Skip to main content

Stigmem Source Attestation Plugin

Experimental source attestation plugin for Stigmem.

This package provides the stigmem-plugin-source-attestation source package for alpha validation. It registers through the stigmem.plugins entry point group and is loaded by stigmem-node only when explicitly installed and configured by an operator.

Status

Source attestation remains experimental. Installing this package does not add assertion-source enforcement, recall source weighting, or federation source guards to the supported default surface. Default installs remain inert unless the plugin is registered and the operator enables the relevant gates.

The package metadata is publication-shaped for the plugin readiness track, but registry publication remains on hold until dry-run evidence and maintainer clearance are recorded. See the feature record under features/source-attestation/ for the current status, evidence, and security notes.

Installation

pip install --pre stigmem-node==0.9.0a8 stigmem-plugin-source-attestation==0.1.0

Enable

Set the plugin gate environment variable to opt in:

export STIGMEM_SOURCE_ATTESTATION_ENABLED=1

The default install is inert; source attestation only activates when the package is installed, discovered through the stigmem.plugins entry point, and the operator enables the gate. Enforcement-specific gates such as STIGMEM_SOURCE_ATTESTATION_ENFORCE_ASSERT_VALIDATION and STIGMEM_SOURCE_ATTESTATION_ENFORCE_FEDERATION_INBOUND remain opt-in and must not be enabled with warn-only mode.

Disable

Unset the plugin gate environment variable, or set it to any value other than 1, true, yes, or on:

unset STIGMEM_SOURCE_ATTESTATION_ENABLED

The plugin returns to inert state at the next process start. No data migration is required; core source, scope, tenant, and audit enforcement continues to hold without plugin participation.

Test

From a Stigmem repository checkout with development dependencies installed:

uv run pytest node/tests/plugins/test_source_attestation_plugin_scaffold.py \
  node/tests/plugins/test_source_attestation_plugin_validation.py

The package itself ships no separate test tree; upstream plugin validation lives in node/tests/plugins/.

Uninstall

pip uninstall stigmem-plugin-source-attestation

Removing the package is sufficient. The gate environment variable becomes moot once the entry point is no longer discoverable.

Project Links

Metadata

Release files for stigmem-plugin-source-attestation 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for stigmem-plugin-source-attestation 0.1.0
File Size Uploaded
stigmem_plugin_source_attestation-0.1.0.tar.gz 6.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for stigmem-plugin-source-attestation 0.1.0
File Interpreter ABI Platform
stigmem_plugin_source_attestation-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 12.9 kB

Release files / stigmem_plugin_source_attestation-0.1.0.tar.gz

Download URL stigmem_plugin_source_attestation-0.1.0.tar.gz
Size 6.3 kB
Tags Source
SHA-256 checksum
How to use checksums
ef9835eca34f7b211ab190fdd00fb71f0f42409733e5dc2a2e0bf8ceb087b675
BLAKE2b-256 checksum
How to use checksums
48baf62d47333580ef3b674526217640febdfafc9919d310e0dea71aab23c527
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.11.15

Release files / stigmem_plugin_source_attestation-0.1.0-py3-none-any.whl

Download URL stigmem_plugin_source_attestation-0.1.0-py3-none-any.whl
Size 6.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5b315b8e323d806eaad20f738d03007c5b002e3db63f415e30a6119ce81ff2bc
BLAKE2b-256 checksum
How to use checksums
48b142ec0b77898f016fd0cc056bde860e876d8d51290a32396e9c79fa23542b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.11.15

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page