Skip to content

Releases: JS-PACKAGE/OPM.js

OPM.js v1.11.1

Choose a tag to compare

@YueyuHoshizora YueyuHoshizora released this 03 Oct 12:00

Performance patch over v1.11 (package 1.11.1, voice format still v7; no API or protocol changes).

  • Sine operators use a deterministic polynomial fastSin (|error| ≤ 2e-10) instead of Math.sin, and all-sine voices take a faster render path.
  • Node 26 npm run benchmark (single machine, not browser/device): standard 8 voices 0.265 → 0.215 ms/block (−19%), standard 32 voices 1.132 → 0.900 (−20%), high 32 voices 1.977 → 1.515 (−23%).
  • Sine output differs from v1.11 by about 1e-10 (not bit-identical).
  • CI (Node 22/24/26, Chromium/Firefox/WebKit) passed; scoped static security review found no evidence-backed issue.
  • Not published to npm. Physical-device, MIDI-hardware and human-listening acceptance remain unverified.

Tarball SHA-256: 4f5ccfcc499c5100645bba97caf9a80d6d2a6e5229c404fc11006ee1a785d58e

OPM.js v1.11

Choose a tag to compare

@YueyuHoshizora YueyuHoshizora released this 03 Oct 11:03

Package 1.11.0 (GitHub release only; not published to npm). Voice format v7 (per-operator waveforms and held noise; v1–v6 inputs still accepted), optional stereo chorus/reverb, MIDI program/drum voice maps with RPN bend sensitivity, and approximate .opm patch import. See CHANGELOG.

CI for this commit (Node 22/24/26, Chromium/Firefox/WebKit) passed: https://github.com/JS-PACKAGE/OPM.js/actions/runs/37117982867

Tarball SHA-256: 48841b22f56824be4199849279555f9fc05f28b87c6aca177bccccf8fbd38cff

Physical-device, MIDI-hardware and human-listening acceptance remain unverified.

OPM.js v1.10

Choose a tag to compare

@YueyuHoshizora YueyuHoshizora released this 03 Oct 08:04

Portable arrangements and expressive exchange

Package 1.10.0, GitHub tag v1.10. Voice format remains v6; zero runtime dependencies.

  • Portable, bounded version-1 Arrangement projects: save/load authored layers, sections, named voices, tempo/meter and synthesis settings. Loading is inert; replay is an explicit musical start, not a DSP checkpoint.
  • Opt-in expressive Standard MIDI file import/export with explicit bend range, channel ownership and grouped loss summaries. Default note-only conversion remains unchanged; unsupported or ambiguous export semantics reject.
  • Workload/host-scoped benchmark capacity candidates with explicit p99 reserve, raw worst/misses and clean diagnostics. No automatic synthesis-quality changes or universal device limits.
  • Bounded local MIDI observation downloads and matching physical-mobile/MIDI/human-listening campaign preparation, plus synchronized public lifecycle/persistence/ownership contracts.
  • Matching generated HTML/API documentation, searchable guides and current-release examples.

Exact reviewed distribution

  • Release commit: 25825a03638915a23a52e254a96a6e77569fa031.
  • Remote CI: Quality and security run 37108065658 completed successfully on this exact commit. All six Node 22/24/26 and Chromium/Firefox/WebKit jobs passed, including unchanged deadline gates, real AudioWorklet smoke/stress and Chromium's installed-package Vite/CSP scenario.
  • Independent scoped static review: Release110Inputs A/B and Release110DspSupply C/D, including final documentation/generated-HTML delta; no evidence-backed blockers. Reviewers executed no runtime gates.
  • Local: 403 behavioral tests; 144 matching distribution assets; strict public/DOM-free core types; numerical sound/preset matrices; isolated installed-package/asset/type security gates; unchanged isolated p99 deadline ratio 1; zero-vulnerability development/runtime/Vite tooling audits.
  • Installed final archive smoke: 83-byte expressive MIDI → inert Arrangement JSON round trip → 10,560 finite deterministic stereo frames → 42,284-byte WAV. Default omission and after-gate control rejection exercised. Numerical signal is not human listening acceptance.
  • Live-tree numbered generated copies were rejected by package checks, preserved and excluded. This asset was rebuilt only from the exact committed canonical tree and independently installed/verified.

Installable archive

Download opm.js-1.10.0.tgz; install it with npm install /actual/path/opm.js-1.10.0.tgz. No consumer build toolchain is required.

  • Size: 1,044,341 bytes.
  • SHA-256: 098d79a90c127058080210e6c973f6f2f1812f824518df1d74283690db273ec7.
  • 192 package entries, including 144 complete JS/map/declaration distribution assets.
  • Generated distribution/documentation matches the final reviewed candidate byte-for-byte.

Acceptance boundaries

Physical iOS/Android interruption/route/long-play, physical MIDI permission/controller/hot-unplug and genuine eighteen-preset human listening findings remain unverified. Automated/desktop signal, injected MIDI, finite PCM and readiness tools do not promote those statuses or listening trims.

This is GitHub distribution only: not npm registry publication/provenance, website deployment, hardware-clone fidelity or all-device glitch-free certification. Historical tags/assets remain unchanged. See the included CHANGELOG and SECURITY records for pre-release native Edge observations and the pinned-local-Chromium launcher limitation; those observations are distinct from remote CI.

OPM.js v1.9

Choose a tag to compare

@YueyuHoshizora YueyuHoshizora released this 03 Oct 02:42

Integration and musical workflows

Package 1.9.0, GitHub tag v1.9. Voice format remains v6; zero runtime dependencies.

  • Portable version-1 score projects, deterministic JSON save/load and tempo-integrating offline beat compilation.
  • Bounded Standard MIDI file format 0/1 PPQN import/export with explicit mappings, warnings and unsupported-content rejection.
  • Transport startup lead fixes cold-start beat-0 scheduling; real late/drop errors remain visible.
  • Independent note/layer gain, quantized Arrangement fades and crossfades without retriggering shared layers.
  • Configurable MIDI CC mappings, effective-control snapshots and adapter-owned sustain cleanup.
  • Two original songs with playback, project save/load and Worker WAV export; thirteen checkout examples.
  • Searchable static HTML guides, complete compiler-derived API reference and DOM-free Node core/project/MIDI declarations.
  • Exact-workload device evidence and explicitly confirmed human-listening findings; neither tool invents acceptance.
  • Cache FM topology in pooled voice slots without changing PCM or relaxing deadline budgets.

Artifact and review

Release commit: 435a6eb12d55245f7ea0c424c6c81e8840603b92.

opm.js-1.9.0.tgz was rebuilt from this exact clean commit in an isolated directory, not the live tree containing unknown numbered generated copies. Archive size: 948,465 bytes; 189 package files, including 47 canonical JS/map/declaration triplets (141 distribution assets). Every distribution asset matches the release commit.

SHA-256:

2f6c4fa7cde42469b3d89b939bf601283bebb6d89bdad91d9f922db0ea83aa9b

Scoped independent static security reviews: Release19Inputs A/B and Release19Supply C/D, including a fresh C/D recheck of the DSP topology-cache repair, with no evidence-backed security findings. Static reviews are not runtime certification.

Local canonical candidate: build, 382 passing behavioral tests, strict source/development/public-consumer type checks, parsed dynamic-code/zero-runtime-dependency gates and installed-package rendering/WAV/assets/DOM-free declaration checks passed. The final archive passed the local artifact verifier; this is not registry verification. A 288-case before/after runtime smoke remains PCM bit-identical across qualities, sample rates, stealing, gain ramps and chunk boundaries.

Final exact-commit Quality and security CI: all six jobs passed — Node 22/24/26 (tests, build, types, sound/preset quality, dependency audits, package security and unchanged p99 deadline gate), plus Chromium/Firefox/WebKit AudioWorklet smoke/stress and Chromium installed-package Vite/CSP.

The initial candidate CI failed Node 22 prepared-burst p99 (3.131281 ms versus a 2.666667 ms deadline) and was never tagged. After the topology-cache repair, final remote Node 22 prepared-burst p99 is 1.941113 ms (ratio 0.727917, median 1.677022 ms), with zero DSP errors/rejected notes. Worst-case 3.106474 ms and 7/2,000 missed deadlines remain reported; passing p99 is not a realtime guarantee. No threshold relaxation or waiver was used.

Installation

npm install https://github.com/YueyuHoshizora/OPM.js/releases/download/v1.9/opm.js-1.9.0.tgz

Consumers need no source checkout or build toolchain. Deploy the complete matching dist/ tree and LICENSE.

Scope

No npm publication is performed. Existing tags/assets remain unchanged. Physical iOS/Android, physical MIDI and genuine human listening remain unverified; numerical and desktop automation evidence does not certify them. Earlier native Chromium signal/UI evidence is retained in CHANGELOG, not represented as a new physical-device result.

OPM.js v1.8.1

Choose a tag to compare

@YueyuHoshizora YueyuHoshizora released this 02 Oct 22:26

Documentation and packaging patch

Package 1.8.1 ships synchronized API/voice-v6 documentation, bilingual runnable usage guides, Transport/grid startup recipes, quality/polyphony limits, performance/MIDI guidance and installed-package deployment/Worker/Vite instructions. Runtime VERSION is 1.8.1; there are no DSP, scheduling, voice-format or public-contract changes. The original v1.8 tag and opm.js-1.8.0.tgz remain unchanged.

Six focused documentation commits and one patch-release commit are included. Release commit: f7abc977a085bd10f058d0b5e93d3ff0c903981a.

Verification and scope

  • Scoped independent static security reviews A/B (Patch181Inputs) and C/D (Patch181DspSupply): approved, no evidence-backed blockers; read-only reviews, not external certification.
  • Local isolated candidate: build, 310/310 behavioral tests, strict source/development/public-contract type checks, AST/source/distribution security gates and installed rendering/WAV/types/asset-CLI checks passed. Full/runtime and standalone Vite tooling audits reported zero vulnerabilities; no runtime dependencies.
  • sound-quality: 2,505 matrix cases + 24 live-control cases, independent spectral/filter/streaming gates; voice-quality completed successfully. Benchmark completed in report-only mode with no acceptance budgets: not a realtime deadline guarantee or listening verdict.
  • Sandboxed, muted native Chromium 150 passed unchanged compiled browser smoke, 768-note stress, and installed-package Vite subpath/CSP/lifecycle/missing-asset/wrong-MIME assertions via a throwaway executable-launch adapter. Fresh pinned Chromium installation timed out after receiving its archive; this native run is not a PASS for that download or a default cached-browser command.
  • Exact README/English/Chinese browser recipes rendered finite nonzero audio, reported VERSION:1.8.1, and had no browser errors or note rejections; screenshots inspected. All three packaged Node recipes passed. All eleven public imports, 32-voice eco/standard/high priority admission, finite rendering and tempo/grid round trips passed from the final installed archive.
  • Checkout: 20 documents / 139 relative links; package: 18 documents / 134 relative links; no file/anchor failures. All 153 packaged files match the final installed bytes, and committed distribution matches the fresh verified build; only the three generated version companions differ from v1.8.

Remote publication gate PASS: exact release-commit CI, all six jobs successful: Node.js 22/24/26 tests/build/types/quality/audit/security/installed-package/warmed-p99 gates and Chromium/Firefox/WebKit native worklet smoke/stress, plus Chromium installed-package Vite/CSP. GitHub emitted a non-failing deprecation annotation for SHA-pinned actions' Node.js 20 metadata being forced onto Node.js 24; no waiver or workflow change was used.

Known unchanged constraint: immediate beat-zero startup with late:'drop' can discard cold-start notes; the documented recipes use count-in/lookahead rather than claim a runtime fix. Physical-device/Web MIDI/listening acceptance and npm registry/provenance are separate, unverified prerequisites. This is a GitHub release only; no npm publication is performed.

Installable asset

opm.js-1.8.1.tgz was packed from the exact committed tree and passed final local-artifact install/render/declaration verification. It is 500,223 bytes.

SHA-256:

60f5102d15ae02b240ec1a296593911125c617984f7a14ab6702cef0af7a2274

SHA-512 SRI:

sha512-6ULKAzRp/3GQx96T3UQQZR5RXMQo0itFYzMkY6sTHp4CFEDuIjx5mxdue0JZQlUqjpVlCHvluTTsvIkZgebxlA==
npm install https://github.com/YueyuHoshizora/OPM.js/releases/download/v1.8.1/opm.js-1.8.1.tgz

Consumers require no checkout or build toolchain. Deploy the complete dist/ tree using the installed opm-assets CLI; the checkout-only Vite example is pinned to v1.8.1 in the guides.

Post-publication acceptance: the annotated v1.8.1 tag resolves to the release commit; GitHub's asset digest, an independent release download and the uploaded archive match the SHA-256 above. Installing the documented GitHub URL into a fresh app matched all 153 packaged files byte-for-byte and passed eleven public imports, all three 32-voice quality modes/priority/finite rendering, tempo/grid round trips and the installed 134-file asset CLI. The downloaded archive also passed installed rendering and public declaration verification.

OPM.js v1.8

Choose a tag to compare

@YueyuHoshizora YueyuHoshizora released this 02 Oct 20:11

OPM.js 1.8.0 adds bounded adaptive music and tempo ramps, priority-aware 1–32 voice performance, expressive parts and an optional Web MIDI adapter, Worker readiness/phase diagnostics, safe asset deployment tools, selective-LFO presets, and adaptive/instrument/bus/FM-designer examples.

Verified locally: 310 behavioral tests, strict types, package/security gates, all-profile acoustic references and assistant-owned native Chromium scenarios. No physical-device or human-listening certification is implied.

See CHANGELOG.md and SECURITY.md for scope and verification evidence. npm registry publication is a separate maintainer-authorized operation and is not implied by this GitHub release.

Installable release package

The previously missing opm.js-1.8.0.tgz asset has been added. It was built in an isolated checkout of the unchanged v1.8 tag (d793d69056c68a971ede1af988338412687227fd), not from the latest branch.

  • Asset: opm.js-1.8.0.tgz (491,851 bytes).
  • SHA-256: bee862d5b3ccaa7c4e8ff959583873c78a8ca8a9f56f4d8b039e490e498e2587.
  • Fresh package verification passed: build, strict source/development/public-contract types, source/generated security checks, installed-package synthesis/WAV, declarations and asset CLI, and local artifact validation. The exact attached archive was independently installed and exercised with zero DSP errors.
  • The asset was downloaded back from GitHub and matched the verified local archive byte-for-byte.
  • The release commit passed Node.js 22/24/26 and Chromium/Firefox/WebKit CI: https://github.com/YueyuHoshizora/OPM.js/actions/runs/37061483772

Install the downloaded package with npm install ./opm.js-1.8.0.tgz. This attachment does not publish to npm or certify registry provenance, physical devices, MIDI hardware, or human listening acceptance.

OPM.js v1.7

Choose a tag to compare

@YueyuHoshizora YueyuHoshizora released this 02 Oct 18:21

Package 1.7.0, canonical voice format v6. GitHub distribution and npm registry publication are separate; this release does not publish to npm. Historical v1.6 artifacts remain immutable.

Musical scheduling, rendering and expressive control

  • Beat-based Transport: AudioContext-clock pause/resume, seek, loops, meter, BPM and bounded tempo maps; only owned musical notes and automation restart, not an exact DSP snapshot.
  • Incremental PCM16/PCM24/Float32 WAV encoding with exact frames and RIFF32 limits, without retaining a complete file.
  • Static same-origin module Worker rendering with progress, cancellation and acknowledged sink backpressure, including transferred-buffer ownership.
  • Part-scoped performance policies: physical key IDs, sustain, polyphonic/mono legato and last/high/low priority; not a MIDI driver.
  • Independently ramped feedback, LFO rate/depths, ratios/fixed frequencies and live ADSR; voice v6 adds per-operator AM/PM targets while strict legacy inputs 1–5 remain accepted.
  • Immutable eco/standard/high DSP profiles (2×/4×/8×); standard preserves the previous default output.
  • Atomic bank replacement, removal and detached canonical JSON export, plus complete declarations, bilingual examples and shared-score demo integration.

Observed release verification

Reviewed release commit: 5312ab8275824cf1d5824badde28e2f53d6378f7.

  • Independent read-only static review: A PASS — Release17Data; B PASS — Release17Protocol; C PASS — Release17DSP; D PASS — Release17Supply. Reviewers ran no runtime gates and certified no external npm settings. No waiver.
  • Fresh clean package 1.7.0 checkout: 272/272 behavioral tests, strict source/development/NodeNext-consumer types, generated build, source/built AST security checks and installed-package render/WAV/types passed. Full tooling/runtime audits found zero vulnerabilities; runtime dependencies are empty. Sound-quality, voice-quality and the report-only local benchmark passed.
  • Actual quality/security CI on the exact reviewed commit: all six jobs passed — Node 22/24/26 and Chromium/Firefox/WebKit. Native AudioWorklet smoke/stress, installed Vite production/CSP deployment, package checks, audits, quality matrices and enforced warmed-p99 benchmark budgets passed. Pages deployment passed on the same commit.
  • The independent v1.7 tag CI run also passed all six jobs on the same release commit before publishing this release.
  • Assistant-managed native Chromium 150: built demo startup and finite nonzero 48-kHz AudioWorklet PCM passed in eco/standard/high, with zero DSP errors. Native Worker eco/PCM16, standard/PCM24 and high/Float32 outputs matched whole-core WAV bytes for 11,520 frames, including transferred sink buffers, one close and no abort/DSP errors in each completed row.
  • All 105 clean generated distribution assets are byte-identical to the canonical committed distribution. The exact attached 119-entry tarball passed isolated local-artifact/installed-consumer verification; duplicated/untracked local assets were excluded without deleting user files.

Artifact

opm.js-1.7.0.tgz — 378,969 bytes.

SHA-256:

01b9f5abfb85d749e4cbd1c750c76e68248aecb8dd06f9a7fd994be406a016e6

Limits

Listening quality, physical iOS/Android interruption behavior, arbitrary-patch alias freedom and the operating-system file chooser remain unverified. Local CPU measurements are host-dependent, not underrun counters. Managed-browser probes also encountered target closures and a ten-second sequential Worker startup deadline; high/Float32 subsequently passed in an isolated fresh managed tab (40.2 ms), not a universal startup guarantee. GitHub Actions reported deprecated action runtime annotations while forcing those pinned actions onto Node 24; all jobs passed. No npm authentication, registry provenance/signatures or registry publication is asserted.

OPM.js v1.6

Choose a tag to compare

@YueyuHoshizora YueyuHoshizora released this 02 Oct 14:17

Package version 1.6.0. GitHub release distribution and npm registry publication are separate operations; the v1.5 artifact remains immutable.

Acoustic quality, expression and adoption

  • Add original independent nested four-op chain/branched/multicarrier references alongside Bessel/feedback/long-stream coverage; replace the former four-pole decimator with a preallocated eighth-order Butterworth cascade. Passband, folded-product rejection, phase, tail and CPU tradeoffs are explicit; no arbitrary-FM alias-free or perceptual claim.
  • Canonicalize voice format v5 with fixed-Hz operators, rate key scaling, pitch envelopes and delayed/phase-selectable note/global LFO. Retain strict original v1–v4 input shapes. Add independent per-operator level multipliers/ramps and note-scaled offline release tails.
  • Preserve supported fixed-Hz/expressive DX7 source fields using documented musical heuristics and actionable substitution/loss warnings; six-to-four topology and hardware timing remain intentionally lossy.
  • Add bounded long-score preparation, capacity estimation, reusable chunked rendering and mixed note/control/stop streaming without removing short-score/worklet/WAV limits.
  • Add same-origin custom worklet assets, multicast subscriptions, timed/abortable command admission waits and terminal disposal alongside restartable close.
  • Expand original curated preset recipes and provenance/register/velocity metadata, numerical host trims and repeatable phrase/A/B audition without rewriting patches for loudness.
  • Expand physical-device recovery scenarios, bounded local observation/status exports and an explicit unverified iOS/Android support matrix.
  • Add post-publication registry byte/integrity/source-provenance/signature/installed-consumer verification to the manual npm workflow; local artifact validation is available without claiming registry publication.
  • Synchronize project guidance and public usage contracts. Physical-device/listening evidence and authorized first npm publication remain external prerequisites.

v1.6 verification record

  • Node.js 26.7.0: 198 behavioral tests, strict source/development/consumer types, source/generated AST gates, installed-package render/WAV/declarations passed; root full/runtime and Vite tooling audits found zero vulnerabilities, with an empty runtime dependency tree. A stale generated dist containing duplicated 2/ 3 suffix files failed the packaged-map gate; it was preserved outside the repository and rebuilt cleanly rather than deleted.
  • Native Chromium 153.0.8010.12 (48 kHz backend, muted) ran the audition UI (A/B measurement, matched-versus-dry reports, PCM16 WAV download, play/stop/dispose and fresh restart), a 60-second/96 kHz bounded render (5,775,360 frames, zero DSP errors) and a 390 px layout check; the event log is now height-limited so long reports do not widen the page. It also ran command-waiter admission, receipt eviction, native abort-signal handling, correlated panic reset, subscription cleanup and terminal disposal against a borrowed context. Worklet stress and the installed Vite subpath/CSP/MIME/404 smoke passed again; the native WebKit 26.6 AudioWorklet smoke passed.
  • Report-only Apple M5 benchmark (48 kHz, 128 frames, 2.667 ms deadline): the order-8 decimator costs more than the former filter. Eight voices with LFO had p99 at 1.575× the deadline and 79 misses; without LFO 1.429× and 45 misses; raw burst 3.323× and prepared burst 2.591×. Worst samples include scheduler/GC pauses (up to 120 ms), so this is a host-dependent tradeoff, not an underrun counter. Measure before enabling dense polyphony on tighter CPU budgets.
  • Not verified: listening quality, physical iOS/Android interruption behavior, locked Playwright 1.56.1, Firefox, Linux WebKit CI and any npm registry operation (npm whoami previously returned ENEEDAUTH). Desktop automation does not earn physical-device acceptance.
  • Waiver: v1.6 was released on GitHub at the maintainer's explicit request without a fresh independent A/B/C/D review (see SECURITY.md). It is not eligible for npm publication until that review record exists.

OPM.js v1.5

Choose a tag to compare

@YueyuHoshizora YueyuHoshizora released this 02 Oct 11:40

OPM.js v1.5

Package version 1.5.0 · Apache-2.0 · zero runtime dependencies.

Highlights

  • Correlated command feedback, all-notes-off and immediate panic, smooth expression/pan/modulation controls, fractional notes, mix gain and global tuning.
  • Bounded reusable patch caching and shared prepared/offline/live scores; oldest, release-first and quietest voice stealing.
  • Voice format 4 with sine, triangle, saw and square LFO waveforms; legacy formats 1/2/3 remain supported.
  • Cancel-by-default interruption recovery, explicit preserve mode, reset/context notifications and the shared-score recovery playground.
  • Independent FM spectral references, two 120-second streaming scenarios, security hardening and executable English/Traditional Chinese guides.

Verified recovery fix

The initial candidate was held after Linux WebKit missed interruption cancellation. This candidate observes context state before and after native resume, handles deferred running/suspended notifications and deduplicates resets. The original browser smoke assertions remain unchanged.

  • 159 behavioral tests, strict source/development/consumer types, source/generated AST security gates and installed-package rendering/WAV/declarations passed locally.
  • Scoped independent security rechecks: Release15Inputs (A/B) and Release15DspSupply (C/D) passed after the observer repair.
  • Exact-commit quality CI passed Node 22/24/26 and native Chromium/Firefox/WebKit jobs, including the previously failing interruption scenario.
  • Exact-tag quality CI completed successfully on attempt 2 at the same commit. Attempt 1 passed all browser/behavior/security gates but Node 22 raw-burst p99 was 2.679757 ms against the 2.666667 ms budget. The retry changed neither source nor budget; this observed variation is not a universal realtime guarantee.
  • Pages deployment passed. Local native WebKit 26.6 and sandboxed muted Chromium smoke also passed.
  • The installed release tarball contains 90 files / 27 JS-map-declaration triplets; every packed file matches commit c73938320b735d6e593d4eaf796c21f867537569. Installed rendering exercised all four LFO waveforms, controls, release/panic and a 2,064-frame score with an 8,300-byte WAV and zero errors.

Distribution

Download opm.js-1.5.0.tgz and verify against SHA256SUMS. This is a GitHub release, not an npm registry publication. npm authentication/trusted publishing remains a separate prerequisite. Physical-phone recovery and universal realtime/chip-fidelity guarantees are not claimed.

SHA-256: bf35ed50a099d74dd4cc89d248e3aa865e47a9d43d3070824c17f352cb79272a

See CHANGELOG for detailed evidence and limitations.

OPM.js v1.4

Choose a tag to compare

@YueyuHoshizora YueyuHoshizora released this 02 Oct 07:19

Highlights

  • Immutable prepared patches and bounded reusable DSP voice state, plus cached worklet patch registration.
  • Live pitch/glide, expression, stereo pan and FM/LFO modulation controls without envelope retriggering; optional per-operator velocity sensitivity.
  • Absolute audio-clock starts, scheduled stops/controls, explicit late-start/drop policy, timestamped lifecycle events and a bounded lookahead scheduler.
  • A 1,728-case numerical sound matrix, native AudioWorklet contention/stealing checks and 108 preset/conversion acceptance cells.
  • Seventh browser example: preset/original-synthetic-DX7 A/B audition, raw peak/RMS reports and locally rendered WAV downloads.
  • Installed-package Vite deployment example with complete worklet/module assets and LICENSE, non-root paths, CSP and MIME/404 failure checks; gated manual npm publishing workflow.

Migration

  • Package version is 1.4.0; release tag is v1.4. Node.js 22+ remains required; there are no runtime dependencies.
  • Canonical voices are version 3. Version 1/2 inputs remain accepted under their original field rules; omitted velocity sensitivity preserves legacy audio. DX7 six-to-four-operator and velocity conversion remain explicitly approximate.
  • opm.voices is a defensive read-only snapshot. Use loadVoice() to replace stored patches.
  • playNote({at}) uses absolute AudioContext seconds and cannot be combined with relative time. Scheduled stop/controls share that clock; same-frame stop precedes onset, then controls. Late-start keeps its full duration; late: 'drop' rejects missed starts.
  • Deploy the complete dist/ tree and retain LICENSE. Every one of its 22 JS modules has a matching map and generated declaration; maps intentionally embed TypeScript source.

Installation

Download opm.js-1.4.0.tgz and SHA256SUMS, verify the digest, then install:

shasum -a 256 -c SHA256SUMS
npm install ./opm.js-1.4.0.tgz

This GitHub release does not publish to the npm registry. See README, both usage guides and CHANGELOG for runnable examples and verification details.

Local verification

  • Node.js 26.7.0 on macOS arm64: build, all 108 tests, strict source/development/generated-consumer types, source/generated AST security gates, installed 1.4.0 render/WAV/types and both npm audits passed. Runtime dependency tree is empty.
  • All 1,728 sound cases and 108 preset/conversion cells passed.
  • Owned isolated headless Chromium 153.0.8010.12 / Playwright 1.63.0, sandboxed and explicitly muted: real stereo/pan, routing/context lifecycle, worklet stress and installed-tarball Vite 8.3.2 production smoke passed. Stress accepted/started 769 notes, stole 760, rejected one intentional late note, peaked at 0.672 and ended with zero active/pending notes and zero DSP errors.
  • Vite /opm-example/ deployment verified real signal/lifecycle, blocked inline CSP, exact deployed LICENSE and visible missing-worklet/wrong-MIME failures.
  • Apple M5 report-only benchmark: 300 warmup blocks excluded, 2,000 measured 128-frame blocks per scenario at 48 kHz. Raw burst p99/worst 1.131/3.303 ms, with one missed 2.667 ms deadline; prepared burst 0.913/1.133 ms, with zero misses. Host/scheduler/GC-dependent observations are not a universal realtime guarantee.

Local browser checks are not locked Playwright 1.56.1 or Firefox/WebKit coverage. Controlled spectral fixtures and unweighted RMS are not hardware-fidelity, arbitrary-FM alias-free or perceptual-LUFS claims. No microphone capture or recording upload was used.

Independent security review

  • Release14Inputs: A/B static approval, including voice/DX7/API/worklet data boundaries and WAV/render/application file inputs.
  • Release14DspSupply: C/D static approval for this GitHub-only release, including bounded DSP callback/pool safety, generated artifacts, deployment licensing and publishing controls.
  • No evidence-backed release blockers remained. Runtime checks were performed separately by 語喵; reviewers did not execute tests or browser checks. External npm trusted-publisher/environment configuration and registry provenance remain unverified prerequisites for a separately authorized npm publication.

Artifact identity

  • Reviewed release commit: 325668c8db47acd553a0501f90267aa0ae6dbdb0
  • Tarball: opm.js-1.4.0.tgz (178,943 bytes; 75 intended entries)
  • SHA-256: 23b3237b5db83c7cbb36a02b04a4610d8ba2104c55fa157272cedc0ce913b994
  • The exact packed artifact was installed separately and exercised prepared pitch parity, live glide/expression/pan, release-to-silence and PCM16 WAV export (4,096 frames / 16,428 WAV bytes, zero DSP errors); all 22 module/map/declaration triplets were checked.

Release-commit CI and deployment

  • Quality and security passed for the exact release commit: Node 22/24/26 and locked-tool browser Chromium/Firefox/WebKit jobs, including numerical matrices, package/security gates and native worklet smoke/stress; Chromium also passed production Vite deployment checks.
  • GitHub Pages deployment passed for the same commit. The live example catalog serves all seven examples.