@meredian-labs/latchpm
v0.1.2
Published
A safer npm install wrapper that audits npm packages before installation.
Downloads
23
Maintainers
Readme
latchpm
latchpm is a narrow local safer npm workflow wrapper.
It audits packages before installation, shows pre-install reports, evaluates local policy, and only then delegates to npm.
latchpm is not a full npm replacement. It is the install-side companion to latchx:
latchx: audit before runlatchpm: audit before install
Package Install Flow
1. Parse the package spec.
2. Resolve npm package metadata through latch-core.
3. Resolve the exact inspected version.
4. Audit the package through the latch-core pipeline.
5. Show a pre-install report.
6. Evaluate local policy.
7. Ask for a decision.
8. Run npm install only after approval.The installed version must match the inspected version.
Usage
Audit without installing:
latchpm audit zod
latchpm inspect zodInstall after approval:
latchpm install zod
latchpm add zodThe interactive decision screen offers:
- install normally
- install with
--ignore-scripts - deny
- view findings
- print JSON
Non-interactive install:
latchpm install zod --yes
latchpm install zod --yes --ignore-scriptsProject install audits direct dependencies from package.json before running npm install:
latchpm install
latchpm install --yesThis version audits direct dependencies only. Transitive dependency auditing is not implemented yet.
Run npm ci after auditing direct dependencies from package.json and package-lock.json when available:
latchpm ci
latchpm ci --yesRemove packages:
latchpm remove zod
latchpm uninstall zod
latchpm remove zod --yesRemove/uninstall does not run an audit. It shows the npm command before delegating to npm uninstall.
Run scripts:
latchpm run test
latchpm run test -- --watch
latchpm run test --yeslatchpm run reads package.json, shows the script command, asks for approval unless --yes is used, then delegates to npm run.
Explicit npm passthrough:
latchpm npm view react versionThis is an escape hatch for unsupported npm commands. No Latch audit is applied.
CI And Agent Usage
CI mode is deterministic and does not prompt.
latchpm audit zod --json --ci --policy ./latch.policy.jsonlatchpm install <package> --json --ci reports only. It does not install unless --yes is present.
latchpm install zod --json --ci
latchpm install zod --ci --yes
latchpm install zod --ci --yes --ignore-scripts
latchpm install --json --ci
latchpm install --ci --yes
latchpm ci --json --ci
latchpm ci --ci --yesExit codes:
0: allowed1: general error2: denied by user3: denied by policy4: package not found5: registry/network error6: integrity verification failed7: analysis failed
Policy Examples
Strict policy:
{
"minScore": 85,
"denyCritical": true,
"denyHigh": true,
"denyLifecycleScripts": true,
"denyNewLifecycleScripts": true,
"denyLikelyObfuscation": true,
"denyIntegrityMissing": true,
"allowedRegistries": ["https://registry.npmjs.org"]
}Relaxed policy with trusted scope:
{
"minScore": 60,
"denyCritical": true,
"trustedScopes": ["@your-org"],
"allowedRegistries": ["https://registry.npmjs.org"]
}See examples/policies/ in the repository for ready-to-use policy files.
Cache And Doctor
latchpm doctor
latchpm cache status
latchpm cache path
latchpm cache clearlatchpm uses the shared Latch cache under:
~/.latch/cacheJSON Report Metadata
Install reports include metadata for future Cloud use:
{
"tool": "latchpm",
"action": "install",
"install": {
"requestedSpec": "zod",
"resolvedInstallSpec": "[email protected]",
"installMode": "report-only"
}
}Project install and ci reports include:
{
"tool": "latchpm",
"action": "install",
"auditScope": {
"directDependencies": 1,
"transitiveAudit": false,
"note": "This version audits direct dependencies only. Transitive dependency auditing is not implemented yet."
}
}installMode can be:
normalignore-scriptsreport-onlydenied
Limitations
- No Cloud dependency.
- No registry/proxy.
- No marketplace.
- No sandboxing.
- No full npm replacement.
- No full project-level install auditing.
- Project
installandciaudit direct dependencies only. - Remove, run, and explicit npm passthrough commands do not run package audits.
- Static scanning can miss behavior and can produce false positives.
Release
Release validation:
npm install
npm run typecheck
npm run build
npm test
npm pack -w @meredian-labs/latchpm --dry-run