# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.AnnounceReport

*class* · *dataclass*

```python
class AnnounceReport
```

Re-exported from: `ocx_sdk._results`

`ocx package announce` — what reached the index (C-061).

**Payload is bare** (D11). Every one of the fourteen keys is always on
the wire; the nullable ones are `null` rather than absent, so all are
read with `_need` and typed `| None` where upstream is `Option`.

**Attributes**

- `package` (`str`) — The announced `<namespace>/<package>`.
- `status` (`str`) — `"updated"` when a rebuilt root was committed, `"unchanged"` when it was byte-identical to the committed one. An unchanged run can still report a pull request it ensured.
- `desc_status` (`str`) — `"updated"` when the package's `__ocx.desc` artifact moved, else `"unchanged"`.
- `forge` (`str`) — `"github"` or `"gitlab"`, as resolved.
- `transport` (`str`) — `"api"` or `"git"`.
- `credential_kind` (`str`) — `"job-token"`, `"token"` or `"none"` — what the identity ladder resolved for the API credential.
- `push_credential_kind` (`str | None`) — `"job-token"`, `"token"`, `"git-helper"`, or `None` under the `api` transport, which pushes nothing.
- `branch` (`str | None`) — The announce branch, or `None` under `--out`.
- `pull_request_url` (`str | None`) — The request's URL, when one was opened or ensured.
- `pull_request_number` (`int | None`) — Its number, likewise.
- `fork` (`str | None`) — The fork the request came from, when `--fork` was given.
- `written_paths` (`tuple[str, ...]`) — Files written under `--out`; empty otherwise.
- `capability_checks` (`tuple[CapabilityCheck, ...]`) — The forge probes, in `CapabilityName` order.
- `reserved_tags_dropped` (`tuple[str, ...]`) — `__ocx` and legacy `sha256.<hex>` tags named on the command line and dropped: a reported fact of a successful run, never a failure.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2362-L2430)

### ocx_sdk.AnnounceReport.forge

*attribute* · *instance attribute*

```python
forge: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2397-L2397)

### ocx_sdk.AnnounceReport.fork

*attribute* · *instance attribute*

```python
fork: str | None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2404-L2404)

### ocx_sdk.AnnounceReport.push_credential_kind

*attribute* · *instance attribute*

```python
push_credential_kind: str | None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2400-L2400)

### ocx_sdk.AnnounceReport.reserved_tags_dropped

*attribute* · *instance attribute*

```python
reserved_tags_dropped: tuple[str, ...]
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2407-L2407)

### ocx_sdk.AnnounceReport.status

*attribute* · *instance attribute*

```python
status: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2395-L2395)

### ocx_sdk.AnnounceReport.transport

*attribute* · *instance attribute*

```python
transport: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2398-L2398)

### ocx_sdk.AnnounceReport.written_paths

*attribute* · *instance attribute*

```python
written_paths: tuple[str, ...]
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2405-L2405)

### ocx_sdk.AnnounceReport.from_json

*method* · *classmethod*

```python
def from_json(raw: str) -> AnnounceReport
```

Parse `ocx --format json package announce` output.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2409-L2430)
