Skip to content

Releases: AssetLib/sdk-js

v0.5.2-preview.1

v0.5.2-preview.1 Pre-release
Pre-release

Choose a tag to compare

@kuuhaku0 kuuhaku0 released this 11 Oct 00:06
  • @assetlib/cli 0.3.0, unchanged from 0.5.1-preview.1 and attached to this release again. @assetlib/sdk-core changes only its version and README.

  • @assetlib/sdk-expo: on iOS and Android, client.resolveAnimation(ref) under the default disk cache policy always returned source: 'poster', so verified Lottie animations never reached the app's player. The native storage adapter accepted only PNG and WebP, so caching the verified JSON threw after a successful download, and it never looked for a cached animation. It now stores application/json as <sha256>.json in the same namespaced cache directory and reads it back. Each JSON entry is capped at 512 KiB (LOTTIE_LIMITS.bytes) and counts toward the same 50 MiB / 100 entry eviction budget as images. Other MIME types are still rejected, and raster storage, .webp compatibility and legacy namespace migration are unchanged. The core still rehashes and revalidates cached JSON on every read. The memory and none policies and Expo web were not affected.

  • Limits: the SDK includes no Lottie player; the app supplies one. A cache write that fails after a verified download still returns the poster, just as a failed image cache write returns the bundled image. Native SVG and PDF delivery are still not implemented. The fix is covered by Node unit tests that run the real adapter source against a simulated Expo filesystem; it has not been run on an iOS or Android device or simulator.

Attached: @assetlib/sdk-core and @assetlib/sdk-expo 0.5.2-preview.1, @assetlib/cli 0.3.0 (unchanged from v0.5.1-preview.1 apart from its README URL), and SHA256SUMS covering those three. Not on npm.

v0.5.1-preview.1

v0.5.1-preview.1 Pre-release
Pre-release

Choose a tag to compare

@kuuhaku0 kuuhaku0 released this 10 Oct 23:43
  • @assetlib/cli 0.3.0. @assetlib/sdk-core and @assetlib/sdk-expo change only their version.

  • @assetlib/cli: assetlib init sets up an Expo app that has no catalog yet. It adopts bundled images as adopt does but starts from no catalog and creates it, copies a checked public configuration to assetlib.public.json, and writes a GitHub Actions workflow that runs assetlib sync from the installed package with the token from a repository secret. It is a dry run unless --apply, refuses an existing catalog, writes nothing when no image can be adopted (exit 3), and never calls Git or the network. --image limits it to chosen images. The workflow gives the token to the sync step only: actions are pinned to commits, checkout keeps no credentials, dependency install scripts are off, values reach scripts as environment variables, literals are validated and single-quoted, and a non-HTTPS console is never written into CI. init never writes through a symlink. The adopt command's behavior and output are unchanged. See the CLI README.

Install the CLI from this release and run its entry file; it is not on npm, and the unscoped assetlib npm name is not ours:

npm install --save-dev https://github.com/AssetLib/sdk-js/releases/download/v0.5.1-preview.1/assetlib-cli-0.3.0.tgz
node ./node_modules/@assetlib/cli/bin/assetlib.mjs init --help

Attached: @assetlib/sdk-core and @assetlib/sdk-expo 0.5.1-preview.1, @assetlib/cli 0.3.0, and SHA256SUMS covering those three. The SDK and CLI packages are not on the npm registry. @assetlib/audit is not attached this time: its source has changed since @assetlib/audit 0.1.0 on npm, and it will ship under a new version. (The "0.1.0" audit tarball attached to v0.5.0-preview.1 was packed from that changed source, so it differs from the npm 0.1.0.)

Checks: npm run verify (core 521, Expo 81, audit 10 and CLI 84 tests, typecheck) and npm run pack:release locally, and CI run 38095916190 on 35e9f76.

v0.5.0-preview.1

v0.5.0-preview.1 Pre-release
Pre-release

Choose a tag to compare

@kuuhaku0 kuuhaku0 released this 10 Oct 04:06
  • @assetlib/cli 0.2.0.

  • Tintable icons, following the Assetlib tintable icon contract. A catalog placement may declare "rendering": "template" (or original, the default). Both codegen copies add rendering: 'template' to the generated reference only for template placements and reject any other value; catalogs without the field generate byte-identical output, and assetlib sync registers the field with the catalog.

  • @assetlib/sdk-core: signed descriptors (placements, state members, variant cells and catalog page images) may carry rendering. A malformed value (null, a non-string, or anything not matching ^[a-z][a-z0-9-]{0,31}$) rejects the release. A reference's rendering must equal the selected descriptor's (absent means original); a mismatch or a well-formed unknown value skips that descriptor like an incompatible size, with no cache read or download, and resolution continues with older retained cache and then the bundled fallback (fallbackReason: 'missing'). AssetRef gains rendering?: 'template' and ResolvedAsset gains rendering. The shared contract corpus adds 15 manifest cases and 10 rendering cases.

  • @assetlib/sdk-expo: TypeScript requires tintColor on AssetlibImage and AssetlibStateImage when asset is a template reference, and a missing tintColor logs one development warning per placement. Template references without pixelWidth and pixelHeight request logical size × PixelRatio.get(), rounded up.

  • Template descriptors come from a console that runs the tintable icon release. Older SDK versions do not check rendering, and older codegen drops it.

  • @assetlib/cli: assetlib sync --references now finds Swift call sites. The Swift SDK's generated accessors lower-camel the group and add an artwork method, so artwork.travel.coast and artwork.travel.coastArtwork(...) now count as references to the ["Travel", "coast"] symbol. These Swift forms apply only to two-segment symbols, and a form that another placement can also produce (for example with a ["Travel", "coastArtwork"] or ["travel", "coast"] symbol in the same catalog) is not credited to either placement. AppAssets, AssetCatalog and artwork matching of the exact symbol is unchanged, and longer names such as artwork.travel.coastline still do not match.

  • @assetlib/audit and the @assetlib/cli reference scan now skip Vendor directories, the common iOS spelling. The ignore list, and the audit's reported scope.ignoredDirectories, now include Vendor. Names still match exactly, so first-party folders such as Coverage or Target are scanned.

Attached: @assetlib/sdk-core and @assetlib/sdk-expo 0.5.0-preview.1, @assetlib/cli 0.2.0, an @assetlib/audit tarball labeled 0.1.0, and SHA256SUMS covering all four. The SDK and CLI packages are not on the npm registry.

Correction, October 10, 2026: the attached audit tarball was packed from source after npm's @assetlib/audit 0.1.0 (it adds the Vendor skip), so despite its label it is not the npm 0.1.0 package. Use @assetlib/audit 0.2.0 on npm, which includes that change.

0.4.1-preview.1

0.4.1-preview.1 Pre-release
Pre-release

Choose a tag to compare

@kuuhaku0 kuuhaku0 released this 09 Oct 23:05

@assetlib/sdk-core and @assetlib/sdk-expo 0.4.1-preview.1, @assetlib/cli 0.1.1

Distributed as exact-version tarballs; install the core and Expo tarballs from this release together. The audit package is unchanged at 0.1.0 and remains on npm. Public configurations from the hosted console are unaffected.

  • @assetlib/cli 0.1.1: the README now installs the CLI from the release tarball instead of npm, where it is not published. No code change from 0.1.0.
  • Public configuration now accepts raw JSON strings and enforces a 4096-byte UTF-8 limit. Object inputs use their JSON serialization. Unknown fields and JSON whitespace count toward the limit.
  • Configurations with duplicate PEM pins or more than 16 pins are now rejected. Each pin must be an Ed25519 SPKI PEM of at most 256 UTF-8 bytes.
  • Near-limit configurations remain reusable by a client: derived IDs are omitted when adding them would exceed 4096 bytes. Supplied IDs and every trusted pin are preserved.
  • The shared contract checks explicit nulls, invalid or mismatched IDs, and keyId without an explicit single pin. When both pin forms are supplied, the single pin must belong to the set; ordered keyIds must match every pin. Any trusted member may sign a release, including a member other than the single pin.
  • The JavaScript tests now run every generated shared config case as both a JSON string and an object, including exact byte boundaries and signatures from a second trusted key and an untrusted key.

Validation on October 9, 2026: npm run verify (core 490, Expo 78, audit 9, CLI 65) and the shared native-contract verifier (226).

0.4.0-preview.1

0.4.0-preview.1 Pre-release
Pre-release

Choose a tag to compare

@kuuhaku0 kuuhaku0 released this 09 Oct 05:19

@assetlib/sdk-core and @assetlib/sdk-expo 0.4.0-preview.1, @assetlib/cli 0.1.0

Distributed as exact-version tarballs; install the core and Expo tarballs from this release together. The audit package is unchanged at 0.1.0 and remains on npm.

  • Staging environment in the public configuration, and a pinned key set (pinnedPublicKeys, keyIds) alongside the single key.
  • Signed variantSchemaVersion: 1 validation and resolution of appearance and arm cells in the fixed order, with cache keys per selected cell; Expo components follow the system color scheme and accept an arm prop.
  • A decide callback supplies the arm from the app's experiment tool, evaluated outside the operation queue with a bounded wait and re-resolution against current state.
  • Opt-in telemetry: coalesced resolve, display, and fallback events with a random per-install id, flushed on an interval, on refresh, on demand, and on app background. Off by default.
  • Storage namespace derived from origin, org, app, and environment only, with a one-time verified migration from the previous formulas, so the replay floor and cache survive key-set changes and the legacy to environment URL switch.
  • New @assetlib/cli: assetlib sync registers a build and its catalog with the console (HTTPS only; loopback HTTP behind an explicit flag), assetlib hash, assetlib check, and assetlib adopt, a dry-run codemod that turns bundled Expo image call sites into declared placements.

Verification: core 251, Expo 78, audit 9, CLI 65 tests; typecheck and build. SHA256SUMS covers every tarball.

0.2.1-preview.1 — Artwork accessibility descriptions

Choose a tag to compare

@kuuhaku0 kuuhaku0 released this 08 Oct 04:54

Image descriptions now travel with the signed artwork descriptor. When an image update falls back to a verified cached release or the bundled image, its accessibility description follows the selected artwork. Locale lookup tries an exact case-insensitive match, parent subtags, then the explicitly declared default language.

Expo applications opt into accessibilityMode="description" or "decorative" per usage. Descriptive mode retains bundled artwork when a remote image lacks metadata, and native accessibilityLabel remains an explicit app override. Decode failures and replaced requests restore the matching bundled description. Checked-in catalog entries can include bundledAccessibility; offline code generation validates and preserves it.

Existing manifests and application code remain compatible. This release adds accessibility to the previously released placement API; it does not include the separate development work on state sets, dynamic collections, animation, or additional cache policies.

Install both matching tarballs as direct dependencies:

npm install \
  https://github.com/AssetLib/sdk-js/releases/download/v0.2.1-preview.1/assetlib-sdk-core-0.2.1-preview.1.tgz \
  https://github.com/AssetLib/sdk-js/releases/download/v0.2.1-preview.1/assetlib-sdk-expo-0.2.1-preview.1.tgz

These are GitHub release artifacts, not an npm registry publication. Core contains built JavaScript and declarations; Expo contains Metro-ready source. SHA-256 checksums are attached. The audit CLI is not included in these release artifacts.

Validation: 103 core tests, including 82 signed cross-platform contract cases; six Expo component tests; nine unchanged audit regression tests; Expo typechecking; clean tarball installation, signed delivery/cache/fallback and offline-generator smoke checks, and consumer TypeScript checks. CI passed for the release commit. Expo component tests use mocked rendering boundaries; this release does not claim native-device, VoiceOver, or TalkBack execution.

Source commit: f1bfc7cd6927efc59e75d522cc03a5928b3652a7.

0.2.0-preview.1 — PNG, sizes, and browser SVG

Choose a tag to compare

@kuuhaku0 kuuhaku0 released this 08 Oct 03:42

Adds signed PNG/WebP rendition selection by explicit pixel width and height, plus opt-in normalized SVG delivery in the browser adapter. The Expo native adapter selects raster output and preserves old WebP caches. Existing schema-1 manifests and the mandatory legacy WebP fallback remain supported.

Install both matching core and Expo tarballs as direct dependencies. Both packages are GitHub release artifacts; they are not published to npm. Checksums are attached. The core package contains built JavaScript/declarations; Expo includes Metro-ready source.

Validation: 80 core tests including 65 shared signed contract cases; nine audit tests; Expo typecheck; Chrome PNG/WebP/SVG decode and wrong-dimension rejection checks. Native Expo UI execution is separate. The standalone Swift/Kotlin SDKs are released in their own repositories.

Assetlib SDK preview 0.1.0-preview.1

Pre-release

Choose a tag to compare

@kuuhaku0 kuuhaku0 released this 08 Oct 01:00

An installable developer preview for signed artwork delivery into typed app placements.

  • TypeScript core: pinned Ed25519 signatures, app-scoped manifests, SHA-256 image verification, durable sequence checks, lazy downloads, and bounded verified cache.
  • Expo 57 adapter: native filesystem and web IndexedDB storage, expo-image rendering, and bundled fallback.
  • Offline placement generator plus a local, read-only asset audit and agent skill.

Install both matching SDK tarballs using the README. Packages are not published on npm. SHA256SUMS is attached.

Validation: 10 core tests, 9 audit tests, Expo typecheck, fresh workspace install, and isolated tarball-consumer typecheck passed. Native device runtime validation remains pending. Experiment assignment, Figma sync, usage telemetry, key rotation, and production operations are outside this preview.