- integrations
- Python
- ocx_sdk
PackageCommands (4 of 16)
PackageCommandsclassdataclass#
Re-exported from
ocx_sdk._clientView sourcedepsmethod#
def deps(*refs: PackageLike, platform: str | None = None, private: bool = False, why: PackageLike | None = None, depth: int | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> DepsReportShow the dependency tree of installed packages.
Parameters
| Name | Type | Default | Description |
|---|---|---|---|
*refs | PackageLike | () | Package identifiers. |
platform | str | None | None | The platform to resolve against. |
private | bool | False | Include the private, self-only edges — ocx’s --self.
Generated launchers pass it; a consumer needs it only when
building a launcher equivalent. |
why | PackageLike | None | None | Explain why this dependency is pulled in. Matched by registry and repository; the tag is ignored. |
depth | int | None | None | Limit the tree depth. None is unlimited. |
timeout | MaybeTimeout | UNSET | Seconds per attempt. Omitted takes the config’s. |
retry | MaybeRetry | UNSET | Retry policy. None opts out; omitted takes the config’s. |
Returns
DepsReport- One root per requested package.
verifymethod#
def verify(ref: PackageLike, *, platform: str | None = None, certificate_identity: str | None = None, certificate_oidc_issuer: str | None = None, key: str | None = None, signature_format: SignatureFormat | None = None, rekor_url: str | None = None, attestation: bool = False, predicate_type: str | None = None, allow_unlogged_signature: bool = False, no_cache: bool = False, sigstore_trusted_root: str | Path | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> VerificationReportVerify a package reference’s signature or attestation (C-012).
A read — not mutating, and keeps the normal retry default (D5).
Keyless verification needs the identity pair: cosign 2.0 made
--certificate-identity and --certificate-oidc-issuer
hard-required together, because without both a signature from
any Fulcio-certified identity passes (D3). Neither is usable
alongside key.
Parameters
| Name | Type | Default | Description |
|---|---|---|---|
ref | PackageLike | required | The package reference to verify. |
platform | str | None | None | Verify one platform’s manifest. |
certificate_identity | str | None | None | The pinned keyless identity. Required
together with certificate_oidc_issuer for keyless
verification. |
certificate_oidc_issuer | str | None | None | The pinned keyless OIDC issuer.
Required together with certificate_identity. |
key | str | None | None | A key reference, for key-based verification. |
signature_format | SignatureFormat | None | None | Restrict to one signature format. 'both' is
write-side only — it names two shapes, and a result cannot
say “either of these satisfied me”. |
rekor_url | str | None | None | A non-default Rekor instance. |
attestation | bool | False | Verify an attestation instead of a signature. |
predicate_type | str | None | None | Restrict attestation verification to this
predicate type. Requires attestation=True. |
allow_unlogged_signature | bool | False | Accept a signature with no transparency log entry. |
no_cache | bool | False | Skip ocx’s verification cache. |
sigstore_trusted_root | str | Path | None | None | A non-default Sigstore trusted root bundle. |
timeout | MaybeTimeout | UNSET | Seconds per attempt. Omitted takes the config’s. |
retry | MaybeRetry | UNSET | Retry policy. None opts out; omitted takes the
config’s. |
Returns
VerificationReport- The verified subject, identity, and matching signatures.
Raises
ValueError- Only one of
certificate_identity/certificate_oidc_issuerwas given, either was given alongsidekey,predicate_typewas given withoutattestation=True, orsignature_formatwas'both'. OcxProcessError- The signature did not verify — this command’s
main outcome, not an edge case.
DataError(65) for a signature or certificate chain that did not hold up,PermissionDeniedError(77) for an identity or issuer that did not match,NotFoundError(79) when nothing is signed at all, andTransparencyLogUnavailableError(83) when Rekor is unreachable.