Packaging and signing
A package is a ZIP file with the extension .shellaro-ext:
manifest.json
dist/extension.js extensions (the "main" file)
pack.json | lab.json Command Packs | Lab Packs
assets/... icon, gallery screenshots and short videos (optional)
README.md shown on the Marketplace details page
CHANGELOG.md shown in the Changelog tab
LICENSE optional
integrity.json written by the CLI
shellaro ext build includes manifest.json, README, CHANGELOG, LICENSE, pack.json, lab.json, everything under dist/ and assets/ (except source maps), and the files the manifest names. Source code, node_modules and everything else stay out.
integrity.json
{
"schemaVersion": 1,
"algorithm": "sha256",
"files": { "README.md": "9f1c...", "dist/extension.js": "4ab0...", "manifest.json": "77e2..." },
"signature": { "algorithm": "ed25519", "keyId": "acme-2026", "value": "<base64>" }
}
Every file except integrity.json must be listed with its SHA-256, and every listed file must exist. Shellaro refuses a package otherwise.
What Shellaro checks before installing
- archive size at most 20 MB, at most 1000 files, at most 64 MB unpacked, 20 MB per file, compression ratio at most 200:1 for files over 1 MB (zip bombs)
- no absolute paths,
.., backslashes, drive letters, control characters, symbolic links, or names that differ only in case - integrity as above; the signature if present
- the manifest (structure in Rust, every rule in TypeScript) and the pack or lab content
- the SHA-256 of the whole file equals what the user reviewed (and, for downloads, what the source announced)
Files are unpacked to a staging folder and moved into %APPDATA%\com.shellaro.app\extensions\installed\<id>\<version> only when everything passed.
Signatures
The signature is Ed25519 over:
shellaro-ext-signature-v1\n<id>\n<version>\n<sha256> <path>\n... (files in byte order of the path)
so it covers the identity and every file. The review dialog shows:
| Status | Meaning |
|---|---|
| Signed by publisher, a publisher you trust | Valid signature by a key in trusted-keys.json |
| Signed with key "id", which you have not marked as trusted | Valid signature, unknown key: proves nothing yet |
| Not signed | Files are intact (integrity), author unknown |
A signature that does not verify refuses the package. A key's publisher must match the manifest's publisher.
Trusted keys: %APPDATA%\com.shellaro.app\extensions\trusted-keys.json:
{ "keys": [{ "keyId": "acme-2026", "publisher": "Acme", "publicKey": "<base64 of the 32-byte Ed25519 key>" }] }
shellaro ext keygen <id> creates a key and prints this entry. The packages in Shellaro's bundled catalog ship inside the installer (and its update signature) and are not signed individually in 0.7.