Automic VaultAutomic Vault

npm / rank 786

Install lavamoat

lavamoat is a NodeJS runtime where modules are defined in [SES][SesGithub] Compartments. It aims to reduce the risk of malicious code in the app dependency graph, known as "software supply chain attacks". Version 11.1.3 via npm; verified 2026-05-28.

install

Install with Automic Vault

Automic Vault
sudo av install npm:lavamoat

Portable and language managers

npmverified · 100%
npm install -g lavamoat

local npm package metadata

Platform notes

  • No package-specific platform notes were present.

overview

Package summary

lavamoat is a NodeJS runtime where modules are defined in [SES][SesGithub] Compartments. It aims to reduce the risk of malicious code in the app dependency graph, known as "software supply chain attacks".

Commands and aliases

  • lavamoat

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for lavamoat. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No npm postinstall script is recorded in package metadata.
  • No Homebrew bottle metadata was recorded.
  • Installs with 11 runtime dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
lavamoatcliglobal executable
lavamoat-run-commandcliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-06-10
manager version11.1.3
manager updated2026-05-28
local dataok
upstreamnot checked
latest detectednot detected

https://github.com/LavaMoat/lavamoat

install metadata

Package metadata

Package keynpm:lavamoat
Version11.1.3
Package managernpm
Package manager pagehttps://www.npmjs.com/package/lavamoat
Homepagehttps://github.com/LavaMoat/lavamoat#readme
Repositoryhttps://github.com/LavaMoat/lavamoat
Upstream docshttps://github.com/LavaMoat/lavamoat#readme
LicenseMIT
Source archivehttps://registry.npmjs.org/lavamoat/-/lavamoat-11.1.3.tgz
Issue trackerhttps://github.com/LavaMoat/lavamoat/issues
Last updated2026-05-28T21:25:39.870Z
Published2026-05-28T21:25:39.870Z
Dependencies@babel/code-frame, @babel/highlight, @lavamoat/aa, bindings, corepack, htmlescape, lavamoat-core, lavamoat-tofu, node-gyp-build, resolve, yargs
Bottlenot recorded
npm postinstallnot defined
Servicenone declared

registry facts

Source database details

Source Databasenpm registry
Dist Tags
Version Count99
Maintainers
  • kumavis
  • naugtur
  • boneskull
Authorkumavis
PublisherGitHub Actions
Engines
Integritysha512-oemeR9jSZ96Avyg+5ina9qUr7M72IhHwGntTdr5S3AFA2fjQUJVgsgmheFMg+B2iwunBfSmQF4xeaymA3ItkMQ==
Shasuma1d08f61a4dfe8077d6987630fd36618bf1e6315
Unpacked Size82,976
File Count0
Created At2020-03-27T04:53:19.858Z
Latest Published At2026-05-28T21:25:39.870Z
Modified At2026-05-28T21:25:40.154Z

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Nucleus package database
  • cross-ecosystem install command graph
  • package relationship graph
  • package version freshness
  • package-page enrichment