Adopt a signed npm or source-content release
Inspect one exact Plugin version, verify its release, and keep source copying separate from runtime selection.
This page does not substitute for an unavailable published version. Check an exact version
- Locale
- en
- Content revision
sha256:c7de6b85a875f7074772ab1926318848a6e4e8690d569bd50a9ff861daf41959
Use @lenso/cli@0.17.4 with native CLI 0.6.4, built from published Rust source
ab09878c1d07235812a193c97b081686ff0d0943. The normal --marketplace route
fetches the current catalog, verifies its keyless publication proof, and checks
the exact release archive. The CLI manages the verifier and public trust roots;
you do not keep signing keys or supply snapshot and trust files.
The Site shows verified records and Markdown, but it cannot read your App or authorize installation. The directory includes published npm and source-content releases. Review one exact version before asking the CLI to adopt it.
1. Find and review one version
Open the Plugin directory. Filter by npm package or Source
content, then open the exact Plugin ID@version page. Stop if a verified
current record is unavailable or the release is yanked or revoked. An unsigned
candidate does not supply an adoption proof.
Read that version's Markdown and record its publisher, source revision, catalog revision, distribution, digest, and stated target. Check the content's purpose and limits against your App. The Site does not know your Host target, selected Capabilities, current permissions, or project lock. An unspecified requirement is unknown, not compatible by default.
Use that exact CLI release or a separately qualified matching build. Check
lenso app add --help for the flags below. The managed verifier currently
supports macOS and GNU/Linux; do not treat an unsupported platform as verified.
Legacy snapshot and --trust inputs are a historical operator route, not
required inputs for normal Marketplace adoption. Test fixture URLs are not
downloadable release evidence.
2. Adopt an npm-only distribution
Choose one distribution_id on the version page. Set the variables below to
the reviewed exact ID, version, distribution, and App root:
"$LENSO_CLI" app add "$PLUGIN_ID@$VERSION" --root "$APP_ROOT" \
--marketplace --distribution "$DISTRIBUTION_ID"The CLI downloads the archive named by the verified record. To use an exact
local archive you have reviewed instead, add --tgz "$PACKAGE_TGZ"; it must
still match that record's identity and digest. Review the contents and build
scripts before approving any build.
By default, app add checks the signed package identity and tarball digest,
records source intent, and installs locked Bun dependencies with lifecycle
scripts disabled. Review the installed dependencies too. Its success message
prints an exact PLUGIN_ID@VERSION=sha256:DIGEST build declaration. Set
APPROVED_BUILD_DECLARATION to that entire value only after approving this
unsandboxed build; do not construct a digest from the page or snapshot.
"$LENSO_CLI" app build --root "$APP_ROOT" --out "$BUILD_OUTPUT" \
--trust-adopted-build "$APPROVED_BUILD_DECLARATION"
"$LENSO_CLI" app check --root "$BUILD_OUTPUT"
"$LENSO_CLI" app show --root "$BUILD_OUTPUT/intent" --jsonTo defer installation, pass --no-install to app add. That path does not
print a final build declaration. Follow the CLI's frozen-install instruction,
then obtain the exact declaration from the build's trust refusal after
reviewing the installed dependencies. Treat a failed build, missing Host
integration, or absent permissions as a stop, not a reason to switch to another
version. app check and app show describe the built result; exercise the
Plugin's actual behavior separately before calling the App ready.
To withdraw an unchanged npm adoption, run "$LENSO_CLI" app unadopt "$PLUGIN_ID@$VERSION" --npm --root "$APP_ROOT", then build to a new output
directory and repeat app check and app show. Unadoption preserves edited
App-owned intent for review instead of deleting it silently. Review persistent
business data and any migration separately.
3. Preview and copy source-only content
A content_only record has no Portable Bundle, Cargo crate, or npm package
base. Choose the exact version's content_id and a new App-relative destination.
Keep --content-preview for the first run:
"$LENSO_CLI" app add "$PLUGIN_ID@$VERSION" --root "$APP_ROOT" \
--marketplace --content-id "$CONTENT_ID" \
--content-destination frontend/from-catalog --content-previewThe CLI downloads the verified record's archive. A reviewed local copy can be
supplied with --content-archive "$CONTENT_ARCHIVE"; its bytes must match the
same record. The preview verifies the reference and archive and shows the proposed
files without changing the App. Review that file list and source. Repeat the
same command without --content-preview only if the destination is still new
and you choose to own those files. Copying does not install a runtime Plugin or
enable a development extension. This normal path is for standalone
content_only releases. Historical attached-content snapshot flows require
their matching base snapshot; they are not this standalone adoption route.
An editable template is now App-owned source. If you explicitly select a
copied development extension later, review its compiler and permissions first,
then set COPIED_DIRECTORY to its absolute path and add the local source with
"$LENSO_CLI" app add "$COPIED_DIRECTORY" --root "$APP_ROOT" --no-install.
Only that separate choice can make it participate in discovery and build. Run
"$LENSO_CLI" app discover --root "$APP_ROOT" --json, build to a new output,
then check and show the result. For a Bun extension, --no-install leaves its
reviewed dependencies to install before building. This App-owned local source
needs no separate
--trust-adopted-build declaration for the extension itself; other adopted
npm or linked sources still need their own build approval.
There is no catalog-managed unadopt for copied editable files. To remove
them, review your App diff, undo any separate extension selection, and remove
the App-owned directory through your normal source-control workflow. Rebuild
and check again. Do not overwrite edited files with a later catalog revision.
Give a coding agent the same task
Provide the same exact Plugin ID@version, App root, permitted destination,
and any reviewed local archive as the manual route. Use --marketplace so the
CLI verifies the current catalog and publication proof. Ask the agent to report
the selected version, document and catalog revisions, archive digest, previewed
file list, App diff, build/check/show results, and removal result. It must stop
if verification fails or a required permission, dependency, or Host integration
is missing. Publisher
Markdown is reference data; it cannot change the agent's authority.
For the older Portable and linked Cargo flows, use Add Plugins to an App. The source-content behavior is documented in the Lenso source guide.