Docs
From a built directory to a cached, integrity-checked URL in three steps. You need Node 18 or later for the CLI.
01Push a release
Install the CLI, point it at a build directory and name a version. Everything inside lands on an immutable path.
npm i -g @shoal/cli shoal cast ./dist --pkg lumen-ui --version 2.8.1
Files become available at https://cdnshoal.com/v/lumen-ui/2.8.1/<file>. Pushing the same version twice is rejected unless the contents are byte-identical.
02Link with integrity
The push output prints a sha384 value for each file. Add it to the tag together with crossorigin, and the browser verifies the response before running it.
<link rel="stylesheet" href="https://cdnshoal.com/v/lumen-ui/2.8.1/lumen.min.css" integrity="sha384-Yk3m0pXb…V9aQ" crossorigin="anonymous"> <script src="https://cdnshoal.com/v/lumen-ui/2.8.1/lumen.min.js" integrity="sha384-q3Zr1uX9…Hk7w" crossorigin="anonymous" defer></script>
Need the digest later? Run shoal hash lumen-ui@2.8.1 lumen.min.js, or read the Digest response header on any file.
03Understand caching
Versioned paths are served as cacheable for a year and flagged immutable, so browsers never revalidate them.
HTTP/2 200 cache-control: public, max-age=31536000, immutable content-encoding: br digest: sha-384=q3Zr1uX9…Hk7w access-control-allow-origin: * x-shoal-pop: mrs1 x-shoal-cache: HIT
/v/…immutable, one year, never purged./npm/pkg@1.x/…range alias, cached for 10 minutes, then re-resolved.x-shoal-poptells you which site answered, handy when comparing latencies.
shoal retire lumen-ui@2.8.1. The path returns 410 Gone after 30 days so cached references fail loudly instead of silently changing.