Skip to content
repo-release-tools
GitHub

rrt artifacts

Content-addressed integrity tracking for generated repository artifacts.

rrt artifacts provides a general-purpose fingerprinting mechanism for any set of generated files in the repository. It hashes every file matched by configured glob patterns, writes the hashes to .rrt/artifacts.lock.toml, and can verify that freshly-generated artifacts still match the committed fingerprints.

This closes the trust loop for generated assets: the code that produces them is version-controlled, the expected hashes are committed, and CI re-generates and re-verifies before any artifact reaches users.

Add [[tool.rrt.artifact_targets]] entries to pyproject.toml (or .rrt.toml):

[[tool.rrt.artifact_targets]]
path = "src/repo_release_tools/assets/badges/*.svg"
description = "Platform badge SVG files"
[[tool.rrt.artifact_targets]]
path = "docs/assets/banner-*.png"
description = "Banner PNG renders"
  • --snapshot — hash all configured targets, write .rrt/artifacts.lock.toml
  • --check — verify hashes match (advisory, exits 0 on mismatch by default)
  • --check --strict — exits 1 on any hash mismatch (for CI gates)
  • --list — display all tracked artifacts and their current hash status
Terminal window
rrt artifacts --snapshot
rrt artifacts --check
rrt artifacts --check --strict
rrt artifacts --list

Nothing is tracked without [[tool.rrt.artifact_targets]] entries. With none configured, every mode reports zero targets and exits 0.

--check is advisory by default: a hash mismatch prints a warning but still exits 0. Pass --strict to fail the build on drift. The rrt-hooks artifacts-check CI gate flips this default and requires --no-strict to downgrade it.

--regenerate only runs targets that declare a command. Targets without one are silently skipped, and a failing command aborts the whole run before the snapshot is rewritten. --dry-run only affects --regenerate; it is rejected alongside --check, --snapshot, or --list.

--snapshot, --check, --list, and --regenerate are mutually exclusive.

Badge families are intentionally complete for the current icon registry across platform, registry, and language labels; see src/repo_release_tools/tools/platform.py if you think one is missing.

Chat is powered by Context7, a third-party service with its own terms and privacy policy.