Repository navigation
Releases: JS-PACKAGE/OPM.js
Release list
OPM.js v1.11.1
Performance patch over v1.11 (package 1.11.1, voice format still v7; no API or protocol changes).
- Sine operators use a deterministic polynomial
fastSin(|error| ≤ 2e-10) instead ofMath.sin, and all-sine voices take a faster render path. - Node 26
npm run benchmark(single machine, not browser/device): standard 8 voices 0.265 → 0.215 ms/block (−19%), standard 32 voices 1.132 → 0.900 (−20%), high 32 voices 1.977 → 1.515 (−23%). - Sine output differs from v1.11 by about 1e-10 (not bit-identical).
- CI (Node 22/24/26, Chromium/Firefox/WebKit) passed; scoped static security review found no evidence-backed issue.
- Not published to npm. Physical-device, MIDI-hardware and human-listening acceptance remain unverified.
Tarball SHA-256: 4f5ccfcc499c5100645bba97caf9a80d6d2a6e5229c404fc11006ee1a785d58e
OPM.js v1.11
Package 1.11.0 (GitHub release only; not published to npm). Voice format v7 (per-operator waveforms and held noise; v1–v6 inputs still accepted), optional stereo chorus/reverb, MIDI program/drum voice maps with RPN bend sensitivity, and approximate .opm patch import. See CHANGELOG.
CI for this commit (Node 22/24/26, Chromium/Firefox/WebKit) passed: https://github.com/JS-PACKAGE/OPM.js/actions/runs/37117982867
Tarball SHA-256: 48841b22f56824be4199849279555f9fc05f28b87c6aca177bccccf8fbd38cff
Physical-device, MIDI-hardware and human-listening acceptance remain unverified.
OPM.js v1.10
Portable arrangements and expressive exchange
Package 1.10.0, GitHub tag v1.10. Voice format remains v6; zero runtime dependencies.
- Portable, bounded version-1 Arrangement projects: save/load authored layers, sections, named voices, tempo/meter and synthesis settings. Loading is inert; replay is an explicit musical start, not a DSP checkpoint.
- Opt-in expressive Standard MIDI file import/export with explicit bend range, channel ownership and grouped loss summaries. Default note-only conversion remains unchanged; unsupported or ambiguous export semantics reject.
- Workload/host-scoped benchmark capacity candidates with explicit p99 reserve, raw worst/misses and clean diagnostics. No automatic synthesis-quality changes or universal device limits.
- Bounded local MIDI observation downloads and matching physical-mobile/MIDI/human-listening campaign preparation, plus synchronized public lifecycle/persistence/ownership contracts.
- Matching generated HTML/API documentation, searchable guides and current-release examples.
Exact reviewed distribution
- Release commit:
25825a03638915a23a52e254a96a6e77569fa031. - Remote CI: Quality and security run 37108065658 completed successfully on this exact commit. All six Node 22/24/26 and Chromium/Firefox/WebKit jobs passed, including unchanged deadline gates, real AudioWorklet smoke/stress and Chromium's installed-package Vite/CSP scenario.
- Independent scoped static review: Release110Inputs A/B and Release110DspSupply C/D, including final documentation/generated-HTML delta; no evidence-backed blockers. Reviewers executed no runtime gates.
- Local: 403 behavioral tests; 144 matching distribution assets; strict public/DOM-free core types; numerical sound/preset matrices; isolated installed-package/asset/type security gates; unchanged isolated p99 deadline ratio 1; zero-vulnerability development/runtime/Vite tooling audits.
- Installed final archive smoke: 83-byte expressive MIDI → inert Arrangement JSON round trip → 10,560 finite deterministic stereo frames → 42,284-byte WAV. Default omission and after-gate control rejection exercised. Numerical signal is not human listening acceptance.
- Live-tree numbered generated copies were rejected by package checks, preserved and excluded. This asset was rebuilt only from the exact committed canonical tree and independently installed/verified.
Installable archive
Download opm.js-1.10.0.tgz; install it with npm install /actual/path/opm.js-1.10.0.tgz. No consumer build toolchain is required.
- Size: 1,044,341 bytes.
- SHA-256:
098d79a90c127058080210e6c973f6f2f1812f824518df1d74283690db273ec7. - 192 package entries, including 144 complete JS/map/declaration distribution assets.
- Generated distribution/documentation matches the final reviewed candidate byte-for-byte.
Acceptance boundaries
Physical iOS/Android interruption/route/long-play, physical MIDI permission/controller/hot-unplug and genuine eighteen-preset human listening findings remain unverified. Automated/desktop signal, injected MIDI, finite PCM and readiness tools do not promote those statuses or listening trims.
This is GitHub distribution only: not npm registry publication/provenance, website deployment, hardware-clone fidelity or all-device glitch-free certification. Historical tags/assets remain unchanged. See the included CHANGELOG and SECURITY records for pre-release native Edge observations and the pinned-local-Chromium launcher limitation; those observations are distinct from remote CI.
OPM.js v1.9
Integration and musical workflows
Package 1.9.0, GitHub tag v1.9. Voice format remains v6; zero runtime dependencies.
- Portable version-1 score projects, deterministic JSON save/load and tempo-integrating offline beat compilation.
- Bounded Standard MIDI file format 0/1 PPQN import/export with explicit mappings, warnings and unsupported-content rejection.
- Transport startup lead fixes cold-start beat-0 scheduling; real late/drop errors remain visible.
- Independent note/layer gain, quantized Arrangement fades and crossfades without retriggering shared layers.
- Configurable MIDI CC mappings, effective-control snapshots and adapter-owned sustain cleanup.
- Two original songs with playback, project save/load and Worker WAV export; thirteen checkout examples.
- Searchable static HTML guides, complete compiler-derived API reference and DOM-free Node core/project/MIDI declarations.
- Exact-workload device evidence and explicitly confirmed human-listening findings; neither tool invents acceptance.
- Cache FM topology in pooled voice slots without changing PCM or relaxing deadline budgets.
Artifact and review
Release commit: 435a6eb12d55245f7ea0c424c6c81e8840603b92.
opm.js-1.9.0.tgz was rebuilt from this exact clean commit in an isolated directory, not the live tree containing unknown numbered generated copies. Archive size: 948,465 bytes; 189 package files, including 47 canonical JS/map/declaration triplets (141 distribution assets). Every distribution asset matches the release commit.
SHA-256:
2f6c4fa7cde42469b3d89b939bf601283bebb6d89bdad91d9f922db0ea83aa9b
Scoped independent static security reviews: Release19Inputs A/B and Release19Supply C/D, including a fresh C/D recheck of the DSP topology-cache repair, with no evidence-backed security findings. Static reviews are not runtime certification.
Local canonical candidate: build, 382 passing behavioral tests, strict source/development/public-consumer type checks, parsed dynamic-code/zero-runtime-dependency gates and installed-package rendering/WAV/assets/DOM-free declaration checks passed. The final archive passed the local artifact verifier; this is not registry verification. A 288-case before/after runtime smoke remains PCM bit-identical across qualities, sample rates, stealing, gain ramps and chunk boundaries.
Final exact-commit Quality and security CI: all six jobs passed — Node 22/24/26 (tests, build, types, sound/preset quality, dependency audits, package security and unchanged p99 deadline gate), plus Chromium/Firefox/WebKit AudioWorklet smoke/stress and Chromium installed-package Vite/CSP.
The initial candidate CI failed Node 22 prepared-burst p99 (3.131281 ms versus a 2.666667 ms deadline) and was never tagged. After the topology-cache repair, final remote Node 22 prepared-burst p99 is 1.941113 ms (ratio 0.727917, median 1.677022 ms), with zero DSP errors/rejected notes. Worst-case 3.106474 ms and 7/2,000 missed deadlines remain reported; passing p99 is not a realtime guarantee. No threshold relaxation or waiver was used.
Installation
npm install https://github.com/YueyuHoshizora/OPM.js/releases/download/v1.9/opm.js-1.9.0.tgzConsumers need no source checkout or build toolchain. Deploy the complete matching dist/ tree and LICENSE.
Scope
No npm publication is performed. Existing tags/assets remain unchanged. Physical iOS/Android, physical MIDI and genuine human listening remain unverified; numerical and desktop automation evidence does not certify them. Earlier native Chromium signal/UI evidence is retained in CHANGELOG, not represented as a new physical-device result.
OPM.js v1.8.1
Documentation and packaging patch
Package 1.8.1 ships synchronized API/voice-v6 documentation, bilingual runnable usage guides, Transport/grid startup recipes, quality/polyphony limits, performance/MIDI guidance and installed-package deployment/Worker/Vite instructions. Runtime VERSION is 1.8.1; there are no DSP, scheduling, voice-format or public-contract changes. The original v1.8 tag and opm.js-1.8.0.tgz remain unchanged.
Six focused documentation commits and one patch-release commit are included. Release commit: f7abc977a085bd10f058d0b5e93d3ff0c903981a.
Verification and scope
- Scoped independent static security reviews A/B (Patch181Inputs) and C/D (Patch181DspSupply): approved, no evidence-backed blockers; read-only reviews, not external certification.
- Local isolated candidate: build, 310/310 behavioral tests, strict source/development/public-contract type checks, AST/source/distribution security gates and installed rendering/WAV/types/asset-CLI checks passed. Full/runtime and standalone Vite tooling audits reported zero vulnerabilities; no runtime dependencies.
sound-quality: 2,505 matrix cases + 24 live-control cases, independent spectral/filter/streaming gates;voice-qualitycompleted successfully. Benchmark completed in report-only mode with no acceptance budgets: not a realtime deadline guarantee or listening verdict.- Sandboxed, muted native Chromium 150 passed unchanged compiled browser smoke, 768-note stress, and installed-package Vite subpath/CSP/lifecycle/missing-asset/wrong-MIME assertions via a throwaway executable-launch adapter. Fresh pinned Chromium installation timed out after receiving its archive; this native run is not a PASS for that download or a default cached-browser command.
- Exact README/English/Chinese browser recipes rendered finite nonzero audio, reported
VERSION:1.8.1, and had no browser errors or note rejections; screenshots inspected. All three packaged Node recipes passed. All eleven public imports, 32-voice eco/standard/high priority admission, finite rendering and tempo/grid round trips passed from the final installed archive. - Checkout: 20 documents / 139 relative links; package: 18 documents / 134 relative links; no file/anchor failures. All 153 packaged files match the final installed bytes, and committed distribution matches the fresh verified build; only the three generated version companions differ from v1.8.
Remote publication gate PASS: exact release-commit CI, all six jobs successful: Node.js 22/24/26 tests/build/types/quality/audit/security/installed-package/warmed-p99 gates and Chromium/Firefox/WebKit native worklet smoke/stress, plus Chromium installed-package Vite/CSP. GitHub emitted a non-failing deprecation annotation for SHA-pinned actions' Node.js 20 metadata being forced onto Node.js 24; no waiver or workflow change was used.
Known unchanged constraint: immediate beat-zero startup with late:'drop' can discard cold-start notes; the documented recipes use count-in/lookahead rather than claim a runtime fix. Physical-device/Web MIDI/listening acceptance and npm registry/provenance are separate, unverified prerequisites. This is a GitHub release only; no npm publication is performed.
Installable asset
opm.js-1.8.1.tgz was packed from the exact committed tree and passed final local-artifact install/render/declaration verification. It is 500,223 bytes.
SHA-256:
60f5102d15ae02b240ec1a296593911125c617984f7a14ab6702cef0af7a2274
SHA-512 SRI:
sha512-6ULKAzRp/3GQx96T3UQQZR5RXMQo0itFYzMkY6sTHp4CFEDuIjx5mxdue0JZQlUqjpVlCHvluTTsvIkZgebxlA==
npm install https://github.com/YueyuHoshizora/OPM.js/releases/download/v1.8.1/opm.js-1.8.1.tgzConsumers require no checkout or build toolchain. Deploy the complete dist/ tree using the installed opm-assets CLI; the checkout-only Vite example is pinned to v1.8.1 in the guides.
Post-publication acceptance: the annotated v1.8.1 tag resolves to the release commit; GitHub's asset digest, an independent release download and the uploaded archive match the SHA-256 above. Installing the documented GitHub URL into a fresh app matched all 153 packaged files byte-for-byte and passed eleven public imports, all three 32-voice quality modes/priority/finite rendering, tempo/grid round trips and the installed 134-file asset CLI. The downloaded archive also passed installed rendering and public declaration verification.
OPM.js v1.8
OPM.js 1.8.0 adds bounded adaptive music and tempo ramps, priority-aware 1–32 voice performance, expressive parts and an optional Web MIDI adapter, Worker readiness/phase diagnostics, safe asset deployment tools, selective-LFO presets, and adaptive/instrument/bus/FM-designer examples.
Verified locally: 310 behavioral tests, strict types, package/security gates, all-profile acoustic references and assistant-owned native Chromium scenarios. No physical-device or human-listening certification is implied.
See CHANGELOG.md and SECURITY.md for scope and verification evidence. npm registry publication is a separate maintainer-authorized operation and is not implied by this GitHub release.
Installable release package
The previously missing opm.js-1.8.0.tgz asset has been added. It was built in an isolated checkout of the unchanged v1.8 tag (d793d69056c68a971ede1af988338412687227fd), not from the latest branch.
- Asset: opm.js-1.8.0.tgz (491,851 bytes).
- SHA-256:
bee862d5b3ccaa7c4e8ff959583873c78a8ca8a9f56f4d8b039e490e498e2587. - Fresh package verification passed: build, strict source/development/public-contract types, source/generated security checks, installed-package synthesis/WAV, declarations and asset CLI, and local artifact validation. The exact attached archive was independently installed and exercised with zero DSP errors.
- The asset was downloaded back from GitHub and matched the verified local archive byte-for-byte.
- The release commit passed Node.js 22/24/26 and Chromium/Firefox/WebKit CI: https://github.com/YueyuHoshizora/OPM.js/actions/runs/37061483772
Install the downloaded package with npm install ./opm.js-1.8.0.tgz. This attachment does not publish to npm or certify registry provenance, physical devices, MIDI hardware, or human listening acceptance.
OPM.js v1.7
Package 1.7.0, canonical voice format v6. GitHub distribution and npm registry publication are separate; this release does not publish to npm. Historical v1.6 artifacts remain immutable.
Musical scheduling, rendering and expressive control
- Beat-based Transport: AudioContext-clock pause/resume, seek, loops, meter, BPM and bounded tempo maps; only owned musical notes and automation restart, not an exact DSP snapshot.
- Incremental PCM16/PCM24/Float32 WAV encoding with exact frames and RIFF32 limits, without retaining a complete file.
- Static same-origin module Worker rendering with progress, cancellation and acknowledged sink backpressure, including transferred-buffer ownership.
- Part-scoped performance policies: physical key IDs, sustain, polyphonic/mono legato and last/high/low priority; not a MIDI driver.
- Independently ramped feedback, LFO rate/depths, ratios/fixed frequencies and live ADSR; voice v6 adds per-operator AM/PM targets while strict legacy inputs 1–5 remain accepted.
- Immutable eco/standard/high DSP profiles (2×/4×/8×); standard preserves the previous default output.
- Atomic bank replacement, removal and detached canonical JSON export, plus complete declarations, bilingual examples and shared-score demo integration.
Observed release verification
Reviewed release commit: 5312ab8275824cf1d5824badde28e2f53d6378f7.
- Independent read-only static review: A PASS — Release17Data; B PASS — Release17Protocol; C PASS — Release17DSP; D PASS — Release17Supply. Reviewers ran no runtime gates and certified no external npm settings. No waiver.
- Fresh clean package 1.7.0 checkout: 272/272 behavioral tests, strict source/development/NodeNext-consumer types, generated build, source/built AST security checks and installed-package render/WAV/types passed. Full tooling/runtime audits found zero vulnerabilities; runtime dependencies are empty. Sound-quality, voice-quality and the report-only local benchmark passed.
- Actual quality/security CI on the exact reviewed commit: all six jobs passed — Node 22/24/26 and Chromium/Firefox/WebKit. Native AudioWorklet smoke/stress, installed Vite production/CSP deployment, package checks, audits, quality matrices and enforced warmed-p99 benchmark budgets passed. Pages deployment passed on the same commit.
- The independent v1.7 tag CI run also passed all six jobs on the same release commit before publishing this release.
- Assistant-managed native Chromium 150: built demo startup and finite nonzero 48-kHz AudioWorklet PCM passed in eco/standard/high, with zero DSP errors. Native Worker eco/PCM16, standard/PCM24 and high/Float32 outputs matched whole-core WAV bytes for 11,520 frames, including transferred sink buffers, one close and no abort/DSP errors in each completed row.
- All 105 clean generated distribution assets are byte-identical to the canonical committed distribution. The exact attached 119-entry tarball passed isolated local-artifact/installed-consumer verification; duplicated/untracked local assets were excluded without deleting user files.
Artifact
opm.js-1.7.0.tgz — 378,969 bytes.
SHA-256:
01b9f5abfb85d749e4cbd1c750c76e68248aecb8dd06f9a7fd994be406a016e6
Limits
Listening quality, physical iOS/Android interruption behavior, arbitrary-patch alias freedom and the operating-system file chooser remain unverified. Local CPU measurements are host-dependent, not underrun counters. Managed-browser probes also encountered target closures and a ten-second sequential Worker startup deadline; high/Float32 subsequently passed in an isolated fresh managed tab (40.2 ms), not a universal startup guarantee. GitHub Actions reported deprecated action runtime annotations while forcing those pinned actions onto Node 24; all jobs passed. No npm authentication, registry provenance/signatures or registry publication is asserted.
OPM.js v1.6
Package version 1.6.0. GitHub release distribution and npm registry publication are separate operations; the v1.5 artifact remains immutable.
Acoustic quality, expression and adoption
- Add original independent nested four-op chain/branched/multicarrier references alongside Bessel/feedback/long-stream coverage; replace the former four-pole decimator with a preallocated eighth-order Butterworth cascade. Passband, folded-product rejection, phase, tail and CPU tradeoffs are explicit; no arbitrary-FM alias-free or perceptual claim.
- Canonicalize voice format v5 with fixed-Hz operators, rate key scaling, pitch envelopes and delayed/phase-selectable note/global LFO. Retain strict original v1–v4 input shapes. Add independent per-operator level multipliers/ramps and note-scaled offline release tails.
- Preserve supported fixed-Hz/expressive DX7 source fields using documented musical heuristics and actionable substitution/loss warnings; six-to-four topology and hardware timing remain intentionally lossy.
- Add bounded long-score preparation, capacity estimation, reusable chunked rendering and mixed note/control/stop streaming without removing short-score/worklet/WAV limits.
- Add same-origin custom worklet assets, multicast subscriptions, timed/abortable command admission waits and terminal disposal alongside restartable close.
- Expand original curated preset recipes and provenance/register/velocity metadata, numerical host trims and repeatable phrase/A/B audition without rewriting patches for loudness.
- Expand physical-device recovery scenarios, bounded local observation/status exports and an explicit unverified iOS/Android support matrix.
- Add post-publication registry byte/integrity/source-provenance/signature/installed-consumer verification to the manual npm workflow; local artifact validation is available without claiming registry publication.
- Synchronize project guidance and public usage contracts. Physical-device/listening evidence and authorized first npm publication remain external prerequisites.
v1.6 verification record
- Node.js 26.7.0: 198 behavioral tests, strict source/development/consumer types, source/generated AST gates, installed-package render/WAV/declarations passed; root full/runtime and Vite tooling audits found zero vulnerabilities, with an empty runtime dependency tree. A stale generated
distcontaining duplicated2/3suffix files failed the packaged-map gate; it was preserved outside the repository and rebuilt cleanly rather than deleted. - Native Chromium 153.0.8010.12 (48 kHz backend, muted) ran the audition UI (A/B measurement, matched-versus-dry reports, PCM16 WAV download, play/stop/dispose and fresh restart), a 60-second/96 kHz bounded render (5,775,360 frames, zero DSP errors) and a 390 px layout check; the event log is now height-limited so long reports do not widen the page. It also ran command-waiter admission, receipt eviction, native abort-signal handling, correlated panic reset, subscription cleanup and terminal disposal against a borrowed context. Worklet stress and the installed Vite subpath/CSP/MIME/404 smoke passed again; the native WebKit 26.6 AudioWorklet smoke passed.
- Report-only Apple M5 benchmark (48 kHz, 128 frames, 2.667 ms deadline): the order-8 decimator costs more than the former filter. Eight voices with LFO had p99 at 1.575× the deadline and 79 misses; without LFO 1.429× and 45 misses; raw burst 3.323× and prepared burst 2.591×. Worst samples include scheduler/GC pauses (up to 120 ms), so this is a host-dependent tradeoff, not an underrun counter. Measure before enabling dense polyphony on tighter CPU budgets.
- Not verified: listening quality, physical iOS/Android interruption behavior, locked Playwright 1.56.1, Firefox, Linux WebKit CI and any npm registry operation (
npm whoamipreviously returned ENEEDAUTH). Desktop automation does not earn physical-device acceptance. - Waiver: v1.6 was released on GitHub at the maintainer's explicit request without a fresh independent A/B/C/D review (see SECURITY.md). It is not eligible for npm publication until that review record exists.
OPM.js v1.5
OPM.js v1.5
Package version 1.5.0 · Apache-2.0 · zero runtime dependencies.
Highlights
- Correlated command feedback, all-notes-off and immediate panic, smooth expression/pan/modulation controls, fractional notes, mix gain and global tuning.
- Bounded reusable patch caching and shared prepared/offline/live scores; oldest, release-first and quietest voice stealing.
- Voice format 4 with sine, triangle, saw and square LFO waveforms; legacy formats 1/2/3 remain supported.
- Cancel-by-default interruption recovery, explicit preserve mode, reset/context notifications and the shared-score recovery playground.
- Independent FM spectral references, two 120-second streaming scenarios, security hardening and executable English/Traditional Chinese guides.
Verified recovery fix
The initial candidate was held after Linux WebKit missed interruption cancellation. This candidate observes context state before and after native resume, handles deferred running/suspended notifications and deduplicates resets. The original browser smoke assertions remain unchanged.
- 159 behavioral tests, strict source/development/consumer types, source/generated AST security gates and installed-package rendering/WAV/declarations passed locally.
- Scoped independent security rechecks: Release15Inputs (A/B) and Release15DspSupply (C/D) passed after the observer repair.
- Exact-commit quality CI passed Node 22/24/26 and native Chromium/Firefox/WebKit jobs, including the previously failing interruption scenario.
- Exact-tag quality CI completed successfully on attempt 2 at the same commit. Attempt 1 passed all browser/behavior/security gates but Node 22 raw-burst p99 was 2.679757 ms against the 2.666667 ms budget. The retry changed neither source nor budget; this observed variation is not a universal realtime guarantee.
- Pages deployment passed. Local native WebKit 26.6 and sandboxed muted Chromium smoke also passed.
- The installed release tarball contains 90 files / 27 JS-map-declaration triplets; every packed file matches commit
c73938320b735d6e593d4eaf796c21f867537569. Installed rendering exercised all four LFO waveforms, controls, release/panic and a 2,064-frame score with an 8,300-byte WAV and zero errors.
Distribution
Download opm.js-1.5.0.tgz and verify against SHA256SUMS. This is a GitHub release, not an npm registry publication. npm authentication/trusted publishing remains a separate prerequisite. Physical-phone recovery and universal realtime/chip-fidelity guarantees are not claimed.
SHA-256: bf35ed50a099d74dd4cc89d248e3aa865e47a9d43d3070824c17f352cb79272a
See CHANGELOG for detailed evidence and limitations.
OPM.js v1.4
Highlights
- Immutable prepared patches and bounded reusable DSP voice state, plus cached worklet patch registration.
- Live pitch/glide, expression, stereo pan and FM/LFO modulation controls without envelope retriggering; optional per-operator velocity sensitivity.
- Absolute audio-clock starts, scheduled stops/controls, explicit late-start/drop policy, timestamped lifecycle events and a bounded lookahead scheduler.
- A 1,728-case numerical sound matrix, native AudioWorklet contention/stealing checks and 108 preset/conversion acceptance cells.
- Seventh browser example: preset/original-synthetic-DX7 A/B audition, raw peak/RMS reports and locally rendered WAV downloads.
- Installed-package Vite deployment example with complete worklet/module assets and LICENSE, non-root paths, CSP and MIME/404 failure checks; gated manual npm publishing workflow.
Migration
- Package version is 1.4.0; release tag is v1.4. Node.js 22+ remains required; there are no runtime dependencies.
- Canonical voices are version 3. Version 1/2 inputs remain accepted under their original field rules; omitted velocity sensitivity preserves legacy audio. DX7 six-to-four-operator and velocity conversion remain explicitly approximate.
opm.voicesis a defensive read-only snapshot. UseloadVoice()to replace stored patches.playNote({at})uses absolute AudioContext seconds and cannot be combined with relativetime. Scheduled stop/controls share that clock; same-frame stop precedes onset, then controls. Late-start keeps its full duration;late: 'drop'rejects missed starts.- Deploy the complete
dist/tree and retain LICENSE. Every one of its 22 JS modules has a matching map and generated declaration; maps intentionally embed TypeScript source.
Installation
Download opm.js-1.4.0.tgz and SHA256SUMS, verify the digest, then install:
shasum -a 256 -c SHA256SUMS
npm install ./opm.js-1.4.0.tgzThis GitHub release does not publish to the npm registry. See README, both usage guides and CHANGELOG for runnable examples and verification details.
Local verification
- Node.js 26.7.0 on macOS arm64: build, all 108 tests, strict source/development/generated-consumer types, source/generated AST security gates, installed 1.4.0 render/WAV/types and both npm audits passed. Runtime dependency tree is empty.
- All 1,728 sound cases and 108 preset/conversion cells passed.
- Owned isolated headless Chromium 153.0.8010.12 / Playwright 1.63.0, sandboxed and explicitly muted: real stereo/pan, routing/context lifecycle, worklet stress and installed-tarball Vite 8.3.2 production smoke passed. Stress accepted/started 769 notes, stole 760, rejected one intentional late note, peaked at 0.672 and ended with zero active/pending notes and zero DSP errors.
- Vite
/opm-example/deployment verified real signal/lifecycle, blocked inline CSP, exact deployed LICENSE and visible missing-worklet/wrong-MIME failures. - Apple M5 report-only benchmark: 300 warmup blocks excluded, 2,000 measured 128-frame blocks per scenario at 48 kHz. Raw burst p99/worst 1.131/3.303 ms, with one missed 2.667 ms deadline; prepared burst 0.913/1.133 ms, with zero misses. Host/scheduler/GC-dependent observations are not a universal realtime guarantee.
Local browser checks are not locked Playwright 1.56.1 or Firefox/WebKit coverage. Controlled spectral fixtures and unweighted RMS are not hardware-fidelity, arbitrary-FM alias-free or perceptual-LUFS claims. No microphone capture or recording upload was used.
Independent security review
- Release14Inputs: A/B static approval, including voice/DX7/API/worklet data boundaries and WAV/render/application file inputs.
- Release14DspSupply: C/D static approval for this GitHub-only release, including bounded DSP callback/pool safety, generated artifacts, deployment licensing and publishing controls.
- No evidence-backed release blockers remained. Runtime checks were performed separately by 語喵; reviewers did not execute tests or browser checks. External npm trusted-publisher/environment configuration and registry provenance remain unverified prerequisites for a separately authorized npm publication.
Artifact identity
- Reviewed release commit:
325668c8db47acd553a0501f90267aa0ae6dbdb0 - Tarball:
opm.js-1.4.0.tgz(178,943 bytes; 75 intended entries) - SHA-256:
23b3237b5db83c7cbb36a02b04a4610d8ba2104c55fa157272cedc0ce913b994 - The exact packed artifact was installed separately and exercised prepared pitch parity, live glide/expression/pan, release-to-silence and PCM16 WAV export (4,096 frames / 16,428 WAV bytes, zero DSP errors); all 22 module/map/declaration triplets were checked.
Release-commit CI and deployment
- Quality and security passed for the exact release commit: Node 22/24/26 and locked-tool browser Chromium/Firefox/WebKit jobs, including numerical matrices, package/security gates and native worklet smoke/stress; Chromium also passed production Vite deployment checks.
- GitHub Pages deployment passed for the same commit. The live example catalog serves all seven examples.