Skip to main content

Jarvis Core

Validate Release PyPI Python License: MIT

jarvis-agent-core is the small typed dependency-free Python contract/runtime library shared by standalone Jarvis and AI Stack Server. It standardizes portable agent behavior without owning product-specific tools, storage, credentials, deployment policy or OS isolation.

Install

Python 3.10+ is required. The current coordinated release is 0.9.5:

python -m pip install "jarvis-agent-core==0.9.5"

For development:

git clone https://github.com/abdullahalrifat/jarvis-core.git
cd jarvis-core
python -m pip install -e . -r requirements-dev.txt
python -m pytest

Capabilities

Core provides typed deterministic contracts/primitives for token accounting, context compaction, artifacts, evidence/verification, model routing/calibration, failure recovery, multi-agent orchestration, instructions/memory, MCP permissions, schedules/remote execution, leases, proof records, citations and evaluation cases. The 0.9.5 line also exposes the shared per-task sandbox policy used by Jarvis and AI Stack Server.

Core deliberately does not access repositories, execute commands, call model endpoints, start MCP processes, persist product sessions, run cloud workers, enforce tenancy, or approve changes. Jarvis/Server must wire contracts into the real execution path; OS sandbox enforcement remains a consumer/runtime responsibility.

See docs/contract-boundaries.md for the enforcement and trust boundary.

Contract enforcement matters

A Core field is not automatically a security control. Consumers must enforce approval before dispatch, durable lease predicates for cloud state, real execution-derived proof, and credential isolation. Independent evidence must also have a verifiable identity and must not be satisfied by reference-only or duplicate evidence for the same claim.

Compatibility and release policy

  • semantic versioning is used while the pre-1.0 API stabilizes;
  • patch releases should remain compatible within a minor line;
  • breaking contracts require coordinated Core/Jarvis/Server releases;
  • publish Core first, then pin consumers to the released package version;
  • an existing GitHub Release is never silently replaced;
  • PyPI publication uses GitHub Actions Trusted Publishing; no long-lived PyPI API token is stored in GitHub.

Current coordinated line:

Core Jarvis AI Stack Server Python
0.9.5 0.9.2 0.9.5 consumer 3.10+

Development

black --check src tests
ruff check src tests --select E9,F63,F7,F82
pytest -q --cov=jarvis_core --cov-report=term-missing --cov-fail-under=85
python -m build
python -m twine check dist/*

Read CONTRIBUTING.md, CODE_OF_CONDUCT.md, SUPPORT.md and SECURITY.md before contributing/reporting issues.

Releases and supply chain

A version bump merged to main is validated against the exact commit, built as a wheel and sdist, checked with Twine, smoke-tested in a clean environment, checksummed, provenance-attested and published as a GitHub Release. The same release workflow then publishes the exact validated distributions to PyPI using Trusted Publishing. Existing immutable releases are never replaced.

Release flow

merge to main
    -> validate + test
    -> build wheel/sdist
    -> clean-environment install check
    -> SHA-256 checksums + provenance attestation
    -> GitHub Release vX.Y.Z
    -> PyPI Trusted Publishing

Consumers should depend on the PyPI package rather than a Git checkout or mutable branch. During local development, use an editable install of a checked-out jarvis-core repository.

License

Jarvis Core is available under the MIT License.

Metadata

Release files for jarvis-agent-core 0.10.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for jarvis-agent-core 0.10.0
File Size Uploaded
jarvis_agent_core-0.10.0.tar.gz 49.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for jarvis-agent-core 0.10.0
File Interpreter ABI Platform
jarvis_agent_core-0.10.0-py3-none-any.whl Python 3 none any Details

Total release size: 99.6 kB

Release files / jarvis_agent_core-0.10.0.tar.gz

Download URL jarvis_agent_core-0.10.0.tar.gz
Size 49.5 kB
Tags Source
SHA-256 checksum
How to use checksums
b7d9bc8e89fe19cf30b758b6158a01d40869a588a23668a63185e50d580f7e1c
BLAKE2b-256 checksum
How to use checksums
9f25d584d72fb4da35fd1a39624359981a9ad0b51a9a6c8189fa6ac8bae51936
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 12, 2026.

Transparency log

Release files / jarvis_agent_core-0.10.0-py3-none-any.whl

Download URL jarvis_agent_core-0.10.0-py3-none-any.whl
Size 50.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3875a01e57f534a9c61ed486a8fa8f2c0854b60bb7ca7d5bcbbd4333f9136bff
BLAKE2b-256 checksum
How to use checksums
f6513483f4888c39c3da2e2ca30c16a2c91af14ea98238f65fb253ad7de2fee2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 12, 2026.

Transparency log

Release history Release notifications | RSS feed

0.16.1

2 release files

0.16.0

2 release files

0.15.0

2 release files

0.14.0

2 release files

0.13.0

2 release files

0.12.0

2 release files

0.11.0

2 release files

0.10.1

2 release files

This release

0.10.0 This release

2 release files

0.9.5

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page