Packages
The multicall binary ships with a built-in default ober TUF registry. Install packages with one command — bare names auto-resolve to ober.
Quick Start
$ jerboa pkg init @me/app
$ jerboa pkg add jerboa-ssh
resolved 1 package: ober/jerboa-ssh 0.1.0 (lisp)
$ jerboa app.ss
(import (jerboa-ssh api)) works — no env wrapper needed
Public Registry
The canonical ober registry lives at git.jerboa.sh/ober/jerboa-registry and is served via Forgejo raw file endpoints. On first use, jpkg syncs TUF metadata into ~/.jerboa/pkg/registries/ober/; package blobs are fetched on demand during install.
TUF Signed
Root, targets, snapshot, timestamp roles with threshold signatures, rollback and freeze protection, and TOFU pinning.
Ed25519 Signatures
Every package release carries a detached Ed25519 signature over its manifest digest. Pure-Scheme verification (RFC 8032 test vectors).
SLSA Provenance
Optional in-toto DSSE provenance envelopes with builder identity and subject digest attestation.
Transparency Log
Append-only hash-chained log of every publish. Inclusion and consistency proofs verified on every jpkg audit.
Deterministic Artifacts
Reproducible .jpkg tarballs: zeroed uid/gid/mtime, sorted paths, deterministic gzip. jpkg verify --rebuild proves it.
Lockfile Enforced
jpkg install materializes exactly jpkg.lock — no resolution, no network, no surprises. Dependency-confusion guard prevents registry switching.
Commands
$ jerboa pkg init @me/app # create jpkg.sexp
$ jerboa pkg add jerboa-ssh # resolves to ober/jerboa-ssh
$ jerboa pkg install # materialize exactly jpkg.lock
$ jerboa pkg list # show locked packages
$ jerboa pkg search ssh # search the ober registry
$ jerboa pkg audit # check advisories + transparency
$ jerboa pkg pack # build a deterministic .jpkg
Available Packages
51 packages published to the ober registry — all TUF-signed with Ed25519 signatures and SLSA provenance. Install any with jerboa pkg add <name>.
Network and Web (11)
0.1.0ober/jerboa-ssh
SSH client and server: agent, Ed25519 keys, SFTP, port forwarding
Source 0.1.0ober/jerboa-sshd
SSH daemon for Jerboa
Source 0.1.0ober/jerboa-ssl
SSL/TLS primitives and FFI
Source 0.1.0ober/jerboa-https
HTTPS client and HTTP server
Source 0.1.0ober/jerboa-smtp
SMTP server and client
Source 0.1.0ober/jerboa-mail
IMAP/SMTP mail client
Source 0.1.0ober/jerboa-dns
DNS client and server
Source 0.1.0ober/jerboa-browser
Programmable Qt WebEngine browser
Source 0.1.0ober/jerboa-webex
Web extraction toolkit
Source 0.1.0ober/jerboa-websearch
Web search engine
Source 0.1.0ober/jerboa-wormhole
Magic-wormhole-style file transfer
Source Data and Crypto (8)
0.1.0ober/jerboa-crypto
Cryptographic primitives and FFI
Source 0.1.0ober/jerboa-db
Database abstractions
Source 0.1.0ober/jerboa-duckdb
DuckDB bindings
Source 0.1.0ober/jerboa-sqlite
Pure Jerboa SQLite engine
Source 0.1.0ober/jerboa-sqlite-ffi
SQLite FFI bindings
Source 0.1.0ober/jerboa-pcre2
PCRE2 regex bindings
Source 0.1.0ober/jerboa-pgp
OpenPGP implementation
Source 0.1.0ober/jerboa-yubikey
YubiKey / FIDO2 bindings
Source Security (6)
0.1.0ober/jerboa-secmon
Security monitoring (SIEM)
Source 0.1.0ober/jerboa-secmonlib
Security monitoring library
Source 0.1.0ober/jerboa-semgrep
Semgrep-style pattern matching
Source 0.1.0ober/jerboa-signal
Signal messenger client
Source 0.1.0ober/jerboa-virus
Pure-Jerboa malware scanner
Source 0.1.0ober/jerboa-gitsafe
Secret-scanning git hooks
Source Systems and CLI (7)
0.1.0ober/jerboa-coreutils
Core utilities (ls, cat, grep, etc.)
Source 0.1.0ober/jerboa-awk
AWK implementation
Source 0.1.0ober/jerboa-sed
SED stream editor
Source 0.1.0ober/jerboa-top
Top-like process monitor
Source 0.1.0ober/jerboa-asm
Assembler and low-level code generation
Source 0.1.0ober/jerboa-fuse
FUSE filesystem support
Source 0.1.0ober/jerboa-inotify
Linux inotify bindings
Source Tools and Editors (4)
0.1.0ober/jerboa-code
Portable AI coding agent
Source 0.1.0ober/jerboa-emacs
Emacs-like editor with terminal and Qt frontends
Source 0.1.0ober/jerboa-treesitter
Tree-sitter parser bindings
Source 0.1.0ober/jerboa-scintilla
Scintilla editor component bindings
Source Platform (7)
0.1.0ober/jerboa-android
Android target support for cross-compilation
Source 0.1.0ober/jerboa-aws
AWS SDK
Source 0.1.0ober/jerboa-drive
Cloud drive abstraction
Source 0.1.0ober/jerboa-edge
Edge computing runtime
Source 0.1.0ober/jerboa-qt
Qt GUI bindings
Source 0.1.0ober/jerboa-proton-bridge
Proton Mail bridge
Source 0.1.0ober/jerboa-protonmail
Proton Mail API client
Source Core (7)
0.1.0ober/jerboa-compat
Cross-implementation compatibility shims
Source 0.1.0ober/jerboa-sinatra
Sinatra-style web framework
Source 0.1.0ober/jerboa-site
Static site generator (this site!)
No public source link listed. 0.1.0ober/jerboa-imagesite
Image hosting site builder
Source 0.1.0ober/jerboa-ssd-recognizer
SSD object detection recognizer
Source 0.1.0ober/jerboa-vision
Computer vision routines
Source 0.1.0ober/jerboa-wafter
Network packet dissector
Source Self-Host a Registry
Anyone can run a private registry: jpkg publish --registry DIR --key FILE bootstraps a TUF-signed staging registry. See the jpkg guide for the full workflow.