SP Package Manager (`spm`)

spm is the official dependency manager and build orchestrator for SP. It interfaces with the official package registry at https://registry.splang.shantopaul.com.

bash
1# 1. Scaffold a project
2spm init my_service
3
4# 2. Add an external dependency
5spm add json@^1.2.0
6
7# 3. Install all dependencies from sp.toml
8spm install
9
10# 4. Compile application with dependencies
11spm build
12
13# 5. Search registry
14spm search http
15
16# 6. Verify lockfile checksums
17spm verify

Cryptographic Lockfile (`sp.lock`)

Whenever spm install or spm add is executed, a deterministic sp.lock file is generated containing the exact resolved version and SHA-256 integrity hash for each package:

# Generated by spm v1.0.0. DO NOT EDIT MANUALLY.
[[package]]
name = "json"
version = "1.2.0"
source = "registry+https://registry.splang.shantopaul.com"
checksum = "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
Tamper Detection
Running spm verify checks every downloaded package archive on disk against the lockfile digest, aborting compilation if a hash mismatch is detected.