# Do we need a policy against one-liner registered packages?

**URL:** <https://discourse.julialang.org/t/do-we-need-a-policy-against-one-liner-registered-packages/54999>\
**Category:** General Usage\
**Created:** [February 10, 2021, 2:57pm UTC](https://discourse.julialang.org/t/do-we-need-a-policy-against-one-liner-registered-packages/54999 "2021-02-10T14:57:50Z")\
**Posts on this page:** 4\
**Page:** 2

<div class="post-metadata">

**Author:** ![GunnarFarneback](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/gunnarfarneback/32/1827_2.png) [@GunnarFarneback](https://discourse.julialang.org/u/GunnarFarneback)\
**Post date:** [February 18, 2021, 9:07pm UTC](https://discourse.julialang.org/t/do-we-need-a-policy-against-one-liner-registered-packages/54999/21 "2021-02-18T21:07:25Z")

</div>

> [@carstenbauer](#):
>
> To systematically share packages with a group of people (instead of everyone), you could create your own separate registry which, in principle, isn’t too hard (see my presumably [outdated notes](https://github.com/crstnbr/TrebstRegistry/blob/master/custom_registry.md))

Yes, those are terribly outdated. Nobody should be using my fork of Registrator anymore. Use [GitHub - GunnarFarneback/LocalRegistry.jl: Create and maintain local registries for Julia packages.](https://github.com/GunnarFarneback/LocalRegistry.jl) instead.

---

<div class="post-metadata">

**Author:** ![Eben60](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/eben60/32/13475_2.png) [@Eben60](https://discourse.julialang.org/u/Eben60)\
**Post date:** [February 19, 2021, 8:35am UTC](https://discourse.julialang.org/t/do-we-need-a-policy-against-one-liner-registered-packages/54999/22 "2021-02-19T08:35:20Z")

</div>

Yes, currently if I try to add an installed on my computer but unregistered package to another one under development, I get an `ERROR: expected package `blablabla [12345678]` to be registered`.

Why wouldn’t it be possible to add the source of this unregistered package to the `Project.toml` (e.g. in a separate section `source`)?

Then allow adding it to other packages and sharing these. Maybe with a warning when I `add` a dependency to such package, and also when one installs a package with dependencies on unregistered packages.

---

<div class="post-metadata">

**Author:** ![ericphanson](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ericphanson/32/215186_2.png) [@ericphanson](https://discourse.julialang.org/u/ericphanson)\
**Post date:** [February 19, 2021, 12:38pm UTC](https://discourse.julialang.org/t/do-we-need-a-policy-against-one-liner-registered-packages/54999/23 "2021-02-19T12:38:26Z")

</div>

If you send the Manifest.toml, then it should work (because it stores the URLs there, as well as the exact versions of every dependency and the exact commit of unregistered dependencies).

---

<div class="post-metadata">

**Author:** ![rikh](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/rikh/32/204104_2.png) [@rikh](https://discourse.julialang.org/u/rikh)\
**Post date:** [February 19, 2021, 1:39pm UTC](https://discourse.julialang.org/t/do-we-need-a-policy-against-one-liner-registered-packages/54999/24 "2021-02-19T13:39:40Z")

</div>

Or, depending on your use-case, provide a script which does Pkg.add before activating the project. See ?Pkg.add for instructions on how to install a project from a Git url. The benefit is that you don’t have to commit the Manifest.toml and keep the Git diff more clear as well as that it will automatically install the newest version unlike the manifest.

[Previous page](https://discourse.julialang.org/t/do-we-need-a-policy-against-one-liner-registered-packages/54999.md?page=1)
