Skip to content

release: resolve v0.0.6 archive, companion, and root dependency evidence (18 rows) #8172

Description

@ll7

Goal / Problem

Resolve the archive/companion/root evidence rows that cannot be admitted from simple metadata alone. This bounded issue covers exactly 18 remaining selected rows: 11 bundled/notice-sensitive rows, four companion slices, and three root/missing-observation rows. It does not decide legal rights; it makes the evidence and stop conditions explicit.

Archetype Metadata

archetype: workflow
evidence_tier: blocked
linked_policy:
  - docs/context/dependency_license_inventory.md
  - docs/context/issue_713_batch_first_issue_workflow.md
  - docs/context/artifact_evidence_vocabulary.md

Scope

Current status

The exact audit identifies 145 policy-pending selected dependency rows plus one cleared llvmlite control row. The two existing batches cover 60 rows. This issue covers the 18 rows whose primary blocker is archive notices, bundled/vendored content, companion-boundary evidence, root candidate binding, or missing ambient observation. The remaining 20 rows are the explicit rights-sensitive/CUDA set in the companion issue.

Bundled / vendored / notice-sensitive (11 rows)

Package / exact version Package ID Lock identity SHA-256 (includes exact artifact list) Frozen-lock artifacts Archive blocker
astunparse / 1.6.3
BSD
astunparse@1.6.3#0c6fc92fb8d8f4d7 0c6fc92fb8d8f4d7643f5cc248581968da64d4a16597ca9a36f74e225169ca03 2 total (1 wheel, 1 sdist)
sdist: astunparse-1.6.3.tar.gz / 5ad93a8456f0d084c3456d059fd9a92cce667963232cbf763eac3bc5b7940872
wheel: astunparse-1.6.3-py2.py3-none-any.whl / c2652417f2c8b5bb325c885ae329bdf3f86424075c4fd1a128674bc6fba4b8e8
bundled AST Unparser BSD text plus PSF section in sdist
google-pasta / 0.2.0
Apache 2.0
google-pasta@0.2.0#d39dd4596f81ced0 d39dd4596f81ced094e82e1e7fb3ea4a0ad1c31ea173defa1a6da77b9e0a6ef5 2 total (1 wheel, 1 sdist)
sdist: google-pasta-0.2.0.tar.gz / c9f2c8dfc8f96d0d5808299920721be30c9eec37f2389f28904f454565c8a16e
wheel: google_pasta-0.2.0-py3-none-any.whl / b32482794a366b5366a32c92a9a9201b107821889935a02b3e51f6b432ea84ed
counterpart/archive license path incomplete; metadata alone is insufficient
loguru / 0.7.3
OSI Approved :: MIT License
loguru@0.7.3#0922784789054631 09227847890546310877b7841d1c939aab71b9489c2fed574a9c347990407765 2 total (1 wheel, 1 sdist)
sdist: loguru-0.7.3.tar.gz / 19480589e77d47b8d85b2c827ad95d49bf31b0dcde16593892eb51dd18706eb6
wheel: loguru-0.7.3-py3-none-any.whl / 31a33c10c8e1e10422bfd431aeb5d351c7cf7fa671e3c4df004162264b28220c
counterpart/archive license path incomplete; metadata alone is insufficient
markdown-it-py / 4.2.0
OSI Approved :: MIT License
markdown-it-py@4.2.0#9e7d8b01cb11865b 9e7d8b01cb11865b8124598743b4ffba4f06a645b4c14160594e2bef017a9c0d 2 total (1 wheel, 1 sdist)
sdist: markdown_it_py-4.2.0.tar.gz / 04a21681d6fbb623de53f6f364d352309d4094dd4194040a10fd51833e418d49
wheel: markdown_it_py-4.2.0-py3-none-any.whl / 9f7ebbcd14fe59494226453aed97c1070d83f8d24b6fc3a3bcf9a38092641c4a
multiple license/notice families or adapted/third-party content
moviepy / 2.2.1
MIT License
moviepy@2.2.1#a7ef462794592f0b a7ef462794592f0b28defc5463574e31372434695a29ecbda1d99ab3436d7381 2 total (1 wheel, 1 sdist)
sdist: moviepy-2.2.1.tar.gz / c80cb56815ece94e5e3e2d361aa40070eeb30a09d23a24c4e684d03e16deacb1
wheel: moviepy-2.2.1-py3-none-any.whl / 6b56803fec2ac54b557404126ac1160e65448e03798fa282bd23e8fab3795060
sdist bundles sample media/assets; separate asset-rights review
optuna / 4.9.0
OSI Approved :: MIT License
optuna@4.9.0#91a7c6ff31f8b344 91a7c6ff31f8b344accd5a22a9e9dfffd763c7173a17f734b45bfa3152e6903f 2 total (1 wheel, 1 sdist)
sdist: optuna-4.9.0.tar.gz / b322e5cbdf1655fb84c37646c4a7a1f391de1b47806bbe222e015825d0a82b87
wheel: optuna-4.9.0-py3-none-any.whl / f52f3be6148654850c92a5860d398fd88ec6b2c84ab68d9c3d07dcff02e7afee
multiple license/notice families or adapted/third-party content
packaging / 26.0
Apache-2.0 OR BSD-2-Clause
packaging@26.0#103e7732053da82b 103e7732053da82b75b59fcfab62b3ca8616ae807fcb3f57b9577c5bdb5279a9 2 total (1 wheel, 1 sdist)
sdist: packaging-26.0.tar.gz / 00243ae351a257117b6a241061796684b084ed1c516a08c48a3f7e147a9d80b4
wheel: packaging-26.0-py3-none-any.whl / b36f1fef9334a5588b4166f8bcd26a14e521f2b55e6b9de3aaa80d3ff7a37529
multiple license/notice families or adapted/third-party content
pyopengl / 3.1.10
OSI Approved :: BSD License
pyopengl@3.1.10#41461804298aec52 41461804298aec527c7f3cecb3d0ec464b88f19f89294d3e4aaefcfdd924e2b0 2 total (1 wheel, 1 sdist)
sdist: pyopengl-3.1.10.tar.gz / c4a02d6866b54eb119c8e9b3fb04fa835a95ab802dd96607ab4cdb0012df8335
wheel: pyopengl-3.1.10-py3-none-any.whl / 794a943daced39300879e4e47bd94525280685f42dbb5a998d336cfff151d74f
wheel bundles freeglut/GLE/COPYING material
seaborn / 0.13.2
OSI Approved :: BSD License
seaborn@0.13.2#f4de17ece7296982 f4de17ece7296982d7356644c3572efccee27ca54b588e3ff748f42781f96ea2 2 total (1 wheel, 1 sdist)
sdist: seaborn-0.13.2.tar.gz / 93e60a40988f4d65e9f4885df477e2fdaff6b73a9ded434c1ab356dd57eefff7
wheel: seaborn-0.13.2-py3-none-any.whl / 636f8336facf092165e27924f223d3c62ca560b1f2bb5dff7ab7fad265361987
multiple license/notice families or adapted/third-party content
sympy / 1.14.0
BSD
sympy@1.14.0#893dd402fbf85ba3 893dd402fbf85ba3359dc755b9ecc7271c5213d85b462bc0f625255c1b79401a 2 total (1 wheel, 1 sdist)
sdist: sympy-1.14.0.tar.gz / d3d3fe8df1e5a0b42f0e7bdf50541697dbe7d23746e894990c030e2b05e72517
wheel: sympy-1.14.0-py3-none-any.whl / e091cc3e99d2141a0ba2847328f5479b05d94a6635cb96148ccb3f34671bd8f5
multiple license/notice families or adapted/third-party content
tqdm / 4.70.0
MPL-2.0 AND MIT
tqdm@4.70.0#ae8222c874c447bc ae8222c874c447bc1809e52cfe14180f579434423e6d26c734087475bc6a1a18 2 total (1 wheel, 1 sdist)
sdist: tqdm-4.70.0.tar.gz / 55b0b0dbd97462d06ebee91e4dac24ed4d4702be82b24f07e6c1d27e08cea220
wheel: tqdm-4.70.0-py3-none-any.whl / 7f585706bfddbdebf89daac705b2dfcc16890130727d3197ca62c732b4310953
metadata is MPL-2.0 AND MIT; outside simple-permissive gate

Companion slices (4 rows)

Package / exact version Package ID Lock identity SHA-256 (includes exact artifact list) Frozen-lock artifacts Companion blocker
optuna-dashboard / 0.20.0
MIT License
optuna-dashboard@0.20.0#8e0b05afb9851ee7 8e0b05afb9851ee791ad1d47302a681985536a948e738231570b1a471decd7b5 2 total (1 wheel, 1 sdist)
sdist: optuna_dashboard-0.20.0.tar.gz / 52a6da480a2500b6993c8fa61c81063b0dbe730edbd9f651c81b318393cca71d
wheel: optuna_dashboard-0.20.0-py3-none-any.whl / 7fe92a6b1ba8f1f77d29ff8a86fa09a01cd736e411e354d0c96c05cd4a86c289
companion slice intentionally deferred; review exact companion boundary
pyee / 13.0.1
MIT
pyee@13.0.1#2e463a2e907f6219 2e463a2e907f6219d8f4ac9728c2dc4e8657ac74e6c46c9e5bd6758251cefb45 2 total (1 wheel, 1 sdist)
sdist: pyee-13.0.1.tar.gz / 0b931f7c14535667ed4c7e0d531716368715e860b988770fc7eb8578d1f67fc8
wheel: pyee-13.0.1-py3-none-any.whl / af2f8fede4171ef667dfded53f96e2ed0d6e6bd7ee3bb46437f77e3b57689228
companion slice intentionally deferred; review exact companion boundary
pyvistaqt / 0.11.4
MIT
pyvistaqt@0.11.4#ad3f6774be583c31 ad3f6774be583c31e73fca084a92901db2b36a36d651ded708d305ba2fc4b015 2 total (1 wheel, 1 sdist)
sdist: pyvistaqt-0.11.4.tar.gz / b2bc92ac34e2bbd729c55fb27719684d4b518a593fce9c877621020d050b4bd5
wheel: pyvistaqt-0.11.4-py3-none-any.whl / f24b166c6835ef3100c1562b6bba411e2a79715cda7fa9f7da999169d2a125de
companion slice intentionally deferred; review exact companion boundary
qtpy / 2.4.3
MIT
qtpy@2.4.3#1e39699cb7192a75 1e39699cb7192a75685d383cada3abed98f56258be615884ca9a20f4bc914c8d 2 total (1 wheel, 1 sdist)
sdist: qtpy-2.4.3.tar.gz / db744f7832e6d3da90568ba6ccbca3ee2b3b4a890c3d6fbbc63142f6e4cdf5bb
wheel: QtPy-2.4.3-py3-none-any.whl / 72095afe13673e017946cc258b8d5da43314197b741ed2890e563cf384b51aa1
companion slice intentionally deferred; review exact companion boundary

Root / missing-observation rows (3 rows)

Package / exact version Package ID Lock identity SHA-256 (includes exact artifact list) Frozen-lock artifacts Binding blocker
robot-sf / editable
robot-sf@editable#5fcb7632e13be8eb 5fcb7632e13be8eb00de96d9a1f5a0391862dd57294a6fc6c2cd1df6a03b917a 0 total (0 wheels, 0 sdists)
full uv.lock artifact set bound by 5fcb7632e13be8eb00de96d9a1f5a0391862dd57294a6fc6c2cd1df6a03b917a
editable root; candidate-bound root tree and bundled-source GPL rights decision required
colorama / 0.4.6
OSI Approved :: BSD License
colorama@0.4.6#fdb0cee4b1d3af6c fdb0cee4b1d3af6cb2d69424c1e7ec25b5ba3147fa6dd30e943e05d79ac5d1b5 2 total (1 wheel, 1 sdist)
sdist: colorama-0.4.6.tar.gz / 08695f5cb7ed6e0531a20572697297273c47b8cae5a63ffc6d6ed5c201be6e44
wheel: colorama-0.4.6-py2.py3-none-any.whl / 4f1d9991f5acc0ca119f9d443620b77f9d6b33703e51011c16baf57afb285fc6
missing ambient metadata observation; candidate binding or reviewed exclusion required
win32-setctime / 1.2.0
MIT license
win32-setctime@1.2.0#da4e084afea9db4c da4e084afea9db4c5bbc907213d98e93517703435dc43d4a5f0c969b356936cb 2 total (1 wheel, 1 sdist)
sdist: win32_setctime-1.2.0.tar.gz / ae1fdf948f5640aae05c511ade119313fb6a30d7eabe25fef9764dca5873c4c0
wheel: win32_setctime-1.2.0-py3-none-any.whl / 95d644c4e708aba81dc3704a116d8cbc974d70b3bdb8be1d150e36be6e9d1390
missing ambient metadata observation; candidate binding or reviewed exclusion required

Evidence boundary

This is a bounded evidence queue, not a legal opinion, redistribution approval, or release approval. The classification below is triage from the exact audit and lock inputs; it does not approve any package. A reviewer must record the source URL, immutable upstream tag/commit (when available), exact archive member paths and bounded text digests, and an accept/revise/reject decision. Any missing or contradictory fact remains blocked.

The authoritative supported surface is profile all (the 12 public extras) from scripts/validation/dependency_license_profiles.v1.json, with ORCA/pyrvo2 excluded by the Option 2 decision in #8021. The canonical lock identity is uv.lock SHA-256 de2b22de6327164a9abda93f9d0a1fdb38316471f17ab6428ebc52ed7da603c6; profile manifest SHA-256 is 14e7fb3dd4b9364f0edcca160157eb503611d50d3708fc578eb8db640cac8b13; policy SHA-256 is a2b481eefb91e9a9813d54800304c9c0abf153f437e98ce3d87a5f408662ef30. The current origin/main checked for this triage is 1f2d789898aa9d5bab047b0d95508267d66e09c1; these three canonical input hashes match the 2026-09-01 audit at c5254f5f243b2fa489b28910b332bc77ab893dcd.

Each row's full lock identity SHA-256 commits the exact package name/version/source, resolution markers, and every frozen artifact filename, URL, size, platform tag, and SHA-256. For rows with more than two artifacts the table keeps the exact digest and count compact; the acceptance receipt must expand every artifact pair and fail on any added, missing, or changed artifact. For one/two-artifact rows the filename/hash pair is shown inline.

Shared prerequisites and stop rules

  • Produce a current sanitized candidate bundle and bind the exact package identities, provenance, manifest, and SBOM before any row can be admitted.
  • Re-run the strict candidate-bound profile-all inventory on the same immutable candidate; do not reuse the historical c525 audit as release evidence.
  • Require an independent reviewer, exact evidence digest, review date, profile all binding, and exact name/version/artifact hashes for every accepted row. No wildcard, metadata-only, or package-name-only admission is valid.
  • If uv.lock, profile/policy hashes, candidate identity, archive/source identity, or row artifact set changes, stop and re-audit the affected rows.
  • Keep the global strict report blocked until all selected rows are resolved; any unresolved, fallback, or degraded result is not release evidence.
  • Update release: define supported v0.0.6 dependencies and the ORCA companion boundary #8021 with the receipt and final row accounting; release: publish a sanitized Robot SF v0.0.6 software package #8017 remains blocked until the full gate passes.

Definition of Done

  • Current candidate bundle binds all 18 exact rows; root source tree, companion boundaries, and all archive member filename/hash/text-digest evidence are recorded.
  • Every bundled, vendored, NOTICE, documentation-license, generated-asset, or counterpart path is listed; unexplained second license family or missing counterpart remains blocked.
  • Companion rows state whether each companion is shipped, external, or source-checkout-only, with exact profile/surface and provenance.
  • Root and missing-observation rows have candidate-bound metadata/SBOM or a reviewed exclusion; no ambient absence is silently treated as approval.
  • Independent reviewer records a row-level accept/revise/reject decision; accepted rows alone enter the exact policy registry.
  • Strict candidate-bound report and receipt are durable and linked from release: define supported v0.0.6 dependencies and the ORCA companion boundary #8021; no legal or release approval is asserted.

Validation / Testing

Estimate / Risk

  • Rough effort: 30–55 reviewer-hours; best estimate 40 hours, confidence 0.75.
  • Risk is high for bundled assets, companions, and root-source redistribution boundaries; stop on any unexplained content or missing evidence. No legal conclusion is inferred.

Parent / Dependency Links

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions