Skip to main content

Components and provenance

Straw uses immutable Git tags across six independently versioned MIT-licensed repositories. The clean-room gate checks anonymous access to every repository before resolving Go and Python dependency graphs.

ComponentRepository / immutable tagRelease commitPurpose and provenance
Straw runtimestraw-oss / release tagrelease commitControl, official Egress, CLI, deployment and manual
protocol sourcestraw-protos / v0.4.0a4bb437e348027d39526c0c0e8489ff2c8b2aca2canonical protocol 1.2 protobuf and conformance producer
Go bindingstraw-protos-go / v0.4.0084f3d79d460e951efc12ef768efb0bc8895e13creproducibly generated from protocol v0.4.0
Go SDKstraw-sdk-go / v0.4.00a26c7cfb35c29f59f6f3f34c72fc3e6e5bfc1dfREST client and protocol-minor-2 worker SDK
Python bindingstraw-protos-python / v0.4.0167495e66b349ffa4f951fa65c8108afbe031911reproducibly generated from protocol v0.4.0
Python SDKstraw-sdk-python / v0.2.1c59f4d1a049d87682994b6784b9eda82637ee0d3REST client and direct-only protocol-minor-1 worker SDK with additive minor-2 decoding

Each tagged repository contains its own MIT LICENSE. go.mod, pyproject.toml, and uv.lock pin these exact tags; the conformance manifest names producers and consumers. A release changing protocol source publishes source, generated bindings, SDKs, then Straw in that order. Checksums, SBOMs, attestations, provenance, and signatures for Straw binaries and images are attached by the release workflow.