occam-gitignore
Deterministic, content-addressed .gitignore generator. Given the same project
tree, always produces the same output, byte-for-byte, with a provenance_hash
header so any third party can verify the result was generated by an honest
implementation of the algorithm.
pipx install occam-gitignore
occam-gitignore apply /path/to/repo # merge into .gitignore, keeping your own lines
occam-gitignore generate /path/to/repo # preview the canonical output on stdout
Why deterministic?
A .gitignore is part of your repo's reproducible build surface. If two
checkouts of the same commit produce different ignore files, your CI is lying.
occam-gitignore fingerprints the project tree, runs a pure function over a
content-addressed templates table + a versioned mined-rules table, and emits an
ignore file annotated with hashes of every input. No I/O ordering, no clock,
no hostname.
Guarantees
- Determinism: identical inputs ⇒ identical bytes (UTF-8, LF, single trailing newline). Property-tested with Hypothesis (P1–P7) and validated by a 32-case conformance suite that any external implementation can run.
- Content addressing: templates and rules table carry
sha256:<12-hex>versions; mismatched declarations are rejected at load time. - Provenance: every emitted
.gitignoreincludes a header with the fullprovenance_hash(Merkle of core + templates + rules_table + content) so drift is onegrepaway. - Supply chain: every release ships with an SPDX SBOM and a SLSA Level 3 build provenance attestation.
Links
- Source: https://github.com/fabriziosalmi/gitignore
- Conformance spec: see
conformance/SPEC.md - Algorithm reference: pure Python in
occam-gitignore-core
MIT licensed.
Metadata
Release files for occam-gitignore 0.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| occam_gitignore-0.4.0.tar.gz | 11.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| occam_gitignore-0.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 27.4 kB
Release files / occam_gitignore-0.4.0.tar.gz
| Download URL | occam_gitignore-0.4.0.tar.gz |
|---|---|
| Size | 11.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
711c3db3d20e8e991495ad634414094fed34942137e6b8c359a636fd7870594b
|
|
BLAKE2b-256 checksum How to use checksums |
b3c735497a2ff48ed8f8c2ecc78b2c7633a8323af2eb280dd6b15aa9c6286deb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / occam_gitignore-0.4.0-py3-none-any.whl
| Download URL | occam_gitignore-0.4.0-py3-none-any.whl |
|---|---|
| Size | 16.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d8df93bfea71ae180b01d31eb4b8b883fad6c332d806b5a6249e4bd679b1a259
|
|
BLAKE2b-256 checksum How to use checksums |
24a9fe8ede3d849a2e2ec29af7644db0522f38e196f8014899f6bf1c249e32ef
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency log