package: reject duplicate manifest checksums

This commit is contained in:
Hermes Agent
2026-09-04 14:57:29 +00:00
parent beac4c634b
commit ae6b52811e
7 changed files with 15 additions and 4 deletions
+1 -1
View File
@@ -298,7 +298,7 @@ packages/
`name:` matches the package name in `claro.project`; a mismatch is reported as
`BAD package manifest name` instead of being treated as a healthy package.
It also compares the complete `checksum:` field, so extra or trailing checksum
text is rejected as `BAD package checksum`.
text, or a duplicate checksum field, is rejected as `BAD package checksum`.
Starter projects created with `claro new MyProject` use the same `manifest-version: 1` and `lock-version: 1` headers as `claro package init`, so the first project files match the package maintenance tools.