- integrations
- Python
- ocx_sdk
PackageCommands (15 of 16)
PackageCommandsclassdataclass#
ocx_sdk._clientView sourcesbommethod#
def sbom(ref: PackageLike, *, platform: str | None = None, summary: bool = False, predicate_type: str | None = None, certificate_identity: str | None = None, certificate_oidc_issuer: str | None = None, key: str | None = None, signature_format: SignatureFormat | None = None, sigstore_trusted_root: str | Path | None = None, rekor_url: str | None = None, no_cache: bool = False, verify: bool | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> SbomListingReportList and verify the SBOM documents attached to a package (C-014).
A read — not mutating. Exits 0 even when candidates were refused;
check summary.status, not the exit code, for a
"partial_failure" listing.
verify gates the same way install/pull’s does (C-008): ocx’s
default is on, but the gate only fires when a [[trust.policy]]
covers the package. verify=True against an uncovered package is a
documented no-op, not enforcement.
ocx’s --output mode is not wrapped: it writes the raw predicate
bytes and prints no listing at all, so there is no report for a
typed method to return. Reach it through
ocx.invoke(["package", "sbom", "--output", "-", str(ref)]), whose
stdout the SDK captures.
Parameters
| Name | Type | Default | Description |
|---|---|---|---|
ref | PackageLike | required | The package reference to list SBOMs for. |
platform | str | None | None | Restrict to one platform’s SBOM. |
summary | bool | False | Also parse each entry as CycloneDX (1.5-1.7 only) and
report its component counts on SbomEntry.summary. An
entry whose document will not parse moves to refused
(reason_kind "sbom_summary_failed") rather than
appearing with an empty summary, so this flag can change
which array an entry lands in — it never empties the
listing, and never touches an entry that parsed. |
predicate_type | str | None | None | Restrict to this predicate type — ocx’s
--type. |
certificate_identity | str | None | None | The pinned keyless identity, for
verifying attached signatures. Required together with
certificate_oidc_issuer, and neither is usable with
key. |
certificate_oidc_issuer | str | None | None | The pinned keyless OIDC issuer. |
key | str | None | None | A key reference, for key-based verification. |
signature_format | SignatureFormat | None | None | Restrict to one signature format. 'both' is
write-side only — it names two shapes, and a result cannot
say “either of these satisfied me”. |
sigstore_trusted_root | str | Path | None | None | A non-default Sigstore trusted root bundle. |
rekor_url | str | None | None | A non-default Rekor instance. |
no_cache | bool | False | Skip ocx’s verification cache. |
verify | bool | None | None | Verify attached signatures. False names no
cryptography, so it cannot be combined with key or with
either certificate flag. |
timeout | MaybeTimeout | UNSET | Seconds per attempt. Omitted takes the config’s. |
retry | MaybeRetry | UNSET | Retry policy. None opts out; omitted takes the
config’s. |
Returns
SbomListingReport- The summary, the listed entries, and anything refused.
Raises
ValueError- The identity pair is incomplete or combined with
key;verify=Falsewas combined withkeyor with a certificate flag; orsignature_formatwas'both'.
spawnmethod#
def spawn(refs: Sequence[PackageLike], argv: Sequence[str], *, platform: str | None = None, clean: bool = False, private: bool = False, env: Mapping[str, EnvValue] | None = None, lazy_mode: LazyMode | None = None, records_dir: str | Path | None = None, records_name: str | None = None, **popen_kw: Any) -> subprocess.Popen[Any]Start a command in a packages’ environment and return Popen.
Parameters
| Name | Type | Default | Description |
|---|---|---|---|
refs | Sequence[PackageLike] | required | Package identifiers to compose. |
argv | Sequence[str] | required | The command and its arguments. Must not be empty. |
platform | str | None | None | The platform to resolve against. |
clean | bool | False | Strip the ambient parent environment before composing. |
private | bool | False | Compose the private surface — ocx’s --self. |
env | Mapping[str, EnvValue] | None | None | Extra [env] entries for this call. |
lazy_mode | LazyMode | None | None | When content downloads — now, or on first use. |
records_dir | str | Path | None | None | Write an execution record — the resolved closure
and executable — under this directory. None leaves it to
[records] dir and OCX_RECORDS_DIR; with none of the
three, no record is written. |
records_name | str | None | None | The record’s filename template, over {time},
{host}, {pid} and {rand}. None leaves it to
[records] name and OCX_RECORDS_NAME. |
**popen_kw | Any | {} | Forwarded to Popen. args, shell, and
executable are rejected. |
Returns
subprocess.Popen[Any]- The running child.
Raises
ValueErrorargvis empty, or a rejected keyword was passed.