Skip to main content

model-provenance-validator

model-provenance-validator keeps model and release claims attached to small, checkable provenance envelopes. It validates the JSON shape that says what the claim is about, where the reference came from, when it was retrieved, and what validation status a maintainer is willing to publish.

The package has no runtime dependencies. It includes a small schema validator for the envelope shape used by the CLI.

Use it when a README, report, model-card note, release packet, or AI workflow claim needs a source reference before the claim is repeated publicly.

Install

python -m pip install model-provenance-validator

For local development:

python -m pip install -e ".[test]"
python -m pytest

Usage

model-provenance-validator envelope.json
model-provenance-validator envelope.json --json
model-provenance-validator *.provenance.json --summary
model-provenance-validator *.provenance.json --summary --json
model-provenance-validator *.provenance.json --proof-packet
model-provenance-validator *.provenance.json

The command exits with status 1 when any envelope fails validation. Malformed or unreadable envelope files are reported as invalid results so batch runs can continue and produce a complete action list.

Use a custom schema:

model-provenance-validator envelope.json --schema schema.json

Run the bundled example:

model-provenance-validator examples/envelopes/release.provenance.json

Envelope shape

Required top-level fields:

  • envelope_version
  • subject
  • source
  • references
  • validation

Allowed source.kind values:

  • official-doc
  • paper
  • release-note
  • local-fixture
  • other

Allowed validation.status values:

  • verified
  • partial
  • unknown

Minimal valid envelope

{
  "envelope_version": "1",
  "subject": "public-surface-sweeper README claim",
  "source": {
    "name": "public-surface-sweeper README",
    "kind": "release-note"
  },
  "references": [
    {
      "name": "Repository README",
      "locator": "https://github.com/HarperZ9/public-surface-sweeper",
      "retrieved_at": "2026-06-13"
    }
  ],
  "validation": {
    "status": "verified",
    "notes": "Claim checked against the public README surface."
  }
}

Example text output

release.provenance.json: valid
draft.provenance.json: invalid
  $.references: expected at least 1 item(s)

Example JSON output

[
  {
    "path": "release.provenance.json",
    "valid": true,
    "errors": []
  }
]

Example summary output

total: 3
valid: 2
invalid: 1
error_count: 1
action_items:
- draft.provenance.json: resolve 1 validation error(s)

Proof-surface packet output

Use --proof-packet when provenance validation should feed repo-proof-index or a release-readiness report. The packet follows the shared proof-surface interop shape: claims, checks, and action items in one JSON object. The generated packet is self-checked before printing so producer drift fails before entering the pipeline.

model-provenance-validator *.provenance.json --proof-packet > provenance.packet.json
repo-proof-index provenance.packet.json --summary

What it validates

  • required fields;
  • JSON object and array shape;
  • non-empty string fields where required;
  • exact constants such as envelope_version: "1";
  • enum values for source kind and validation status;
  • unexpected fields when additionalProperties is false.

What it does not do

  • It does not fetch the referenced source.
  • It does not decide whether the underlying claim is true.
  • It does not prove a model is safe.
  • It does not certify provenance.
  • It does not replace human review of the referenced material.

Release-readiness use

model-provenance-validator is the provenance-envelope point in a proof-surface pipeline:

claim -> source reference -> provenance envelope -> validation result -> proof index

Its job is to keep model/reference claims from floating without a source, retrieval date, and validation status.

Authorship

Created and maintained by Zain Dana Harper. Claude Code contributed to the initial implementation.

Release files for model-provenance-validator 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for model-provenance-validator 0.1.1
File Size Uploaded
model_provenance_validator-0.1.1.tar.gz 10.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for model-provenance-validator 0.1.1
File Interpreter ABI Platform
model_provenance_validator-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 20.2 kB

Release files / model_provenance_validator-0.1.1.tar.gz

Download URL model_provenance_validator-0.1.1.tar.gz
Size 10.5 kB
Tags Source
SHA-256 checksum
How to use checksums
c6016fe79e6653b7f474088f31c666139abb0da7840ae9e5531803055aef6271
BLAKE2b-256 checksum
How to use checksums
e7ee8446a8df6107f63d86b9bad1cd96df4f1b54ae8c0258c5bcdbd4207d92b8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 14, 2026.

Transparency log

Release files / model_provenance_validator-0.1.1-py3-none-any.whl

Download URL model_provenance_validator-0.1.1-py3-none-any.whl
Size 9.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
cd8dc7f141e3c26057fc908b68fbe3052aba66da2d52b05b5a64a36cd44cad8c
BLAKE2b-256 checksum
How to use checksums
52ab07a4c2d1ff4cfd08af3efaf215beb622413116f40984d51c95413ad18834
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 14, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page