🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

@abdoknbgit/tau-installer

Package Overview
Dependencies
Maintainers
1
Versions
4
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@abdoknbgit/tau-installer

Install Tau globally with its reviewed npm lifecycle scripts allowed for this install only.

latest
Source
npmnpm
Version
0.1.3
Version published
Maintainers
1
Created
Source

Tau Installer

@abdoknbgit/tau-installer installs Tau globally. On npm 11.16 and newer, it allows only Tau's reviewed npm lifecycle scripts for that single install command. Older npm versions use npm's normal lifecycle-script behavior because they do not support the command-scoped policy.

Node.js 20.18.1 or newer is required.

Install or update to the latest Tau

npx -y @abdoknbgit/tau-installer@latest

Install an exact Tau version

Tau's updater can pin the release it already selected:

npx -y @abdoknbgit/tau-installer@latest --tau-version 0.92.15

--tau-version accepts an exact semantic version only. Tags and ranges such as latest, ^0.92.15, and 0.92.x are rejected.

Inspect without installing

npx -y @abdoknbgit/tau-installer@latest --dry-run

The installer has no dependencies and no lifecycle scripts of its own. It runs the invoking npm CLI with shell: false. On npm 11.16 and newer, it passes the reviewed list through a command-line --allow-scripts option. It never runs npm config set and never changes the user's persistent npm configuration.

For this command only, the installer also disables inherited ignore-scripts and dangerously-allow-all-scripts settings, disables inherited npm dry-run and package-lock-only modes, forces executable bin links, includes supported optional dependencies, and, where supported, enables strict script policy. On npm 11.16 and newer, required reviewed scripts can run while an unreviewed dependency script stops the install.

The installer checks the invoking npm version first. npm 11.16 and newer receive the command-only --allow-scripts list. Older npm versions omit that unsupported option because they run lifecycle scripts normally.

Tau's release tests derive the reviewed list from package-lock.json and fail when a production dependency adds or removes an install script. This keeps the installer policy explicit without changing users' persistent npm configuration.

Keywords

tau

FAQs

Package last updated on 17 Jul 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts