Repository navigation
OPM.js v1.9
Integration and musical workflows
Package 1.9.0, GitHub tag v1.9. Voice format remains v6; zero runtime dependencies.
- Portable version-1 score projects, deterministic JSON save/load and tempo-integrating offline beat compilation.
- Bounded Standard MIDI file format 0/1 PPQN import/export with explicit mappings, warnings and unsupported-content rejection.
- Transport startup lead fixes cold-start beat-0 scheduling; real late/drop errors remain visible.
- Independent note/layer gain, quantized Arrangement fades and crossfades without retriggering shared layers.
- Configurable MIDI CC mappings, effective-control snapshots and adapter-owned sustain cleanup.
- Two original songs with playback, project save/load and Worker WAV export; thirteen checkout examples.
- Searchable static HTML guides, complete compiler-derived API reference and DOM-free Node core/project/MIDI declarations.
- Exact-workload device evidence and explicitly confirmed human-listening findings; neither tool invents acceptance.
- Cache FM topology in pooled voice slots without changing PCM or relaxing deadline budgets.
Artifact and review
Release commit: 435a6eb12d55245f7ea0c424c6c81e8840603b92.
opm.js-1.9.0.tgz was rebuilt from this exact clean commit in an isolated directory, not the live tree containing unknown numbered generated copies. Archive size: 948,465 bytes; 189 package files, including 47 canonical JS/map/declaration triplets (141 distribution assets). Every distribution asset matches the release commit.
SHA-256:
2f6c4fa7cde42469b3d89b939bf601283bebb6d89bdad91d9f922db0ea83aa9b
Scoped independent static security reviews: Release19Inputs A/B and Release19Supply C/D, including a fresh C/D recheck of the DSP topology-cache repair, with no evidence-backed security findings. Static reviews are not runtime certification.
Local canonical candidate: build, 382 passing behavioral tests, strict source/development/public-consumer type checks, parsed dynamic-code/zero-runtime-dependency gates and installed-package rendering/WAV/assets/DOM-free declaration checks passed. The final archive passed the local artifact verifier; this is not registry verification. A 288-case before/after runtime smoke remains PCM bit-identical across qualities, sample rates, stealing, gain ramps and chunk boundaries.
Final exact-commit Quality and security CI: all six jobs passed — Node 22/24/26 (tests, build, types, sound/preset quality, dependency audits, package security and unchanged p99 deadline gate), plus Chromium/Firefox/WebKit AudioWorklet smoke/stress and Chromium installed-package Vite/CSP.
The initial candidate CI failed Node 22 prepared-burst p99 (3.131281 ms versus a 2.666667 ms deadline) and was never tagged. After the topology-cache repair, final remote Node 22 prepared-burst p99 is 1.941113 ms (ratio 0.727917, median 1.677022 ms), with zero DSP errors/rejected notes. Worst-case 3.106474 ms and 7/2,000 missed deadlines remain reported; passing p99 is not a realtime guarantee. No threshold relaxation or waiver was used.
Installation
npm install https://github.com/YueyuHoshizora/OPM.js/releases/download/v1.9/opm.js-1.9.0.tgzConsumers need no source checkout or build toolchain. Deploy the complete matching dist/ tree and LICENSE.
Scope
No npm publication is performed. Existing tags/assets remain unchanged. Physical iOS/Android, physical MIDI and genuine human listening remain unverified; numerical and desktop automation evidence does not certify them. Earlier native Chromium signal/UI evidence is retained in CHANGELOG, not represented as a new physical-device result.