# Otōto 2.11

> Source: <https://ototo.dev/changelog#v2.11>
> Published: 2026-10-01 18:04:17+00:00

- **Inside JARs, without unpacking.**`ototo outline lib/core.jar` lists a JAR, WAR, wheel or any other ZIP by directory, with what its manifest says, and`ototo read lib/core.jar!org.demo.Shelf` gives a class as its declarations: generics,`throws` , parameter names and constants, read from the class file itself, with no`unzip` , no`javap` and no JDK. Any other entry reads like a file (`lib/core.jar!META-INF/MANIFEST.MF` , with`:10-40` or`#name` ), a library inside a WAR is one more`!` , and a class says where its source is when a`-sources.jar` sits beside the JAR. Nothing is unpacked to disk, and a secrets file in an archive is neither listed nor read. Claude is told: the CLAUDE.md block gains a line, and the Bash hook now sends`unzip -l` ,`unzip -p` ,`jar tf` and`javap` on such a file to`ototo read` .
- **It is a plugin, `archive`, of a new kind.** It comes with this package like the others. A plugin of this kind is lent the bytes of the files its own globs name (`.jar` ,`.zip` ,`.class` …), read-only, and nothing else: no other file, no network.`ototo plugins` shows it as "opens …".
- **Your dependencies' JARs, if you say so.** A dependency's JAR is usually outside the repository, where Otōto reads nothing.`dependency_caches = true` in`config.toml` lets`read` and`outline` look into the archives in`~/.m2/repository` and`~/.gradle/caches` (or the directories you list), by absolute path: archives only, nothing else there, never a write, and off unless you set it.`/add-dir ~/.m2/repository` in Claude Code is the other way, for one session. An organisation can enforce the setting, off included, and`ototo doctor` says which directories are read.
- **Plugins are published on their own.** A new or fixed plugin no longer waits for a release of Otōto: each has its own version, and the download channel has a signed index of them.`ototo plugins available` says how each stands to the one you have (the same, newer, or in need of a later Otōto), and`ototo plugins update` brings yours up to the channel's. It only goes forward a version, and nothing updates by itself. The index must be signed by Otōto's release key, and each plugin still needs its own signature by a key in your`allowed_signers` .
- **A plugin you can rebuild.** The index names the commit each plugin was built from:`sh dist/reproduce.sh --plugin archive` in the source rebuilds it and compares it with the channel's file, as`sh dist/reproduce.sh` does for a release.
- Upgrading from 2.10: `ototo update` , as before. It installs the`archive` plugin with the rest; restart open Claude Code or OpenCode sessions to load it.
