Supply Chain Security Protocol

Security & Cryptographic Integrity

The SP Package Registry is engineered with strict cryptographic verification to defend against supply chain tampering, unauthorized substitutions, and dependency confusion attacks.

SHA-256 Digest Verification

Every published archive is indexed with an authoritative SHA-256 hash. SPM recomputes the hash on download and halts immediately if there is any mismatch.

Deterministic Lockfiles

Every project generates an immutable sp.lock containing exact version pins and cryptographic checksums for CI/CD consistency.

Zero Script Execution

Unlike other ecosystems, SPM does NOT permit arbitrary pre-install or post-install shell script execution during dependency downloads.

Deterministic Lockfile Specification (sp.lock)

The SP lockfile records the authoritative source and SHA-256 checksum for every direct and indirect dependency:

sp.lock
[[package]]
name = "crypto"
version = "1.0.4"
source = "registry+https://registry.splang.shantopaul.com"
checksum = "c3d4e5f60718293a4b5c6d7e8f90123456789abcdef0123456789abcdef01234"
dependencies = []

[[package]]
name = "http"
version = "1.1.0"
source = "registry+https://registry.splang.shantopaul.com"
checksum = "b2c3d4e5f60718293a4b5c6d7e8f90123456789abcdef0123456789abcdef01"
dependencies = [
    "crypto 1.0.4",
    "json 1.2.0"
]

Verifying Package Integrity Locally

You can inspect and verify local cache integrity at any time using native SPM commands:

Verify Specific Package

Validates downloaded tarball against the registry API checksum.

spm verify crypto 1.0.4
Audit Dependency Tree

Scans all active project dependencies for known security advisories.

spm audit
Responsible Vulnerability Disclosure

If you discover a security issue or vulnerability in any package published to the SP Registry, please contact our Security Working Group before public disclosure. We coordinate with package authors to issue patched releases swiftly.

security@splang.shantopaul.comPGP Key ID: 0x4F8E29C1