# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.SweepReport

*class* · *dataclass*

```python
class SweepReport
```

Re-exported from: `ocx_sdk._results`

`ocx package sign --tags` / `attest --tags` (or `--tags-file`) (C-017, D2).

Upstream is generic (`sweep.rs:152`,
`SweepReport<R> { tags: Vec<SweptTagReport<R>> }`); this is its Python
shape for both instantiations. Carries no `command` or `exit_code`
field — both are `#[serde(skip)]` upstream.

**Payload is enveloped** (D11): the envelope's `data` holds
`{"tags": [...]}`, and its `exit_code` — not part of `data` — is the
process's own. A partially-failed sweep exits non-zero, so a `failed`
row usually arrives through `partial_report(err)` rather than a normal
return (D10); both paths parse through this same `from_json`.

**Attributes**

- `tags` (`tuple[SweptTagReport, ...]`) — One row per swept tag. A plain `Vec` upstream with no `skip`, so always present, not absent-when-empty.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1882-L1915)

### ocx_sdk.SweepReport.tags

*attribute* · *instance attribute*

```python
tags: tuple[SweptTagReport, ...]
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1902-L1902)

### ocx_sdk.SweepReport.from_json

*method* · *classmethod*

```python
def from_json(raw: str, row: Callable[[Mapping[str, Any]], _SweepRow]) -> SweepReport
```

Parse an enveloped sweep payload from a swept `sign` or `attest`.

**Parameters**

- `raw` (`str`) — Captured stdout.
- `row` (`Callable[[Mapping[str, Any]], _SweepRow]`) — Parses each row's `report` object — see `SweptTagReport.from_dict`.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1904-L1915)
