Sources
The Marketplace reads packages from sources (Marketplace > Sources). Whatever the source, every package is checked and shown for review before it is installed.
| Source | Where | Notes |
|---|---|---|
| Shellaro (built in) | Inside the installer | Always there, works offline. |
| Index | index.json at an https URL, or in a local or shared folder | A static web server, a Git host's raw files, an internal server, a network share. |
| Folder of packages | A local folder of .shellaro-ext files | Each file is read and checked; if the folder has an index.json, that is used. |
| Marketplace API | A server implementing Marketplace API v1 | No public server exists yet; add one if you run it. |
Remote addresses must use https; plain http is accepted only for 127.0.0.1 and localhost (testing). Downloads must match the SHA-256 the source announced.
When several sources offer the same package id, the newest version that fits this Shellaro wins (the built-in catalog wins ties). Installed packages with a newer compatible version appear under Updates.
index.json
{
"schemaVersion": 1,
"name": "Team packages",
"items": [
{
"id": "acme.k8s-tools",
"type": "extension",
"name": "K8s Tools",
"publisher": "Acme",
"version": "1.2.0",
"description": "Pods and logs for the active server.",
"category": "Containers & Kubernetes",
"tags": ["kubernetes"],
"status": "working",
"featured": false,
"permissions": ["ui.sidebar", "remote.exec"],
"networkHosts": [],
"engines": { "shellaro": ">=0.7.0" },
"summary": "11 KB of code",
"readme": "# K8s Tools\n...",
"changelog": "# Changelog\n...",
"license": "MIT",
"homepage": "https://example.com",
"package": "packages/acme.k8s-tools-1.2.0.shellaro-ext",
"sha256": "<64 hex digits of the package file>",
"size": 11234
}
]
}
packageis relative toindex.jsonor an absolute https URL. Items withoutpackageandsha256are listed as Planned.status:working,prototype,sample,planned; shown on every card.permissions,readme,changelogare for display before download; the package's own manifest is what counts at review time.shellaro ext publish --index <folder>writes and updates this file for you.
Git and private sources
Put index.json and packages/ in a repository and point an Index source at the raw URL of index.json (it must be reachable over https without interactive login), or clone it and use the local folder. Shellaro does not run Git itself.