[-] sunbytes@programming.dev 2 points 2 days ago* (last edited 2 days ago)

It just wasn't my day, and we put a lot of effort into it, so being told that I said it does not matter kind of set me off a bit.
Anyway, lock files and package integrity verification have been pushed, there may still be a few details to iron out, but it seems to be working so far. Let me know if you find something that looks wrong or if you think about anything that is missing.

[-] sunbytes@programming.dev 3 points 3 days ago

Absolutely, there are preliminary work on package integrity verification it's simply non-food paying work as you can imagine but it will be committed anytime soon.
I know lock files are done by now, it will just take few more changes to have package integrity verification aswell.
We just didn’t expect people to want a full-featured package manager right away, but it’s going to happen.
Thank you for these wise advices, and again, you're more than welcome to join if you find time!

[-] sunbytes@programming.dev 2 points 3 days ago* (last edited 3 days ago)

Selling? It's free software mate lol
No addon depends on each other yet, we're fine we got plenty of time to fix a week old projet
If you want to stand out, you can do so here and just so you know, commits are coming 😘

[-] sunbytes@programming.dev 1 points 4 days ago* (last edited 4 days ago)

What prevents bad actors from changing stuff under the hood?

You'd have to hack into the asset store and upload another zip archive there to update the official registry, I guess 😄

verifying via checksum could be helpful here

Indeed, lock files and checksums are planned
It's still in early development and if you can help with any of this please suggest changes on the repo

Also if you're into decentralization you can own your manifest

48
Paco - The tiny package manager (store.godotengine.org)
submitted 4 days ago* (last edited 4 days ago) by sunbytes@programming.dev to c/godot@programming.dev

Paco is a free tiny package manager that provides a safer way to manage dependencies by downloading and installing packages from a trusted and predefined array rather than shipping addons and / or binaries directly with the project.

It's pretty much like Python, Go, or Ruby, where project dependencies can be installed from a list of packages and versions.

We’d love to get any feedback on this and know what you'd like to see improved

Thanks! 👋

sunbytes

0 post score
0 comment score
joined 4 days ago