Skip to main content

snoai-mda-config

Python source-mode loader for MDA v1.0 configuration artifacts.

This package mirrors the TypeScript @snoai/mda-config and Rust snoai-mda-config loader contract. The v1.0 surface covers frontmatter extraction, MDA source-schema validation, integrity verification, requires.network enforcement, trusted-runtime verifier hooks, and consumer pydantic validation.

Python does not perform real Rekor transport or Sigstore cryptography by itself. When verify_signatures=True, callers must provide a trust policy, Rekor client, and Sigstore verifier hook. Missing verifier pieces fail closed.

from pathlib import Path
from pydantic import BaseModel
from snoai_mda_config import load_mda_source


class Preset(BaseModel, extra="forbid"):
    name: str
    description: str
    metadata: dict | None = None
    integrity: dict | None = None
    signatures: list[dict] | None = None


config = load_mda_source(
    Path("preset.mda"),
    schema=Preset,
    verify_integrity=True,
)

For signed presets, also pass verify_signatures=True, trust_policy=..., rekor_client=..., and verifier hooks. For production trusted-runtime loading, prefer trusted_runtime=True with a strict policy:

config = load_mda_source(
    Path("preset.mda"),
    schema=Preset,
    trusted_runtime=True,
    trust_policy={
        "version": 1,
        "trustedSigners": [
            {
                "type": "sigstore-oidc",
                "issuer": "https://token.actions.githubusercontent.com",
                "subject": "repo:OWNER/REPO:ref:refs/heads/main",
            }
        ],
        "rekor": {"url": "https://rekor.sigstore.dev"},
    },
    rekor_client=rekor_client,
    sigstore_verifier=sigstore_verifier,
)

did:web is supported through a did_web_verifier hook. If a policy trusts did:web and that hook is absent, loading fails closed with trust-policy-violation. For capability enforcement, pass enforce_requires=True with allowed_networks=[...].

Metadata

Release files for snoai-mda-config 1.1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for snoai-mda-config 1.1.2
File Size Uploaded
snoai_mda_config-1.1.2.tar.gz 18.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for snoai-mda-config 1.1.2
File Interpreter ABI Platform
snoai_mda_config-1.1.2-py3-none-any.whl Python 3 none any Details

Total release size: 41.3 kB

Release files / snoai_mda_config-1.1.2.tar.gz

Download URL snoai_mda_config-1.1.2.tar.gz
Size 18.2 kB
Tags Source
SHA-256 checksum
How to use checksums
9e9126a23ea3e568fadc1fd8a9e96d1b06e469fe8628b70c282995117b0c4f24
BLAKE2b-256 checksum
How to use checksums
ee0fcd643f22414b2c20b5a2388181cfb4c27a7d2840d6272d5efb039cd6fb7b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on May 29, 2026.

Transparency log

Release files / snoai_mda_config-1.1.2-py3-none-any.whl

Download URL snoai_mda_config-1.1.2-py3-none-any.whl
Size 23.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b81d79c497a7b1e047ab65ba4ca60f130d725830f4d40ef30d66bd0aa572e1f5
BLAKE2b-256 checksum
How to use checksums
0b86c3f62dbdec301cad93eb38a24e5cb133cbb86619241afa37d930b066a01e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on May 29, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.1.2 This release

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page