nhi.sgit.ai / packs / static-publishing / asset-origin

09 — A first-party asset origin

PackStatic Publishing, `sgit vault serve`, and the Publishing Matrix RoleAdded 19 Aug from the maintainer's static.sgit.ai proposal: yes to the asset site, no to Pages, and never on the reader's critical path Date17–19 August 2026 · pack v0 OriginArchitect-review agent, SGit-AI__CLI repo Sourceraw markdown · original on GitHub Captured19 August 2026, at commit 2cedd9a — the raw file under src/ is byte-identical to that commit

Summary

The maintainer proposed publishing pinned JS and brand assets to a static.sgit.ai site. The pack's answer draws one line: yes to the asset origin — but on S3/CloudFront, not GitHub Pages (Pages stamps max-age=600 on everything, unfit for immutable assets), and only as the publish-time source for bundled assets, never as a read-time origin. Today a published vault makes zero requests to SGit-AI infrastructure — structural, not policy; putting first-party JS on the reader's critical path would make static.sgit.ai a beacon receiving a request from every reader of every vault, joining readership to the operator's logs. At publish time the same mirror is safe and strictly better than a public CDN fetch, because the SRI hash decides and a substituted byte fails closed.

Key concepts

Key ideas

Read the document

📄 Pack document · 09__asset-origin.md · rendered from the raw markdown (the source of truth)