This release is a pre-release and may not be stable for production use.
Sourcebound
Sourcebound is a documentation engine and CLI for maintainers who need code and prose to change together. It binds selected claims to their defining sources, so drifted documentation fails locally and in CI instead of reaching readers.
Install the stable release and catch your first stale claim.
The final sourcebound verify command prints a sourcebound.outcome.v2 receipt with "ok": true.
Before adoption, audit reports bounded repository-neutral advisories. A manifest turns integrity checks into gates; policy markers opt compatible writing rules into specific documents. Neither authorizes Sourcebound to flatten repository-native forms.
| If you need to... | Start with | You will leave with... |
|---|---|---|
| Try the repair loop | Runnable tutorial | A failed drift check and a repaired page |
| Choose a command | CLI reference | The command and its write boundary |
| Configure a binding | Manifest reference | A source-bound fact with the right depth |
| Review a pull request | Coverage-stating verdict | One pinned state with gaps, skips, and non-claims visible |
| Turn a review issue into tests | Improvement candidates | Separate documentation and product tests without gate authority |
| Evaluate human or agent tasks | Evaluation guide | A replayable result bound to its context and scorer |
| Build grounded release notes | Release guide | A factual delta with source evidence |
| Measure recurring operational problems | Opt-in feedback loop | Bounded envelopes and a receipted improvement case |
| Understand trust boundaries | Security model | The process and host guarantees |
Why Sourcebound exists
A stale sentence does not fail loudly. It keeps a straight face after the code has moved on, and reviewers have no mechanical way to identify the false claim. Sourcebound gives each protected fact a source, then checks that relationship again in CI.
Declared sources own the protected facts. A packaged policy enforces the deterministic form floor; authored judgment still owns motivation, pedagogy, and voice. Static adapters read common code and schema formats, while declared commands run under explicit process controls. The engine can repair bound regions, rank static count and column candidates, enforce accepted source-claim relationships, and project canonical text and visual records into purpose-built human and agent surfaces with local receipts.
Human review can improve a sentence. It cannot make the sentence fail when its defining source changes. The deterministic seam explains how Sourcebound separates source evidence, optional phrasing, and gate authority.
Install in the repository you want to protect
From that repository, download the latest stable wheel, install it in an isolated environment, and run the manifest-free audit:
release_dir="$(mktemp -d)"
gh release download --repo owieschon/sourcebound \
--pattern 'sourcebound-*-py3-none-any.whl' --dir "$release_dir"
python3 -m venv .venv
source .venv/bin/activate
python -m pip install "$release_dir"/sourcebound-*.whl
sourcebound audit
After reviewing the assessment, inspect the files that init proposes before accepting its gate:
sourcebound init --no-model
git diff -- .sourcebound.yml .sourcebound/repository-surface.md README.md llms.txt
sourcebound check
sourcebound verify
An established, unregistered README stays byte-for-byte authored. Init writes its detected catalog to .sourcebound/repository-surface.md; a new README or one that adopted the register may own that region directly.
After a bound source changes, run check, then use drive for a declared repair. Run project when a declared projection depends on the repaired document, then run verify. The tutorial shows the failure before the repair; the support guide covers mature-repository adoption.
How the pieces fit
Three inputs stay separate before the deterministic core:
- Authored intent records why a surface matters. Sourcebound preserves that purpose; it does not infer its priority or turn judgment into gate authority.
- Repository contract declares sources, binding mechanisms, process limits, and projections. Policy markers scope compatible form checks; they do not certify voice.
- Change state combines base and head refs with that contract to produce an immutable impact plan. Static adapters and bounded commands produce typed evidence. Each mechanism proves only its declared relationship; accepted source-claim checks are separate, and unbound prose stays visibly unknown.
The core exposes four job-specific exits:
- Repair bounded prose.
drivewrites only planned regions.projectruns separately when a declared output depends on changed documentation. - Reject stale changes.
checkandverdictare read-only. The verdict names changed, bound, unbound, and skipped surfaces. - Publish agent context.
projectwrites declared outputs such asllms.txtand context bundles. - Record local state.
verifyemits its own outcome receipt.
verdict and verify produce independent receipts. Neither certifies unbound or judgment prose. The product contract defines each authority boundary.
Current boundaries
- Catalog coverage detects source additions, removals, and replacements; it does not validate prose.
- Source-claim discovery ranks static count and identifier-set candidates. A candidate remains advisory until the repository accepts its exact document and source relationship.
- Declared processes use time, I/O, and environment controls. The host owns network isolation; see the security model.
- The manifest decides what Sourcebound evaluates. Authored purpose records goals; Sourcebound does not infer or certify them.
- Feedback is off by default. Enabled runs queue bounded local envelopes; only an explicit
feedback flushcontacts the configured sink, and delivery cannot change a gate result.
Use the learning path for examples. The product contract owns parser, write-boundary, and exit-code details.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distributions
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file sourcebound-1.2.1rc1-py3-none-any.whl.
File metadata
- Download URL: sourcebound-1.2.1rc1-py3-none-any.whl
- Upload date:
- Size: 1.9 MB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
e8dcd1cdd548aaefe5eb629d3b62ddd11182a0e6d42ca3763f965ec9d78c5c18
|
|
| MD5 |
94d04b6f9478657e926d4a1d126058d7
|
|
| BLAKE2b-256 |
8f4ac09f9c2188e82bd884f4245ba602372f3c0957042d09e2f6b5d7cc6511e9
|
Provenance
The following attestation bundles were made for sourcebound-1.2.1rc1-py3-none-any.whl:
Publisher:
release.yml on owieschon/sourcebound
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
sourcebound-1.2.1rc1-py3-none-any.whl -
Subject digest:
e8dcd1cdd548aaefe5eb629d3b62ddd11182a0e6d42ca3763f965ec9d78c5c18 - Sigstore transparency entry: 2206344865
- Sigstore integration time:
-
Permalink:
owieschon/sourcebound@32a22bcdaf83169152904601a7de8d11a95e2e05 -
Branch / Tag:
refs/tags/v1.2.1rc1 - Owner: https://github.com/owieschon
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@32a22bcdaf83169152904601a7de8d11a95e2e05 -
Trigger Event:
push
-
Statement type: