Hope is not a dependency strategy.

Tapid is a package manager for JavaScript and TypeScript. For supported installs, it checks registry-declared artifact integrity and records the dependency graph before changing your project.

curl -fsSL https://tapid.dev/install.sh | bash

Check first. Install second.

Tapid uses a normal package.json, npm registry metadata, and experimental JSR specs when they expose a compatible npm artifact. For supported installs, before it writes node_modules, it checks the registry-declared SHA-512, records exact package identities and dependency edges in tapid.lock, and keeps dependency install scripts disabled. A changed artifact stops before activation, and --offline --frozen replays the verified inputs without resolving the graph again.

Read the install checks
zsh ยท ~/projects/demo
mkdir democd demotapid inittapid i is-charRegistry metadata progress: 1 package(s) fetchedArtifact verification progress: 1/1Materialization progress: 1/1Installed 1 package(s)tapid install --offline --frozenReplay snapshot progress: 1/1Materialization progress: 1/1Replayed lockfile: 1 package(s)

What changes when Tapid installs a package

Tapid does not make the dependency disappear into node_modules. It validates the supported request, records the result, and only replaces managed files after those checks pass.

  1. Pick a version

    Tapid binds a supported request to an exact version, registry, and dependency edge.

  2. Check the archive

    It compares the downloaded archive with the SHA-512 value declared in registry metadata.

  3. Write the record

    It records the manifest digest, package identities, dependency edges, and tree digests in tapid.lock.

  4. Update the folder

    It stages node_modules and replaces the managed tree only after those checks pass.

The lockfile is what Tapid checks again.

It binds the project manifest to exact package identities and verified tree inputs. Offline and frozen modes validate those inputs before activation.

Understand package identity
{
  "lockfileVersion": 6,
  "rootManifestDigest": "sha256-1b29ee1e427f07156521d6139b52e13685ea6f426b2b6fbba996d3fd8e22311f",
  "resolverVersion": "0",
  "roots": [
    "https://registry.npmjs.org|[email protected]|peer=-|platform=os=;cpu=;libc="
  ],
  "packages": {
    "https://registry.npmjs.org|[email protected]|peer=-|platform=os=;cpu=;libc=": {
      "registry": "https://registry.npmjs.org",
      "name": "is-char",
      "version": "1.1.11",
      "artifactIntegrity": "sha512-luFc27hBTXRWLg+T0A6+eQ+7wYbOZAHyJTDrnTpdSnygoxLgBH9TqArCUN1EQKPcfcDgtTf/xlYOUuZaC64a+w==",
      "registryIntegrityDeclared": true,
      "unpackedDigest": "sha256-2bb3d71bdd17c193a9e24f1f203b79cf8049b9f9493511f8d05dca26d77219a7",
      "treeDigest": "sha256-2bb3d71bdd17c193a9e24f1f203b79cf8049b9f9493511f8d05dca26d77219a7",
      "artifactUrl": "https://registry.npmjs.org/is-char/-/is-char-1.1.11.tgz",
      "platformContext": "os=;cpu=;libc=",
      "dependencies": {}
    }
  }
}
Captured from a local Tapid 0.0.8 run with [email protected]. Tapid records the registry, exact version, archive integrity, and tree digest so frozen replay can check the same package again. It does not certify the package as safe.

Installable now. Deliberately bounded.

Tapid ships public releases for macOS, Linux, and Windows. The client supports a deliberately bounded npm-compatible workflow: enough to evaluate verified installs and offline replay, but not a drop-in replacement for npm or pnpm.

What works now

  • npmjs.com packages and experimental jsr.io specs when metadata includes a usable npm artifact and SHA-512 integrity
  • Public installers for macOS, Linux, and Windows from immutable GitHub release assets
  • Registry-declared SHA-512 integrity required by default for online installs
  • Canonical schema-6 lockfiles and verified store replay
  • Managed node_modules and executable metadata
  • Dependency lifecycle scripts suppressed during installation
  • Explicit root project scripts with argument and exit-code forwarding
Evaluate the current pathInstall a public release, run one supported package flow, and inspect the result.
Open getting started