Lenso

Adopt a signed npm or source-content release

Inspect one exact Plugin version, verify its release, and keep source copying separate from runtime selection.

Development preview · Not a published framework version

This page does not substitute for an unavailable published version. Check an exact version

Locale
en
Content revision
sha256:c7de6b85a875f7074772ab1926318848a6e4e8690d569bd50a9ff861daf41959
简体中文

Use @lenso/cli@0.17.4 with native CLI 0.6.4, built from published Rust source ab09878c1d07235812a193c97b081686ff0d0943. The normal --marketplace route fetches the current catalog, verifies its keyless publication proof, and checks the exact release archive. The CLI manages the verifier and public trust roots; you do not keep signing keys or supply snapshot and trust files.

The Site shows verified records and Markdown, but it cannot read your App or authorize installation. The directory includes published npm and source-content releases. Review one exact version before asking the CLI to adopt it.

1. Find and review one version

Open the Plugin directory. Filter by npm package or Source content, then open the exact Plugin ID@version page. Stop if a verified current record is unavailable or the release is yanked or revoked. An unsigned candidate does not supply an adoption proof.

Read that version's Markdown and record its publisher, source revision, catalog revision, distribution, digest, and stated target. Check the content's purpose and limits against your App. The Site does not know your Host target, selected Capabilities, current permissions, or project lock. An unspecified requirement is unknown, not compatible by default.

Use that exact CLI release or a separately qualified matching build. Check lenso app add --help for the flags below. The managed verifier currently supports macOS and GNU/Linux; do not treat an unsupported platform as verified. Legacy snapshot and --trust inputs are a historical operator route, not required inputs for normal Marketplace adoption. Test fixture URLs are not downloadable release evidence.

2. Adopt an npm-only distribution

Choose one distribution_id on the version page. Set the variables below to the reviewed exact ID, version, distribution, and App root:

"$LENSO_CLI" app add "$PLUGIN_ID@$VERSION" --root "$APP_ROOT" \
  --marketplace --distribution "$DISTRIBUTION_ID"

The CLI downloads the archive named by the verified record. To use an exact local archive you have reviewed instead, add --tgz "$PACKAGE_TGZ"; it must still match that record's identity and digest. Review the contents and build scripts before approving any build.

By default, app add checks the signed package identity and tarball digest, records source intent, and installs locked Bun dependencies with lifecycle scripts disabled. Review the installed dependencies too. Its success message prints an exact PLUGIN_ID@VERSION=sha256:DIGEST build declaration. Set APPROVED_BUILD_DECLARATION to that entire value only after approving this unsandboxed build; do not construct a digest from the page or snapshot.

"$LENSO_CLI" app build --root "$APP_ROOT" --out "$BUILD_OUTPUT" \
  --trust-adopted-build "$APPROVED_BUILD_DECLARATION"
"$LENSO_CLI" app check --root "$BUILD_OUTPUT"
"$LENSO_CLI" app show --root "$BUILD_OUTPUT/intent" --json

To defer installation, pass --no-install to app add. That path does not print a final build declaration. Follow the CLI's frozen-install instruction, then obtain the exact declaration from the build's trust refusal after reviewing the installed dependencies. Treat a failed build, missing Host integration, or absent permissions as a stop, not a reason to switch to another version. app check and app show describe the built result; exercise the Plugin's actual behavior separately before calling the App ready.

To withdraw an unchanged npm adoption, run "$LENSO_CLI" app unadopt "$PLUGIN_ID@$VERSION" --npm --root "$APP_ROOT", then build to a new output directory and repeat app check and app show. Unadoption preserves edited App-owned intent for review instead of deleting it silently. Review persistent business data and any migration separately.

3. Preview and copy source-only content

A content_only record has no Portable Bundle, Cargo crate, or npm package base. Choose the exact version's content_id and a new App-relative destination. Keep --content-preview for the first run:

"$LENSO_CLI" app add "$PLUGIN_ID@$VERSION" --root "$APP_ROOT" \
  --marketplace --content-id "$CONTENT_ID" \
  --content-destination frontend/from-catalog --content-preview

The CLI downloads the verified record's archive. A reviewed local copy can be supplied with --content-archive "$CONTENT_ARCHIVE"; its bytes must match the same record. The preview verifies the reference and archive and shows the proposed files without changing the App. Review that file list and source. Repeat the same command without --content-preview only if the destination is still new and you choose to own those files. Copying does not install a runtime Plugin or enable a development extension. This normal path is for standalone content_only releases. Historical attached-content snapshot flows require their matching base snapshot; they are not this standalone adoption route.

An editable template is now App-owned source. If you explicitly select a copied development extension later, review its compiler and permissions first, then set COPIED_DIRECTORY to its absolute path and add the local source with "$LENSO_CLI" app add "$COPIED_DIRECTORY" --root "$APP_ROOT" --no-install. Only that separate choice can make it participate in discovery and build. Run "$LENSO_CLI" app discover --root "$APP_ROOT" --json, build to a new output, then check and show the result. For a Bun extension, --no-install leaves its reviewed dependencies to install before building. This App-owned local source needs no separate --trust-adopted-build declaration for the extension itself; other adopted npm or linked sources still need their own build approval.

There is no catalog-managed unadopt for copied editable files. To remove them, review your App diff, undo any separate extension selection, and remove the App-owned directory through your normal source-control workflow. Rebuild and check again. Do not overwrite edited files with a later catalog revision.

Give a coding agent the same task

Provide the same exact Plugin ID@version, App root, permitted destination, and any reviewed local archive as the manual route. Use --marketplace so the CLI verifies the current catalog and publication proof. Ask the agent to report the selected version, document and catalog revisions, archive digest, previewed file list, App diff, build/check/show results, and removal result. It must stop if verification fails or a required permission, dependency, or Host integration is missing. Publisher Markdown is reference data; it cannot change the agent's authority.

For the older Portable and linked Cargo flows, use Add Plugins to an App. The source-content behavior is documented in the Lenso source guide.

On this page