module
Lapis::Docs::B_LAPIS_CLI_AND_TOOLCHAIN::M_ADDON_STORE_AND_SECURITY
Overview
Addon Store & Security Auditing
Comprehensive guide to managing community and third-party GDExtension addons in Lapis, including automated security checks, Git version pinning, vendoring, and project synchronization.
Executive Summary & Key Topics
| Topic | Method / Anchor | Description |
|---|---|---|
| Addon Management Capabilities | .topic_00_addon_capabilities |
Listing of features provided by lapis addon and lapis install-addon. |
| Installing Addons from Git | .topic_01_installing_from_git |
Cloning and installing community addons with branch and tag pinning. |
| Automated Security & Integrity Auditing | .topic_02_security_auditing |
How Lapis protects projects from untrusted third-party addon code. |
| Dependency & Plugin Synchronization | .topic_03_dependency_and_plugin_sync |
Automatic synchronization with shard.yml and project.godot. |
| Vendoring Addons for Offline Builds | .topic_04_vendoring_and_offline_builds |
Freezing addon source code directly in the repository. |
Related Guides & Source References
- Addon CLI Command:
tools/lapis/src/commands/install_addon.cr - Shard Manager:
tools/lapis/src/commands/shard_manager.cr - Specifications:
tools/lapis/spec/install_addon_spec.cr
Defined in:
libgodot/docs/b_lapis_cli_and_toolchain/m_addon_store_and_security.crClass Method Summary
-
.topic_00_addon_capabilities : Nil
Addon Management Capabilities: Listing of features provided by lapis addon and lapis install-addon.
-
.topic_01_installing_from_git : Nil
Installing Addons from Git: Cloning and installing community addons with branch and tag pinning.
-
.topic_02_security_auditing : Nil
Automated Security & Integrity Auditing: How Lapis protects projects from untrusted third-party addon code.
-
.topic_03_dependency_and_plugin_sync : Nil
Dependency & Plugin Synchronization: Automatic synchronization with shard.yml and project.godot.
-
.topic_04_vendoring_and_offline_builds : Nil
Vendoring Addons for Offline Builds: Freezing addon source code directly in the repository.
Class Method Detail
Addon Management Capabilities: Listing of features provided by lapis addon and lapis install-addon.
Key Topics & Information
- Git URL Installation: Clone and install directly from GitHub, GitLab, or Git hosts
- Automated Security Audit: Blocks dangerous shell scripts, binaries, and path traversal
- Atomic Registration: Updates shard.yml and enables plugin in project.godot
- Vendoring Support: Freezes addon source code locally for self-contained repositories
- Clean Uninstallation: Removes files and disables plugins without leaving dangling references
Installing Addons from Git: Cloning and installing community addons with branch and tag pinning.
To install an addon directly from a Git repository:
# Install latest version
lapis addon install https://github.com/sol-vin/lapis_dialogue.git
# Pin to a specific release branch or tag
lapis addon install https://github.com/sol-vin/lapis_inventory.git --branch=v2.1.0
# Install from a local folder during development
lapis addon install ../my_local_addon
Automated Security & Integrity Auditing: How Lapis protects projects from untrusted third-party addon code.
Before copying files into addons/, Lapis conducts an automated security audit:
- Path Traversal Protection: Ensures no archive or git symlink escapes outside the target addon folder.
- Script Verification: Scans for unauthorized executables, obfuscated binaries, or rogue post-install shell scripts.
- ClassDB Conflict Detection: Checks if custom node names clash with existing engine classes or installed addons.
Dependency & Plugin Synchronization: Automatic synchronization with shard.yml and project.godot.
When an addon is installed or removed, Lapis synchronizes two primary manifests:
project.godot: Automatically appends the plugin path toeditor_plugins/enabled:[editor_plugins] enabled=["res://addons/lapis_dialogue/plugin.cfg"]shard.yml: Tracks the addon version or git dependency underaddons:and runsshards install.
Vendoring Addons for Offline Builds: Freezing addon source code directly in the repository.
For enterprise game projects or offline air-gapped CI environments:
lapis addon install https://github.com/sol-vin/lapis_dialogue.git --vendor
The --vendor flag extracts the complete source code directly into addons/ and src/ without depending on external Git repositories at compile time.