Skip to main content

LLM-augmented static code analysis tooling.

Project description

Phase 0 Python Package Skeleton

Phase 0 establishes the package surfaces that later implementation phases use. This repository already contains Phases 1-8, so the Phase 0 pass is additive: existing indexing, storage, MCP, SARIF, plugin, and QA modules remain intact.

Current Phase 0 baseline:

  • Python floor: 3.12.
  • Dependency manager: uv with uv.lock as supply-chain evidence.
  • CLI framework: Typer + Rich.
  • JSONL writers: orjson.
  • Formatting/lint order: isort, black, then ruff.
  • Architecture gate: .importlinter plus uv run lint-imports.

Implemented skeleton surfaces:

  • llm_sca_tooling.config: typed defaults, JSON/TOML loading, environment overrides, and redacted config output.
  • llm_sca_tooling.errors: package-level structured errors.
  • llm_sca_tooling.telemetry: logger setup and JSONL trace writer.
  • llm_sca_tooling.operations: file-backed run-record writer and budget monitor.
  • llm_sca_tooling.governance: permission profiles and policy evaluator.
  • llm_sca_tooling.harness: Harness Condition Sheet writer.
  • llm_sca_tooling.cli.main: Typer/Rich llm-sca-tooling command entrypoint.
  • llm_sca_tooling.plugins.registry.NoOpPlugin: no-op plugin for skeleton registry tests.

The historical evidence-sca CLI remains available for existing graph and MCP commands.

Useful commands:

uv sync --extra dev
llm-sca-tooling --version
llm-sca-tooling version
llm-sca-tooling config show
llm-sca-tooling config validate
llm-sca-tooling harness status
llm-sca-tooling run create demo
make verify
make verify-baseline

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

llm_sca_tooling-0.2.1.tar.gz (971.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

llm_sca_tooling-0.2.1-py3-none-any.whl (552.0 kB view details)

Uploaded Python 3

File details

Details for the file llm_sca_tooling-0.2.1.tar.gz.

File metadata

  • Download URL: llm_sca_tooling-0.2.1.tar.gz
  • Upload date:
  • Size: 971.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for llm_sca_tooling-0.2.1.tar.gz
Algorithm Hash digest
SHA256 f6550261c61831b18782a5e88b5584545abd532883af4a1eca56ef77d8541753
MD5 bde0ef90ce1f7bca974a08d587810a12
BLAKE2b-256 d0bbda3b55e1b17cd36eb5c5d401ce678b7cec67b9ef98757acdd8d57e58645e

See more details on using hashes here.

Provenance

The following attestation bundles were made for llm_sca_tooling-0.2.1.tar.gz:

Publisher: release.yml on grammy-jiang/evidence-sca

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file llm_sca_tooling-0.2.1-py3-none-any.whl.

File metadata

  • Download URL: llm_sca_tooling-0.2.1-py3-none-any.whl
  • Upload date:
  • Size: 552.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for llm_sca_tooling-0.2.1-py3-none-any.whl
Algorithm Hash digest
SHA256 11a30bc0e246fbd2ae4482194b07a5107e3dd53a506c24d7741112c8671c5090
MD5 d3f8b1ff124abf6897548a542d4b0460
BLAKE2b-256 2ece698a660161885b1ac13e7d06e8c9d2f94d4dbf354aa48e25ffcfbdb042f7

See more details on using hashes here.

Provenance

The following attestation bundles were made for llm_sca_tooling-0.2.1-py3-none-any.whl:

Publisher: release.yml on grammy-jiang/evidence-sca

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page