@dbrij/ship-capacitor
v0.1.0
Published
Dbrij Ship live updates for Capacitor and Ionic apps: signed web-asset bundles with verify-before-apply and boot-canary rollback.
Readme
@dbrij/ship-capacitor
Dbrij Ship live updates for Capacitor and Ionic apps: signed web-asset bundles (your built dist/ as a zip), verified on device, staged rollouts, boot-canary rollback.
Install
npm i @dbrij/ship @dbrij/ship-capacitor
npx cap syncUse
import { createShip } from '@dbrij/ship';
import { notifyAppReady, syncShipUpdates } from '@dbrij/ship-capacitor';
import { Preferences } from '@capacitor/preferences';
const ship = createShip({
appKey: 'shp_...',
channel: 'production',
binaryVersion: '1.2.0',
platform: 'capacitor',
storage: {
getItem: async (k) => (await Preferences.get({ key: k })).value,
setItem: async (k, v) => Preferences.set({ key: k, value: v }),
},
});
// Once your app has rendered:
await notifyAppReady(ship); // disarms the boot canary + reports 'applied'
await syncShipUpdates(ship, { signPublicKey: 'BASE64_KEY_FROM_DASHBOARD' });Release bundles are a zip of your built web assets (dist/), uploaded on the Ship dashboard. A staged update serves on the next launch; mandatory updates reload immediately. A bundle that never reaches notifyAppReady is reverted on the following start and reported, so the rollout can freeze itself server-side.
Safety model
Same as the React Native plugin: sha256 + ed25519 verification against your pinned public key before extraction (with a zip-slip guard), fail-closed on devices that cannot verify (Android below 13), and the binary's own assets as the untouchable fallback.
