7.6.1 swift package-collection add

原文链接: https://docs.swift.org/latest/documentation/packagemanagerdocs/packagecollectionadd/

7.6.1 swift package-collection add

添加一个新的集合。

概述

这个子命令添加托管在 Web 上的包集合(要求 HTTPS):

1
2
$ swift package-collection add https://www.example.com/packages.json
Added "Sample Package Collection" to your package collections.

或者位于本地文件系统中:

1
2
$ swift package-collection add file:///absolute/path/to/packages.json
Added "Sample Package Collection" to your package collections.

可选的 order 提示可以用来对集合排序,并可能影响搜索结果中的排序:

1
2
$ swift package-collection add https://www.example.com/packages.json [--order N]
Added "Sample Package Collection" to your package collections.

已签名的包集合

包集合的发布者可以对集合签名以保护其内容。在导入之前,包管理器会检查已签名集合的签名是否有效。如果校验失败,包管理器会返回错误:

1
2
$ swift package-collection add https://www.example.com/bad-packages.json
The collection's signature is invalid. If you would like to continue please rerun command with '--skip-signature-check'.

用户可以在出现错误的情况下继续添加集合,或者通过传入 --skip-signature-check 标志预先跳过对某个包集合的签名检查:

1
$ swift package-collection add https://www.example.com/packages.json --skip-signature-check

对于托管在 Web 上的包集合,发布者可以要求包管理器强制实施签名要求。如果某个包集合本应已签名但实际上没有,用户会看到下面这条错误消息:

1
2
$ swift package-collection add https://www.example.com/bad-packages.json
The collection is missing required signature, which means it might have been compromised.

这种情况下用户不应添加该包集合。

关于签名验证的更多细节,参见已签名的包集合。

受信任的根证书

作为签名验证的一部分,包管理器会验证证书以确保根证书受信任。

1
2
$ swift package-collection add https://www.example.com/packages.json
The collection's signature cannot be verified due to missing configuration.

用户可以明确表示信任某个发布者及其发布的全部集合:取得该发布者的根证书并保存到 ~/.swiftpm/config/trust-root-certs 即可。根证书必须是 DER 编码的。由于包管理器信任某个根证书之下的所有证书链,取决于安装了哪些根证书,某些发布者可能已被隐式信任,用户无需逐个显式指定。

未签名的包集合

用户在尝试添加未签名的包集合时会得到错误:

1
2
$ swift package-collection add https://www.example.com/packages.json
The collection is not signed. If you would still like to add it please rerun 'add' with '--trust-unsigned'.

要继续,用户必须通过传入 --trust-unsigned 标志来确认信任:

1
$ swift package-collection add https://www.example.com/packages.json --trust-unsigned

--skip-signature-check 标志对未签名的集合没有效果。

用法

package-collection add <collection-url> [--order=<order>]
  [--trust-unsigned] [--skip-signature-check]
  [--package-path=<package-path>] [--cache-path=<cache-path>]
  [--config-path=<config-path>]
  [--security-path=<security-path>]
  [--scratch-path=<scratch-path>]
  [--swift-sdks-path=<swift-sdks-path>]
  [--toolset=<toolset>...]
  [--pkg-config-path=<pkg-config-path>...]
  [--enable-dependency-cache] [--disable-dependency-cache]
  [--enable-build-manifest-caching]
  [--disable-build-manifest-caching]
  [--manifest-cache=<manifest-cache>]
  [--enable-experimental-prebuilts]
  [--disable-experimental-prebuilts] [--verbose]
  [--very-verbose|vv] [--quiet] [--color-diagnostics]
  [--no-color-diagnostics] [--disable-sandbox] [--netrc]
  [--enable-netrc] [--disable-netrc]
  [--netrc-file=<netrc-file>] [--enable-keychain]
  [--disable-keychain]
  [--resolver-fingerprint-checking=<resolver-fingerprint-checking>]
  [--resolver-signing-entity-checking=<resolver-signing-entity-checking>]
  [--enable-signature-validation]
  [--disable-signature-validation] [--enable-prefetching]
  [--disable-prefetching]
  [--force-resolved-versions|disable-automatic-resolution|only-use-versions-from-resolved-file]
  [--skip-update] [--disable-scm-to-registry-transformation]
  [--use-registry-identity-for-scm]
  [--replace-scm-with-registry]
  [--default-registry-url=<default-registry-url>]
  [--configuration=<configuration>] [--=<Xcc>...]
  [--=<Xswiftc>...] [--=<Xlinker>...] [--=<Xcxx>...]
  [--triple=<triple>] [--sdk=<sdk>] [--toolchain=<toolchain>]
  [--swift-sdk=<swift-sdk>] [--sanitize=<sanitize>...]
  [--auto-index-store] [--enable-index-store]
  [--disable-index-store]
  [--enable-parseable-module-interfaces] [--jobs=<jobs>]
  [--use-integrated-swift-driver]
  [--explicit-target-dependency-import-check=<explicit-target-dependency-import-check>]
  [--build-system=<build-system>] [--=<debug-info-format>]
  [--enable-dead-strip] [--disable-dead-strip]
  [--disable-local-rpath] [--version] [--help]
  • collection-url:

要添加的集合的 URL。

  • –order=<order>:

所添加集合的排序顺序。

  • –trust-unsigned:

即使集合未签名也信任它。

  • –skip-signature-check:

如果集合已签名则跳过签名检查。

  • –package-path=<package-path>:

指定要操作的包路径(默认为当前目录)。这会先切换工作目录,然后再执行其他任何操作。

  • –cache-path=<cache-path>:

指定共享缓存目录的路径。

  • –config-path=<config-path>:

指定共享配置目录的路径。

  • –security-path=<security-path>:

指定共享安全目录的路径。

  • –scratch-path=<scratch-path>:

指定自定义的临时构建目录路径。(默认 .build)

  • –swift-sdks-path=<swift-sdks-path>:

包含已安装 Swift SDK 的目录路径。

  • –toolset=<toolset>:

指定为目标平台构建时使用的工具集 JSON 文件。可以多次使用该选项来指定多个工具集。各个工具集会按指定顺序合并为当前构建的单个最终工具集。

  • –pkg-config-path=<pkg-config-path>:

指定搜索 pkg-config .pc 文件的替代路径。可以多次使用该选项来指定多个路径。

  • –enable-dependency-cache|disable-dependency-cache:

获取依赖时使用共享缓存。

  • –enable-build-manifest-caching|disable-build-manifest-caching:

  • –manifest-cache=<manifest-cache>:

Package.swift 清单的缓存模式。有效取值:shared(共享缓存)、local(包的构建目录)、none(禁用)

  • –enable-experimental-prebuilts|disable-experimental-prebuilts:

是否对宏使用预编译的 swift-syntax 库。

  • –verbose:

提高详细程度,包含信息性输出。

  • –very-verbose|vv:

提高详细程度,包含调试输出。

  • –quiet:

降低详细程度,只包含错误输出。

  • –color-diagnostics|no-color-diagnostics:

在向 TTY 输出时启用或禁用彩色诊断信息。默认情况下,连接到 TTY 时启用彩色诊断,否则禁用。

  • –disable-sandbox:

执行子进程时禁用沙箱。

  • –netrc:

即使在其他凭据存储更优先的情况下也使用 netrc 文件。

  • –enable-netrc|disable-netrc:

从 netrc 文件加载凭据。

  • –netrc-file=<netrc-file>:

指定 netrc 文件的路径。

  • –enable-keychain|disable-keychain:

在 macOS 钥匙串中查找凭据。

  • –resolver-fingerprint-checking=<resolver-fingerprint-checking>:

  • –resolver-signing-entity-checking=<resolver-signing-entity-checking>:

  • –enable-signature-validation|disable-signature-validation:

验证从注册表下载的已签名包发布的签名。

  • –enable-prefetching|disable-prefetching:

  • –force-resolved-versions|disable-automatic-resolution|only-use-versions-from-resolved-file:

只使用 Package.resolved 文件中的版本,如果该文件已过期则解析失败。

  • –skip-update:

在解析期间跳过从远程更新依赖。

  • –disable-scm-to-registry-transformation:

禁用从源代码管理到注册表的转换。

  • –use-registry-identity-for-scm:

在注册表中查找源代码管理依赖,并尽可能使用它们的注册表标识,以帮助在两种来源之间去重。

  • –replace-scm-with-registry:

在注册表中查找源代码管理依赖,并尽可能改用注册表来获取它们,而不是用源代码管理。

  • –default-registry-url=<default-registry-url>:

要使用的默认注册表 URL,用于替代 registries.json 配置文件。

  • –configuration=<configuration>:

以指定配置构建

  • –=<Xcc>:

把标志传递给所有 C 编译器调用。

  • –=<Xswiftc>:

把标志传递给所有 Swift 编译器调用。

  • –=<Xlinker>:

把标志传递给所有链接器调用。

  • –=<Xcxx>:

把标志传递给所有 C++ 编译器调用。

  • –triple=<triple>:

  • –sdk=<sdk>:

  • –toolchain=<toolchain>:

  • –swift-sdk=<swift-sdk>:

筛选构建时要使用的特定 Swift SDK。

  • –sanitize=<sanitize>:

打开针对错误行为的运行时检查,可能取值:address、thread、undefined、scudo。

  • –auto-index-store|enable-index-store|disable-index-store:

启用或禁用构建期间建立索引的特性。

  • –enable-parseable-module-interfaces:

  • –jobs=<jobs>:

构建过程中并行启动的任务数量。

  • –use-integrated-swift-driver:

  • –explicit-target-dependency-import-check=<explicit-target-dependency-import-check>:

一个标志,表明本次构建应检查各个目标是否只导入它们显式声明的依赖。

  • –build-system=<build-system>:

  • –=<debug-info-format>:

要使用的调试信息格式。

  • –enable-dead-strip|disable-dead-strip:

禁用/启用链接器的死代码剥离。

  • –disable-local-rpath:

默认不再把 $ORIGIN/@loader_path 加入 rpath。

  • –version:

显示版本。

  • –help:

显示帮助信息。