Skip to content

Releases: ivanbright/astrocoda

Release list

Astrocoda 0.1.0

Choose a tag to compare

@ivanbright ivanbright released this 30 Sep 12:16

First public release.

MIT source: https://github.com/ivanbright/astrocoda

Install the scaffolder and start a project in one command:

uvx --from "git+https://github.com/ivanbright/astrocoda#subdirectory=cli" astrocoda init myproject

The CLI downloads this asset, verifies it against the Ed25519 public key embedded
in the package, and refuses to scaffold anything that does not match. The wheels/
directory contains vendored dependencies for offline installs.

What the verification actually does:

  • The manifest signature covers every field, including schema and version.
  • Every file is checked against its recorded SHA-256 before anything is copied.
  • Archive members that would resolve outside the cache are refused.
  • A cache entry that fails verification is deleted, never reused.

astrocoda init --offline scaffolds from an already-verified cached release, and
astrocoda init <name> --source <path> scaffolds from a local tree.