szl-pin
One hash commits to a supplied frontier snapshot. pin_estate takes unique
repository names and full head SHAs and produces a single estate_hash — same
pairs, same hash, any machine, order-independent and offline-verifiable.
pin_diff validates both pins before naming every moved, added, or removed
repository head.
A pin proves the exact caller-supplied set. It does not prove that the input census was complete, fresh, authorized, healthy, deployed, or live. Bind those claims through the applicable source census, CI witness, publication receipt, runtime readback, and proof/evaluation records.
Why
The estate ships fast, with repository heads moving throughout a work session. A source-qualified census can be converted into one recomputable snapshot hash, and a later qualified snapshot can be compared with a diff that names the changed repositories. Compose those records with CI witnesses and provider or runtime receipts without treating any one layer as proof of another.
Usage
pip install -e . pytest && python -m pytest tests/ -q
python -m szl_pin.pin pin --heads heads.json --by stephen --note "friday pin"
python -m szl_pin.pin diff --a pin-1400.json --b pin-1600.json
heads.json is [ ["szl-crosscheck", "51193553..."], ...] using full 40-character
commit SHAs. Repository names must be non-empty, trimmed, and unique
(case-insensitively) within the input.
Fail-closed verification
Before comparing pins, pin_diff revalidates each input's schema, entry shape,
unique repository names, SHA format, declared repository count, and recomputed
canonical SHA-256. Malformed, ambiguous, or tampered pins return INVALID
rather than being collapsed into an apparently clean diff.
Historical evidence boundary
receipts/2026-09-05T0051Z-alignment-sweep-1.json is preserved as a historical,
explicitly partial census artifact. It is not a szl.estate-pin/v1 head pin and
must not be passed to pin_diff or represented as a complete current estate
snapshot.
Doctrine
- A head is a 40-character hexadecimal commit SHA or pinning fails closed.
- Repository names are non-empty, trimmed, and unique within a pin.
- Entries are sorted by repository name; caller order never changes the hash.
- Each input pin is self-verified before a drift result is emitted.
- A pin is a snapshot of supplied facts, not a claim of census completeness, health, publication, or runtime state.
License
Apache-2.0 — canonical organization text (see LICENSE pointer).
Metadata
Release files for szl-pin 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| szl_pin-0.1.0.tar.gz | 9.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| szl_pin-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 19.4 kB
Release files / szl_pin-0.1.0.tar.gz
| Download URL | szl_pin-0.1.0.tar.gz |
|---|---|
| Size | 9.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f4c7dee55108ecf1dde341c615abc3b57cdd6501f3ac33df55d1f37ce6b5d60b
|
|
BLAKE2b-256 checksum How to use checksums |
c0e68cbca7232cec56f0bf6a46c54ba2023a5532ccb4540115557a9bca5619a9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency logRelease files / szl_pin-0.1.0-py3-none-any.whl
| Download URL | szl_pin-0.1.0-py3-none-any.whl |
|---|---|
| Size | 9.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
ec7fa62977302819420e74b7e97e1842cdc18ba5fe7b69570cff3a863c800be7
|
|
BLAKE2b-256 checksum How to use checksums |
22ce31de2e372ed2da15e232e4f1fb42c452ac9e0cd490cf8c8a43ca40865ee6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency log