Skip to main content

LLM-augmented static code analysis tooling.

Project description

Phase 0 Python Package Skeleton

Phase 0 establishes the package surfaces that later implementation phases use. This repository already contains Phases 1-8, so the Phase 0 pass is additive: existing indexing, storage, MCP, SARIF, plugin, and QA modules remain intact.

Current Phase 0 baseline:

  • Python floor: 3.12.
  • Dependency manager: uv with uv.lock as supply-chain evidence.
  • CLI framework: Typer + Rich.
  • JSONL writers: orjson.
  • Formatting/lint order: isort, black, then ruff.
  • Architecture gate: .importlinter plus uv run lint-imports.

Implemented skeleton surfaces:

  • llm_sca_tooling.config: typed defaults, JSON/TOML loading, environment overrides, and redacted config output.
  • llm_sca_tooling.errors: package-level structured errors.
  • llm_sca_tooling.telemetry: logger setup and JSONL trace writer.
  • llm_sca_tooling.operations: file-backed run-record writer and budget monitor.
  • llm_sca_tooling.governance: permission profiles and policy evaluator.
  • llm_sca_tooling.harness: Harness Condition Sheet writer.
  • llm_sca_tooling.cli.main: Typer/Rich llm-sca-tooling command entrypoint.
  • llm_sca_tooling.plugins.registry.NoOpPlugin: no-op plugin for skeleton registry tests.

The historical evidence-sca CLI remains available for existing graph and MCP commands.

Useful commands:

uv sync --extra dev
llm-sca-tooling --version
llm-sca-tooling version
llm-sca-tooling config show
llm-sca-tooling config validate
llm-sca-tooling harness status
llm-sca-tooling run create demo
make verify
make verify-baseline

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

llm_sca_tooling-0.2.3.tar.gz (1.0 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

llm_sca_tooling-0.2.3-py3-none-any.whl (616.0 kB view details)

Uploaded Python 3

File details

Details for the file llm_sca_tooling-0.2.3.tar.gz.

File metadata

  • Download URL: llm_sca_tooling-0.2.3.tar.gz
  • Upload date:
  • Size: 1.0 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for llm_sca_tooling-0.2.3.tar.gz
Algorithm Hash digest
SHA256 822d16e71d154b7b155c3ab8b37503737d958a0425f89904954b1230a0f602d3
MD5 4040d4989cb693b39248c87367b26d68
BLAKE2b-256 5945d0b68dd73e7b560f264176ade7204c81dbf790629c102c25d7c965c847da

See more details on using hashes here.

Provenance

The following attestation bundles were made for llm_sca_tooling-0.2.3.tar.gz:

Publisher: release.yml on grammy-jiang/evidence-sca

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file llm_sca_tooling-0.2.3-py3-none-any.whl.

File metadata

  • Download URL: llm_sca_tooling-0.2.3-py3-none-any.whl
  • Upload date:
  • Size: 616.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for llm_sca_tooling-0.2.3-py3-none-any.whl
Algorithm Hash digest
SHA256 66ade650ad51e5ecfb0407b718fc29e1706ae047ef1c7fa6037ddc1834c70b6a
MD5 83e0e5eb885a6904ab119cdd4f2e1ff1
BLAKE2b-256 68ef01b0c8684db9ecaa5210e64872788c2bc80bb5823e0626168b47f970f4de

See more details on using hashes here.

Provenance

The following attestation bundles were made for llm_sca_tooling-0.2.3-py3-none-any.whl:

Publisher: release.yml on grammy-jiang/evidence-sca

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page