One publishable surface ships from this repo today: the OCI static bundle (ckp:static) per SPEC.OCI.BUNDLE.v0.4, attestation-gated (this file renders only after gh attestation verify passes). npm is not a delivery channel for this library (operator ruling 2026-08-18): publishing is disabled deliberately — the workflow gate is off and package.json carries "private": true. Note @conceptkernel/cklib@1.0.0 remains on the public registry from an early publish and is not a supported artifact. See Repo packages view for the full version history.
Per PROVENANCE.md, every digest below verifies under gh attestation verify oci://… --repo ConceptKernel/CK.Lib.Js. Versions before v1.3.9 predate the attestation wiring and never appear here — re-publishing them would change digests and break the immutability promise.
docker pull ghcr.io/conceptkernel/ck-lib-js:1.6.6 → declare as a static_web (routed) or layer_sources (additive merge) entry in your bundle.yaml per SPEC.OCI.BUNDLE.v0.4. The bundle lands the facade + transport + cache at image root (/ck.js, /ck-client.js, /ck-store.js, /vendor/) ready for spec-standard COPY --from=cklib_source / dest/.
| arch | Pull URI | Also tagged | Digest | Created (UTC) |
|---|---|---|---|---|
| amd64 | ghcr.io/conceptkernel/ck-lib-js:1.6.6 |
latest |
sha256:cb2e0c6b42372ae91dc123822240ebb0168dbc0c0180e1c884daa871f56990c6 |
2026-09-12 08:45:21 UTC |
| arm64 | ghcr.io/conceptkernel/ck-lib-js:1.6.6 |
latest |
sha256:4fa3cd12a2f599d764313f99c71aa83ea25f76ea4e625aa1d42b08eda489cd32 |
2026-09-12 08:45:21 UTC |
| Artifact type | OCI image index (multi-arch); org.opencontainers.image.designation=ckp:static |
| Aggregate index | ghcr.io/conceptkernel/ck-lib-js:1.6.6 (also tagged latest) |
| Aggregate digest | sha256:7ac5ac4eebc0e84c0ea141c186bf50a24f584307a974944bcb656648f241d066 |
| Provenance | SLSA Build Provenance v1, Sigstore-backed, pushed as OCI referrer |
| Built by | Workflow run #34684045039 |
| Built from commit | f45ba5bc1987c268aa4ac6981d536e04889cd777 |
| Verify (CLI) | gh attestation verify oci://ghcr.io/conceptkernel/ck-lib-js:1.6.6 --repo ConceptKernel/CK.Lib.Js |
| Release notes | https://github.com/ConceptKernel/CK.Lib.Js/releases/tag/v1.6.6 |
| Repo packages view | https://github.com/ConceptKernel/CK.Lib.Js/pkgs/container/ck-lib-js |
# Multi-arch index (Docker's manifest negotiation picks the right arch)
gh attestation verify oci://ghcr.io/conceptkernel/ck-lib-js:1.6.6 \
--repo ConceptKernel/CK.Lib.Js
# A specific per-arch leaf
gh attestation verify oci://ghcr.io/conceptkernel/ck-lib-js@sha256:cb2e0c6b42372ae91dc123822240ebb0168dbc0c0180e1c884daa871f56990c6 \
--repo ConceptKernel/CK.Lib.JsA successful verify means: signed by GitHub's Fulcio CA against the OIDC token of the v1.6.6 oci-publish workflow run, recorded in Sigstore's Rekor transparency log, subject digest matches the pulled artifact.
In your bundle.yaml (per SPEC.OCI.BUNDLE.v0.3):
spec_version: 0.3
# Shape A — routed mount under a path the FastAPI/static server exposes:
static_web:
- source_image: ghcr.io/conceptkernel/ck-lib-js:1.6.6
route: /cklib
attestation_repo: ConceptKernel/CK.Lib.Js
# …or additive filesystem merge into the final image:
layer_sources:
- source_image: ghcr.io/conceptkernel/ck-lib-js:1.6.6
into: /app/cklib/
attestation_repo: ConceptKernel/CK.Lib.JsThe build MUST run gh attestation verify oci://ghcr.io/conceptkernel/ck-lib-js:1.6.6 --repo ConceptKernel/CK.Lib.Js before the consuming image is pushed (SPEC.OCI.BUNDLE.v0.3 §4 build-time gate).
Browser consumption (after the bundle is mounted at /cklib/):
<script type="module">
import { CKClient } from '/cklib/ck-client.js';
const ck = new CKClient({ kernel: 'pgCK.Task' });
await ck.connect();
</script>latesttracks the most recent attested CK.Lib.Js tag on the multi-arch image index. Both arches resolve transparently via Docker's manifest negotiation — nolatest-amd64/latest-arm64split.- Tagged versions are immutable on GHCR. Pin by version (
1.6.6) in production bundles; uselatestonly for development. - The OCI bundle is anonymous public pull — no GHCR auth required.
- Per
PROVENANCE.mdRule 2: do not consider an artifact "shipped" if its digest does not verify undergh attestation verify.
See CHANGELOG.md for what changed per version.
Rendered automatically by
.github/workflows/oci-publish.ymlon 2026-09-12 08:45:21 UTC aftergh attestation verifyaccepted the aggregate digest above.