x07-package
This skill documents the single canonical workflow for dependency management in X07 using the built-in package manager (x07 pkg...).
When to use
Use this skill when:
- adding/updating dependencies,
- generating/verifying lockfiles,
- publishing a package to an index/registry.
Canonical commands
- Create a publishable package repo (for
x07 pkg publish):
- x07 init --package
- Add a dependency entry to
x07.jsonand sync the lockfile:
- x07 pkg add <name>@<version> --sync
- Generate or update a project lockfile:
- x07 pkg lock --project x07.json
- Non-mutating whole-project validation (no emit):
- x07 check --project x07.json
- Reverse-lookup which package provides a module:
- x07 pkg provides <module-id>
- List available versions of a package:
- x07 pkg versions <name> - x07 pkg versions <name> --refresh
- Verify a lockfile is up to date (CI mode):
- x07 pkg lock --project x07.json --check - If you intentionally accept risk in CI: add --allow-yanked and/or --allow-advisories
- Pack a package directory deterministically:
- x07 pkg pack --package <dir> --out <out.x07pkg>
- Login (store credentials for an index):
- Interactive: x07 pkg login --index <url> - Non-interactive: printf '%s' "$X07_TOKEN" | x07 pkg login --index <url> --token-stdin
- Publish:
- x07 pkg publish --package <dir> --index <url>
Notes
- Official registry index URL:
sparse+https://registry.x07.io/index/ - Publishing to the official registry requires non-empty
descriptionanddocsinx07-package.json. - The lockfile path is controlled by
x07.json(lockfile) and defaults tox07.lock.json. - When fetching is required,
x07 pkg lockdefaults to the official registry index; override with--index <url>. - Sparse index reads (including
x07 pkg versions) may be cached; use--refreshafter publishing to force a cache-busting fetch (HTTP/HTTPS indexes only). - Canonical project manifests use
x07.project@0.3.0.x07.project@0.2.0is accepted for legacy manifests, butproject.patchrequires@0.3.0. - In
--checkmode, when the index can be consulted, lock validation also fails on yanked dependencies and active advisories unless explicitly allowed. - Use
project.patchinx07.jsonto override transitive dependency versions (for example, moving off yanked/advised versions). - Patch paths under
.x07/deps/...are treated as vendored deps (fetchable) duringx07 pkg lockhydration; patch paths elsewhere are local-only and must exist on disk. - Official packages may declare required helper packages via
meta.requires_packages. When present,x07 pkg lockmay add and fetch these transitive deps (and updatex07.json). - If dependencies are already present on disk,
x07 pkg lockcan run without--indexusing--offline.
See also: https://x07lang.org/docs/packages/publishing-by-example/