Skip to main content

airom — Python SDK

Python SDK for AIROM, the open-source AI Bill of Materials (AIBOM) scanner. Discover AI assets — models, prompts, datasets, embeddings, vector databases, frameworks, serving infrastructure — across code, containers, and Kubernetes, and get them back as typed Python objects.

pip install airom

This installs both the airom command and the Python library — the wheel ships the scanner binary itself into your environment's bin/, so there is nothing else to install:

$ airom --version
airom 0.4.2

$ airom fs ./my-app -o table          # the CLI, globally

Quick start

import airom

inv = airom.fs("./my-app", min_confidence=0.8)

for c in inv.by_kind(airom.ComponentKind.HOSTED_LLM):
    print(c.name, c.provider.or_default("-"), c.confidence)
    for occ in c.evidence.occurrences:
        print(f"   {occ.location.path}:{occ.location.line}  [{occ.detector_id}]")
gpt-4.1 openai 0.87
   src/rag.py:88  [rules/openai/model-literal]
   src/agent.py:12  [rules/openai/sdk-import]

Every component carries the evidence that justifies it — that is the point of AIROM, and the SDK hands you all of it.

Scanning

airom.scan("./app")                       # auto-detect: path, git URL, or image ref
airom.fs("./app")                         # a directory tree
airom.repo("https://github.com/o/r")      # remote (shallow clone) or a local worktree
airom.image(input="img.tar")              # docker save -o img.tar <ref>
airom.k8s(manifests="./deploy")           # offline: enumerate workload images
airom.version()                           # the underlying binary's ToolInfo

Common keyword args mirror the CLI flags: select, rules, ignore, min_confidence, max_file_size, io_budget, parallel, no_cache, cache_dir, offline, stats, plus binary, timeout, and cwd. None leaves the tool's own default in place — the SDK never invents defaults.

min_confidence=0.8 is the practical high-signal filter: on general-purpose directories, extension-only dataset detection and keyword-only generation-param detection emit low-confidence (0.5–0.6) noise. Note the application root always survives the filter — it is the scan target, not a finding.

select tokens are detector IDs or tags, not languages — "-dataset/file", not "python". Run airom detectors list (or airom.raw(["detectors", "list"])) to see them.

Not wired yet: pulling an image from a live registry/daemon, and live-cluster Kubernetes scanning. Both fail with a clear error. Use image(input=...) / an OCI layout and k8s(manifests=...) today.

Tri-state fields

version, provider, download_location and release_time are tri-state, and the SDK preserves the distinction rather than collapsing it into None:

JSON Meaning Opt
key omitted does not apply Presence.ABSENT
null applies, but undetermined (SPDX NOASSERTION) Presence.UNKNOWN
a value known Presence.KNOWN
c.version.known           # bool — only True when a real value is present
c.version.or_none()       # value, or None (collapses absent and unknown)
c.version.or_default("-") # value, or your fallback
c.version.presence        # the full distinction, when you need it

Navigating the graph

inv.components                  # sorted, deterministic
inv.by_kind("vector-db", "framework")
inv.get("airom:1f3a9b2c4d5e6f70")
inv.application                 # the scan-root component
inv.edges_from(c.id)            # typed, evidenced relationships
inv.unknowns                    # "looked relevant, could not process" — honesty channel
inv.stats.files_walked          # requires stats=True
len(inv); [c for c in inv]      # Inventory is sized and iterable

CI gating

A fail_on match is a verdict, not an error — the scan succeeded and the AIBOM is complete, so it is reported rather than raised:

res = airom.execute(
    ["fs", "./app"],
    options=airom.ScanOptions(fail_on="hosted-llm&confidence>=0.9", exit_code=7),
)
if res.policy_matched:
    raise SystemExit(res.exit_code)

Often you don't need fail_on at all — you have the whole graph, so gate in Python:

risky = [c for c in inv if c.model and c.model.pickle_risk]
if risky:
    raise SystemExit(f"unsafe pickle globals in: {[c.name for c in risky]}")

Errors

Exception Raised when
BinaryNotFoundError the airom executable could not be located
ScanError a fatal scan failure (exit 2): unreadable target, clone failure, bad flags
OutputError no parseable AIBOM, or an unsupported schemaVersion

Detector errors are not exceptions: they degrade to inv.unknowns records and the scan still succeeds. That is AIROM's degrade-by-default contract, and the SDK preserves it.

The binary

The SDK shells out to the airom binary and decodes its native JSON — the lossless superset every other format (CycloneDX, SARIF, YAML, table) projects from. Resolution order:

  1. the binary= argument
  2. a copy bundled in the wheel (airom/_bin/airom)
  3. $AIROM_BINARY
  4. airom on PATH

Platform wheels bundle the binary as a script, so pip installs it into the environment's bin/ (Scripts\ on Windows): pip install airom gives you a working airom command on PATH and the importable library, with no Python shim in between. In a virtualenv it is on PATH as soon as the venv is active; pipx install airom or pip install --user airom puts it on PATH globally.

The library resolves the binary without relying on PATH at all (it consults the environment's scripts dir directly), so import airom works even from an unactivated venv's interpreter.

Platforms with no wheel

Wheels are published for macOS (Intel + Apple Silicon), Linux (x86-64 + arm64, glibc + musl), and Windows (x86-64 + arm64). Every one is installed and executed on the platform it targets before it is published; see the smoke jobs in release-pypi.yml.

Anywhere else, pip falls back to the sdist, which ships the Python library and no binary — and cannot build one, since it does not contain the Go module. Rather than install successfully and leave you without a scanner, that build now fails and says so. To proceed, either install the binary for your platform from the releases page and put it on your PATH, or take the library alone:

AIROM_SKIP_BUNDLE=1 pip install airom

The second form is the right one when you already run the standalone binary and only want import airom. Resolution then falls through to $AIROM_BINARY or airom on PATH.

Development

cd sdk/python
pip install -e ".[dev]"
pytest            # builds the binary from the checkout and tests against it
mypy && ruff check .

The suite runs against the real binary, not mocks: a wrapper tested only against mocks proves nothing about the contract it wraps.

Building a wheel needs the Go toolchain (the build hook compiles the binary with CGO_ENABLED=0) and fails without it, because a wheel with no binary installs no airom command. Set AIROM_SKIP_BUNDLE=1 for a pure-Python wheel on purpose.

Publishing

Releases are published by .github/workflows/release-pypi.yml using PyPI Trusted Publishing (OIDC): GitHub Actions authenticates to PyPI directly, so there is no API token stored as a secret, and none to leak or rotate.

One-time setup

On pypi.org/manage/account/publishing, add a pending publisher:

Field Value
PyPI project name airom
Owner airomhq
Repository name airom
Workflow name release-pypi.yml
Environment (leave blank)

That is all — no secret is added to GitHub.

Cutting a release

The workflow runs on every push to main that touches the SDK or the scanner, but publishes only when the version is new: PyPI permanently refuses to re-upload a version (even a deleted one), so the workflow compares __version__ against the index and skips cleanly if it is already there.

So a release is exactly one deliberate act:

# sdk/python/src/airom/__init__.py
__version__ = "0.1.0"     # bump, commit, merge to main -> published

Publishing is irreversible: a version number is burned forever once used, and yanking does not free it. Test the whole path first with the manual workflow_dispatch run against TestPyPI (which needs its own pending publisher at test.pypi.org).

License

Apache-2.0, same as AIROM.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

airom-0.4.2.tar.gz (26.8 kB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

airom-0.4.2-py3-none-win_arm64.whl (5.3 MB view details)

Uploaded Python 3Windows ARM64

airom-0.4.2-py3-none-win_amd64.whl (6.0 MB view details)

Uploaded Python 3Windows x86-64

airom-0.4.2-py3-none-musllinux_1_2_x86_64.whl (5.8 MB view details)

Uploaded Python 3musllinux: musl 1.2+ x86-64

airom-0.4.2-py3-none-musllinux_1_2_aarch64.whl (5.2 MB view details)

Uploaded Python 3musllinux: musl 1.2+ ARM64

airom-0.4.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (5.8 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ x86-64

airom-0.4.2-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl (5.2 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ ARM64

airom-0.4.2-py3-none-macosx_11_0_arm64.whl (5.4 MB view details)

Uploaded Python 3macOS 11.0+ ARM64

airom-0.4.2-py3-none-macosx_10_9_x86_64.whl (5.9 MB view details)

Uploaded Python 3macOS 10.9+ x86-64

File details

Details for the file airom-0.4.2.tar.gz.

File metadata

  • Download URL: airom-0.4.2.tar.gz
  • Upload date:
  • Size: 26.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for airom-0.4.2.tar.gz
Algorithm Hash digest
SHA256 7e39c1913b0398dea6fc3d6bc8b4b5f6cefdb71bf76c9e56bfef80dccf50eb7f
MD5 d6afa9691fc1c38b6507a5bbf3375af9
BLAKE2b-256 3ffedd5c5c7657a8878ec1b9a751e17956acfb3dd0155ddd5a57424300e06325

See more details on using hashes here.

Provenance

The following attestation bundles were made for airom-0.4.2.tar.gz:

Publisher: release-pypi.yml on airomhq/airom

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file airom-0.4.2-py3-none-win_arm64.whl.

File metadata

  • Download URL: airom-0.4.2-py3-none-win_arm64.whl
  • Upload date:
  • Size: 5.3 MB
  • Tags: Python 3, Windows ARM64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for airom-0.4.2-py3-none-win_arm64.whl
Algorithm Hash digest
SHA256 05a8eef6c106ba740c08ccfcd127a5d97a3d19b557d1df5c5219a8cf4efe352a
MD5 d9638d9986a135d5f343f89c5ee608b7
BLAKE2b-256 62177cf99fc438fa6762c11f98bf8a3af7a976d64aab0a523418f5a827a3b945

See more details on using hashes here.

Provenance

The following attestation bundles were made for airom-0.4.2-py3-none-win_arm64.whl:

Publisher: release-pypi.yml on airomhq/airom

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file airom-0.4.2-py3-none-win_amd64.whl.

File metadata

  • Download URL: airom-0.4.2-py3-none-win_amd64.whl
  • Upload date:
  • Size: 6.0 MB
  • Tags: Python 3, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for airom-0.4.2-py3-none-win_amd64.whl
Algorithm Hash digest
SHA256 513c52e8b68516fcaaf471c884c37f453e1624185f3b9731a0a28ef19ae5c1c1
MD5 23f46ec24befebe5895685b0534b34bb
BLAKE2b-256 78bb2909c4b0006ebdb01acd64e72b17e9524adc2523dbcf2d0f70c0dfd07680

See more details on using hashes here.

Provenance

The following attestation bundles were made for airom-0.4.2-py3-none-win_amd64.whl:

Publisher: release-pypi.yml on airomhq/airom

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file airom-0.4.2-py3-none-musllinux_1_2_x86_64.whl.

File metadata

  • Download URL: airom-0.4.2-py3-none-musllinux_1_2_x86_64.whl
  • Upload date:
  • Size: 5.8 MB
  • Tags: Python 3, musllinux: musl 1.2+ x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for airom-0.4.2-py3-none-musllinux_1_2_x86_64.whl
Algorithm Hash digest
SHA256 aa7ca7d989227b582db7e3a82a8185e01a4ac5480a621122cedf776bda429e11
MD5 c2a9b377950ccdb9281b7f31d2ba86ad
BLAKE2b-256 97dbe2daee66e4bec87c71856da82f75c75248d4084136f787cbd5c0e48b5176

See more details on using hashes here.

Provenance

The following attestation bundles were made for airom-0.4.2-py3-none-musllinux_1_2_x86_64.whl:

Publisher: release-pypi.yml on airomhq/airom

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file airom-0.4.2-py3-none-musllinux_1_2_aarch64.whl.

File metadata

File hashes

Hashes for airom-0.4.2-py3-none-musllinux_1_2_aarch64.whl
Algorithm Hash digest
SHA256 f5a8e1ded7952326b216d24abbdb49c307432cf09d804fa9bfc70aece7d1de14
MD5 a7e526f379bfb129d214b85c8d818ee6
BLAKE2b-256 174767bd66d762147731e3189e9d77550fd20a94971134b91c2c835fafa7ec36

See more details on using hashes here.

Provenance

The following attestation bundles were made for airom-0.4.2-py3-none-musllinux_1_2_aarch64.whl:

Publisher: release-pypi.yml on airomhq/airom

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file airom-0.4.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for airom-0.4.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 5a9ac103d09545cac35d2ba72316ce97b8f4bf2a7629e4e2a9b3e76024163828
MD5 3cf98fc0693045467995bc6eb415d701
BLAKE2b-256 a55541efd26165c16bb7c8340df5569bbebb241ff46c60d340d7bdbc3e6f74c1

See more details on using hashes here.

Provenance

The following attestation bundles were made for airom-0.4.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:

Publisher: release-pypi.yml on airomhq/airom

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file airom-0.4.2-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl.

File metadata

File hashes

Hashes for airom-0.4.2-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Algorithm Hash digest
SHA256 395f8bbc64ee19bd5e95234ce9642f80cc49fa120060e807551e539b6c33f376
MD5 459b1012d7433246a1058ad11118e608
BLAKE2b-256 f7e7732d2747452c607deb0c44b85fb7a2ea937d51d0363911b6911b5bdabd7d

See more details on using hashes here.

Provenance

The following attestation bundles were made for airom-0.4.2-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl:

Publisher: release-pypi.yml on airomhq/airom

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file airom-0.4.2-py3-none-macosx_11_0_arm64.whl.

File metadata

  • Download URL: airom-0.4.2-py3-none-macosx_11_0_arm64.whl
  • Upload date:
  • Size: 5.4 MB
  • Tags: Python 3, macOS 11.0+ ARM64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for airom-0.4.2-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 48f1249575b0918ab29fc9e499bd0d891a4ba36c970343523c0ca6d178c1538e
MD5 6c0864b788500e70cf7d32b6b16ef593
BLAKE2b-256 f45dcebcd3c5a19b52122f8bf0e5f02073ec30d8b9ca4394d1a5843de5859f83

See more details on using hashes here.

Provenance

The following attestation bundles were made for airom-0.4.2-py3-none-macosx_11_0_arm64.whl:

Publisher: release-pypi.yml on airomhq/airom

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file airom-0.4.2-py3-none-macosx_10_9_x86_64.whl.

File metadata

File hashes

Hashes for airom-0.4.2-py3-none-macosx_10_9_x86_64.whl
Algorithm Hash digest
SHA256 f5834249dbb661c893eeb7fb064e9601b80a92fb3f5ebfd2bf818732c6f48434
MD5 ba7e742f5352831b86109ba85387dce8
BLAKE2b-256 8f1d50377b25c95c188d9a006dca224d5a7880f24eae26236678eac81e762ed2

See more details on using hashes here.

Provenance

The following attestation bundles were made for airom-0.4.2-py3-none-macosx_10_9_x86_64.whl:

Publisher: release-pypi.yml on airomhq/airom

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.4.4

9 files

0.4.3

9 files

This release

0.4.2 This release

9 files

0.4.1

9 files

0.4.0

9 files

0.3.9

9 files

0.3.8

9 files

0.3.7

8 files

0.3.6

8 files

0.3.5

8 files

0.3.4

8 files

0.3.3

8 files

0.3.2

8 files

0.3.1

8 files

0.3.0

8 files

0.2.2

8 files

0.2.1

8 files

0.2.0

8 files

0.1.9

8 files

0.1.8

8 files

0.1.7

8 files

0.1.6

8 files

0.1.5

8 files

0.1.4

8 files

0.1.3

8 files

0.1.2

8 files

0.1.1

8 files

0.1.0

8 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page