Skip to main content

szl-pin

PyPI Python

One hash commits to a supplied frontier snapshot. pin_estate takes unique repository names and full head SHAs and produces a single estate_hash — same pairs, same hash, any machine, order-independent and offline-verifiable. pin_diff validates both pins before naming every moved, added, or removed repository head.

A pin proves the exact caller-supplied set. It does not prove that the input census was complete, fresh, authorized, healthy, deployed, or live. Bind those claims through the applicable source census, CI witness, publication receipt, runtime readback, and proof/evaluation records.

Why

The estate ships fast, with repository heads moving throughout a work session. A source-qualified census can be converted into one recomputable snapshot hash, and a later qualified snapshot can be compared with a diff that names the changed repositories. Compose those records with CI witnesses and provider or runtime receipts without treating any one layer as proof of another.

Usage

pip install -e . pytest && python -m pytest tests/ -q
python -m szl_pin.pin pin --heads heads.json --by stephen --note "friday pin"
python -m szl_pin.pin diff --a pin-1400.json --b pin-1600.json

heads.json is [ ["szl-crosscheck", "51193553..."], ...] using full 40-character commit SHAs. Repository names must be non-empty, trimmed, and unique (case-insensitively) within the input.

Fail-closed verification

Before comparing pins, pin_diff revalidates each input's schema, entry shape, unique repository names, SHA format, declared repository count, and recomputed canonical SHA-256. Malformed, ambiguous, or tampered pins return INVALID rather than being collapsed into an apparently clean diff.

Historical evidence boundary

receipts/2026-09-05T0051Z-alignment-sweep-1.json is preserved as a historical, explicitly partial census artifact. It is not a szl.estate-pin/v1 head pin and must not be passed to pin_diff or represented as a complete current estate snapshot.

Doctrine

  • A head is a 40-character hexadecimal commit SHA or pinning fails closed.
  • Repository names are non-empty, trimmed, and unique within a pin.
  • Entries are sorted by repository name; caller order never changes the hash.
  • Each input pin is self-verified before a drift result is emitted.
  • A pin is a snapshot of supplied facts, not a claim of census completeness, health, publication, or runtime state.

License

Apache-2.0 — canonical organization text (see LICENSE pointer).

Metadata

Release files for szl-pin 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for szl-pin 0.1.1
File Size Uploaded
szl_pin-0.1.1.tar.gz 10.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for szl-pin 0.1.1
File Interpreter ABI Platform
szl_pin-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 19.9 kB

Release files / szl_pin-0.1.1.tar.gz

Download URL szl_pin-0.1.1.tar.gz
Size 10.1 kB
Tags Source
SHA-256 checksum
How to use checksums
59a89056ee86699f5b2b93d3c2bed46a0962bcc80281e0fd03a303dc61936d05
BLAKE2b-256 checksum
How to use checksums
e44523b3f655cbde68643a022b142a134c239ebf9bb47db55307b11a31bc3f60
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / szl_pin-0.1.1-py3-none-any.whl

Download URL szl_pin-0.1.1-py3-none-any.whl
Size 9.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7eb6b019a58504633ed46c42a51ba2043e409c2ff9e8f5f99abe2e2084503aca
BLAKE2b-256 checksum
How to use checksums
0542a2ffc69fc9a04d12978bbad497de9c60d60785819a174694f24a035a458c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page