package: validate lock release versions

This commit is contained in:
Hermes Agent
2026-09-05 23:43:06 +00:00
parent ef534aaa2b
commit 0fd4ca19e9
5 changed files with 36 additions and 3 deletions
+7 -1
View File
@@ -77,7 +77,13 @@ If `package doctor` reports `BAD lock checksum: math-tools`, check the `math-too
BAD lock version: expected exactly one lock-version: 1 line
```
The doctor leaves your files unchanged. After reviewing your project and package manifests, run `claro package lock` to regenerate the lockfile, then run `claro package doctor` again. Spaces around the value and capitalization of the field name are accepted, as with other lockfile fields. Valid generated lockfiles continue to work unchanged; this check does not add registry downloads or verify package content hashes.
The lockfile must also contain exactly one current release line, `version: v1.18.26`. A missing, stale, blank, or duplicate release line fails with:
```text
BAD lock release version: expected exactly one version: v1.18.26 line
```
The doctor leaves your files unchanged. After reviewing your project and package manifests, run `claro package lock` to regenerate the lockfile, then run `claro package doctor` again. Spaces around values and capitalization of the lock-format field name are accepted, as with other lockfile fields. Valid generated lockfiles continue to work unchanged; this check does not add registry downloads or verify package content hashes.
## Project-name safety