Any remote file
Vendor JavaScript, CSS, licenses, source maps, executables, or other release files. Muamba only needs source URLs, destination paths, and integrity locks.
Running lock accepts the first response and records its SHA-384 digest. Commit those files for offline builds; every later copy must match.
go get -tool github.com/araihu/muamba/cmd/muamba@v0.0.3Prebuilt releases need no Go installation.
schema: 1
resources:
alpine:
version: "3.14.9"
downloads:
runtime:
url: https://unpkg.com/alpinejs@${version}/dist/cdn.min.js
path: assets/vendor/alpine/${version}/alpine.min.js
integrity: sha384-…One manifest. One set of locked bytes.
First response, fixed identity
The digest detects later changes. It does not authenticate the publisher or content. You remain responsible for choosing trustworthy source URLs.
Review each URL, then run lock. It accepts the first response and writes its SHA-384 digest atomically.
Default verify checks materialized files offline. Run verify --all-platforms to check every locked cache variant.
Sync checks the destination first, then the cache, then the network. Cached or remote bytes must match the lock before the destination changes.
Built for reproducible inputs
Vendor JavaScript, CSS, licenses, source maps, executables, or other release files. Muamba only needs source URLs, destination paths, and integrity locks.
Stage every file in a grouped dependency before the manifest or visible destinations change.
Generate deterministic, package-scoped registries with normalized digests for cache-busting URLs.
Pin exact GOOS/GOARCH executables with one destination, explicit size limits, file modes, and per-target locks.
Start with one remote file