docsloth.dev
Publish components
The registry is open and federated: publish to the hosted marketplace, your own registry, a Git repository or a package registry. Installing from an external source never levies a fee.
From scaffold to published package
- Forge scaffolds a manifest and source; the manifest is validated against the SDK policy before it is written.
- Declare trust honestly: pure, interactive or connected. Connected components must describe their tools; the host grants capabilities per publication.
- Ship a prop schema and fixture so hosts can validate props and render a conformance fallback.
- Test behaviour and accessibility: keyboard operation, reduced motion and an axe pass are part of the checklist.
- Sign and pin: artifacts are addressed by digest; a mismatch blocks installation.
What the host will refuse
- Install scripts of any kind on control-plane hosts.
- Components that request undeclared network or execution permissions.
- Manifests without a pinned digest, or with a digest that does not match the artifact.
- Anything that tries to reach secrets: components receive capability endpoints, never credentials.
Actions
Actions
- Create package
The component SDK validates manifests and builds signed artifacts; scaffolding is manual in 1.0.0 because no forge command ships. No account or cost.
- Run conformance
Conformance helpers ship in @docsloth/test-kit; they run locally against your fixtures and props schema, not in a hosted service.
- Submit
No hosted registry submission is enabled in this build; publish to your own registry, Git repository or package source. The host refusal rules are listed below.