Skip to main content

szl-openshell-receipts

PyPI Python

Governed, hash-chained receipts and an independent policy reach-delta witness for sandboxed agent runtimes such as NVIDIA OpenShell.

v0.2

  • ingest-log: parses OpenShell-style audit tokens (HTTP:* DENIED/ALLOWED, CONFIG:PROPOSED/APPROVED/REJECTED/LOADED) into receipts. Only line digests and key=value fields are kept, never raw lines.
  • delta: SZL reach-set witness. Computes what a policy change adds and flags the four categories OpenShell's prover reasons about, using an independent simplified model.
  • Two-witness gate: ALLOW_ELIGIBLE only when this witness and the supplied prover result both report nothing.
  • Approval receipts bind candidate hash and a digest of the review token.
  • Controls ledger (governance/controls.json) with doctrine labels.
  • Combined multimodal digest.

Honest status

See governance/controls.json. Chain, gate, approvals and multimodal digest are MEASURED by tests. Live OpenShell field mapping and credential isolation are UNKNOWN. Signing is UNAVAILABLE; receipts are UNSIGNED_HONEST. Examples are SYNTHETIC. The reach model is not the OpenShell policy schema.

Usage

pip install .
szl-openshell-receipts ingest-log examples/openshell.sample.log --policy examples/policy.readonly-audit.yaml --commit <sha> --out r.jsonl
szl-openshell-receipts verify r.jsonl
szl-openshell-receipts delta examples/policy.before.json examples/policy.after.json --prover-findings capability_expansion
szl-openshell-receipts controls governance/controls.json

Study notes: docs/STUDY.md.

Metadata

Release files for szl-openshell-receipts 0.3.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for szl-openshell-receipts 0.3.1
File Size Uploaded
szl_openshell_receipts-0.3.1.tar.gz 15.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for szl-openshell-receipts 0.3.1
File Interpreter ABI Platform
szl_openshell_receipts-0.3.1-py3-none-any.whl Python 3 none any Details

Total release size: 29.6 kB

Release files / szl_openshell_receipts-0.3.1.tar.gz

Download URL szl_openshell_receipts-0.3.1.tar.gz
Size 15.0 kB
Tags Source
SHA-256 checksum
How to use checksums
b08b133da0abb834d8a2154f95ca29c1ec10a96730ca2e58200055b7967244ed
BLAKE2b-256 checksum
How to use checksums
51f37131213803747c492dfdf80e18281c752582329c9673f726cf5c05fd9c13
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / szl_openshell_receipts-0.3.1-py3-none-any.whl

Download URL szl_openshell_receipts-0.3.1-py3-none-any.whl
Size 14.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b1a27c9d8c074563bd5dd4fcdd5c5883447e9e3dcb4d8ce5f43886c48556d6f4
BLAKE2b-256 checksum
How to use checksums
93fb76946ca9afec8be9ab4f60968086354c6a3ad6b29e7c0c76c2ef7dd422a1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.3.1 This release

2 release files

0.3.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page