- integrations
- Bazel
- Reference
- Bazel
- Reference
- Rules and macros
- ocx_package_repo
ocx_package_repo
ocx_package_repo
Section titled “ocx_package_repo”
load("@rules_ocx//ocx:defs.bzl", "ocx_package_repo")
ocx_package_repo(name, allow_unverified, allow_yanked, bins, config, index, isolated_home,
no_config, ocx, package, patch_snapshot, pins, platform, resolved_platform,
sigstore_trusted_root)
Provisions a single OCX package from an OCI registry.
//:content is the package tree; every executable the package declares as
its public surface (ocx package inspect --closure) becomes a runnable
target //:<name> (host-platform repos only). A package shipping no
complete binaries metadata falls back to scanning the composed PATH, which
also exposes its private executables — //:env.bzl’s OCX_SCANNED_PACKAGES
names the packages that forced it. For reproducibility, commit an index
snapshot and reference it
via index (tags then resolve frozen from the snapshot), or pin
per-platform manifest digests via pins — plain floating tags resolve at
fetch time and log the resolved digest.
With bins, provisioning is lazy: nothing is installed at fetch time, and
each named executable becomes a launcher re-entering ocx package exec —
content materializes on first execution and never becomes a Bazel action
input (//:content is not available in lazy mode).
ATTRIBUTES