# Install lavamoat

lavamoat is a NodeJS runtime where modules are defined in [SES][SesGithub] Compartments. It aims to reduce the risk of malicious code in the app dependency graph, known as "software supply chain attacks". Version 11.1.3 via npm; verified 2026-05-28.

## Install

```sh
sudo av install npm:lavamoat
```

Additional install commands:

### Portable and language managers

- npm (100%):

```sh
npm install -g lavamoat
```

  Evidence: local npm package metadata

## Package Facts

- **Package key:** npm:lavamoat
- **Package manager:** npm
- **Package manager URL:** <https://www.npmjs.com/package/lavamoat>
- **Version:** 11.1.3
- **Source summary:** lavamoat is a NodeJS runtime where modules are defined in [SES][SesGithub] Compartments. It aims to reduce the risk of malicious code in the app dependency graph, known as "software supply chain attacks".
- **Homepage:** <https://github.com/LavaMoat/lavamoat#readme>
- **Repository:** <https://github.com/LavaMoat/lavamoat>
- **Upstream docs:** <https://github.com/LavaMoat/lavamoat#readme>
- **License:** MIT
- **Source archive:** <https://registry.npmjs.org/lavamoat/-/lavamoat-11.1.3.tgz>
- **Issue tracker:** <https://github.com/LavaMoat/lavamoat/issues>
- **Published:** 2026-05-28T21:25:39.870Z
- **Last updated:** 2026-05-28T21:25:39.870Z
- **Generated:** 2026-06-10T07:18:26+00:00

## Executables

- lavamoat (cli)
- lavamoat-run-command (cli)
- lavamoat (alias)

## Dependencies

- @babel/code-frame
- @babel/highlight
- @lavamoat/aa
- bindings
- corepack
- htmlescape
- lavamoat-core
- lavamoat-tofu
- node-gyp-build
- resolve
- yargs

## Install Behavior

- Post-install hook: not defined
- Bottle: not available

## Freshness

- Page generated: 2026-06-10
- Package-manager version: 11.1.3
- Package-manager updated: 2026-05-28
- Local data status: ok
- Upstream repository: https://github.com/LavaMoat/lavamoat
- info: No cached GitHub release or tag data was available.

## Sicherheitshinweise

Für lavamoat wurde kein passendes lokales Secret-Handling-Manifest gefunden. Nucleus-Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.


## Source Database Details

- **Source Database:** npm registry
- **Dist Tags:** Latest: 11.1.3
- **Version Count:** 99
- **Maintainers:** kumavis, naugtur, boneskull
- **Author:** kumavis
- **Publisher:** GitHub Actions
- **Engines:** Node: ^20.19.0 || ^22.5.1 || ^24.0.0
- **Integrity:** sha512-oemeR9jSZ96Avyg+5ina9qUr7M72IhHwGntTdr5S3AFA2fjQUJVgsgmheFMg+B2iwunBfSmQF4xeaymA3ItkMQ==
- **Shasum:** a1d08f61a4dfe8077d6987630fd36618bf1e6315
- **Unpacked Size:** 82,976
- **File Count:** 0
- **Created At:** 2020-03-27T04:53:19.858Z
- **Latest Published At:** 2026-05-28T21:25:39.870Z
- **Modified At:** 2026-05-28T21:25:40.154Z


## Related Links

- [Language runtime packages](https://www.automicvault.com/de/pkg/language-runtime-packages/) - Matched curated package taxonomy and local package facts.
- [lavamoat-core](https://www.automicvault.com/de/pkg/npm/lavamoat-core/) - Package names and metadata indicate a similar tool family. Shared terms: babel, core, lavamoat, lavamoat-core, lavamoat-tofu.
- [@vercel/nft](https://www.automicvault.com/de/pkg/npm/vercel-nft/) - Both packages touch the same language runtime or ecosystem. Shared terms: are, bindings, build, gyp, modules.
- [gitnexus](https://www.automicvault.com/de/pkg/npm/gitnexus/) - Both packages touch the same language runtime or ecosystem. Shared terms: build, code, core, graph, gyp.

## Sources

- Nucleus package database
- package-page enrichment
- package version freshness
- package relationship graph
- cross-ecosystem install command graph
