Skip to main content

Ladex

A bill of lading for AI.

version 0.1.0 GitHub stars license MIT python 3.12+ tests 139 passing CycloneDX ML-BOM EU AI Act Art. 50


You already require a bill of lading for physical cargo and an SBOM for software. Ladex is the one for AI — it records what AI is aboard your codebase, from whom, and under what terms, captured at the moment the code is written rather than discovered after the fact.

Ladex is a shift-left AI governance tool for developers. When you write an AI-relevant line of code — importing an agent framework, loading a Hugging Face model, calling an inference API, provisioning a GPU node pool in Terraform — Ladex detects it and answers three questions:

  1. What is this?  model / dataset / agent framework / vector store / inference API
  2. What does it obligate?  EU AI Act Art. 50 disclosure, Annex III high-risk triggers
  3. What's auto-verifiable vs. what needs a human?  CVEs and licenses resolve automatically. Training-data provenance and consent basis can't be derived by any scanner — they're flagged UNDOCUMENTED and require a signed human attestation, never a fake green checkmark.

The output is a CycloneDX ML-BOM committed to your repo, diffable in PRs, with signed attestations for the fields no tool can derive.

Ladex records what's aboard; it does not block attacks.

What it does

detect (Python + Terraform + Kubernetes)
  → enrich    PyPI licenses · OSV CVEs · Hugging Face model cards   (cached, offline-capable)
  → obligate  EU AI Act Art. 50 — applies / may-apply / silent; derivable vs. attestation
  → BOM       deterministic CycloneDX ML-BOM that diffs cleanly in PRs
  → attest    in-toto/DSSE signature fills an UNDOCUMENTED gap with a verifiable declaration

surfaces:  CLI   +   VS Code (LSP, inline diagnostics as you type)   — one shared engine

Install

Requires uv and Python 3.12.

git clone https://github.com/aibhuyan/ladex
cd ladex
uv sync
uv run ladex --version

Quickstart

# See every AI component in a repo (silent on non-AI code)
uv run ladex scan path/to/repo

# Add real facts: licenses, CVEs, model cards (cached; --offline works from cache)
uv run ladex scan path/to/repo --enrich

# What does it obligate under the EU AI Act? (declare project facts to resolve "may apply")
uv run ladex policy check path/to/repo --user-facing

# Produce the committable, deterministic ML-BOM
uv run ladex scan path/to/repo --write-bom aibom.cdx.json

# Sign a human answer for a gap no scanner can fill, then verify it
uv run ladex attest "sentence-transformers/all-MiniLM-L6-v2" \
    --claim provenance --value "Curated public corpora, reviewed 2026-08"
uv run ladex verify

Example

app.py
   7:10  inference_api    openai.client       openai.OpenAI (OpenAI)
  12:9   model            openai.model-id     gpt-4o (OpenAI)

infra/main.tf
  20:1   vector_store     iac.tf.vector-store-unencrypted   HIGH   aws_opensearch_domain.vectors
                                                                   - Vector store is not encrypted at rest

Summary: 3 detection(s) across 2 of 2 file(s) scanned.

In your editor

The VS Code extension is a thin client over the same engine — inline diagnostics as you type, nothing on non-AI code. Install it, no repo checkout needed:

  1. Install the engine so the extension can call it: pip install ladex (or uv tool install ladex).
  2. Grab ladex-<version>.vsix from the Releases page → Extensions panel → Install from VSIX… (Marketplace listing coming soon).

Then open any Python file that uses an AI library. See extensions/vscode/README.md for configuration and development.

Design principles

  • One engine, three surfaces. The IDE, CLI, and (v2) PR check all call the same Python engine — the editor can never disagree with the gate.
  • Ruthless silence. If a line isn't AI-relevant, Ladex says nothing.
  • Honest gaps. UNDOCUMENTED is a valid, valuable output. A green checkmark only appears when something was actually verified — or signed by a named human.
  • Policy as versioned data. Taxonomy and EU AI Act rules are updatable bundles, not code.

Scope (v1)

Python + Terraform + Kubernetes detection. EU AI Act. Two surfaces (CLI + VS Code). The GitHub PR check and evidence graph are v2.

Development

uv run ruff check .
uv run mypy
uv run pytest

Pre-commit (ruff + mypy) runs on every commit; run uv run pre-commit install once.

License

MIT — see LICENSE.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ladex-0.1.0.tar.gz (259.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ladex-0.1.0-py3-none-any.whl (62.4 kB view details)

Uploaded Python 3

File details

Details for the file ladex-0.1.0.tar.gz.

File metadata

  • Download URL: ladex-0.1.0.tar.gz
  • Upload date:
  • Size: 259.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.11.23 {"installer":{"name":"uv","version":"0.11.23","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

File hashes

Hashes for ladex-0.1.0.tar.gz
Algorithm Hash digest
SHA256 c52bde2b5c8cd6a7f8bc343b838f1dbcce1a55e1cd92a1c880a8d55c2b8bfae6
MD5 229d70b04aaf9409bd3f8c9a13b995ca
BLAKE2b-256 0d5dcd3d3448a614c7acdc67065724ff1506843084352c40e101221902aee551

See more details on using hashes here.

File details

Details for the file ladex-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: ladex-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 62.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.11.23 {"installer":{"name":"uv","version":"0.11.23","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

File hashes

Hashes for ladex-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 9cbdc248867c7e1890340de7ca208a4f52e03b82fd20e9e384a2f47638c0a264
MD5 1c602297e267566a5164daacb60c612a
BLAKE2b-256 93f17534dd8bb84069da3eb5be66ca733ae4d94780a1812e71181894c4043cdd

See more details on using hashes here.

Release history Release notifications | RSS feed

0.2.0

2 files

0.1.4

2 files

0.1.3

2 files

0.1.2

2 files

0.1.1

2 files

This release

0.1.0 This release

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page