snoai-mda-config
Python source-mode loader for MDA v1.0 configuration artifacts.
This package mirrors the TypeScript @snoai/mda-config and Rust
snoai-mda-config loader contract. The v1.0 surface covers frontmatter
extraction, MDA source-schema validation, integrity verification,
requires.network enforcement, trusted-runtime verifier hooks, and
consumer pydantic validation.
Python does not perform real Rekor transport or Sigstore cryptography by
itself. When verify_signatures=True, callers must provide a trust policy,
Rekor client, and Sigstore verifier hook. Missing verifier pieces fail closed.
from pathlib import Path
from pydantic import BaseModel
from snoai_mda_config import load_mda_source
class Preset(BaseModel, extra="forbid"):
name: str
description: str
metadata: dict | None = None
integrity: dict | None = None
signatures: list[dict] | None = None
config = load_mda_source(
Path("preset.mda"),
schema=Preset,
verify_integrity=True,
)
For signed presets, also pass verify_signatures=True,
trust_policy=..., rekor_client=..., and verifier hooks. For production
trusted-runtime loading, prefer trusted_runtime=True with a strict policy:
config = load_mda_source(
Path("preset.mda"),
schema=Preset,
trusted_runtime=True,
trust_policy={
"version": 1,
"trustedSigners": [
{
"type": "sigstore-oidc",
"issuer": "https://token.actions.githubusercontent.com",
"subject": "repo:OWNER/REPO:ref:refs/heads/main",
}
],
"rekor": {"url": "https://rekor.sigstore.dev"},
},
rekor_client=rekor_client,
sigstore_verifier=sigstore_verifier,
)
did:web is supported through a did_web_verifier hook. If a policy trusts
did:web and that hook is absent, loading fails closed with
trust-policy-violation. For capability enforcement, pass
enforce_requires=True with allowed_networks=[...].
Metadata
Release files for snoai-mda-config 1.1.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| snoai_mda_config-1.1.2.tar.gz | 18.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| snoai_mda_config-1.1.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 41.3 kB
Release files / snoai_mda_config-1.1.2.tar.gz
| Download URL | snoai_mda_config-1.1.2.tar.gz |
|---|---|
| Size | 18.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
9e9126a23ea3e568fadc1fd8a9e96d1b06e469fe8628b70c282995117b0c4f24
|
|
BLAKE2b-256 checksum How to use checksums |
ee0fcd643f22414b2c20b5a2388181cfb4c27a7d2840d6272d5efb039cd6fb7b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on May 29, 2026.
Transparency logRelease files / snoai_mda_config-1.1.2-py3-none-any.whl
| Download URL | snoai_mda_config-1.1.2-py3-none-any.whl |
|---|---|
| Size | 23.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b81d79c497a7b1e047ab65ba4ca60f130d725830f4d40ef30d66bd0aa572e1f5
|
|
BLAKE2b-256 checksum How to use checksums |
0b86c3f62dbdec301cad93eb38a24e5cb133cbb86619241afa37d930b066a01e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on May 29, 2026.
Transparency log