diff --git a/README.md b/README.md
index 1f11e18..9b90c90 100644
--- a/README.md
+++ b/README.md
@@ -14,13 +14,21 @@ Documentation:
## Install
-It's a CLI application, not a library dependency — install it as a tool:
+Released from this repository, not from PyPI — there is no `icebergsca` package on PyPI, and
+anything published under that name is not this project. It's a CLI application, not a library
+dependency, so install it as a tool:
```bash
-uv tool install icebergsca # or: uvx icebergsca scan .
-pipx install icebergsca
+uv tool install git+https://github.com/IcebergAI/IcebergSCA@v0.1.0
+pipx install git+https://github.com/IcebergAI/IcebergSCA.git@v0.1.0
+
+# or run it without installing
+uvx --from git+https://github.com/IcebergAI/IcebergSCA@v0.1.0 icebergsca scan .
```
+Pin the tag: without `@v0.1.0` you get whatever `main` is at that moment. Upgrade by re-running
+the same command against a newer tag with `--force`.
+
## Usage
```bash
@@ -105,7 +113,9 @@ SARIF and CycloneDX are validated against the official published schemas in the
### GitHub Actions
```yaml
-- run: uvx icebergsca scan . --format sarif --output icebergsca.sarif
+- run: >-
+ uvx --from git+https://github.com/IcebergAI/IcebergSCA@v0.1.0
+ icebergsca scan . --format sarif --output icebergsca.sarif
- uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: icebergsca.sarif
diff --git a/src/icebergsca/.agents/skills/icebergsca/SKILL.md b/src/icebergsca/.agents/skills/icebergsca/SKILL.md
index 4260855..9cf3c84 100644
--- a/src/icebergsca/.agents/skills/icebergsca/SKILL.md
+++ b/src/icebergsca/.agents/skills/icebergsca/SKILL.md
@@ -25,12 +25,19 @@ dependency graph, checks each package against [OSV](https://osv.dev), and report
icebergsca scan ./myproject
```
-The tool is a CLI application, not a library. Install it as a tool, not as a dependency:
+The tool is a CLI application, not a library. Install it as a tool, not as a dependency. It is
+released from its GitHub repository; there is **no `icebergsca` package on PyPI**, so
+`pip install icebergsca` does not install this project.
```bash
-uv tool install icebergsca # or run ad hoc: uvx icebergsca scan .
+uv tool install git+https://github.com/IcebergAI/IcebergSCA@v0.1.0
+
+# or run ad hoc, without installing
+uvx --from git+https://github.com/IcebergAI/IcebergSCA@v0.1.0 icebergsca scan .
```
+Pin the tag. Without `@v0.1.0` you get whatever `main` is at that moment.
+
## Machine-readable output
Always request JSON when a program or agent will read the result. The table format is for
diff --git a/src/icebergsca/.agents/skills/icebergsca/references/ci-integration.md b/src/icebergsca/.agents/skills/icebergsca/references/ci-integration.md
index 085981e..8f46d2d 100644
--- a/src/icebergsca/.agents/skills/icebergsca/references/ci-integration.md
+++ b/src/icebergsca/.agents/skills/icebergsca/references/ci-integration.md
@@ -31,7 +31,9 @@ A built-in `--fail-on ` flag is planned but not yet implemented.
```yaml
- name: Scan dependencies
- run: uvx icebergsca scan . --format sarif --output icebergsca.sarif
+ run: >-
+ uvx --from git+https://github.com/IcebergAI/IcebergSCA@v0.1.0
+ icebergsca scan . --format sarif --output icebergsca.sarif
- uses: github/codeql-action/upload-sarif@v3
with:
@@ -77,7 +79,9 @@ jobs:
- uses: astral-sh/setup-uv@v8
- name: Scan
- run: uvx icebergsca scan . --exclude 'tests/fixtures/**' --format sarif --output sca.sarif
+ run: >-
+ uvx --from git+https://github.com/IcebergAI/IcebergSCA@v0.1.0
+ icebergsca scan . --exclude 'tests/fixtures/**' --format sarif --output sca.sarif
- uses: github/codeql-action/upload-sarif@v3
if: always()
@@ -93,7 +97,9 @@ because the code changed.
```yaml
- name: Generate SBOM
- run: uvx icebergsca sbom . --output sbom.cdx.json
+ run: >-
+ uvx --from git+https://github.com/IcebergAI/IcebergSCA@v0.1.0
+ icebergsca sbom . --output sbom.cdx.json
- uses: actions/upload-artifact@v5
with:
diff --git a/website/docs/index.md b/website/docs/index.md
index 86eee77..d7c0c09 100644
--- a/website/docs/index.md
+++ b/website/docs/index.md
@@ -29,14 +29,27 @@ check.
## Install and scan
```bash
-uv tool install icebergsca # or run it ad hoc: uvx icebergsca scan .
-pipx install icebergsca
+uv tool install git+https://github.com/IcebergAI/IcebergSCA@v0.1.0
+pipx install git+https://github.com/IcebergAI/IcebergSCA.git@v0.1.0
-icebergsca scan ./myproject
+# or run it without installing
+uvx --from git+https://github.com/IcebergAI/IcebergSCA@v0.1.0 icebergsca scan .
```
It is a CLI application, not a library — install it as a tool rather than adding
-it to the dependency tree it is meant to be auditing.
+it to the dependency tree it is meant to be auditing. Then point it at a project:
+
+```bash
+icebergsca scan ./myproject
+```
+
+!!! info "Released from the repository, not from PyPI"
+
+ There is no `icebergsca` package on PyPI, and anything published under that
+ name is not this project.
+
+ Pin the tag: without `@v0.1.0` you get whatever `main` is at that moment.
+ Upgrade by re-running the same command against a newer tag with `--force`.
{ .term }
diff --git a/website/docs/output.md b/website/docs/output.md
index f22f3d8..89da8fc 100644
--- a/website/docs/output.md
+++ b/website/docs/output.md
@@ -66,7 +66,9 @@ The complete field reference ships with the package, in
## SARIF and GitHub code scanning
```yaml
-- run: uvx icebergsca scan . --format sarif --output icebergsca.sarif
+- run: >-
+ uvx --from git+https://github.com/IcebergAI/IcebergSCA@v0.1.0
+ icebergsca scan . --format sarif --output icebergsca.sarif
- uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: icebergsca.sarif
@@ -156,7 +158,9 @@ jobs:
- uses: astral-sh/setup-uv@v8
- name: Scan
- run: uvx icebergsca scan . --exclude 'tests/fixtures/**' --format sarif --output sca.sarif
+ run: >-
+ uvx --from git+https://github.com/IcebergAI/IcebergSCA@v0.1.0
+ icebergsca scan . --exclude 'tests/fixtures/**' --format sarif --output sca.sarif
- uses: github/codeql-action/upload-sarif@v3
if: always()
diff --git a/website/zensical.toml b/website/zensical.toml
index 95ccda1..780ea57 100644
--- a/website/zensical.toml
+++ b/website/zensical.toml
@@ -78,10 +78,9 @@ toggle.name = "Switch to light mode"
icon = "fontawesome/brands/github"
link = "https://github.com/IcebergAI/IcebergSCA"
-# A PyPI social link belongs here too, but icebergsca has no release yet
-# (pypi.org/pypi/icebergsca/json is a 404) and a footer icon that 404s is
-# exactly the kind of unearned claim this tool exists to complain about.
-# Restore it with the first release.
+# No PyPI social link: IcebergSCA is released from its repository and there is
+# no icebergsca package on PyPI. A footer icon pointing at a name we do not own
+# would send readers to whoever registers it first.
# ----------------------------------------------------------------------------
# Markdown extensions (carried over from the Zensical default template)