Hope is not a dependency strategy.
Tapid is a package manager for JavaScript and TypeScript. For supported installs, it checks registry-declared artifact integrity and records the dependency graph before changing your project.
curl -fsSL https://tapid.dev/install.sh | bashCheck first. Install second.
Tapid uses a normal package.json, npm registry metadata, and experimental JSR specs when they expose a compatible npm artifact. For supported installs, before it writes node_modules, it checks the registry-declared SHA-512, records exact package identities and dependency edges in tapid.lock, and keeps dependency install scripts disabled. A changed artifact stops before activation, and --offline --frozen replays the verified inputs without resolving the graph again.
mkdir democd demotapid inittapid i is-charRegistry metadata progress: 1 package(s) fetchedArtifact verification progress: 1/1Materialization progress: 1/1Installed 1 package(s)tapid install --offline --frozenReplay snapshot progress: 1/1Materialization progress: 1/1Replayed lockfile: 1 package(s)What changes when Tapid installs a package
Tapid does not make the dependency disappear into node_modules. It validates the supported request, records the result, and only replaces managed files after those checks pass.
Pick a version
Tapid binds a supported request to an exact version, registry, and dependency edge.
Check the archive
It compares the downloaded archive with the SHA-512 value declared in registry metadata.
Write the record
It records the manifest digest, package identities, dependency edges, and tree digests in tapid.lock.
Update the folder
It stages node_modules and replaces the managed tree only after those checks pass.
The lockfile is what Tapid checks again.
It binds the project manifest to exact package identities and verified tree inputs. Offline and frozen modes validate those inputs before activation.
Understand package identity{
"lockfileVersion": 6,
"rootManifestDigest": "sha256-1b29ee1e427f07156521d6139b52e13685ea6f426b2b6fbba996d3fd8e22311f",
"resolverVersion": "0",
"roots": [
"https://registry.npmjs.org|[email protected]|peer=-|platform=os=;cpu=;libc="
],
"packages": {
"https://registry.npmjs.org|[email protected]|peer=-|platform=os=;cpu=;libc=": {
"registry": "https://registry.npmjs.org",
"name": "is-char",
"version": "1.1.11",
"artifactIntegrity": "sha512-luFc27hBTXRWLg+T0A6+eQ+7wYbOZAHyJTDrnTpdSnygoxLgBH9TqArCUN1EQKPcfcDgtTf/xlYOUuZaC64a+w==",
"registryIntegrityDeclared": true,
"unpackedDigest": "sha256-2bb3d71bdd17c193a9e24f1f203b79cf8049b9f9493511f8d05dca26d77219a7",
"treeDigest": "sha256-2bb3d71bdd17c193a9e24f1f203b79cf8049b9f9493511f8d05dca26d77219a7",
"artifactUrl": "https://registry.npmjs.org/is-char/-/is-char-1.1.11.tgz",
"platformContext": "os=;cpu=;libc=",
"dependencies": {}
}
}
}[email protected]. Tapid records the registry, exact version, archive integrity, and tree digest so frozen replay can check the same package again. It does not certify the package as safe.Installable now. Deliberately bounded.
Tapid ships public releases for macOS, Linux, and Windows. The client supports a deliberately bounded npm-compatible workflow: enough to evaluate verified installs and offline replay, but not a drop-in replacement for npm or pnpm.
What works now
- npmjs.com packages and experimental jsr.io specs when metadata includes a usable npm artifact and SHA-512 integrity
- Public installers for macOS, Linux, and Windows from immutable GitHub release assets
- Registry-declared SHA-512 integrity required by default for online installs
- Canonical schema-6 lockfiles and verified store replay
- Managed node_modules and executable metadata
- Dependency lifecycle scripts suppressed during installation
- Explicit root project scripts with argument and exit-code forwarding