package: validate manifest names

This commit is contained in:
Hermes Agent
2026-09-03 16:23:21 +00:00
parent 7450c306be
commit d29390d143
5 changed files with 21 additions and 1 deletions
+4
View File
@@ -293,6 +293,10 @@ claro.lock
packages/
```
`claro package doctor` also checks that every listed package has a manifest whose
`name:` matches the package name in `claro.project`; a mismatch is reported as
`BAD package manifest name` instead of being treated as a healthy package.
Starter projects created with `claro new MyProject` use the same `manifest-version: 1` and `lock-version: 1` headers as `claro package init`, so the first project files match the package maintenance tools.
Project names and package names are checked so unsafe names such as `../bad` are rejected before Claro creates folders. Names must also be 64 characters or fewer, which keeps generated project and package paths predictable. If an unsafe package name is already present in `claro.project`, `claro package doctor`, `claro package lock`, `claro package list`, `claro package init`, `claro package add`, and lockfile refreshes during `claro package remove` flag it instead of treating it as safe lockfile data. `claro package remove` can also remove the exact unsafe entry, so a learner can repair a bad project file without Claro using that unsafe name as a folder path. `claro package doctor` also verifies listed package lockfile checksums, reports stale lock entries, and rejects lockfile package entries that are not listed in `claro.project`.