vendor select <name> --add/--remove/--mode all changes what a source
contributes without advancing the pinned rev: ids are validated against
the pinned upstream (typos abort listing available ids), collisions
re-run, renames from the lockfile are honored, and the external area is
rewritten via the same staging-swap as update. include mode grows and
shrinks the include list; all mode --remove moves ids onto exclude;
--mode all resets to everything. Failed selects mutate nothing.
Closes beads: agent-lib-cd3
- admin-protected client config (flag > AGENT_LIB_CONFIG > platform default),
token used for basic auth only, redacted from all errors and files
- work-repo pull via go-git (bare cache clone + fetch, remote re-pointed on
config change), clean failure keeps previous state
- inventory: own items + external areas from lockfile; MCP inventoried but
never deployed
- manifest v1 records name/type/origin/revision/content-hash per item,
deterministic bytes; folder hashes over sorted relpath+filehash lines so
tree and disk hashes agree
- shared deploy package (atomic temp+rename, exec-bit preserving) now backs
both curator materialization and client deployment
- sync validates and hashes everything before the first mutation; second run
is a byte-level no-op