Releases: ivanbright/astrocoda
Releases · ivanbright/astrocoda
Release list
Astrocoda 0.1.0
First public release.
MIT source: https://github.com/ivanbright/astrocoda
Install the scaffolder and start a project in one command:
uvx --from "git+https://github.com/ivanbright/astrocoda#subdirectory=cli" astrocoda init myproject
The CLI downloads this asset, verifies it against the Ed25519 public key embedded
in the package, and refuses to scaffold anything that does not match. The wheels/
directory contains vendored dependencies for offline installs.
What the verification actually does:
- The manifest signature covers every field, including
schemaandversion. - Every file is checked against its recorded SHA-256 before anything is copied.
- Archive members that would resolve outside the cache are refused.
- A cache entry that fails verification is deleted, never reused.
astrocoda init --offline scaffolds from an already-verified cached release, and
astrocoda init <name> --source <path> scaffolds from a local tree.