The pith suite contract
pith-zip is part of the pith suite (pith-hash). Every suite repository follows the same rules; CI enforces them mechanically:
- Naming: a library is always
pith-<domain>(pith-image,pith-audio,pith-zip, ...). The curator/repository of repositories is the barepith-hash. Never invent a second naming scheme inside the suite. - Version pinning: cross-library dependencies pin
~0.1(e.g.pith-image = { version = "~0.1", path = "../pith-image" }). The whole suite moves together inside 0.1.x; breaking changes require a suite-wide version bump, never a silent minor drift. - Zero third-party dependencies: every crate depends only on other
pith-*crates plusstd.scripts/check-zero-deps.py(run in CI) fails the build on any other crate, for normal, build and dev dependencies alike. - No unsafe: every crate root carries
#![forbid(unsafe_code)]. - Hex-exact vectors:
reference.jsonat the repo root is the cross-language source of truth. Thegen-referencebinary regenerates it; CI verifies the committed copy is current (gen-reference verify), and CD ships the regenerated file with every SDK artifact. Python, Node and Go SDKs MUST test against the same bytes.
Repository layout
crates/ one published crate per suite lib (pith-<domain>)
tools/gen-reference the vector generator binary (bin name: gen-reference)
sdk/python ctypes wheel; build backend reads PITH_CDYLIB_DIR
sdk/node koffi-based package; prebuilds/<os-arch>/ carry the cdylib
sdk/go cgo binding; go.mod carries the module's cgo flags
fuzz/corpus fuzz inputs, replayed by tests/fuzz_corpus.rs (parser crates)
reference.json hex-exact cross-SDK test vectors
Install
Rust (the core library):
Python / Node / Go SDKs are published from the same cdylib on every release; see the release assets or the package registries for the matching version.
Quick start
(Add example commands here.)
Contributing
See CONTRIBUTING.md.
Security
See SECURITY.md.
License
MIT © pith-hash