Pin by commit in the docs, tags trip pub up

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013F4NWNvYcdeSgqbWMT1VQ7
This commit is contained in:
ImBenji
2026-09-23 18:53:41 +01:00
co-authored by Claude Opus 5.5
parent b269201919
commit 21c380595f
3 changed files with 31 additions and 14 deletions
+13 -7
View File
@@ -30,7 +30,7 @@ Everything here is MIT licensed, see [LICENSE](LICENSE).
## Install
The packages arent on pub.dev. Git-depend on this repo, pick the package with
`path:`, and pin a tag:
`path:`, and pin the commit of a release tag:
```yaml
dependencies:
@@ -38,20 +38,26 @@ dependencies:
git:
url: https://git.imbenji.dev/IMBENJI.NET/Garage-SDKs.git
path: garage_auth
ref: v0.1.0
ref: b2692019197e60d44ddd3ecab4917caf71ff45c3 # v0.1.0
garage_entitlements:
git:
url: https://git.imbenji.dev/IMBENJI.NET/Garage-SDKs.git
path: garage_entitlements
ref: v0.1.0
ref: b2692019197e60d44ddd3ecab4917caf71ff45c3 # v0.1.0
```
Pin a tag, dont float `main`. `garage_entitlements` decides who gets the paid
Pin, dont float `main`. `garage_entitlements` decides who gets the paid
features, and "it changed under us" is not a fun thing to debug.
`garage_entitlements` and `garage_iap` layer on `garage_auth`. You get it
transitively, but declare it too — you'll be constructing a `GarageAuth`
yourself anyway, and keep all of them on the same `ref`.
Use the tag's **full commit hash**, not the tag name. `garage_entitlements` and
`garage_iap` pull in `garage_auth` by relative path, which pub turns into a git
dep at the resolved commit hash — so if your app asks for `garage_auth` at
`v0.1.0`, pub sees two different sources for the same package and refuses to
resolve. Same hash on every garage package and it just works. Keep the tag name
in a comment so you can tell which release it is.
You'll be constructing a `GarageAuth` yourself, so declare `garage_auth`
directly even when you only really want entitlements or iap.
**Working on the SDKs at the same time as an app?** Point the app at a local
checkout with a gitignored `pubspec_overrides.yaml`, so edits hot reload with