# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.SbomEntry

*class* · *dataclass*

```python
class SbomEntry
```

Re-exported from: `ocx_sdk._results`

One SBOM document `sbom` listed (C-014).

Field list verified against `sbom.rs:104-162`.

**Attributes**

- `predicate_type` (`str`) — The SBOM's predicate type URI (CycloneDX, SPDX, ...).
- `verified` (`bool`) — Whether a signature was verified over this document. `False` means it is attached raw, with no identity behind it — this is ocx policy, not a cosign or CycloneDX term.
- `shadowed` (`bool`) — Whether a platform-level SBOM of the *same* `predicate_type` supersedes this index-level one. Always present; `False` is a true claim, not an absence.
- `subject_digest` (`str`) — The manifest digest this SBOM describes.
- `referrer_digest` (`str`) — This SBOM document's own digest. **Not always a manifest digest** — for a verified `.att` sidecar it is a layer blob digest (`sbom.rs:128-148`); feeding it to a manifest fetch 404s. Same caveat `SignatureEntry`/`VerificationReport` carry for their own `referrer_digest`.
- `certificate_identity` (`str | None`) — The Fulcio certificate's identity, when `verified` and the signature is keyless.
- `certificate_oidc_issuer` (`str | None`) — The Fulcio certificate's OIDC issuer, when `verified` and the signature is keyless.
- `signed_at` (`str | None`) — When the signature was produced, as ocx spelled it, when `verified`.
- `summary` (`SbomSummaryOut | None`) — Component counts, when the call carried `--summary` and this entry parsed successfully as CycloneDX 1.5-1.7 — see `SbomSummaryOut`. `None` otherwise; the listing itself still works without `--summary`, it just leaves this unpopulated.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2057-L2114)

### ocx_sdk.SbomEntry.subject_digest

*attribute* · *instance attribute*

```python
subject_digest: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2093-L2093)

### ocx_sdk.SbomEntry.summary

*attribute* · *class attribute* · *instance attribute*

```python
summary: SbomSummaryOut | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2098-L2098)

### ocx_sdk.SbomEntry.verified

*attribute* · *instance attribute*

```python
verified: bool
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2091-L2091)

## ocx_sdk.SbomListingReport

*class* · *dataclass*

```python
class SbomListingReport
```

Re-exported from: `ocx_sdk._results`

`ocx package sbom` — the full listing (C-014).

**Payload is enveloped** (D11): `from_json` unwraps `data`. Exits 0 even
when candidates were refused — check `summary.status`, not the exit
code.

**Attributes**

- `summary` (`ListingSummary`) — Counts and overall status.
- `entries` (`tuple[SbomEntry, ...]`) — SBOM documents ocx listed. A plain `Vec` upstream with no `skip`, so always present, not absent-when-empty.
- `refused` (`tuple[RefusedEntry, ...]`) — Candidates ocx rejected outright. Same as `entries`.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2179-L2206)

### ocx_sdk.SbomListingReport.entries

*attribute* · *instance attribute*

```python
entries: tuple[SbomEntry, ...]
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2195-L2195)

### ocx_sdk.SbomListingReport.refused

*attribute* · *instance attribute*

```python
refused: tuple[RefusedEntry, ...]
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2196-L2196)

### ocx_sdk.SbomListingReport.summary

*attribute* · *instance attribute*

```python
summary: ListingSummary
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2194-L2194)

### ocx_sdk.SbomListingReport.from_json

*method* · *classmethod*

```python
def from_json(raw: str) -> SbomListingReport
```

Parse `ocx --format json package sbom` output (full listing).

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2198-L2206)
