Repository navigation
0.4.1-preview.1
Pre-release
Pre-release
·
33 commits
to main
since this release
@assetlib/sdk-core and @assetlib/sdk-expo 0.4.1-preview.1, @assetlib/cli 0.1.1
Distributed as exact-version tarballs; install the core and Expo tarballs from this release together. The audit package is unchanged at 0.1.0 and remains on npm. Public configurations from the hosted console are unaffected.
@assetlib/cli0.1.1: the README now installs the CLI from the release tarball instead of npm, where it is not published. No code change from 0.1.0.- Public configuration now accepts raw JSON strings and enforces a 4096-byte UTF-8 limit. Object inputs use their JSON serialization. Unknown fields and JSON whitespace count toward the limit.
- Configurations with duplicate PEM pins or more than 16 pins are now rejected. Each pin must be an Ed25519 SPKI PEM of at most 256 UTF-8 bytes.
- Near-limit configurations remain reusable by a client: derived IDs are omitted when adding them would exceed 4096 bytes. Supplied IDs and every trusted pin are preserved.
- The shared contract checks explicit nulls, invalid or mismatched IDs, and
keyIdwithout an explicit single pin. When both pin forms are supplied, the single pin must belong to the set; orderedkeyIdsmust match every pin. Any trusted member may sign a release, including a member other than the single pin. - The JavaScript tests now run every generated shared config case as both a JSON string and an object, including exact byte boundaries and signatures from a second trusted key and an untrusted key.
Validation on October 9, 2026: npm run verify (core 490, Expo 78, audit 9, CLI 65) and the shared native-contract verifier (226).