package: reject unsafe project names

This commit is contained in:
Hermes Agent
2026-09-03 00:19:56 +00:00
parent 475b54eb6a
commit 21716568a5
6 changed files with 32 additions and 5 deletions
+1 -1
View File
@@ -295,7 +295,7 @@ packages/
Starter projects created with `claro new MyProject` use the same `manifest-version: 1` and `lock-version: 1` headers as `claro package init`, so the first project files match the package maintenance tools.
Package names are checked so unsafe names such as `../bad` are rejected when adding packages. Names must also be 64 characters or fewer, which keeps generated package paths predictable. If an unsafe name is already present in `claro.project`, `claro package doctor`, `claro package lock`, and lockfile refreshes during `claro package remove` flag it instead of treating it as safe lockfile data.
Project names and package names are checked so unsafe names such as `../bad` are rejected before Claro creates folders. Names must also be 64 characters or fewer, which keeps generated project and package paths predictable. If an unsafe package name is already present in `claro.project`, `claro package doctor`, `claro package lock`, and lockfile refreshes during `claro package remove` flag it instead of treating it as safe lockfile data.
## Standard-library path and collection helpers