# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.CascadeReport

*class* · *dataclass*

```python
class CascadeReport
```

Re-exported from: `ocx_sdk._results`

One package's rolling-tag audit — the `check` document, and the `report` inside a `repair` entry.

First-cut depth: the rows, the index findings and the tag lists are
typed; `aliases` and `unrepairable` are carried as opaque mappings
(`Integration.payload`'s precedent) until a consumer needs their fields.

**Attributes**

- `identifier` (`str`) — The physical repository the graph was read from.
- `logical` (`str | None`) — The logical name the caller gave, when it differed.
- `aliases` (`Mapping[str, Mapping[str, Any]]`) — Rolling tag to its alias state (`{"state": "present"}`, `{"state": "absent"}`, or `{"state": "not-an-index", "digest": ...}`), untyped.
- `rows` (`tuple[SlotRow, ...]`) — One slot per (rolling tag, platform).
- `index_findings` (`tuple[IndexFinding, ...]`) — Public-index disagreements; empty off `ocx.sh`.
- `ignored_tags` (`tuple[str, ...]`) — Tags the audit skipped — the keep tags among them.
- `unrepairable` (`tuple[Mapping[str, Any], ...]`) — Findings `repair` refuses to fix, each `{tag, reason, digest?}`, untyped.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2608-L2659)

### ocx_sdk.CascadeReport.ref

*property*

```python
ref: PackageRef
```

The audited repository, as a `PackageRef`.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2638-L2640)

### ocx_sdk.CascadeReport.from_dict

*method* · *classmethod*

```python
def from_dict(data: Mapping[str, Any]) -> CascadeReport
```

Build from one decoded `reports` entry (or a repair entry's `report`).

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2647-L2659)

## ocx_sdk.ClaimOwner

*class* · *dataclass*

```python
class ClaimOwner
```

Re-exported from: `ocx_sdk._results`

One forge account on a `claim` report, as author or owner.

**Attributes**

- `login` (`str`) — The forge's canonical login spelling.
- `id` (`int`) — The forge's immutable numeric account id.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2433-L2448)

### ocx_sdk.ClaimOwner.id

*attribute* · *instance attribute*

```python
id: int
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2443-L2443)

### ocx_sdk.ClaimOwner.login

*attribute* · *instance attribute*

```python
login: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2442-L2442)

### ocx_sdk.ClaimOwner.from_dict

*method* · *classmethod*

```python
def from_dict(data: Mapping[str, Any]) -> ClaimOwner
```

Build from a decoded `author` or `owners` entry.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2445-L2448)
