The v0.4.0 release commit claimed the [tool.uv.sources] entry "never reaches consumers". Measured against the pushed tag in clean environments, that is wrong in one direction and understated in the other: - uv, installing this package from git, DOES pick the guard up from the tag automatically. uv reads pyproject.toml when it builds from the source tree, so the source applies to the consumer too, not just to development here. - pip does not read it, and fails outright: "No matching distribution found for llm-ingestion-guard<0.3,>=0.2". The guard must be installed from its own tag FIRST. Verified that the guard-first order then installs cleanly and that the shipped adapter runs against the real guard in that environment. What did hold is the part that matters for the pin: the built wheel carries `Requires-Dist: llm-ingestion-guard<0.3,>=0.2`, so the range is still the declared dependency and the git URL is still a channel. README now states the pip order as the default instruction, with the uv shortcut beside it, because a consumer hitting the resolution error would otherwise read it as a broken release.
63 lines
2.6 KiB
TOML
63 lines
2.6 KiB
TOML
[build-system]
|
|
requires = ["hatchling"]
|
|
build-backend = "hatchling.build"
|
|
|
|
[project]
|
|
name = "llm-ingestion-okf"
|
|
version = "0.4.0"
|
|
description = "Shared OKF (Open Knowledge Format) ingestion library: spec-based connectors, bundle inbox, and external-bundle import, with security delegated to llm-ingestion-guard."
|
|
readme = "README.md"
|
|
license = "MIT"
|
|
requires-python = ">=3.10"
|
|
authors = [{ name = "Kjell Tore Guttormsen" }]
|
|
classifiers = [
|
|
"Development Status :: 2 - Pre-Alpha",
|
|
"Intended Audience :: Developers",
|
|
"Operating System :: OS Independent",
|
|
"Programming Language :: Python :: 3",
|
|
"Programming Language :: Python :: 3.10",
|
|
]
|
|
# Exactly one runtime dependency, ever: the security boundary. Everything
|
|
# else is stdlib. The version range is the real pin — it resolves normally
|
|
# against a package index, and is satisfied today by the git+https tag
|
|
# install documented in the README (a direct reference is an install-time
|
|
# channel, not a dependency declaration).
|
|
dependencies = ["llm-ingestion-guard>=0.2,<0.3"]
|
|
|
|
[project.optional-dependencies]
|
|
# Reserved for binary file-type extraction parsers (pdf/docx/xlsx).
|
|
# Populated when Door B's binary extraction is implemented.
|
|
extract = []
|
|
|
|
[dependency-groups]
|
|
dev = ["pytest>=8", "mypy>=1.14", "ruff>=0.9"]
|
|
|
|
[tool.hatch.build.targets.wheel]
|
|
packages = ["src/llm_ingestion_okf"]
|
|
|
|
[tool.ruff]
|
|
line-length = 100
|
|
target-version = "py310"
|
|
|
|
[tool.mypy]
|
|
strict = true
|
|
python_version = "3.10"
|
|
|
|
# llm-ingestion-guard ships no py.typed marker, so its symbols arrive as Any.
|
|
# The adapter coerces every value it carries across the seam to a concrete
|
|
# type, which is what keeps --strict meaningful on this side of it.
|
|
[[tool.mypy.overrides]]
|
|
module = ["llm_ingestion_guard", "llm_ingestion_guard.*"]
|
|
ignore_missing_imports = true
|
|
|
|
# Install CHANNEL for the guard, which is not on a package index yet. It is
|
|
# uv-specific, and it reaches further than a dev-only setting: measured
|
|
# 2026-07-25, a consumer installing this package from git WITH UV picks the
|
|
# guard up from this tag automatically, because uv reads this file when it
|
|
# builds from the source tree. pip does not read it — it resolves
|
|
# [project.dependencies] alone and fails with "No matching distribution found
|
|
# for llm-ingestion-guard" until the guard is installed from its own tag first
|
|
# (README). Either way the range above stays the pin: the built wheel carries
|
|
# `Requires-Dist: llm-ingestion-guard<0.3,>=0.2`, verified against the wheel.
|
|
[tool.uv.sources]
|
|
llm-ingestion-guard = { git = "https://git.fromaitochitta.com/open/llm-ingestion-pipeline-security.git", tag = "v0.2.0" }
|