Register, review and certify packages
Put module versions in the package registry, approve their licences, review them, and have a different person certify them for releases.
Before you begin
A package is one version of one module. A release can only carry packages that are Reviewed or Certified. Four roles share the work so no one person can push a package through alone.
Register packages
Sync from this build
- Open Platform > Packages > Packages.
- Press Sync from this build.
- Read the result: 'Registered n, refreshed n, drifted n, unchanged n.'
Every module of this build becomes a Draft package with the source Build manifest, the licence Proprietary (a2NSoft), its digest and its file count. Running it again with no code change gives all unchanged.
Sync never rewrites a reviewed version. If the files of a Reviewed or Certified package have changed, the package is marked drifted: the Digest column shows a warning mark and the Overview tile Drifted packages goes up. It returns to normal when the files match again.
Register an uploaded package
- Press Register a package.
- Enter the Code (capitals, digits and
_, 2 to 40 characters, starting with a letter, for exampleX_DEMO) and Version (1.0.0). Both are fixed after saving. - Enter the Title, the Artifact SHA-256 (exactly 64 hex characters), the origin, the licence and the support owner.
- Enter Core versions, the range of the core it supports:
1,1.x,^1.2.0,>=1.0, <2.0. This build is core 1.0.0. - Enter Dependencies, one per line as
CODE range(FIN >=1.0). Each code once. - Save. The package is a Draft of kind custom, with licence review Pending.
Only a draft can be edited. A reviewed or certified version cannot change: register a new version instead.
Review and certify
- Licence review. An approver opens the package and presses Licence review, chooses Approved, Not required or Rejected, and adds a note. A note is required to reject.
- Review. A release manager opens the Review checks tab, which lists every open problem, and presses Review. It is refused until the licence review is Approved or Not required, a support owner or maintainer is named, every dependency exists as a reviewed version, there is no dependency cycle ('Dependency cycle: A -> B -> A.') and the core range includes this build ('X_DEMO 1.0.0 needs core 2; this build is core 1.0.0.').
- Certify. A different approver presses Certify. The person who reviewed or registered the package cannot certify it: 'Somebody other than the person who prepared this package version must approve it.'
The package is now Certified and offered in release package pickers. The Capabilities list shows it as Certified.
Send back and retire
- Send back returns a Reviewed version to Draft. A reason is required. A draft cannot be sent back.
- Retire (configuration owner) takes a version out of use. It is refused while a release that is approved or active still runs it: 'Release REL-0001 still runs this version.' It is also refused when it is the only reviewed version of a package that another reviewed package depends on.
What happens next
A certified package appears on the Packages tab of a release. The App install gate also asks the registry: when the flag platform.enforce_registry is on, an app whose package has no reviewed or certified version cannot be installed: ''finance' needs package FIN, which has no reviewed or certified version in the package registry.'
The record
Open a package to see its tabs: Details, Review checks (draft and reviewed only), Versions and use (all versions, which packages need it, which releases carry it) and History. The smart buttons show Dependencies, Needed by and Digest.
Good to know
- Version must look like
1.4.0: '1.4' is refused with 'Use a version such as 1.4.0.' - Two registrations of the same code and version are refused: 'That version of the package is already registered.'
- The step names in a few refusal messages are misspelled, for example 'A draft package cannot be certifyed.' This means the package is in the wrong stage for that step.