tapid docs
Concepts

Package identity

How names, versions, registries, and artifact digests fit together.

A package request is not an identity. acme-widget@^2.4 describes a name and a version range, but it does not identify the code that a project will install.

Follow one request to one artifact

A useful package decision binds the request to all of these values:

TermWhat it answersExample
Package nameWhich package did the request name?acme-widget
Version rangeWhich releases are acceptable?^2.4
Resolved releaseWhich exact version was selected?2.7.1
Registry identityWhich registry object supplied it?npmjs.org/acme-widget
Artifact digestWhich exact bytes will be used?sha512-...
Lockfile entryWhat must a later operation reproduce?tapid.lock record

The range is a constraint. The resolved release is a selection. The artifact digest identifies the bytes. The registry identity prevents the same name and version from silently referring to different registry objects.

Why the lockfile matters

A later offline or frozen operation should not resolve the request again. It should validate the lockfile's manifest digest, package identities, tree digests, and verified store content before activating managed node_modules.

That behavior is implemented for populated projects. A registry-backed install and replay print:

Installed 1 package(s)
Replayed lockfile: 1 package(s)

The lockfile schema records the registry-qualified package identity, exact version, artifact integrity, integrity provenance, verified tree digest, dependency edges, and root selections needed for replay.

What is implemented and what is planned

The current CLI resolves and installs a bounded npm-compatible subset, validates schema-6 lockfiles, and supports deterministic replay from verified store trees. Registry-wide publisher provenance, private-registry authentication, complete npm compatibility, and user-facing policy decisions remain planned or incomplete.

Read Evidence and policy to see how an exact identity would feed a decision, then return to Getting started for the supported replay command and current status.