Skip to content

Help build a safer package manager.

Tapid is open source, and we want people who care about software supply chains to help shape it. We are looking for developers, security researchers, maintainers, and early users who want package installation to be controlled and inspectable.

There is useful work for every perspective.

Tapid is still a development release. Contributions can change both what it supports and how clearly it communicates its limits.

Build the package manager

Work on registry support, dependency resolution, lockfiles, deterministic installs, and the CLI developers use every day.

Pressure-test the security model

Review trust boundaries, challenge our assumptions, and help design verification and transparency features that hold up in practice.

Run Tapid on real projects

Try the development release where dependency changes happen, report unsupported workflows, and help improve compatibility and documentation.

Package installation deserves better defaults.

Package managers make it easy to bring third-party code into a project, but fetching, trusting, and executing that code often happen as one opaque action. Tapid is separating those decisions: verify the downloaded archive, record the exact dependency tree, and leave lifecycle scripts disabled unless the developer chooses otherwise.

A matching registry checksum does not prove that a package is safe. The project should be explicit about that boundary while making every install easier to inspect and reproduce.