Portable and language managers
npm install -g lavamoatlocal npm package metadata
npm / rank 2092
lavamoat is a NodeJS runtime where modules are defined in [SES][SesGithub] Compartments. It aims to reduce the risk of malicious code in the app dependency graph, known as "software supply chain attacks". Version 11.1.4 via npm; verified 2026-06-25.
install
npm install -g lavamoatlocal npm package metadata
overview
lavamoat is a NodeJS runtime where modules are defined in [SES][SesGithub] Compartments. It aims to reduce the risk of malicious code in the app dependency graph, known as "software supply chain attacks".
security posture
No matching local secret-handling manifest was found for lavamoat. Nucleus package metadata is still published here so future coverage has a stable package URL.
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
executables
| Command | Kind | Exposure | Note |
|---|---|---|---|
lavamoat | executable | indexed executable | Discovered from the local executable index. |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
install metadata
| Package key | npm:lavamoat |
|---|---|
| Version | 11.1.4 |
| Package manager | npm |
| Homepage | https://github.com/LavaMoat/lavamoat#readme |
| Last updated | 2026-06-25T12:03:12.741Z |
| Pulse | updated |
| Bottle | not recorded |
| Service | none declared |
source trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.