Skip to content

CoDuck Flags v0.1.0

Latest

Choose a tag to compare

@LiamBMX LiamBMX released this 04 Sep 06:38
· 1 commit to main since this release

CoDuck Flags 0.1.0

The first public release of CoDuck Flags: an MIT-licensed, headless feature-rollout SDK for Node.js and TypeScript.

npm install @coduckai/flags

npm package · Quickstart · Targeting guide

The normal install includes the runtime and its core automatically. Management, the embedded server, OpenFeature integration and compatibility vectors are separate optional packages. All six packages are publicly available at 0.1.0; no hosted account, dashboard or product CLI is required.

Included

  • Synchronous local flag evaluation, typed variations, account and attribute targeting, reusable segments and deterministic percentage rollouts.
  • Live HTTP/SSE configuration, watched files, polling recovery, last-known-good caching and explicit stale state.
  • Kill switches, revision ordering, reasoned safe defaults and privacy-safe evaluation hooks.
  • A management SDK and optional authenticated single-node configuration server with optimistic concurrency and atomic file storage.
  • ESM, CommonJS and TypeScript declarations; optional OpenFeature compatibility. Node.js 22.13+ is required, with Node 22/24 CI.

Verified release

Source tag v0.1.0 points to e24e70a8fa4e32cf3967b59a1800d8f9a5399165. Exact-source CI passed on Node 22 and 24.

  • Anonymous registry metadata and downloaded tarball hashes match all six approved release archives.
  • A clean, fresh-cache npm install of all six published versions passed lockfile integrity checks, ESM/CommonJS loading and strict TypeScript declaration checks.
  • The installed quickstart returned true TARGETING_MATCH pro-beta.
  • The installed live example returned false before release, true after the live update and false after the kill switch.
  • A separate normal SDK-only install added exactly two packages (runtime and core), enabled the Pro account, excluded the free account and returned the safe default for a missing flag.
  • The source release gate passed 71 SDK tests, three release-policy tests and nine real HTTP/SSE protocol assertions.

The attached registry-verification.json records the public-download and consumer verification. manifest.json records the clean release source, archive contents and pre-publication checks. SHA256SUMS.txt covers the six attached package archives, which are the exact bytes published to npm.

Evidence boundaries

The recorded browser baseline has 38 assertions across eight real local SDK-consumer journeys. It is historical browser evidence, not a new production rollout. Its scope and review limitations remain documented.

This first release was published interactively using maintainer 2FA and has no build-provenance attestation. The guarded GitHub publishing workflow is prepared, but per-package trusted-publisher configuration is not yet set up. The previously attempted dependency-advisory refresh timed out; no new passing audit is claimed.

CoDuck production adoption, customer exposure instrumentation and multi-node control-plane operation are separate work. Flags do not replace authorization or entitlement checks.