pkg.sopackage field notes

brew / rank 847

Install luarocks with Homebrew

Package manager for the Lua programming language. Version 3.13.0 via Homebrew; verified from local package data.

agent safety

Agent safety answer

luarocks manages Lua packages and can install or publish project dependencies.

Credential access

Reads environment variables, server credentials, and local package config.

Remote mutation

Can install packages and interact with package servers.

Publish/artifact risk

Can publish Lua rocks and generated package artifacts.

Recommended control

Gate upload, install scripts, and credentialed server operations.

Agent-use guidance

Allow dependency queries; require approval for package publication and secret-backed actions.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install luarocks

provider-native install command

overview

Package summary

Package manager for the Lua programming language

Commands and aliases

  • luarocks
  • luarocks-admin

history

Project history and usage

LuaRocks is the package manager and public package repository system for Lua modules. It introduced the rockspec-centered workflow that lets Lua packages declare metadata, dependencies, sources, and build rules in Lua.

Project history

The LuaRocks project describes itself as the package manager for the Lua programming language. Its repository README and wiki say it installs modules as self-contained packages called rocks and supports local and remote repositories plus multiple local rocks trees.

LuaRocks' documentation centers on the rockspec: a Lua metadata file that tells the tool how to fetch, build, and install a package. This design made LuaRocks both a package installer and a lightweight build/publishing convention for Lua modules, including modules with native C extensions.

Adoption history

LuaRocks became the default package-distribution culture for much of Lua outside application-specific ecosystems. The official site surfaces recent modules, labels, weekly download counts, root manifests, custom manifests, mirrors, and upload flows, showing that LuaRocks is both a CLI and the central package index.

The input metadata shows broad OS package coverage: LuaRocks is available through Homebrew, MacPorts, Debian, Ubuntu, Fedora, Alpine, Arch, Nix, Scoop, and Chocolatey. That matters because Lua projects often need LuaRocks before they can install testing tools, web frameworks, OpenResty libraries, or native-binding modules.

How it is used

The command-line interface is luarocks. It supports installing, building, packing, uploading, searching, showing, removing, testing, and configuring rocks, and can operate against selected servers, trees, and dependency modes.

Package authors write a rockspec, tag or publish their source, and submit or upload the rockspec. LuaRocks can build from source, make from a local checkout, pack source or binary rocks, and publish artifacts that users install without needing the original source-control tool.

Why package nerds care

LuaRocks is central package-nerd infrastructure for Lua because it defines the names, versions, build metadata, binary/source artifact formats, and repository manifests that other tools consume. It is the closest analogue to npm, RubyGems, or CPAN for Lua, but with Lua-specific details such as Lua-version-specific trees and native module paths.

It is also historically important because it works across stock Lua and LuaJIT ecosystems. That cross-runtime support, plus package-manager availability on Unix and Windows, made it the practical bootstrap path for Lua dependency management.

Timeline

  • 2000s: LuaRocks emerges as Lua's rockspec-based package manager.
  • 2010s: Development and distribution consolidate around the GitHub repository and luarocks.org.
  • 2020s: Documentation moves from the GitHub wiki into the repository docs folder.
  • 2026: GitHub lists LuaRocks 3.13.0 as the latest release, dated Jan 28, 2026.

Related projects

  • Lua is the language ecosystem LuaRocks packages target.
  • LuaJIT is a common LuaRocks runtime target and package dependency.
  • OpenResty libraries such as lua-resty modules are commonly distributed through LuaRocks.

security posture

Risk level: orange

generalized runtime or code generation signal. infrastructure mutation or orchestration signal.

Risk classifier

orange risk · medium confidence · infrastructure

Why

  • generalized runtime or code generation signal
  • infrastructure mutation or orchestration signal

Signals

  • text:package manager
  • text:programming language

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
$XDG_CONFIG_HOME/luarocks/upload_config.lua~/.config/luarocks/upload_config.lua~/.luarocks/upload_config.lua

Credential files

Credential-bearing paths to review before unattended agent runs.

Unix
$XDG_CONFIG_HOME/luarocks/upload_config.lua~/.config/luarocks/upload_config.lua~/.luarocks/upload_config.lua

executables

Installed executables

CommandKindExposureNote
luarocksexecutableindexed executableDiscovered from the local executable index.
luarocks-adminexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version3.13.0
manager updated
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:luarocks
Version3.13.0
Package managerHomebrew
Homepagehttps://luarocks.org/
Repositoryhttps://github.com/luarocks/luarocks
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • Nucleus package database
  • curated agent safety answer
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation