# Install retire

Retire is a tool for detecting use of vulnerable libraries. Version 5.4.3 via npm; verified 2026-05-26.

## Install

```sh
sudo av install npm:retire
```

Additional install commands:

### Portable and language managers

- npm (100%):

```sh
npm install -g retire
```

  Evidence: local npm package metadata

## Package Facts

- **Package key:** npm:retire
- **Package manager:** npm
- **Package manager URL:** <https://www.npmjs.com/package/retire>
- **Version:** 5.4.3
- **Source summary:** Retire is a tool for detecting use of vulnerable libraries
- **Homepage:** <https://github.com/RetireJS/retire.js#readme>
- **Repository:** <https://github.com/RetireJS/retire.js>
- **Upstream docs:** <https://github.com/RetireJS/retire.js#readme>
- **License:** Apache-2.0
- **Source archive:** <https://registry.npmjs.org/retire/-/retire-5.4.3.tgz>
- **Issue tracker:** <https://github.com/RetireJS/retire.js/issues>
- **Published:** 2026-05-26T09:14:27.191Z
- **Last updated:** 2026-05-26T09:14:27.191Z
- **Generated:** 2026-06-10T07:18:26+00:00

## Executables

- retire (cli)

## Dependencies

- ansi-colors
- astronomical
- commander
- proxy-agent
- walkdir
- zod

## Build Dependencies

- @types/chai
- @types/jest
- @types/node
- @types/uuid
- @typescript-eslint/eslint-plugin
- @typescript-eslint/parser
- chai
- eslint
- eslint-config-prettier
- jsonschema
- prettier
- ts-jest
- ts-node
- typescript

## Install Behavior

- Post-install hook: not defined
- Bottle: not available

## Freshness

- Page generated: 2026-06-10
- Package-manager version: 5.4.3
- Package-manager updated: 2026-05-26
- Local data status: ok
- Upstream repository: https://github.com/RetireJS/retire.js
- info: No cached GitHub release or tag data was available.

## 安全说明

没有找到 retire 的匹配本地密钥处理 manifest。Nucleus 软件包元数据仍在此发布，以便未来覆盖拥有稳定的软件包 URL。


## Source Database Details

- **Source Database:** npm registry
- **Dist Tags:** Beta: 2.0.0-beta.13, Latest: 5.4.3
- **Version Count:** 148
- **Maintainers:** kozmic, eoftedal
- **Author:** Erlend Oftedal
- **Publisher:** GitHub Actions
- **Engines:** Node: >= 18.0.0
- **Integrity:** sha512-a+CNXfbCTC/kAQLeFxfN9/kts1NlFMo5lrjBefmFssdOJy0XYPNpRN4k63hwIhhzyzPvHziZrQHWKdJNf6Lp5g==
- **Shasum:** b5bdbe160d1bc28d588a1f77d3e23eee6a1d870e
- **Unpacked Size:** 108,509
- **File Count:** 0
- **Created At:** 2013-10-29T18:55:26.848Z
- **Latest Published At:** 2026-05-26T09:14:27.191Z
- **Modified At:** 2026-05-26T09:14:27.463Z


## Related Links

- [Developer build packages](https://www.automicvault.com/zh-hans/pkg/developer-build-tools/) - Matched curated package taxonomy and local package facts.
- [retire](https://www.automicvault.com/zh-hans/pkg/brew/retire/) - Same normalized package name appears in another local ecosystem. Shared terms: analysis, composition, detecting, libraries, retire.
- [@openapitools/openapi-generator-cli](https://www.automicvault.com/zh-hans/pkg/npm/openapitools-openapi-generator-cli/) - Local package facts share a topical domain. Shared terms: agent, commander, generator, libraries, proxy.
- [@mcp-use/cli](https://www.automicvault.com/zh-hans/pkg/npm/mcp-use-cli/) - Local package facts share a topical domain. Shared terms: commander, is, use, zod.
- [retire](https://www.automicvault.com/zh-hans/pkg/brew/retire/) - Same normalized package name exists in another local package ecosystem.

## Sources

- Nucleus package database
- package-page enrichment
- package version freshness
- package relationship graph
- cross-ecosystem install command graph
