- integrations
- Python
- ocx_sdk
PackageCommands (2 of 16)
PackageCommandsclassdataclass#
Re-exported from
ocx_sdk._clientView sourcecascade_repairmethod#
def cascade_repair(*refs: PackageLike, dry_run: bool = False, announce_tags: str | Path | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> CascadeRepairReportRe-point packages’ rolling tags at the content their versions imply.
Publishes nothing new — every index it writes references content the
registry already serves. mutating=not dry_run (D5), as copy:
the preview writes nothing and keeps the session retry policy.
Report-then-fail like cascade_check: exit 65 with the report
when a finding remains — on a dry_run, having planned anything is
the finding — so report.clean is the answer, not an exception.
Repairing the registry does not update the public index. Pass
announce_tags to record the tags this run moved, then hand that
file to announce(..., tags_file=...).
Parameters
| Name | Type | Default | Description |
|---|---|---|---|
*refs | PackageLike | () | Packages to repair. |
dry_run | bool | False | Compute and report the plan without writing. |
announce_tags | str | Path | None | None | Write the rolling tags this run moved or created to this file, one per line. Takes one package per run — ocx exits 64 when it is given more. |
timeout | MaybeTimeout | UNSET | Seconds per attempt. Omitted takes the config’s. |
retry | MaybeRetry | UNSET | Retry policy. None opts out; omitted takes the config’s
— which D5 resolves to no retries unless dry_run. |
Returns
CascadeRepairReport- One entry per package, carrying the exit code.
Raises
UsageError- A package names a digest or a non-version tag, or
announce_tagswas given with more than one package (exit 64). DataError- Exit 65 without a report.
pullmethod#
def pull(*refs: PackageLike, platform: str | None = None, verify: bool | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> Mapping[str, str]Download packages into the store without creating symlinks.
Parameters
| Name | Type | Default | Description |
|---|---|---|---|
*refs | PackageLike | () | Package identifiers. |
platform | str | None | None | The platform to resolve against. |
verify | bool | None | None | Verify each package’s Sigstore signature before storing
it. None leaves ocx’s default, which is on. The gate fires
only where a [[trust.policy]] covers the package, so True
against an uncovered package is a documented no-op rather
than enforcement. False also beats an ambient
OCX_NO_VERIFY, which the SDK neutralizes on every spawn. |
timeout | MaybeTimeout | UNSET | Seconds per attempt. Omitted takes the config’s. |
retry | MaybeRetry | UNSET | Retry policy. None opts out; omitted takes the config’s. |
Returns
Mapping[str, str]- A store path per identifier — a bare string here, unlike the
Mapping[str, str]- project tier’s
pulland unlikewhich.
Raises
OcxProcessError- ocx 0.6 verifies a covered package’s signature before storing it, so this call can fail where the identical call against a 0.5.x binary succeeded — no code change on the caller’s side, only a newer binary. The exit codes, and why none of them retry, are in the guide’s “Errors & credentials” section on verification.