Releases: LimeTip/tapid
Release list
v0.0.10
Tapid 0.0.10 release notes
Tapid 0.0.10 adds experimental policy-controlled root-script execution on macOS 26, restores upgrades using published GitHub releases, and checks executable documentation against source and release binaries. This is a development release, not a production-support or full npm-compatibility milestone.
Root-script execution
- Runs explicitly selected root
package.jsonscripts through default-on, fail-closed policy enforcement. - Requires checked-in
tapid.tomlpermissions and explicitassurance = "restricted"for the experimental macOS 26 Restricted backend. - Preserves forwarded arguments, including
tapid run dev -- --hostname 127.0.0.1 --port 3001. - Adds optional Node runtime selection, a byte-verified private Node snapshot, an allowlist-only environment, and controlled executable lookup.
- Reports launch enforcement and completion limitations through human-readable or JSON sandbox receipts.
- Keeps dependency lifecycle scripts disabled during installation.
Upgrades
- Restores
tapid upgradeagainst the canonical GitHub Releases API and the published platform archives withSHA256SUMSverification. - Prefers signed stable-channel discovery; the GitHub fallback applies when the default discovery endpoints are unavailable, not when explicit custom endpoints fail.
- Rejects invalid received signed-discovery metadata rather than treating a validation failure as an outage and falling back to weaker verification or cached recovery.
- Validates archive contents, stages executable replacement, preserves Unix executable permissions, and supports last-known-good recovery.
- Records whether release verification used signatures, checksums, or an unknown historical provenance.
- Adds documentation for
tapid upgrade --dry-run. Clients older than 0.0.10 can be upgraded by rerunning the public installer.
Documentation validation
- Adds executable documentation contracts with isolated source and published-binary lanes. The reviewed 0.0.10 capability expectation is not a claim that its unpublished artifacts have already passed validation.
- Adds a published Unix self-upgrade journey with an independently installed destination digest/version check and persisted verification-provenance checks. Release-time same-version replacement is distinct from previous-version upgrade evidence; Windows self-upgrade is not covered by this journey.
- Retains cross-platform package-installation smoke coverage. Actual 0.0.10 public results are a post-publication release gate, not inferred from source tests.
- Corrects outdated upgrade availability statements in the README, CLI documentation, release runbook, and threat model.
Limitations
- Native sandbox execution is experimental on macOS 26 and relies on deprecated/private Seatbelt interfaces. Support is behaviorally probed and unavailable required restrictions fail before target execution.
- Restricted does not guarantee complete descendant ownership or cleanup. Detached descendants can survive; process-group cleanup is best effort. Retained private runtime snapshots may consume temporary storage until safe host cleanup.
- ManagedTree, configured timeout/output/process/memory limits, and native Linux/Windows containment remain unsupported. No unsandboxed fallback or
--no-sandboxescape is implemented. network = truepermits unrestricted networking. Forwarded hostname and port arguments are application settings, not network policy enforcement.- GitHub archives and their checksums share the same provider trust boundary. The published release path provides integrity checking, not independent release authentication, platform code signing, or release provenance verification.
- Existing npm compatibility and package-management limitations remain; this release does not add workspaces, private-registry authentication, or dependency lifecycle-script approval.
Changed package versions
| Package | Version |
|---|---|
tapid-release-client |
0.0.3 |
tapid-runner |
0.0.4 |
tapid |
0.0.10 |
The release-client version changes because its public release-state model now records verification provenance and Fetcher requires an explicit typed fetch_metadata_with_limit implementation. Existing library consumers must implement that method when upgrading from 0.0.2; rejected responses must not be classified as fetch outages. The CLI dependency requirement selects the new version. Unchanged supporting crates retain their existing versions.
v0.0.9
Tapid 0.0.9 release notes
Tapid 0.0.9 makes the supported installation path and workspace package documentation easier to discover and prepares every changed crate for an independently versioned crates.io release.
Installation and documentation
- Promotes the public
tapid.devshell and PowerShell installers as the primary installation path. - Adds CI, crates.io version and download, Docs.rs, license, and Rust 1.88+ badges to the root README and every crate README.
- Adds the missing
tapid-release-clientREADME and replaces outdated scaffold and platform-verification descriptions. - Keeps current limitations explicit: Tapid remains a development release and the checksum and archive share the same GitHub trust boundary.
Crates.io publication
- Considers every publishable workspace package instead of only the dependency closure reachable from
tapid. - Skips exact package versions that already exist on crates.io.
- Publishes missing versions in dependency order and publishes
tapidlast. - Rejects publishable packages that depend on an unpublishable workspace runtime dependency unless that exact dependency version already exists on crates.io.
Package versions
| Package | Version |
|---|---|
tapid-archive |
0.0.4 |
tapid-attestations |
0.0.3 |
tapid-core |
0.0.5 |
tapid-linker |
0.0.5 |
tapid-lockfile |
0.0.9 |
tapid-manifest |
0.0.7 |
tapid-policy |
0.0.3 |
tapid-protocol |
0.0.3 |
tapid-publish |
0.0.3 |
tapid-registry-client |
0.0.5 |
tapid-release-client |
0.0.2 |
tapid-resolver |
0.0.5 |
tapid-runner |
0.0.3 |
tapid-signatures |
0.0.3 |
tapid-store |
0.0.5 |
tapid-test-support |
0.0.2 |
tapid-transparency |
0.0.3 |
tapid |
0.0.9 |
tapid-protocol 0.0.3 and tapid-publish 0.0.3 were already assigned but not published. This release retains those versions and publishes their current packaged contents rather than incrementing them again.
v0.0.8
Tapid 0.0.8 release notes
Tapid 0.0.8 introduces a simpler GitHub-native release process and strengthens installation safety across supported platforms.
Release distribution
- Builds native archives for x86-64 and Arm64 on Linux, macOS, and Windows.
- Publishes deterministic SHA-256 checksums alongside the six archives.
- Creates a draft GitHub release for explicit review before publication.
- Triggers public installation and binary-execution smoke tests on Ubuntu, macOS, and Windows after publication.
Installer safety
- Enforces bounded HTTPS downloads and conservative archive and executable size limits for stable archive installation.
- Verifies checksums before extraction and constrains archives to one expected executable.
- Stages installation before replacing an existing binary and preserves recoverability on failure.
- Handles single-member Windows release archives consistently.
- Rejects unsafe or ambiguous installation destinations, including drive-relative Windows paths.
Upgrade behavior
The incomplete tapid upgrade command has been removed. Upgrade by rerunning the public installer with the desired immutable release version. Authenticated self-update can be reconsidered when its trust and recovery model is complete.
Tapid v0.0.7
What's Changed
- fix: reject symlinked managed ownership markers by @doug-fostery in #43
- fix: escape apostrophes in Windows PowerShell shims by @doug-fostery in #45
- fix(cli): preserve Windows child exit codes by @doug-fostery in #46
- fix: prevent caret range upper-bound overflow by @doug-fostery in #47
- fix(manifest): accept npm registry prefixes by @doug-fostery in #50
- fix: follow stable channel manifest indexes by @doug-fostery in #60
- fix: make bootstrap Ed25519 verification portable by @doug-fostery in #62
- fix(cli): persist upgrade state after activation by @doug-fostery in #61
- fix(lockfile): canonicalize root manifest digests by @doug-fostery in #51
- refactor: adopt modular monolith architecture by @arvid-berndtsson in #64
- fix: align installers with published release manifest by @doug-fostery in #59
- fix(resolver): support npm major-only caret ranges by @arvid-berndtsson in #70
- fix(npm): skip prerelease metadata for stable resolution by @arvid-berndtsson in #71
- fix(install): materialize cyclic dependency graphs by @doug-fostery in #65
- fix(manifest): preserve unknown package.json fields by @doug-fostery in #63
- fix: preserve hyphenated platform contexts by @doug-fostery in #66
- fix(install): complete real npm dependency flow by @arvid-berndtsson in #83
- fix(release): publish every installer platform by @arvid-berndtsson in #107
- fix(resolver): support npm partial version ranges by @arvid-berndtsson in #110
Full Changelog: v0.0.6...v0.0.7
Tapid v0.0.5
Tapid v0.0.5 is the first release of the npm-compatible consumer workflow.
Included:
- Deterministic npm dependency resolution and tapid.lock replay
- SHA-512 integrity verification and safe archive extraction
- Content-addressed package storage
- Deterministic node_modules materialization and executable shims
- Explicit root-script execution through tapid run
- Lifecycle scripts disabled during installation
- Linux, macOS, and Windows CI validation
Published crates:
- tapid-core 0.0.2
- tapid-manifest 0.0.3
- tapid-archive 0.0.2
- tapid-linker 0.0.2
- tapid-lockfile 0.0.4
- tapid-registry-client 0.0.2
- tapid-resolver 0.0.2
- tapid-store 0.0.2
- tapid 0.0.5
Known limitations are documented in docs/compatibility.md and docs/threat-model.md.