RegShape
Icon by @graffitonic on Instagram. Previous icon available here.
RegShape (from REGistry reSHAPE) is a CLI tool and a Python library for manipulating artifacts in an OCI registry. While there are many other tools that can do this (see ORAS, regclient, or Google's crane), the goal of RegShape is to provide flexibility to manipulate the requests with an intention to break the consistency of the artifacts.
You can use RegShape in two modes:
- Standard mode — interact with registries as you would with any other tool: pull and push manifests, blobs, tags, and more.
- Expert / break mode — manually craft requests to test registry implementations and probe their security boundaries.
RegShape is written in Python and offers Python libraries that can be leveraged to build your own tools. The CLI is built on top of the libraries and uses the Click framework.
Note: The tool is still in early development and the API is not stable yet.
Installation
git clone https://github.com/toddysm/regshape.git
cd regshape
pip install -e .
Quick Start
Ping a registry to verify connectivity:
regshape ping registry-1.docker.io
Retrieve a manifest:
regshape manifest get -i docker.io/library/alpine:latest
List tags for a repository:
regshape tag list -i docker.io/library/alpine
Documentation
Guides
Architecture & Design
CLI Command Specs
| Command | Spec |
|---|---|
| Auth | specs/cli/auth.md |
| Blob | specs/cli/blob.md |
| Catalog | specs/cli/catalog.md |
| Manifest | specs/cli/manifest.md |
| Tag | specs/cli/tag.md |
| Referrer | specs/cli/referrer.md |
| Ping | specs/cli/ping.md |
| Layout | specs/cli/layout.md |
| Layout Push | specs/cli/layout-push.md |
| Formatting | specs/cli/formatting.md |
Library Specs
- Models — Blob, Catalog, Error, Manifest, Referrer, Tags
- Operations — Blobs, Catalog, Manifests, Referrers, Tags
Contributing
See CONTRIBUTING.md for instructions on setting up your development environment.
Security
To report a vulnerability, please see SECURITY.md.
License
This project is licensed under the Apache License 2.0 — see the LICENSE file for details.
Metadata
Release files for regshape 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| regshape-0.1.1.tar.gz | 168.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| regshape-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 387.2 kB
Release files / regshape-0.1.1.tar.gz
| Download URL | regshape-0.1.1.tar.gz |
|---|---|
| Size | 168.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ec73e915b34428c554ced528a37d5c40fcc1d0bb9b0300431a94da77e42afab1
|
|
BLAKE2b-256 checksum How to use checksums |
6aa2890a8e938199d0d0af10c8e62a81767cfa8168b22bb15c568073ec7d5dab
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on May 18, 2026.
Transparency logRelease files / regshape-0.1.1-py3-none-any.whl
| Download URL | regshape-0.1.1-py3-none-any.whl |
|---|---|
| Size | 218.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d3c0550a0d8cac7f58472329d05b723f8d10bffcbcc24eab5b3e344bff0ef385
|
|
BLAKE2b-256 checksum How to use checksums |
6ea4045a26c5a47a05e2384bc5bf228f7862cd421e55e4484b5c4454c6dfca5e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on May 18, 2026.
Transparency log