Skip to main content

LLM-augmented static code analysis tooling.

Project description

Phase 0 Python Package Skeleton

Phase 0 establishes the package surfaces that later implementation phases use. This repository already contains Phases 1-8, so the Phase 0 pass is additive: existing indexing, storage, MCP, SARIF, plugin, and QA modules remain intact.

Current Phase 0 baseline:

  • Python floor: 3.12.
  • Dependency manager: uv with uv.lock as supply-chain evidence.
  • CLI framework: Typer + Rich.
  • JSONL writers: orjson.
  • Formatting/lint order: isort, black, then ruff.
  • Architecture gate: .importlinter plus uv run lint-imports.

Implemented skeleton surfaces:

  • llm_sca_tooling.config: typed defaults, JSON/TOML loading, environment overrides, and redacted config output.
  • llm_sca_tooling.errors: package-level structured errors.
  • llm_sca_tooling.telemetry: logger setup and JSONL trace writer.
  • llm_sca_tooling.operations: file-backed run-record writer and budget monitor.
  • llm_sca_tooling.governance: permission profiles and policy evaluator.
  • llm_sca_tooling.harness: Harness Condition Sheet writer.
  • llm_sca_tooling.cli.main: Typer/Rich llm-sca-tooling command entrypoint.
  • llm_sca_tooling.plugins.registry.NoOpPlugin: no-op plugin for skeleton registry tests.

The historical evidence-sca CLI remains available for existing graph and MCP commands.

Useful commands:

uv sync --extra dev
llm-sca-tooling --version
llm-sca-tooling version
llm-sca-tooling config show
llm-sca-tooling config validate
llm-sca-tooling harness status
llm-sca-tooling run create demo
make verify
make verify-baseline

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

llm_sca_tooling-0.1.0.tar.gz (969.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

llm_sca_tooling-0.1.0-py3-none-any.whl (551.2 kB view details)

Uploaded Python 3

File details

Details for the file llm_sca_tooling-0.1.0.tar.gz.

File metadata

  • Download URL: llm_sca_tooling-0.1.0.tar.gz
  • Upload date:
  • Size: 969.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for llm_sca_tooling-0.1.0.tar.gz
Algorithm Hash digest
SHA256 9e6687295ab5ab2021c64b03cc2a7f41916d8bdfb84604a7f2bd633af3cd4b35
MD5 917d93b6f6e0b0c7b71e1033b7d9cb0a
BLAKE2b-256 5a8677364d4684f9d6031e73ab10332b3e3ffa6f44c225602f9aa03f5d458986

See more details on using hashes here.

Provenance

The following attestation bundles were made for llm_sca_tooling-0.1.0.tar.gz:

Publisher: release.yml on grammy-jiang/evidence-sca

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file llm_sca_tooling-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: llm_sca_tooling-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 551.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for llm_sca_tooling-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 82644e27a9414c6fee26ef8c84229ae967d079cfc7cf01bf7e666670a15f6474
MD5 c5d561b67cf005fd6aa789e821397804
BLAKE2b-256 ba0819ef1a64c42ff74564e2c81ec79e45f3abd4df5090eeaa9093291abf8bf5

See more details on using hashes here.

Provenance

The following attestation bundles were made for llm_sca_tooling-0.1.0-py3-none-any.whl:

Publisher: release.yml on grammy-jiang/evidence-sca

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page