Official SPM Publishing Guide

Publishing to the SP Registry

The SP Package Registry connects your libraries and tools to developers worldwide. Follow this guide to prepare, test, sign, and publish your SP package.

1

Configure Package Manifest (sp.toml)

Every SP package requires a valid sp.toml in the project root containing metadata, dependencies, license, and repository links.

sp.toml
[package]
name = "my-awesome-lib"
version = "1.0.0"
authors = ["Your Name <you@example.com>"]
description = "A high-performance algorithm library for SP"
license = "MIT"
readme = "README.md"
repository = "https://github.com/username/my-awesome-lib"
keywords = ["algorithms", "performance", "math"]
category = "utilities"

[dependencies]
json = "^1.2.0"

[dev-dependencies]
test-bench = "^1.0.0"
2

Run Pre-Publication Verification

Ensure all unit tests pass, code adheres to official formatting, and there are no compiler warnings before publishing.

1. Run Test Suite

Verify 100% of your test cases pass with the native test runner.

spc test
2. Code Formatting

Check formatting idempotency against the standard style guide.

spc fmt --check
3

Authenticate SPM CLI

To publish under your developer namespace, authenticate using an API publish token issued by the SP Registry.

$spm login --token <YOUR_API_TOKEN>

Tokens are securely stored in your local user profile (~/.spm/credentials) with restricted file permissions.

4

Publish Your Package

Execute the publish command from within the directory containing your sp.toml:

$spm publish
Packaging source tarball...
Computing SHA-256 digest: e3b0c44298fc1c149afbf4c8...
Uploading package to registry.splang.shantopaul.com...
✓ Successfully published my-awesome-lib@1.0.0
Package Immutability & Yank Policy

To ensure reproducible builds across the globe, packages published to the SP Registry are permanent and immutable. Once version 1.0.0 is published, its tarball and SHA-256 hash can never be modified or replaced.

If a critical bug or vulnerability is discovered, you can use spm yank <version> to prevent new installations while allowing existing sp.lock builds to function uninterrupted.