nostrbasedocs
Start building
Guide
.md

Setup and commands

Use Node 22.12+ and npm 11.16.0. The package is ESM. TypeScript 5.9.3 is pinned because the declaration build does not support TypeScript 7.

npm ci
npm ci --prefix site
npm run prepare:quality
npm run check
Command Purpose
npm run format Format with Biome
npm run format-check Check formatting
npm run lint Run Biome lint rules
npm run typecheck Check source, tests, and examples
npm run test-unit Unit and component contracts, types, async races, and durable failure cases
npm run test-integration Local WebSocket/HTTP, restart recovery, shared resources, and packed SDK consumer
npm run test-e2e Existing packaged Fieldwork application checks in three browsers
npm run test-baseline Actual staged-hook and secret-scanner contracts in disposable Git repositories
npm run test-mutations Check that eight named tests detect deliberate behavioral faults in a temporary copy
npm test Run the fast unit and integration projects
npm run prepare:integrations Prepare pinned services, browser engines, and the extension
npm run test-extended Run all local environment projects after preparation
npm run test-live-services Run compatibility checks against explicitly configured endpoints
npm run build Build ESM, source maps, and declarations
npm run check Run the fast SDK gates
npm run check-ci SDK gate, documentation, secrets, workflows, baseline contracts, and mutation checks
npm run prepare:quality Install checksum-pinned Gitleaks and actionlint
npm run check-secrets Scan project source with fully redacted findings
npm run check-staged Check index formatting, lint, secrets, and working-tree types
npm run check-workflows Validate workflow syntax with pinned actionlint
npm run audit:dependencies Report advisories for all four npm locks without an invented severity gate
npm pack Run checks and build a distributable archive
npm audit Report dependency advisories
npm run docs:dev Build the SDK and serve documentation locally
npm run docs:build Check and build static documentation; verify links and API coverage
npm run docs:preview Preview the documentation build

Install documentation dependencies with npm ci --prefix site. See docs/README.md for content sources and authoring.

Local tests use development identities and loopback services. See environment projects for Docker, browser, Deno, and extension setup. Live checks connect only to explicitly configured endpoints and require separate opt-in for writes. For a downstream application, install the built tarball and import nostrbase.

See testing for the contract map, fixture rules, fault checks, commands, and environment limits. Add a test only when it protects a stated contract or a specific regression. Do not add tests to meet a line coverage percentage. Async tests must control their race boundary and release resources when an assertion fails.

Change and release rules

Keep the public API, record protocol, examples, and tests in the same change. Test author checks, signer failures, version ties, deletes, partial publications, and resource cleanup when their paths change. Update the changelog for public changes.

Run npm run check before review and npm run check-ci before merge. The pre-commit hook checks staged formatting, lint, and secrets without rewriting the index, then checks working-tree types. Enable it with git config core.hooksPath .githooks after prepare:quality. The hook is enabled in the current local repository; each fresh checkout must opt in. npm installation does not change Git configuration.

Keep /Users/fungus/dev/nostrbase on clean main as the control checkout. Future implementation work uses an isolated worktree from a recorded clean commit. No upstream remote or registry publishing is configured. Get independent review before substantive merges and releases. See the engineering baseline, ownership map, security policy, and release policy.

The project owner selects maintainers, a registry name, and the release destination before publication. No person or organization is assumed to own release approval.

Controls register

Control Applies Status Evidence Owner Exception expiry
Reproducible dependencies SDK and tooling Configured package-lock.json, pinned dev tools Project maintainer —
Format, lint, types, tests, build Each change Local gates npm run check Contributor —
Relay integration Transport changes Automated Local WebSocket tests Contributor —
Signature and author checks Writes and reads Automated SDK and regression tests Project maintainer —
API/wire compatibility Public releases Documented Protocol v1, type tests, changelog Release maintainer —
Fast commit hook Local contributors Locally enabled; opt-in per checkout .githooks/pre-commit Contributor —
Staged content checks Local commits Configured and locally enabled check-staged, core.hooksPath Contributor —
Source/history secrets Commits and CI Configured Gitleaks pins, .gitleaks.toml, security.yml Repository maintainer —
Workflow and docs validity Pull requests Local gates check-ci, actionlint, site compiler/link checker Repository maintainer —
Dependency advisories/updates Four npm projects and actions Reporting/configured audit:dependencies, Dependabot Repository maintainer —
Dependency install scripts Four npm projects Strict version-pinned policy .npmrc and allowScripts Repository maintainer —
Ownership and change review Substantive changes Documented MAINTAINERS.md, PR template Project owner Named accounts before hosting
Release traceability/recovery Publication Documented docs/releasing.md Release owner —
Isolated bootstrap worktree Initial source commit Closed bootstrap exception No base commit existed at task start; isolated verification followed Project owner Initial baseline commit
GitHub checks Hosted repository Unverified external .github/workflows/check.yml Repository owner —
Independent release review Public release Pending No release has been made Repository owner Before publication
Protected branches and npm access Hosted repository and registry Unverified external No remote/registry setup Repository owner —

The pre-release source is version 0.2.0. CI files describe intended checks; local evidence does not prove hosted enforcement. See verification for local results. Named GitHub/npm maintainers, branch protections, private vulnerability reporting, publication access, and hosted CI remain external setup work for the project owner.

Search guides, API methods, and protocols.