Automic VaultAutomic Vault

brew

boa mit Homebrew, Nix installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für boa in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install boa

local Homebrew formula metadata

Linux

Nixverifiziert · 92%
nix profile install nixpkgs#boa

nixpkgs package indexes · pkgs/by-name/bo/boa/package.nix · Quelle: api.github.com

Überblick

Paketzusammenfassung

Embeddable and experimental Javascript engine written in Rust

Befehle und Aliase

  • boa

Verlauf

Projektgeschichte und Nutzung

Boa is an embeddable experimental JavaScript engine written in Rust, with a CLI and Rust crates for parsing, interpreting, and embedding ECMAScript.

Projektgeschichte

Boa began as Jason Williams's Rust JavaScript-engine experiment. The Boa about page says it was introduced at JSConf EU 2019, and the JSConf EU talk page describes Williams building an engine from scratch in Rust during the previous year.

The project grew into the boa-dev organization and a set of crates centered on boa_engine. Its README describes an experimental lexer, parser, and interpreter that tracks the evolving ECMAScript specification.

Adoptionsgeschichte

Boa's adoption is mostly developer and embedders' adoption rather than browser adoption. It is carried by Homebrew and Nix and published through Rust's crate ecosystem, where Rust programs can embed it directly.

The project's public releases and blog posts emphasize conformance progress, embeddability, WebAssembly use, and keeping pace with Test262 and ECMAScript changes.

Wie es verwendet wird

Users can run the boa CLI for experiments, but the more important use case is embedding boa_engine in Rust applications that need JavaScript evaluation without linking to V8.

Boa is also useful for language-engine work: implementers can study parser, runtime, built-in-object, and conformance work in a Rust codebase that is smaller and more approachable than production browser engines.

Warum Paket-Nerds sich dafür interessieren

Boa matters to package nerds because JavaScript engines are usually huge C++ dependencies. A Rust-native, crate-published engine changes the packaging shape for applications that only need embeddable JS semantics.

Its significance is still experimental: package users should not read the Homebrew formula as a Node.js replacement. The interesting part is the long-term Rust ecosystem bet on standards-conforming embeddable scripting.

Zeitleiste

  • 2018-2019: Jason Williams builds a JavaScript engine from scratch in Rust.
  • 2019-06: Boa is introduced at JSConf EU 2019.
  • 2021-06: Boa v0.12 is announced on the official blog.
  • 2021-09: Boa v0.13 blog post highlights embedding in Rust projects and WebAssembly use.
  • 2020s: boa-dev continues publishing boa_engine and tracking ECMAScript/Test262 conformance.

Related projects

  • V8, SpiderMonkey, and JavaScriptCore: production browser/server JavaScript engines Boa is often compared against but does not replace.
  • QuickJS, MuJS, and Kiesel: smaller embeddable JavaScript engines in adjacent niches.
  • Test262: the official ECMAScript conformance suite Boa uses as a progress target.
  • Rust crates such as boa_engine and boa_parser: the packaged Rust components behind the CLI and embedding story.

Sicherheitslage

Risikostufe: grün

narrow executable package without higher-risk signals.

Risikoklassifikator

grün Risiko · niedrig Konfidenz · appliance

Warum

  • narrow executable package without higher-risk signals

Signale

  • metadata:no-higher-risk-signals

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Build-Metadaten listen 2 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
boacliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version0.21.1
Manager aktualisiert2026-06-22
lokale DatenOK
Upstreamaktuell
neueste erkannte Versionv0.21.1

https://github.com/boa-dev/boa

  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:boa
Version0.21.1
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/boa
Homepagehttps://github.com/boa-dev/boa
Repositoryhttps://github.com/boa-dev/boa
Upstream-Dokumentationhttps://boajs.dev/docs/intro
LizenzMIT OR Unlicense
Quellarchivhttps://github.com/boa-dev/boa/archive/refs/tags/v0.21.1.tar.gz
Zuletzt aktualisiert2026-06-22T14:02:54-07:00
Pulseupdated
Build-Abhängigkeitenpkgconf, rust
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameboa
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

boa

nix profile install nixpkgs#boa
  • normalized package name match
  • Abgeglichen nach: Boa
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/bo/boa/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment