Skip to content
ocx
install

PackageCommands (15 of 16)

PackageCommandsclassdataclass#

Re-exported from ocx_sdk._clientView source

sbommethod#

def sbom(ref: PackageLike, *, platform: str | None = None, summary: bool = False, predicate_type: str | None = None, certificate_identity: str | None = None, certificate_oidc_issuer: str | None = None, key: str | None = None, signature_format: SignatureFormat | None = None, sigstore_trusted_root: str | Path | None = None, rekor_url: str | None = None, no_cache: bool = False, verify: bool | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> SbomListingReport

List and verify the SBOM documents attached to a package (C-014).

A read — not mutating. Exits 0 even when candidates were refused; check summary.status, not the exit code, for a "partial_failure" listing.

verify gates the same way install/pull’s does (C-008): ocx’s default is on, but the gate only fires when a [[trust.policy]] covers the package. verify=True against an uncovered package is a documented no-op, not enforcement.

ocx’s --output mode is not wrapped: it writes the raw predicate bytes and prints no listing at all, so there is no report for a typed method to return. Reach it through ocx.invoke(["package", "sbom", "--output", "-", str(ref)]), whose stdout the SDK captures.

Parameters

NameTypeDefaultDescription
refPackageLikerequiredThe package reference to list SBOMs for.
platformstr | NoneNoneRestrict to one platform’s SBOM.
summaryboolFalseAlso parse each entry as CycloneDX (1.5-1.7 only) and report its component counts on SbomEntry.summary. An entry whose document will not parse moves to refused (reason_kind "sbom_summary_failed") rather than appearing with an empty summary, so this flag can change which array an entry lands in — it never empties the listing, and never touches an entry that parsed.
predicate_typestr | NoneNoneRestrict to this predicate type — ocx’s --type.
certificate_identitystr | NoneNoneThe pinned keyless identity, for verifying attached signatures. Required together with certificate_oidc_issuer, and neither is usable with key.
certificate_oidc_issuerstr | NoneNoneThe pinned keyless OIDC issuer.
keystr | NoneNoneA key reference, for key-based verification.
signature_formatSignatureFormat | NoneNoneRestrict to one signature format. 'both' is write-side only — it names two shapes, and a result cannot say “either of these satisfied me”.
sigstore_trusted_rootstr | Path | NoneNoneA non-default Sigstore trusted root bundle.
rekor_urlstr | NoneNoneA non-default Rekor instance.
no_cacheboolFalseSkip ocx’s verification cache.
verifybool | NoneNoneVerify attached signatures. False names no cryptography, so it cannot be combined with key or with either certificate flag.
timeoutMaybeTimeoutUNSETSeconds per attempt. Omitted takes the config’s.
retryMaybeRetryUNSETRetry policy. None opts out; omitted takes the config’s.

Returns

SbomListingReport
The summary, the listed entries, and anything refused.

Raises

ValueError
The identity pair is incomplete or combined with key; verify=False was combined with key or with a certificate flag; or signature_format was 'both'.

spawnmethod#

def spawn(refs: Sequence[PackageLike], argv: Sequence[str], *, platform: str | None = None, clean: bool = False, private: bool = False, env: Mapping[str, EnvValue] | None = None, lazy_mode: LazyMode | None = None, records_dir: str | Path | None = None, records_name: str | None = None, **popen_kw: Any) -> subprocess.Popen[Any]

Start a command in a packages’ environment and return Popen.

Parameters

NameTypeDefaultDescription
refsSequence[PackageLike]requiredPackage identifiers to compose.
argvSequence[str]requiredThe command and its arguments. Must not be empty.
platformstr | NoneNoneThe platform to resolve against.
cleanboolFalseStrip the ambient parent environment before composing.
privateboolFalseCompose the private surface — ocx’s --self.
envMapping[str, EnvValue] | NoneNoneExtra [env] entries for this call.
lazy_modeLazyMode | NoneNoneWhen content downloads — now, or on first use.
records_dirstr | Path | NoneNoneWrite an execution record — the resolved closure and executable — under this directory. None leaves it to [records] dir and OCX_RECORDS_DIR; with none of the three, no record is written.
records_namestr | NoneNoneThe record’s filename template, over {time}, {host}, {pid} and {rand}. None leaves it to [records] name and OCX_RECORDS_NAME.
**popen_kwAny{}Forwarded to Popen. args, shell, and executable are rejected.

Returns

subprocess.Popen[Any]
The running child.

Raises

ValueError
argv is empty, or a rejected keyword was passed.