Skip to main content

Turnkey CI verification for Mipiti threat model assertions

Project description

mipiti-verify

Turnkey CI verification for Mipiti threat model assertions. Security controls that never drift.

Install

pip install mipiti-verify[all]

Usage

# Verify all models in the workspace (recommended)
mipiti-verify run --all \
  --api-key $MIPITI_API_KEY \
  --tier2-provider openai \
  --tier2-model gpt-4o-mini \
  --project-root .

# Verify a single model
mipiti-verify run <model_id> \
  --api-key $MIPITI_API_KEY \
  --tier2-provider openai \
  --project-root .

# List pending assertions
mipiti-verify list <model_id>

# Show verification report
mipiti-verify report <model_id>

API keys are workspace-scoped — --all verifies every model accessible by the key.

API key scopes

Prefix Scope Use
mk_ Developer Local development. Runs assertions but does not submit results.
mv_ Verifier CI pipelines. Runs assertions and submits results to update verification status.

Developer keys skip result submission automatically — no --dry-run needed.

Key flags

Flag Default Description
--reverify / --no-reverify --reverify Re-verify all assertions, not just pending. Catches regressions.
--changed-files FILE none Only verify assertions referencing files listed in FILE. Use git diff --name-only HEAD~1 > changed.txt.
--concurrency N 1 Max concurrent Tier 2 LLM calls. Tune based on API rate limits.
--dry-run off Run verifiers but don't submit results.
--output github text Emit GitHub Actions annotations (errors, warnings, notices).
--tier2-provider none AI provider: openai, anthropic, or ollama. Omit for Tier 1 only.
--tier2-model gpt-4o Model name (e.g., gpt-4o-mini, claude-sonnet-4-5-20250514).

GitHub Action

- uses: Mipiti/mipiti-verify@v0.10.0
  with:
    api-key: ${{ secrets.MIPITI_API_KEY }}
    all: true
    tier2-provider: openai
    tier2-model: gpt-4o-mini
    tier2-api-key: ${{ secrets.OPENAI_API_KEY }}

All assertions are re-verified by default. Use reverify: false to only check new assertions (e.g., to reduce Tier 2 API costs on PRs). Omitting tier2-provider runs Tier 1 only — controls won't reach "verified" status without Tier 2.

Development

git clone https://github.com/Mipiti/mipiti-verify.git
cd mipiti-verify
pip install -e ".[dev]"
python -m pytest -v

License

Proprietary. Copyright (c) 2026 Mipiti, LLC. All rights reserved. See LICENSE for details.

Project details


Release history Release notifications | RSS feed

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

mipiti_verify-0.15.0.tar.gz (35.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

mipiti_verify-0.15.0-py3-none-any.whl (32.2 kB view details)

Uploaded Python 3

File details

Details for the file mipiti_verify-0.15.0.tar.gz.

File metadata

  • Download URL: mipiti_verify-0.15.0.tar.gz
  • Upload date:
  • Size: 35.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for mipiti_verify-0.15.0.tar.gz
Algorithm Hash digest
SHA256 60115f936b3fe4ef687b171f3a834e917391dbc4cb7825c1429badf199a2792b
MD5 89a4df0d69f6b7630aff0229989269a9
BLAKE2b-256 1c450fd9f70768824077aa88f2ca75bc8ba9a5a6ec6a12a95d49d4b873eb77de

See more details on using hashes here.

Provenance

The following attestation bundles were made for mipiti_verify-0.15.0.tar.gz:

Publisher: publish.yml on Mipiti/mipiti-verify

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file mipiti_verify-0.15.0-py3-none-any.whl.

File metadata

  • Download URL: mipiti_verify-0.15.0-py3-none-any.whl
  • Upload date:
  • Size: 32.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for mipiti_verify-0.15.0-py3-none-any.whl
Algorithm Hash digest
SHA256 4230cda7357828d51af1f82972d13eb16a5a2971f6886cd665dfb8dd0b6793bc
MD5 ddd180aa3f08feb2c4ccfbbee02d1765
BLAKE2b-256 2af8b949621cf874343512d62e3bb6391f82f4aba0f9f8afcc5270d8170680df

See more details on using hashes here.

Provenance

The following attestation bundles were made for mipiti_verify-0.15.0-py3-none-any.whl:

Publisher: publish.yml on Mipiti/mipiti-verify

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page