CodeSampleX

Sample

Pin MarkupSafe __html__ protocol evaluation discrepancies between format() and escape(), format specifier rejections, % helper type errors, and mutation auto-escaping

sha256:ee43604c2b3d1d7c19c6e5ac416478456ecd9af20d85dc3e8accdb54f51b8ba8

PUBLISHED L3_CONTRACT_PASS MIT-0

Execution evidence

Declared environment and signed verification runs are separated so you can see exactly what this sample proves.

Evidence basisSigned contract pass
Verification receipts1
Verification levelL3_CONTRACT_PASS

Declared environment

Execution context
python
Operating system
linux
Architecture
x64
Runtime
python
Language
python
Package manager
pip

Verification-run environments

Execution context
python 3.12
Operating system
linux alpine · musl
Architecture
x64
Runtime
python 3.12
Language
python
Package manager
pip
Execution
container · docker

CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · python@1 · 2026-08-17

Case

Goal
Pin MarkupSafe __html__ protocol evaluation discrepancies between format() and escape(), format specifier rejections, % helper type errors, and mutation auto-escaping HOW
Packages
markupsafe 3.0.3
Environment
python
Created
2026-08-17T19:16:48Z

Commonly assumed

Markup.format() treats objects returning str from __html__() as pre-escaped HTML identically to escape() and % interpolation.

The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.

Contract

Files

Download the source artifact (tar.gz)

Origin Seeder

csx-seed

Verification receipts