsule verify, and check them with 7.49.0 whatever version a capsule's page names.
The section below is the [7.49.0] summary from CHANGELOG.md, where every line traces to a full entry or, under "Cutting this release", to the commit it names. The entries themselves (eight carried from [Unreleased], and one written at the cut) follow it in the file.
A minor release: a security repair to how python -m styxx.capsule verify checks a v0.1 OATH
capsule, the diff gate's PATH-2a overlay, the GitHub Action's new default, and what else merged on
main after 7.48.1. Upgrade with pip install -U styxx==7.49.0. For anyone who verifies capsules
made by someone else, upgrading is the fix. The entries headed [Unreleased] until this cut are
kept whole below, in the order this file carried them; entries written at this cut say so in their
opening line.
Security: capsule verification (GHSA-3g8h-qcfm-25xw)
- Layer 2 of a v0.1 capsule,
python -m styxx.capsule verify, re-runscertifyon the embedded
document and receipts. Before this release it checked the document and receipt hashes and
compared only the verdict (from 7.48.0 by class, its, N uncoveredsuffix stripped), the counts
and the status of each ledger row the certificate carries, and it read the payload by text
without checking the page around it, so a
capsule whose certificate was edited to say what its bytes do not verified. Run at this cut from
the v7.47.0, v7.48.0 and v7.48.1 tag trees, each over capsules it minted itself: a certificate
edited to report 0 uncovered (the D1 forgery), a deleted ledger row, a row'sreceipt_ref
pointed at another receipt, a row's epistemics flag flipped, and a genuine payload hidden in an
HTML comment ahead of one whose document reads otherwise all verify under 7.48.0 and 7.48.1.
7.47.0's certify writes no uncovered band, so D1 has nothing to edit in its own capsules; 7.47.0
verifies the other four, and verifies D1 applied to a capsule a later styxx minted, whose honest
form it fails. 7.49.0 fails every one of them. Affected: 7.47.0, 7.48.0 and 7.48.1. - Not closed, by the operator's decision: 7.49.0 still accepts the page every styxx rendered before
it, since honest capsules carry it. Around that page, the D1 forgery posed as older than the
uncovered band (the band fields and the receipt binding deleted, another issuer's hash) exits 0,
and 7.49.0 prints the installed verifier's verdict beside the embedded one, six NOT CHECKED lines
and three advisories, one naming the number nothing checked and one saying every styxx below
7.49.0 passes forgeries 7.49.0 fails. Around the page 7.49.0 mints, the same pose fails. The older
page tells its reader to pip install the payload'sverifier.pip, which the minter chooses, and
7.47.0, 7.48.0 and 7.48.1 each pass this pose around either page. - Until you can upgrade: an exit 0 from 7.47.0, 7.48.0 or 7.48.1 says only that the payload it read,
which need not be the one a browser draws, carries bytes matching its certificate's hashes, and
that the verdict (by class in 7.48.0 and 7.48.1), the counts and the status of each row the
certificate carries reproduce. To rely on a document's numbers, certify the document and receipts
you mean to rely on yourself (python -m styxx.certify DOC RECEIPTS...) and read that
certificate, not the capsule's or its page.
For users of the diff gate (python -m styxx.diffgate, gate_diff_text, gate_diff, the
commit-msg and agent hooks)
- PATH-2a: where the #97, #121 or #101 mechanism can have made a VERIFIED or CONTRADICTED verdict
wrong, the claim is now UNCHECKABLE, and its reason names the verdict withheld, the defect and the
reading without the overlay. The overlay never adds an accusation and never makes a verdict
VERIFIED; the three defects are not repaired. On the lab's committed corpora it withholds 80 of
2,231 decided claims (3.6%; entry below).--strictfails on each new abstention, as on any
UNCHECKABLE. - A contradicted claim is printed as
[CONTRADICTED]with its reason, not as[LIE], in the demo,
the hooks and the bookmarklet, and the demo's closing line says how many claims the diff
contradicts. Records, verdicts and exit codes are unchanged.
For users of the GitHub Action (uses: fathom-lab/styxx@...)
- It reports by default.
soft-faildefaults to"true": every verdict goes in the job summary,
each contradicted claim is named in an annotation, and the gate's verdicts never fail the job.
Only an explicitsoft-fail: "false"blocks. A workflow on@mainhas run with this default
since it merged; the reasons and figures are in the entry below. - The Action imports the
styxxpackage beside its script, at the ref the workflow names, not the
one pip installs, so@mainand a workflow pinned to this release's tag both run PATH-2a.
For users who verify capsules, beyond the security repair: verify compares every field
certify writes, type for type, and prints by name each field an older certificate lacks
(NOT CHECKED), the fields it takes as stated by the minter, and every advisory; it escapes control
characters in what it prints; a sweep of 600 malformed single-field mutations now ends in a
problem, not a traceback, and in styxx.charon in an UNRESOLVED or not-reproduced line (two
classes a review found still end verify in a traceback, so #196 stays open). A newly minted
page shows a verdict only after its hashes match, and its install line names
styxx>=7.49.0, not the minter's version. A capsule of a renamed copy now fails, and
capsule create refuses some certificates older styxx issued (re-certify, then mint). All ten
committed v0.1 capsules still verify, each with an advisory that it states a styxx below 7.49.0.
The v0.2 and sworn pages' install lines are not repaired.
What did not change. styxx/certify.py, styxx/sworn.py and styxx/corpus_audit.py are the
files 7.48.1 shipped, so certify, sworn and corpus_audit read as they did. Outside the PATH-2a block
and the printed label the diff gate reads as 7.48.1 did, and the path accusation stays withheld.
Nothing in a capsule is signed.
Also in this release
- Priority sentences that no survey priced are withdrawn from docstrings and printed strings in the
package and from the docs, and the prior art is credited with dates (entry below). - In the repository, not the wheel:
SECURITY.mdsends reports through GitHub private
vulnerability reporting instead of an email address the lab cannot confirm receives mail;
7.48.1's Zenodo record (10.5281/zenodo.23200977); andweb/gate/README.md's run-book pin, held
topy_side.pyby a test.
Cutting this release
styxx/_version.pyis 7.49.0 (3e8722c), the floor the capsule page names for layer 2
(_LAYER2_FLOORandconst FLOORinstyxx/capsule.py), andCITATION.cffgivesversion
7.49.0 anddate-released2026-10-07 (25d3554).conformance/sworn/was regenerated for the version stamp (3e8722c; entry below): 15 vectors
took new ids, 0 moved, and no expected outcome changed.README.md, which becomes the PyPI page, was audited at this cut against the tree it ships with.
Its 89 tag-pinned links now name v7.49.0 instead of v7.48.0 (0a4c479), on the same lines, so
zenodo/MANIFEST.json's line citations hold; no other line changed.web/gate/README.mdsaid PATH-2a was not released; it now says 7.49.0 ships it (7a418e2).
Integrity
| file | sha256 |
|---|---|
styxx-7.49.0-py3-none-any.whl |
272f5cb384088888ede45044a4d51f24e81001278148f4555e3045440c22d01b |
styxx-7.49.0.tar.gz |
a45e74c20766d952830c6f7eda7d5d4f220c8626632e58b4def29d742f13e9e2 |
Built by publish.yml on Ubuntu from tag v7.49.0 (commit c6e00da02673ec6a2e84919f17f56a2e4435a8c9), uploaded to PyPI, and attached here. Checked on 2026-10-07:
- both files as published on PyPI have these hashes, and so do the assets on this page;
- a clean virtual environment installing
styxx==7.49.0from PyPI reports 7.49.0; - that install verifies a committed capsule from
papers/, printing its NOT CHECKED lines; - around a page it mints, it fails every forgery in the advisory's table (the D1 edit, a deleted ledger row, a repointed
receipt_ref, a flipped epistemics flag, the decoy payload) and the D1 forgery posed as older than the uncovered band; around the older page it fails every one of those but the pose, which it passes with six NOT CHECKED lines, as the advisory says; python -m styxx.diffgate --demoprints CONTRADICTED and no LIE.
The upload used an API token, so there are no PEP 740 attestations; check these hashes instead (see SECURITY.md).
Archived on Zenodo as 10.5281/zenodo.23221755, the next version of the styxx software record (concept 10.5281/zenodo.19758618), with the source bundle of this tag, the wheel and the sdist.
🤖 Release prepared with Claude Code