Publishing to the SP Registry
The SP Package Registry connects your libraries and tools to developers worldwide. Follow this guide to prepare, test, sign, and publish your SP package.
Configure Package Manifest (sp.toml)
Every SP package requires a valid sp.toml in the project root containing metadata, dependencies, license, and repository links.
[package]
name = "my-awesome-lib"
version = "1.0.0"
authors = ["Your Name <you@example.com>"]
description = "A high-performance algorithm library for SP"
license = "MIT"
readme = "README.md"
repository = "https://github.com/username/my-awesome-lib"
keywords = ["algorithms", "performance", "math"]
category = "utilities"
[dependencies]
json = "^1.2.0"
[dev-dependencies]
test-bench = "^1.0.0"Run Pre-Publication Verification
Ensure all unit tests pass, code adheres to official formatting, and there are no compiler warnings before publishing.
Verify 100% of your test cases pass with the native test runner.
spc testCheck formatting idempotency against the standard style guide.
spc fmt --checkAuthenticate SPM CLI
To publish under your developer namespace, authenticate using an API publish token issued by the SP Registry.
Tokens are securely stored in your local user profile (~/.spm/credentials) with restricted file permissions.
Publish Your Package
Execute the publish command from within the directory containing your sp.toml:
To ensure reproducible builds across the globe, packages published to the SP Registry are permanent and immutable. Once version 1.0.0 is published, its tarball and SHA-256 hash can never be modified or replaced.
If a critical bug or vulnerability is discovered, you can use spm yank <version> to prevent new installations while allowing existing sp.lock builds to function uninterrupted.