tapid lock verify
Validate tapid.lock before replay.
Syntax
verify is currently the only tapid lock subcommand. The current client does not expose separate lockfile create, update, or repair commands. Online tapid install writes the lockfile as part of a successful dependency install.
Validate tapid.lock in the current project. The command reads the fixed tapid.lock path, parses the JSON, and checks the lockfile's supported schema, package identities, roots, dependency edges, URLs, integrity values, and required provenance fields.
When to use it
Run this before an offline or frozen install when you want a separate validation step:
The successful output is:
tapid lock verify does not fetch registry metadata, compare the lockfile with the current package.json, inspect the verified store, or create a missing lockfile. Use tapid install --offline --frozen when you need the full replay check before activation.
Common failures
- A missing
tapid.lockcannot be verified. - Invalid JSON or an unsupported lockfile version is rejected.
- Non-canonical roots, dangling dependencies, mismatched package keys, invalid URLs, or invalid integrity values are rejected.
- A schema-5 file may parse, but replay still requires online regeneration because it lacks the current integrity-provenance contract.