loremfile
Download loremfile.dev sample files and check every byte against the published manifest.
$ pip install loremfile
$ loremfile get pdf/minimal.pdf mp4/720p-5s.mp4
written mp4/720p-5s.mp4 1,974,574 bytes
written pdf/minimal.pdf 317 bytes
files=2, dest=loremfile-fixtures
Everything it does can be done with curl and sha256sum -c. What it adds is doing it
correctly by default: every file is verified, and a file that fails is not written.
Commands
| Command | |
|---|---|
loremfile get PATH… |
Download those fixtures into --dest (default loremfile-fixtures), verifying each. |
loremfile get --format svg --format pdf |
The same for every published file of a format. |
loremfile list [--format F] [--tag T] [--max-bytes N] |
What is published, without downloading. |
loremfile verify [PATH…] |
Check files already on disk against the manifest. |
Every command takes --json for scripts, --quiet, and --catalog-version X.Y.Z to
refuse to run if loremfile.dev has moved on. get also takes --force (overwrite) and
--dry-run (what it would fetch, and how many bytes).
Exit codes: 0 fine, 1 a file failed verification or is missing, 2 the request was
wrong, 3 loremfile.dev could not be read.
What it will not do
- Write a file it could not verify. There is no
--no-verify. - Talk to any host but loremfile.dev. No mirror option, and redirects off the host are not followed.
- Take credentials. Nothing it does needs authentication, so it accepts none.
- Exceed the published rate limit: one file at a time, a pause between them, and a 429 is waited out rather than retried tightly.
- Generate fixtures. Those are built in a pinned toolchain image; a client that made its own would produce different bytes and undermine the only promise the project makes.
Python versions
3.11, 3.12, 3.13 and 3.14, tested in CI on Linux, macOS and Windows. The floor is the oldest CPython still receiving security fixes when a release is cut; a new one is supported within six weeks of its release, and an end-of-life one is dropped in the next minor release.
Zero dependencies — standard library only.
In GitHub Actions, prefer the action
- uses: kumarprabhashanand/loremfile/action@action-v1
with:
paths: pdf/minimal.pdf mp4/720p-5s.mp4
It is shell only and needs no install step. This client is for everywhere else: a laptop,
a Makefile, a CI system that is not Actions, or Windows — which the action does not
support because it needs sha256sum.
One name, two tools
The console script installed here is loremfile, which is also the name of the
repository's own development CLI (the one that generates and publishes the fixtures).
They are never installed together — that tool lives only inside the project's toolchain
image — but a contributor who installs both into one environment gets whichever was
installed last. The published package contains the client only: no generators, no
validators, no uploader, no infrastructure code.
Licence
MIT for the client; the files it downloads are CC0.
Release files for loremfile 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| loremfile-0.1.0.tar.gz | 13.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| loremfile-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 23.5 kB
Release files / loremfile-0.1.0.tar.gz
| Download URL | loremfile-0.1.0.tar.gz |
|---|---|
| Size | 13.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a8d99adbbbabaabdeecfefa5b6feaf124a5a85212d3ae52f84e5f1f4ea66b8fd
|
|
BLAKE2b-256 checksum How to use checksums |
c08220f58c8f330e3b821e5a87cc2f757fe25ee43011efc019373ee7dcd06c8d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.
Transparency logRelease files / loremfile-0.1.0-py3-none-any.whl
| Download URL | loremfile-0.1.0-py3-none-any.whl |
|---|---|
| Size | 10.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d2c908db2add2bfc1c7f9dd541daecc84b69a4189e19459f9fc195569401a038
|
|
BLAKE2b-256 checksum How to use checksums |
83d23a2ddf2969435348260409ac74989a9c4bb5846a7eebd8d78eb35574be16
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.
Transparency log