# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.PackageCommands

*class* · *dataclass*

```python
class PackageCommands
```

Re-exported from: `ocx_sdk._client`

The `ocx package` command group — machine tier.

Package operations act on the `$OCX_HOME` store and its candidate and
current symlinks. They take no project path and are CWD-independent by
construction; a path appears only where the CLI itself takes one.

Every method is multi-identifier native, mirroring the CLI's `PKG...`
with one shared resolution.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1470-L3367)

### ocx_sdk.PackageCommands.sbom

*method*

```python
def sbom(ref: PackageLike, *, platform: str | None = None, summary: bool = False, predicate_type: str | None = None, certificate_identity: str | None = None, certificate_oidc_issuer: str | None = None, key: str | None = None, signature_format: SignatureFormat | None = None, sigstore_trusted_root: str | Path | None = None, rekor_url: str | None = None, no_cache: bool = False, verify: bool | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> SbomListingReport
```

List and verify the SBOM documents attached to a package (C-014).

A read — not mutating. Exits 0 even when candidates were refused;
check `summary.status`, not the exit code, for a
`"partial_failure"` listing.

`verify` gates the same way `install`/`pull`'s does (C-008): ocx's
default is on, but the gate only fires when a `[[trust.policy]]`
covers the package. `verify=True` against an uncovered package is a
documented no-op, not enforcement.

ocx's `--output` mode is not wrapped: it writes the raw predicate
bytes and prints no listing at all, so there is no report for a
typed method to return. Reach it through
`ocx.invoke(["package", "sbom", "--output", "-", str(ref)])`, whose
stdout the SDK captures.

**Parameters**

- `ref` (`PackageLike`) — The package reference to list SBOMs for.
- `platform` (`str | None`) (default: `None`) — Restrict to one platform's SBOM.
- `summary` (`bool`) (default: `False`) — Also parse each entry as CycloneDX (1.5-1.7 only) and report its component counts on `SbomEntry.summary`. An entry whose document will not parse **moves** to `refused` (`reason_kind` `"sbom_summary_failed"`) rather than appearing with an empty summary, so this flag can change which array an entry lands in — it never empties the listing, and never touches an entry that parsed.
- `predicate_type` (`str | None`) (default: `None`) — Restrict to this predicate type — ocx's `--type`.
- `certificate_identity` (`str | None`) (default: `None`) — The pinned keyless identity, for verifying attached signatures. Required together with `certificate_oidc_issuer`, and neither is usable with `key`.
- `certificate_oidc_issuer` (`str | None`) (default: `None`) — The pinned keyless OIDC issuer.
- `key` (`str | None`) (default: `None`) — A key reference, for key-based verification.
- `signature_format` (`SignatureFormat | None`) (default: `None`) — Restrict to one signature format. `'both'` is write-side only — it names two shapes, and a result cannot say "either of these satisfied me".
- `sigstore_trusted_root` (`str | Path | None`) (default: `None`) — A non-default Sigstore trusted root bundle.
- `rekor_url` (`str | None`) (default: `None`) — A non-default Rekor instance.
- `no_cache` (`bool`) (default: `False`) — Skip ocx's verification cache.
- `verify` (`bool | None`) (default: `None`) — Verify attached signatures. `False` names no cryptography, so it cannot be combined with `key` or with either certificate flag.
- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's.

**Returns**

- (`SbomListingReport`) — The summary, the listed entries, and anything refused.

**Raises**

- `ValueError` — The identity pair is incomplete or combined with
`key`; `verify=False` was combined with `key` or with a
certificate flag; or `signature_format` was `'both'`.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L2830-L2942)

### ocx_sdk.PackageCommands.spawn

*method*

```python
def spawn(refs: Sequence[PackageLike], argv: Sequence[str], *, platform: str | None = None, clean: bool = False, private: bool = False, env: Mapping[str, EnvValue] | None = None, lazy_mode: LazyMode | None = None, records_dir: str | Path | None = None, records_name: str | None = None, **popen_kw: Any) -> subprocess.Popen[Any]
```

Start a command in a packages' environment and return `Popen`.

**Parameters**

- `refs` (`Sequence[PackageLike]`) — Package identifiers to compose.
- `argv` (`Sequence[str]`) — The command and its arguments. Must not be empty.
- `platform` (`str | None`) (default: `None`) — The platform to resolve against.
- `clean` (`bool`) (default: `False`) — Strip the ambient parent environment before composing.
- `private` (`bool`) (default: `False`) — Compose the private surface — ocx's `--self`.
- `env` (`Mapping[str, EnvValue] | None`) (default: `None`) — Extra `[env]` entries for this call.
- `lazy_mode` (`LazyMode | None`) (default: `None`) — When content downloads — now, or on first use.
- `records_dir` (`str | Path | None`) (default: `None`) — Write an execution record — the resolved closure and executable — under this directory. `None` leaves it to `[records] dir` and `OCX_RECORDS_DIR`; with none of the three, no record is written.
- `records_name` (`str | None`) (default: `None`) — The record's filename template, over `{time}`, `{host}`, `{pid}` and `{rand}`. `None` leaves it to `[records] name` and `OCX_RECORDS_NAME`.
- `**popen_kw` (`Any`) (default: `{}`) — Forwarded to `Popen`. `args`, `shell`, and `executable` are rejected.

**Returns**

- (`subprocess.Popen[Any]`) — The running child.

**Raises**

- `ValueError` — `argv` is empty, or a rejected keyword was passed.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1747-L1789)
