Skip to main content

LLM-augmented static code analysis tooling.

Project description

Phase 0 Python Package Skeleton

Phase 0 establishes the package surfaces that later implementation phases use. This repository already contains Phases 1-8, so the Phase 0 pass is additive: existing indexing, storage, MCP, SARIF, plugin, and QA modules remain intact.

Current Phase 0 baseline:

  • Python floor: 3.12.
  • Dependency manager: uv with uv.lock as supply-chain evidence.
  • CLI framework: Typer + Rich.
  • JSONL writers: orjson.
  • Formatting/lint order: isort, black, then ruff.
  • Architecture gate: .importlinter plus uv run lint-imports.

Implemented skeleton surfaces:

  • llm_sca_tooling.config: typed defaults, JSON/TOML loading, environment overrides, and redacted config output.
  • llm_sca_tooling.errors: package-level structured errors.
  • llm_sca_tooling.telemetry: logger setup and JSONL trace writer.
  • llm_sca_tooling.operations: file-backed run-record writer and budget monitor.
  • llm_sca_tooling.governance: permission profiles and policy evaluator.
  • llm_sca_tooling.harness: Harness Condition Sheet writer.
  • llm_sca_tooling.cli.main: Typer/Rich llm-sca-tooling command entrypoint.
  • llm_sca_tooling.plugins.registry.NoOpPlugin: no-op plugin for skeleton registry tests.

The historical evidence-sca CLI remains available for existing graph and MCP commands.

Useful commands:

uv sync --extra dev
llm-sca-tooling --version
llm-sca-tooling version
llm-sca-tooling config show
llm-sca-tooling config validate
llm-sca-tooling harness status
llm-sca-tooling run create demo
make verify
make verify-baseline

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

llm_sca_tooling-0.2.0.tar.gz (970.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

llm_sca_tooling-0.2.0-py3-none-any.whl (551.6 kB view details)

Uploaded Python 3

File details

Details for the file llm_sca_tooling-0.2.0.tar.gz.

File metadata

  • Download URL: llm_sca_tooling-0.2.0.tar.gz
  • Upload date:
  • Size: 970.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for llm_sca_tooling-0.2.0.tar.gz
Algorithm Hash digest
SHA256 b0d379c17dd5370a7d4308888ab725b6369d14cd2c0d17952b7f8b8b0670354a
MD5 af07ea7ffb3774cdf6b3f11631ae53c8
BLAKE2b-256 db3728e34cadc85ea71269b7666294585acc3c9c1da979332e2c432e9efd366e

See more details on using hashes here.

Provenance

The following attestation bundles were made for llm_sca_tooling-0.2.0.tar.gz:

Publisher: release.yml on grammy-jiang/evidence-sca

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file llm_sca_tooling-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: llm_sca_tooling-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 551.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for llm_sca_tooling-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 2ee5e8969d8ea4e4dc8e755c25b9474e72f5d5797abcd2cae30bd805eadaa386
MD5 a483af7bef6a2473364cb7312fbadcac
BLAKE2b-256 72d452ecd02cfead72e2b11ea2061b0fbf5d3104e5fb8fa113bd979dbcc061f5

See more details on using hashes here.

Provenance

The following attestation bundles were made for llm_sca_tooling-0.2.0-py3-none-any.whl:

Publisher: release.yml on grammy-jiang/evidence-sca

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page