Archive Utilities
compressTask and decompressTask support integrations that package or inspect task releases. Task authors normally use thyme upload.
compressTask
import { compressTask, type CompressResult } from '@thyme-labs/sdk'
function compressTask(
source: string,
bundle: string,
permissions?: string,
): CompressResult
interface CompressResult {
zipBuffer: Uint8Array
checksum: string
}Packages source.ts and bundle.js, plus permissions.json when a string is supplied. The permissions argument is raw JSON text, not a parsed object. It is not validated by this helper.
The result contains the ZIP bytes and a lowercase hexadecimal SHA-256 checksum covering the entire archive. Compression uses level 6. The root helper uses Node's crypto module, so use the reader-only subpath when a runtime cannot load Node APIs.
The CLI uses its own deterministic ZIP timestamp handling for repeatable uploads. The SDK helper does not promise byte-identical archives across invocations; hash the returned bytes rather than assuming a checksum from source text alone.
decompressTask
import {
decompressTask,
type DecompressResult,
} from '@thyme-labs/sdk/archive-reader'
function decompressTask(zip: Uint8Array | ArrayBuffer): DecompressResult
interface DecompressResult {
source: string
bundle: string
permissions?: string
}The reader is also exported from the package root. It returns decoded UTF-8 strings. permissions is absent when the ZIP has no manifest; an empty manifest entry returns an empty string. Validate that text using the release manifest contract before using it.
| Guard | Limit or behavior |
|---|---|
| Compressed archive | At most 10 MiB. |
| Declared decompressed size of selected entries | At most 50 MiB. |
| Total ZIP entries | At most 16, including ignored entries. |
| Required entries | Exactly named source.ts and bundle.js. Missing entries throw. |
| Optional entry | Exactly named permissions.json. |
| Duplicate selected entries | Rejected to avoid ambiguous content. |
| Other entries | Counted toward the entry limit, but ignored and not inflated. |
Reading an archive does not verify an expected checksum, execute or typecheck the bundle, validate the permission manifest, or prove that the source and bundle match. An upload integration must perform those checks at its own boundary.