CodeSampleX

Sample

Configure Pillow decompression bomb protection via Image.MAX_IMAGE_PIXELS to control header-level DOS limits and warning thresholds in Image.open.

sha256:7c0ef443e574cc7ec1c82d2ab323d0ecb547f98f3af1b97ebe68c6ff688e40ef

PUBLISHED L3_CONTRACT_PASS MIT-0

Execution evidence

Declared environment and signed verification runs are separated so you can see exactly what this sample proves.

Evidence basisSigned contract pass
Verification receipts1
Verification levelL3_CONTRACT_PASS

Declared environment

Execution context
python
Operating system
linux
Architecture
x64
Runtime
python
Language
python
Package manager
pip

Verification-run environments

Execution context
python 3.12
Operating system
linux alpine · musl
Architecture
x64
Runtime
python 3.12
Language
python
Package manager
pip
Execution
container · docker

CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · python@1 · 2026-08-17

Case

Goal
Configure Pillow decompression bomb protection via Image.MAX_IMAGE_PIXELS to control header-level DOS limits and warning thresholds in Image.open. HOW
Packages
pillow 10.4.0
Environment
python
Created
2026-08-17T11:44:15Z

Commonly assumed

Image.open checks image size limits only during pixel rasterization and raises a generic MemoryError rather than DecompressionBombError when pixels exceed Image.MAX_IMAGE_PIXELS.

The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.

Contract

Files

Download the source artifact (tar.gz)

Origin Seeder

csx-seed

Verification receipts