Skip to main content

ZenScraper

Build CodeQL PyPI version Python versions Snyk package health OpenSSF Scorecard

A command line tool to collect AMD uCode!

Overview

ZenScraper gathers AMD CPU microcode (uCode) patches from public upstream repositories, extracts the individual patches from their containers, and stores them under a single directory with a consistent, content-addressed naming scheme. Patches that already exist are de-duplicated by SHA-256, and a hash mismatch on a same-named patch is reported as an error.

Currently supported sources:

  • Linux Firmware: the linux-firmware repository (amd-ucode containers, extracted into individual patches).
  • Platomav CPUMicrocodes: the platomav/CPUMicrocodes repository (AMD patches).

Each source is walked across its full git history, so superseded patches are collected as well as current ones.

Installation

pip install zenscraper

Usage

Run the tool to scrape every supported source into the current directory:

zenscraper

Options:

Option Default Description
--workdir, -w ./workdir Directory for temporary and cached files (the cloned repos are kept here between runs).
--outdir, -o . (current directory) Directory where the collected patches are stored.

Output

Collected patches are written to a patches/ subdirectory of --outdir. Each file is named after its parsed header fields and a short content hash, for example:

family19_cpuid00A20F12_rev0a201210_date20240611_enc00_sha1a2b3c4d5e6f.bin

The fields encode the CPU family, CPU ID, update revision, build date, encryption flag (when present) and the first 12 hex digits of the patch's SHA-256 hash.

Provenance catalog

catalog.json is both a manifest of the collection and a record of where its patches were found upstream. Every stored patch gets an entry carrying:

  • Identity: its canonical file name, full SHA-256 (the name holds only 12 digits of it) and size, so the catalog can be used to verify the collection.
  • Metadata: family, CPU ID, patch level, build date, encryption flag and whether the patch is signed, decoded once so consumers do not have to parse the binaries to index them.
  • Sightings: every commit of every source whose tree carried the patch, with the path it had there. Patches that ship inside a container record the container's path and the patch's position among its uCode sections.
  • first_seen: derived from the sightings: the oldest commit of each source that carried the patch.
{
  "name": "family19_cpuid00A20F12_rev0a201210_date20240611_enc00_sha1a2b3c4d5e6f.bin",
  "sha256": "1a2b3c4d5e6f...",
  "size": 5568,
  "family": "0x19",
  "cpuid": "00A20F12",
  "patch_level": "0a201210",
  "date": "2024-06-11",
  "encrypted": false,
  "signed": true,
  "stored": true,
  "first_seen": {
    "linux-firmware": {
      "commit": "abc123...",
      "commit_date": "2024-06-20T12:03:44+00:00",
      "path": "amd-ucode/microcode_amd_fam19h.bin",
      "container_index": 42
    }
  },
  "sightings": [ "..." ]
}

Metadata

Release files for zenscraper 1.0.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for zenscraper 1.0.4
File Size Uploaded
zenscraper-1.0.4.tar.gz 22.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for zenscraper 1.0.4
File Interpreter ABI Platform
zenscraper-1.0.4-py3-none-any.whl Python 3 none any Details

Total release size: 46.7 kB

Release files / zenscraper-1.0.4.tar.gz

Download URL zenscraper-1.0.4.tar.gz
Size 22.4 kB
Tags Source
SHA-256 checksum
How to use checksums
9083b073dbd2a17b1c76281b59a8f557e46bfed56a9810584e941453d03c0889
BLAKE2b-256 checksum
How to use checksums
86e7e35837923f722f4b811c97cee1f983c25a204562b01b23ef7a74c475e593
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 19, 2026.

Transparency log

Release files / zenscraper-1.0.4-py3-none-any.whl

Download URL zenscraper-1.0.4-py3-none-any.whl
Size 24.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
d22b24c225fdab65754689af51af4838200f8414fa13c21f396a3701b43cde68
BLAKE2b-256 checksum
How to use checksums
9805477be0126ce57ad9253db7ef8df878fd90365cb411034d3d279f65b689cf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 19, 2026.

Transparency log

Release history Release notifications | RSS feed

1.0.6

2 release files

1.0.5

2 release files

This release

1.0.4 This release

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page