Build the package manager
Work on registry support, dependency resolution, lockfiles, deterministic installs, and the CLI developers use every day.
Tapid is open source, and we want people who care about software supply chains to help shape it. We are looking for developers, security researchers, maintainers, and early users who want package installation to be controlled and inspectable.
Tapid is still a development release. Contributions can change both what it supports and how clearly it communicates its limits.
Work on registry support, dependency resolution, lockfiles, deterministic installs, and the CLI developers use every day.
Review trust boundaries, challenge our assumptions, and help design verification and transparency features that hold up in practice.
Try the development release where dependency changes happen, report unsupported workflows, and help improve compatibility and documentation.
Package managers make it easy to bring third-party code into a project, but fetching, trusting, and executing that code often happen as one opaque action. Tapid is separating those decisions: verify the downloaded archive, record the exact dependency tree, and leave lifecycle scripts disabled unless the developer chooses otherwise.
A matching registry checksum does not prove that a package is safe. The project should be explicit about that boundary while making every install easier to inspect and reproduce.