Packages

The multicall binary ships with a built-in default ober TUF registry. Install packages with one command — bare names auto-resolve to ober.

Quick Start

$ jerboa pkg init @me/app
$ jerboa pkg add jerboa-ssh
resolved 1 package: ober/jerboa-ssh 0.1.0 (lisp)
$ jerboa app.ss
(import (jerboa-ssh api)) works — no env wrapper needed

Public Registry

The canonical ober registry lives at git.jerboa.sh/ober/jerboa-registry and is served via Forgejo raw file endpoints. On first use, jpkg syncs TUF metadata into ~/.jerboa/pkg/registries/ober/; package blobs are fetched on demand during install.

TUF Signed

Root, targets, snapshot, timestamp roles with threshold signatures, rollback and freeze protection, and TOFU pinning.

Ed25519 Signatures

Every package release carries a detached Ed25519 signature over its manifest digest. Pure-Scheme verification (RFC 8032 test vectors).

SLSA Provenance

Optional in-toto DSSE provenance envelopes with builder identity and subject digest attestation.

Transparency Log

Append-only hash-chained log of every publish. Inclusion and consistency proofs verified on every jpkg audit.

Deterministic Artifacts

Reproducible .jpkg tarballs: zeroed uid/gid/mtime, sorted paths, deterministic gzip. jpkg verify --rebuild proves it.

Lockfile Enforced

jpkg install materializes exactly jpkg.lock — no resolution, no network, no surprises. Dependency-confusion guard prevents registry switching.

Commands

$ jerboa pkg init @me/app          # create jpkg.sexp
$ jerboa pkg add jerboa-ssh      # resolves to ober/jerboa-ssh
$ jerboa pkg install             # materialize exactly jpkg.lock
$ jerboa pkg list                # show locked packages
$ jerboa pkg search ssh          # search the ober registry
$ jerboa pkg audit               # check advisories + transparency
$ jerboa pkg pack                # build a deterministic .jpkg

Available Packages

51 packages published to the ober registry — all TUF-signed with Ed25519 signatures and SLSA provenance. Install any with jerboa pkg add <name>.

Network and Web (11)

0.1.0

ober/jerboa-ssh

SSH client and server: agent, Ed25519 keys, SFTP, port forwarding

Source
0.1.0

ober/jerboa-sshd

SSH daemon for Jerboa

Source
0.1.0

ober/jerboa-ssl

SSL/TLS primitives and FFI

Source
0.1.0

ober/jerboa-https

HTTPS client and HTTP server

Source
0.1.0

ober/jerboa-smtp

SMTP server and client

Source
0.1.0

ober/jerboa-mail

IMAP/SMTP mail client

Source
0.1.0

ober/jerboa-dns

DNS client and server

Source
0.1.0

ober/jerboa-browser

Programmable Qt WebEngine browser

Source
0.1.0

ober/jerboa-webex

Web extraction toolkit

Source
0.1.0

ober/jerboa-websearch

Web search engine

Source
0.1.0

ober/jerboa-wormhole

Magic-wormhole-style file transfer

Source

Data and Crypto (8)

0.1.0

ober/jerboa-crypto

Cryptographic primitives and FFI

Source
0.1.0

ober/jerboa-db

Database abstractions

Source
0.1.0

ober/jerboa-duckdb

DuckDB bindings

Source
0.1.0

ober/jerboa-sqlite

Pure Jerboa SQLite engine

Source
0.1.0

ober/jerboa-sqlite-ffi

SQLite FFI bindings

Source
0.1.0

ober/jerboa-pcre2

PCRE2 regex bindings

Source
0.1.0

ober/jerboa-pgp

OpenPGP implementation

Source
0.1.0

ober/jerboa-yubikey

YubiKey / FIDO2 bindings

Source

Security (6)

0.1.0

ober/jerboa-secmon

Security monitoring (SIEM)

Source
0.1.0

ober/jerboa-secmonlib

Security monitoring library

Source
0.1.0

ober/jerboa-semgrep

Semgrep-style pattern matching

Source
0.1.0

ober/jerboa-signal

Signal messenger client

Source
0.1.0

ober/jerboa-virus

Pure-Jerboa malware scanner

Source
0.1.0

ober/jerboa-gitsafe

Secret-scanning git hooks

Source

Systems and CLI (7)

0.1.0

ober/jerboa-coreutils

Core utilities (ls, cat, grep, etc.)

Source
0.1.0

ober/jerboa-awk

AWK implementation

Source
0.1.0

ober/jerboa-sed

SED stream editor

Source
0.1.0

ober/jerboa-top

Top-like process monitor

Source
0.1.0

ober/jerboa-asm

Assembler and low-level code generation

Source
0.1.0

ober/jerboa-fuse

FUSE filesystem support

Source
0.1.0

ober/jerboa-inotify

Linux inotify bindings

Source

Tools and Editors (4)

0.1.0

ober/jerboa-code

Portable AI coding agent

Source
0.1.0

ober/jerboa-emacs

Emacs-like editor with terminal and Qt frontends

Source
0.1.0

ober/jerboa-treesitter

Tree-sitter parser bindings

Source
0.1.0

ober/jerboa-scintilla

Scintilla editor component bindings

Source

Platform (7)

0.1.0

ober/jerboa-android

Android target support for cross-compilation

Source
0.1.0

ober/jerboa-aws

AWS SDK

Source
0.1.0

ober/jerboa-drive

Cloud drive abstraction

Source
0.1.0

ober/jerboa-edge

Edge computing runtime

Source
0.1.0

ober/jerboa-qt

Qt GUI bindings

Source
0.1.0

ober/jerboa-proton-bridge

Proton Mail bridge

Source
0.1.0

ober/jerboa-protonmail

Proton Mail API client

Source

Core (7)

0.1.0

ober/jerboa-compat

Cross-implementation compatibility shims

Source
0.1.0

ober/jerboa-sinatra

Sinatra-style web framework

Source
0.1.0

ober/jerboa-site

Static site generator (this site!)

No public source link listed.
0.1.0

ober/jerboa-imagesite

Image hosting site builder

Source
0.1.0

ober/jerboa-ssd-recognizer

SSD object detection recognizer

Source
0.1.0

ober/jerboa-vision

Computer vision routines

Source
0.1.0

ober/jerboa-wafter

Network packet dissector

Source

Self-Host a Registry

Anyone can run a private registry: jpkg publish --registry DIR --key FILE bootstraps a TUF-signed staging registry. See the jpkg guide for the full workflow.