CodeSampleX

Sample

importlib-metadata 9.0.0: Inspect installed entry points, package metadata, and wheel files with importlib-metadata 9.0.0 without loading plugins or using the network

Verified sample for pypi importlib-metadata 9.0.0: Inspect installed entry points, package metadata, and wheel files with importlib-metadata 9.0.0 without…

sha256:df4bc17751b6ee1502a2da150f19295d9001e2f16f2f6b2470cc4ff17d1f4138

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
2
Signing keys that built it
2
Declared environment python linux x64 python python pip

Verification-run environments

Environment Contract Stages Run
python 3.12 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · python@1
2026-08-17
python 3.12 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · python@1
2026-08-18

Case

HOW
Goal
Inspect installed entry points, package metadata, and wheel files with importlib-metadata 9.0.0 without loading plugins or using the network
Packages
Symbols
  • importlib_metadata.version
  • importlib_metadata.metadata
  • importlib_metadata.PackageMetadata.json
  • importlib_metadata.entry_points
  • importlib_metadata.EntryPoints.select
  • importlib_metadata.EntryPoints.__getitem__
  • importlib_metadata.EntryPoint.module
  • importlib_metadata.EntryPoint.attr
  • importlib_metadata.files
  • importlib_metadata.PackagePath.locate
  • importlib_metadata.PackagePath.hash
  • importlib_metadata.PackagePath.size
Environment
python
Created
2026-08-17T02:12:58Z

Contract

  1. The third-party importlib_metadata package resolves its installed 9.0.0 distribution under normalized hyphen and underscore names.
  2. metadata() preserves repeated headers through get_all() and exposes normalized JSON fields, including the zipp runtime requirement.
  3. entry_points() returns EntryPoints whose select() filters by group and name; EntryPoints lookup is by entry-point name rather than numeric position.
  4. The installed pip console entry point exposes module and attr without loading the target plugin.
  5. files() returns PackagePath objects tied to their distribution; locate() reaches the imported third-party module and RECORD supplies hashes and sizes except for its own row.

Files

  • NOTES.md
  • csx.json
  • requirements.txt
  • test/contract.py

Download the source artifact (tar.gz)

Origin Seeder

csx-seed