Package identity
How names, versions, registries, and artifact digests fit together.
A package request is not an identity. acme-widget@^2.4 describes a name and a version range, but it does not identify the code that a project will install.
Follow one request to one artifact
A useful package decision binds the request to all of these values:
| Term | What it answers | Example |
|---|---|---|
| Package name | Which package did the request name? | acme-widget |
| Version range | Which releases are acceptable? | ^2.4 |
| Resolved release | Which exact version was selected? | 2.7.1 |
| Registry identity | Which registry object supplied it? | npmjs.org/acme-widget |
| Artifact digest | Which exact bytes will be used? | sha512-... |
| Lockfile entry | What must a later operation reproduce? | tapid.lock record |
The range is a constraint. The resolved release is a selection. The artifact digest identifies the bytes. The registry identity prevents the same name and version from silently referring to different registry objects.
Why the lockfile matters
A later offline or frozen operation should not resolve the request again. It should validate the lockfile's manifest digest, package identities, tree digests, and verified store content before activating managed node_modules.
That behavior is implemented for populated projects. A registry-backed install and replay print:
The lockfile schema records the registry-qualified package identity, exact version, artifact integrity, integrity provenance, verified tree digest, dependency edges, and root selections needed for replay.
What is implemented and what is planned
The current CLI resolves and installs a bounded npm-compatible subset, validates schema-6 lockfiles, and supports deterministic replay from verified store trees. Registry-wide publisher provenance, private-registry authentication, complete npm compatibility, and user-facing policy decisions remain planned or incomplete.
Read Evidence and policy to see how an exact identity would feed a decision, then return to Getting started for the supported replay command and current status.