Skip to content
ocx
install

PackageCommands (4 of 16)

PackageCommandsclassdataclass#

Re-exported from ocx_sdk._clientView source

depsmethod#

def deps(*refs: PackageLike, platform: str | None = None, private: bool = False, why: PackageLike | None = None, depth: int | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> DepsReport

Show the dependency tree of installed packages.

Parameters

NameTypeDefaultDescription
*refsPackageLike()Package identifiers.
platformstr | NoneNoneThe platform to resolve against.
privateboolFalseInclude the private, self-only edges — ocx’s --self. Generated launchers pass it; a consumer needs it only when building a launcher equivalent.
whyPackageLike | NoneNoneExplain why this dependency is pulled in. Matched by registry and repository; the tag is ignored.
depthint | NoneNoneLimit the tree depth. None is unlimited.
timeoutMaybeTimeoutUNSETSeconds per attempt. Omitted takes the config’s.
retryMaybeRetryUNSETRetry policy. None opts out; omitted takes the config’s.

Returns

DepsReport
One root per requested package.

verifymethod#

def verify(ref: PackageLike, *, platform: str | None = None, certificate_identity: str | None = None, certificate_oidc_issuer: str | None = None, key: str | None = None, signature_format: SignatureFormat | None = None, rekor_url: str | None = None, attestation: bool = False, predicate_type: str | None = None, allow_unlogged_signature: bool = False, no_cache: bool = False, sigstore_trusted_root: str | Path | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> VerificationReport

Verify a package reference’s signature or attestation (C-012).

A read — not mutating, and keeps the normal retry default (D5).

Keyless verification needs the identity pair: cosign 2.0 made --certificate-identity and --certificate-oidc-issuer hard-required together, because without both a signature from any Fulcio-certified identity passes (D3). Neither is usable alongside key.

Parameters

NameTypeDefaultDescription
refPackageLikerequiredThe package reference to verify.
platformstr | NoneNoneVerify one platform’s manifest.
certificate_identitystr | NoneNoneThe pinned keyless identity. Required together with certificate_oidc_issuer for keyless verification.
certificate_oidc_issuerstr | NoneNoneThe pinned keyless OIDC issuer. Required together with certificate_identity.
keystr | NoneNoneA key reference, for key-based verification.
signature_formatSignatureFormat | NoneNoneRestrict to one signature format. 'both' is write-side only — it names two shapes, and a result cannot say “either of these satisfied me”.
rekor_urlstr | NoneNoneA non-default Rekor instance.
attestationboolFalseVerify an attestation instead of a signature.
predicate_typestr | NoneNoneRestrict attestation verification to this predicate type. Requires attestation=True.
allow_unlogged_signatureboolFalseAccept a signature with no transparency log entry.
no_cacheboolFalseSkip ocx’s verification cache.
sigstore_trusted_rootstr | Path | NoneNoneA non-default Sigstore trusted root bundle.
timeoutMaybeTimeoutUNSETSeconds per attempt. Omitted takes the config’s.
retryMaybeRetryUNSETRetry policy. None opts out; omitted takes the config’s.

Returns

VerificationReport
The verified subject, identity, and matching signatures.

Raises

ValueError
Only one of certificate_identity/ certificate_oidc_issuer was given, either was given alongside key, predicate_type was given without attestation=True, or signature_format was 'both'.
OcxProcessError
The signature did not verify — this command’s main outcome, not an edge case. DataError (65) for a signature or certificate chain that did not hold up, PermissionDeniedError (77) for an identity or issuer that did not match, NotFoundError (79) when nothing is signed at all, and TransparencyLogUnavailableError (83) when Rekor is unreachable.