# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.SbomSummaryOut

*class* · *dataclass*

```python
class SbomSummaryOut
```

Re-exported from: `ocx_sdk._results`

CycloneDX component counts for one SBOM entry, under `--summary` (C-014, `sbom.rs:166-177`).

**Not a second top-level shape.** `--summary` does not change `sbom`'s
JSON root — it populates this struct per-entry, at
`SbomEntry.summary`, for each entry that parsed successfully as
CycloneDX 1.5-1.7. Nothing like `ListingSummary`'s seven fields:
`sbom()` needs no overload, and this is built with `from_dict`, never
`from_json`, because it never sits at a JSON root.

**Attributes**

- `spec_version` (`str`) — The CycloneDX spec version this document declares.
- `component_count` (`int`) — How many components the document lists.
- `serial_number` (`str | None`) — The document's serial number, when it declares one.
- `top_level_component` (`str | None`) — The root component's name, when the document declares one.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2144-L2176)

### ocx_sdk.SbomSummaryOut.component_count

*attribute* · *instance attribute*

```python
component_count: int
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2164-L2164)

### ocx_sdk.SbomSummaryOut.serial_number

*attribute* · *class attribute* · *instance attribute*

```python
serial_number: str | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2165-L2165)

### ocx_sdk.SbomSummaryOut.spec_version

*attribute* · *instance attribute*

```python
spec_version: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2163-L2163)

### ocx_sdk.SbomSummaryOut.top_level_component

*attribute* · *class attribute* · *instance attribute*

```python
top_level_component: str | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2166-L2166)

### ocx_sdk.SbomSummaryOut.from_dict

*method* · *classmethod*

```python
def from_dict(data: Mapping[str, Any]) -> SbomSummaryOut
```

Build from the decoded `summary` object of one `SbomEntry`.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2168-L2176)
