package: block add when manifest has unsafe names

This commit is contained in:
Hermes Agent
2026-09-03 02:23:31 +00:00
parent 21716568a5
commit 4258a341ce
5 changed files with 17 additions and 5 deletions
+1 -1
View File
@@ -98,7 +98,7 @@ Ready now:
- local project files such as `claro.project`, `claro.lock`, and `packages/`
- starter projects from `claro new` now use the same manifest-version and lock-version headers as `claro package init`
- project-name safety checks for `claro new`, so unsafe names such as `../bad` are rejected before Claro creates folders
- package-name safety checks when adding packages, including the 64-character package-name limit, when `claro package doctor` audits an existing `claro.project`, when `claro package lock` writes lockfile data, and when `claro package remove` refreshes the lockfile after an edit
- package-name safety checks when adding packages, including the 64-character package-name limit, when `claro package doctor` audits an existing `claro.project`, when `claro package lock` writes lockfile data, when `claro package add` sees unsafe names already present in `claro.project`, and when `claro package remove` refreshes the lockfile after an edit
Still needed:
- install from local path