deps: 🔒️ raise the spawnllm floor to 0.13.4 so a killed spawn leaves no token on disk - #121
Merged
Merged
Conversation
…no token on disk Context: spawnllm 0.13.3 and earlier ran their isolated `claude -p` calls against a temp config directory and wrote a `.credentials.json` copy of the OAuth token into it for the child to read. Every spawn killed before its cleanup left that copy on disk, and Claude Code migrated each one into a login-Keychain item. One machine carried 345. Summary: `spawnllm>=0.13.2,<0.14` becomes `spawnllm>=0.13.4,<0.14`, and `uv lock` moves the pin from 0.13.2 to 0.13.4. Motivation: the `<0.14` ceiling already admitted 0.13.4, so a fresh resolve picked the fix up while an existing lock stayed on 0.13.2. Raising the floor makes the fixed version the only resolution, which is what a security fix needs. Details: spawnllm 0.13.4 (yasyf/spawnllm#9) passes the token through `CLAUDE_CODE_OAUTH_TOKEN`, so there is nothing on disk for a kill to strand. capt-hook drives those spawns from `captain_hook/context.py` and `captain_hook/review/pipeline.py`, on every LLM hook and every review, and a hook whose caller's deadline abandons it is killed by design. The lock diff carries spawnllm's own version and artifacts and no transitive dependency change.
yasyf
force-pushed
the
chore/spawnllm-0.13.4
branch
from
September 17, 2026 22:26
94f38f1 to
a2e7abc
Compare
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
yasyf
added a commit
that referenced
this pull request
Sep 17, 2026
Context: #121 is on main and unreleased. It raises the spawnllm floor to 0.13.4, whose fix keeps an isolated `claude -p` spawn from writing an OAuth token copy a kill can strand. Summary: moves the Unreleased entry under the 12.41.1 heading. Motivation: the heading has to name a version before the tag that releases it. Details: a patch bump, since the release carries one dependency fix and no API change. No entry text changes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Context
spawnllm 0.13.3 and earlier ran their isolated
claude -pcalls against a temp config directory and wrote a.credentials.jsoncopy of the OAuth token into it for the child to read. Every spawn killed before its cleanup left that copy on disk, and Claude Code migrated each one into a login-Keychain item. One machine carried 345.capt-hook drives those spawns from
captain_hook/context.pyandcaptain_hook/review/pipeline.py, on every LLM hook and every review, and a hook whose caller's deadline abandons it is killed by design. spawnllm 0.13.4 (yasyf/spawnllm#9) passes the token throughCLAUDE_CODE_OAUTH_TOKEN, so there is nothing on disk for a kill to strand.Summary
spawnllm>=0.13.2,<0.14becomesspawnllm>=0.13.4,<0.14, anduv lockmoves the pin from 0.13.2 to 0.13.4. The ceiling already admitted 0.13.4, so a fresh resolve picked the fix up while an existing lock stayed on 0.13.2; raising the floor makes the fixed version the only resolution, which is what a security fix needs. The lock diff carries no transitive dependency change, andUnreleasedgains aFixedentry.Testing
uv sync --extra dev, thenuv run pytestagainst the relocked environment.importlib.metadata.version("spawnllm")reports0.13.4there.