Skip to main content

PyPI Python CI Supply Chain SLSA L3 Sigstore OpenSSF Scorecard MIT

GODML

Governed, Observable & Declarative Machine Learning Framework

Production-grade MLOps for teams that need traceability, compliance, and a verified supply chain — without the infrastructure overhead.


Quick start

pip install godml
godml init my-project
godml run -f godml.yml

That's it. No cloud account required for local training.


What is GODML?

GODML is a Python framework that wraps the full ML lifecycle — data prep, training, evaluation, monitoring, and deployment — behind a single declarative YAML config. Every run produces a signed, auditable artifact trail.

Raw data → Compliance check → Train → Evaluate → Registry → Deploy → Monitor
               (PII/GDPR)    (XGB/RF/LR)  (cross-val)  (MLflow)  (Docker)  (drift)

Why GODML over plain sklearn + MLflow?

Problem Without GODML With GODML
Reproducibility Manual notebooks Declarative YAML, locked hashes
Compliance Ad-hoc checks Built-in PCI-DSS, GDPR, HIPAA
Supply chain No SBOM SLSA L3 provenance + signed SBOM
Audit trail Scattered logs Unified lineage per run
Multi-model Custom glue code Registry + notebook_api

Installation

Core (no optional deps)

pip install godml

With extras

pip install "godml[advisor]"   # LLM-powered recommendations (gpt4all)
pip install "godml[deep]"      # LSTM forecasting (tensorflow + keras)
pip install "godml[aws]"       # SageMaker deployment
pip install "godml[api]"       # REST inference server (fastapi + uvicorn)
pip install "godml[dev]"       # Full dev suite (tests, lint, coverage)

Configuration

A minimal godml.yml:

name: customer-churn
version: 1.0.0
provider: mlflow

dataset:
  uri: ./data/churn.csv
  hash: auto

model:
  type: xgboost
  hyperparameters:
    max_depth: 6
    learning_rate: 0.1
    n_estimators: 300

metrics:
  - name: auc
    threshold: 0.85
  - name: accuracy
    threshold: 0.80

governance:
  owner: ml-team@company.com
  tags:
    - compliance: gdpr
    - environment: production

deploy:
  realtime: true
  batch_output: ./outputs/predictions.csv

Run it:

godml run -f godml.yml

Notebook API

For interactive work in Jupyter:

from godml import GodmlNotebook

nb = GodmlNotebook()
nb.load_data("./data/churn.csv", target="churn")
nb.train_model("xgboost", {"max_depth": 6, "n_estimators": 300})
nb.evaluate(["auc", "accuracy", "f1"])
nb.save_model("churn_v1")

AI-powered advisor

from godml.notebook_api import advisor_full_report, tune_model

# Get model + metric recommendations for your dataset
report = advisor_full_report(df, target="churn")
print(report["recommended_models"])   # ['xgboost', 'random_forest']
print(report["data_quality"])         # quality score + issues

# Auto-tune with Optuna
result = tune_model(
    model_type="xgboost",
    X=X_train, y=y_train,
    max_trials=50,
    metric="auc",
)
print(f"Best AUC: {result['best_score']:.4f}")

Supported model types

Key Algorithm
xgboost / xgb XGBoost
random_forest / rf scikit-learn RandomForest
logistic_regression / logreg scikit-learn LogisticRegression
lstm LSTM forecasting (requires [deep])

Compliance

from godml.compliance_service import PciDssCompliance, GdprCompliance

compliance = PciDssCompliance()
clean_df = compliance.apply(df)          # masks PAN, CVV, account numbers

gdpr = GdprCompliance()
report = gdpr.apply(df)                  # anonymizes PII per GDPR rules

Built-in compliance modules: PCI-DSS, GDPR, HIPAA, SOX.
Custom rules: subclass BaseCompliance and implement apply(df).


Architecture

┌──────────────────────────────────────────────────────┐
│                    GODML Framework                   │
├────────────────┬─────────────┬───────────────────────┤
│  Interfaces    │  Notebook   │  CLI  │  REST API      │
├────────────────┴─────────────┴───────────────────────┤
│  Core Services                                       │
│  ┌───────────┐ ┌───────────┐ ┌──────────────────────┐│
│  │ Advisor   │ │ Config    │ │ Pipeline Engine      ││
│  └───────────┘ └───────────┘ └──────────────────────┘│
├──────────────────────────────────────────────────────┤
│  ML Services                                         │
│  ┌───────────┐ ┌───────────┐ ┌──────────────────────┐│
│  │ DataPrep  │ │ Model     │ │ Monitoring           ││
│  │ +PII scan │ │ Registry  │ │ +Drift detection     ││
│  └───────────┘ └───────────┘ └──────────────────────┘│
├──────────────────────────────────────────────────────┤
│  Providers:  MLflow │ SageMaker │ Docker │ Local      │
└──────────────────────────────────────────────────────┘

Supply chain & security

GODML ships with a SLSA Level 3 supply chain — every release is built in an isolated GitHub Actions environment with unforgeable provenance.

Artifact Standard Signature Transparency
sbom.spdx.json SPDX 2.3 Cosign OIDC (keyless) Rekor log
sbom.cyclonedx.json CycloneDX 1.6 SLSA provenance GitHub Release assets
provenance.intoto.jsonl SLSA v1 / in-toto slsa-github-generator Rekor log

Verify the SBOM yourself

# Download from GitHub Releases
cosign verify-blob \
  --bundle sbom.spdx.bundle \
  --certificate-identity-regexp "https://github.com/DAGMALIA/godml/.github/workflows/safety_scan.yml" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  sbom.spdx.json

Verify SLSA provenance

slsa-verifier verify-artifact dist/godml-*.whl \
  --provenance-path provenance.intoto.jsonl \
  --source-uri github.com/DAGMALIA/godml \
  --source-tag v1.1.0

CI security controls

Control Tool Status
SAST Bandit ✅ Blocks on HIGH/CRITICAL
Dependency CVEs pip-audit + Safety ✅ Weekly + per PR
SHA-pinned actions Dependabot ✅ Auto-pinned
PyPI publish OIDC Trusted Publisher ✅ No API tokens
Branch protection GitHub Ruleset ✅ PR + status checks
Tag protection GitHub Ruleset ✅ v* immutable
Score OpenSSF Scorecard ✅ Published weekly

CLI reference

godml init <project>         # scaffold new project
godml run -f godml.yml       # execute pipeline from config
godml deploy <project> <env> # deploy model to environment
godml --version              # print version

Roadmap

v1.2.0 — Q3 2026

  • Interactive drift dashboard (Streamlit)
  • A/B testing framework
  • Optuna distributed tuning

v1.3.0 — Q4 2026

  • Kubernetes operator
  • Real-time streaming inference
  • Multi-tenant model registry

v2.0.0 — 2027

  • Multi-cloud provider abstraction (Vertex AI, Azure ML)
  • Federated learning support
  • SOC2 / ISO27001 documentation kit

Contributing

git clone https://github.com/DAGMALIA/godml.git
cd godml
pip install -e ".[dev]"
pytest tests/ --cov=godml

See CONTRIBUTING.md for branch conventions and PR checklist.


License

MIT — see LICENSE.


Built by DAGMALIA · PyPI · Support

Release files for godml 1.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for godml 1.3.0
File Size Uploaded
godml-1.3.0.tar.gz 107.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for godml 1.3.0
File Interpreter ABI Platform
godml-1.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 243.8 kB

Release files / godml-1.3.0.tar.gz

Download URL godml-1.3.0.tar.gz
Size 107.5 kB
Tags Source
SHA-256 checksum
How to use checksums
a581bc7d1520ce100238455fac9f20e0cc0cac8d90d9fb81be6bd81a9bb752d7
BLAKE2b-256 checksum
How to use checksums
e95e52907b91efb6de151495b08eb11ea0554a9cd7eabb7b47f17f85ac908294
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 9, 2026.

Transparency log

Release files / godml-1.3.0-py3-none-any.whl

Download URL godml-1.3.0-py3-none-any.whl
Size 136.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a4fe6ab230696f95e38216998fff36d3b7a7d4a488f2b26dc3da045a1f1000f5
BLAKE2b-256 checksum
How to use checksums
b7b3cf25415bc686bbd631baf6574f19ff0cc59396c7dfbaa54a54b0e901d0a7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 9, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.3.0 This release

2 release files

1.2.4

2 release files

1.2.3

2 release files

1.2.2

2 release files

1.2.1

2 release files

1.2.0

2 release files

1.1.2

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

0.4.9

2 release files

0.4.8

2 release files

0.4.7

2 release files

0.4.6

2 release files

0.4.5

2 release files

0.4.4

2 release files

0.4.3

2 release files

0.4.2

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page