SP Package Manager (`spm`)
spm is the official dependency manager and build orchestrator for SP. It interfaces with the official package registry at https://registry.splang.shantopaul.com.
bash
1# 1. Scaffold a project2spm init my_service34# 2. Add an external dependency5spm add json@^1.2.067# 3. Install all dependencies from sp.toml8spm install910# 4. Compile application with dependencies11spm build1213# 5. Search registry14spm search http1516# 6. Verify lockfile checksums17spm verify
Cryptographic Lockfile (`sp.lock`)
Whenever spm install or spm add is executed, a deterministic sp.lock file is generated containing the exact resolved version and SHA-256 integrity hash for each package:
# Generated by spm v1.0.0. DO NOT EDIT MANUALLY. [[package]] name = "json" version = "1.2.0" source = "registry+https://registry.splang.shantopaul.com" checksum = "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
Tamper Detection
Running
spm verify checks every downloaded package archive on disk against the lockfile digest, aborting compilation if a hash mismatch is detected.