module Lapis::Docs::B_LAPIS_CLI_AND_TOOLCHAIN::M_ADDON_STORE_AND_SECURITY

Overview

Addon Store & Security Auditing

Comprehensive guide to managing community and third-party GDExtension addons in Lapis, including automated security checks, Git version pinning, vendoring, and project synchronization.

Executive Summary & Key Topics

Topic Method / Anchor Description
Addon Management Capabilities .topic_00_addon_capabilities Listing of features provided by lapis addon and lapis install-addon.
Installing Addons from Git .topic_01_installing_from_git Cloning and installing community addons with branch and tag pinning.
Automated Security & Integrity Auditing .topic_02_security_auditing How Lapis protects projects from untrusted third-party addon code.
Dependency & Plugin Synchronization .topic_03_dependency_and_plugin_sync Automatic synchronization with shard.yml and project.godot.
Vendoring Addons for Offline Builds .topic_04_vendoring_and_offline_builds Freezing addon source code directly in the repository.

Related Guides & Source References

Defined in:

libgodot/docs/b_lapis_cli_and_toolchain/m_addon_store_and_security.cr

Class Method Summary

Class Method Detail

def self.topic_00_addon_capabilities : Nil #

Addon Management Capabilities: Listing of features provided by lapis addon and lapis install-addon.

Key Topics & Information

  • Git URL Installation: Clone and install directly from GitHub, GitLab, or Git hosts
  • Automated Security Audit: Blocks dangerous shell scripts, binaries, and path traversal
  • Atomic Registration: Updates shard.yml and enables plugin in project.godot
  • Vendoring Support: Freezes addon source code locally for self-contained repositories
  • Clean Uninstallation: Removes files and disables plugins without leaving dangling references

def self.topic_01_installing_from_git : Nil #

Installing Addons from Git: Cloning and installing community addons with branch and tag pinning.

To install an addon directly from a Git repository:

# Install latest version
lapis addon install https://github.com/sol-vin/lapis_dialogue.git

# Pin to a specific release branch or tag
lapis addon install https://github.com/sol-vin/lapis_inventory.git --branch=v2.1.0

# Install from a local folder during development
lapis addon install ../my_local_addon

def self.topic_02_security_auditing : Nil #

Automated Security & Integrity Auditing: How Lapis protects projects from untrusted third-party addon code.

Before copying files into addons/, Lapis conducts an automated security audit:

  • Path Traversal Protection: Ensures no archive or git symlink escapes outside the target addon folder.
  • Script Verification: Scans for unauthorized executables, obfuscated binaries, or rogue post-install shell scripts.
  • ClassDB Conflict Detection: Checks if custom node names clash with existing engine classes or installed addons.

def self.topic_03_dependency_and_plugin_sync : Nil #

Dependency & Plugin Synchronization: Automatic synchronization with shard.yml and project.godot.

When an addon is installed or removed, Lapis synchronizes two primary manifests:

  1. project.godot: Automatically appends the plugin path to editor_plugins/enabled:
    [editor_plugins]
    enabled=["res://addons/lapis_dialogue/plugin.cfg"]
  2. shard.yml: Tracks the addon version or git dependency under addons: and runs shards install.

def self.topic_04_vendoring_and_offline_builds : Nil #

Vendoring Addons for Offline Builds: Freezing addon source code directly in the repository.

For enterprise game projects or offline air-gapped CI environments:

lapis addon install https://github.com/sol-vin/lapis_dialogue.git --vendor

The --vendor flag extracts the complete source code directly into addons/ and src/ without depending on external Git repositories at compile time.