- integrations
- Bazel
- Reference
- Module extension
Module extension
The ocx module extension.
Bootstraps the pinned ocx CLI (@ocx_tool) and declares repositories that
provision tools through it. The implementation is a pure function of the
tags — all host detection and environment access happens inside the
repository rules — so the extension is marked reproducible and stays out of
MODULE.bazel.lock.
ocx = use_extension("@rules_ocx//ocx:extensions.bzl", "ocx")
ocx.download(dist_manifest, triple, version)
ocx.package(name, bins, config, index, isolated_home, no_config, package, patch_snapshot, pins,
platform_aliases, platforms)
ocx.policy(allow_unverified, allow_yanked, sigstore_trusted_root)
ocx.project(name, bins, config, groups, isolated_home, no_config, ocx_lock, ocx_toml,
patch_snapshot, platform)
Provisions tools through the OCX package manager.
Always creates @ocx_tool (the pinned ocx CLI). ocx.project() provisions
a workspace toolchain from ocx.toml/ocx.lock; ocx.package() provisions
individual OCI packages; ocx.policy() sets the build’s weakening posture
(root module only). See the tag class docs for details.
TAG CLASSES
download
Section titled “download”Overrides the ocx CLI bootstrap. Root module only; at most one.
Attributes
package
Section titled “package”Provisions a single OCX package from an OCI registry.
Attributes
policy
Section titled “policy”Sets the build’s weakening posture — unverified installs, yanked releases, a pinned sigstore trusted root — as a function of MODULE.bazel alone. Root module only; at most one.
Attributes
project
Section titled “project”Provisions the toolchain of a workspace ocx.toml + ocx.lock. Root module only.
Attributes