Skip to content

About LimeTip

I'm Arvid Berndtsson, the founder of LimeTip. We're building Tapid to give developers and coding agents more control over dependency installation.

The top half of Arvid Berndtsson in front of a green brick wall

Why LimeTip is building Tapid

The Shai-Hulud worm was the reason Tapid began. Compromised npm packages ran malicious code during installation, stole credentials, and used them to infect more packages. The attack showed how a routine development step could expose a developer's machine and the credentials stored on it. Read GitHub's account of the attack.

Installing a dependency is a decision to bring someone else's code into your software. Developers need to know which packages entered a project and whether installation ran any of their code. Coding agents can make those changes in seconds, but the team shipping the software still has to review and maintain the result. Tapid gives both developers and agents the same controlled installation path.

LimeTip's products

LimeTip began in 2024 with VAT validation. Tapid is now the company's development focus, addressing the risks around software dependencies. VAT Validation remains available as a separate product.

Tapid

A free package manager for JavaScript and TypeScript. It checks supported downloads against registry checksums, records exact dependencies, and leaves dependency install scripts disabled.

VAT Validation

An app and API for checking European VAT numbers and retrieving company details where available. Use it for individual checks or integrate it into your software.

The free Tapid CLI is available today. It supports a limited set of npm-compatible installation workflows. The product page and documentation explain that scope so you can assess whether it fits your project before adopting it.

The decisions behind Tapid

Make dependency changes reviewable

An installation should leave a record of what changed. Tapid records exact package versions and dependency relationships in tapid.lock. Keep that record with the project so dependency updates have something concrete to review and later installations can reuse the same inputs.

Treat install scripts as code execution

A package can run code before you import it into an application. Dependency lifecycle scripts are one way that happens. Tapid leaves those scripts disabled during installation, giving developers a boundary between downloading a dependency and executing its setup code.

Use the same controls for coding agents

A package added by an agent still becomes part of the software a team ships. Tapid gives agents the same CLI workflow developers use. The resulting dependency record lets people inspect the installation instead of relying only on the agent's description of what it changed.

Separate integrity from code safety

Matching a registry checksum confirms that a download matches the registry's record. A malicious package can match that checksum too. LimeTip is developing AI scanning to examine dependency code for signs of malicious behavior. That scanning is not available in the current CLI.

Contributors are helping build Tapid

Tapid now has volunteer contributors helping with the project on GitHub. Thank you to everyone who has taken the time to contribute. You can follow development, browse the work in progress, or get involved through the repository.

Explore Tapid on GitHub

FAQ

What is LimeTip?

LimeTip AB is a Swedish limited company founded by Arvid Berndtsson and registered in May 2024. It develops Tapid and operates VAT Validation.

What is LimeTip focused on now?

Tapid is the current development focus. Work covers dependency installation and the planned scanning of malicious dependency code. The Tapid product page separates what the CLI supports today from what is still in development.

Is VAT Validation still available?

Yes. VAT Validation remains available through its app and API. You receive 250 free credits for a one-time product test. Ongoing use requires a paid subscription with monthly credits.

How can I contact LimeTip?

Use the contact page for product questions or feedback. For support, include the command or request you ran and the result you received, so the issue can be reproduced.

Start with Tapid

If you or a coding agent are adding dependencies to a project, explore how Tapid handles installation. The product page explains its current checks, the dependency record it creates, and the workflows it supports.

A person standing in front of a doormat that says 'Welcome'
©
Photo by Andrew Neel•Unsplash

Try the free CLI

Follow the installation guide to get started. For questions about using Tapid in your project, or about VAT Validation, contact LimeTip.