LuaRocks¶
- ID
luarocks- Links
- Upstream stars
⭐ 3,736
- Last commit
2026-08-16
- Version requirement
>= 3.9.1
- Platforms
🅱️ BSD · 🐧 Linux · 🍎 macOS · ⨂ Unix · 🪟 Windows
- Operations
installed·outdated·search·install·upgrade·upgrade_all·remove- purl types
pkg:luarocks/- CLI name
luarocks- Every call
luarocks --no-project <command>- Issues and PRs
- Source
LuaRocks, the package manager for Lua modules.
A package is a rock, identified by the bare name every listing prints. Its
version carries a packaging revision after a dash (3.1.2-0), kept verbatim
because that is the form luarocks install accepts back.
Caution
The listing reports every configured tree at once, while install and
remove act on the default tree only: removing a rock that lives in
another tree fails and names the tree it searched.
What mpm adds to luarocks¶
Through mpm, luarocks gains:
a one-command
upgrade --allthat refreshes every outdated package in a single run--exactand--extendedsearch, to narrow to exact names or match descriptions
Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover luarocks alongside every other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.
Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.
Your luarocks commands, in mpm¶
You already know luarocks: each operation maps one-to-one onto mpm, in an interface shared by every manager.
To… |
With |
With |
|---|---|---|
List what’s installed |
|
|
List outdated packages |
|
|
Search for a package |
|
|
Install a package |
|
|
Upgrade one package |
|
|
Upgrade everything |
— |
|
Remove a package |
|
|
Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.
Operations¶
Operation |
Supported |
Notes |
|---|---|---|
|
✅ |
A rock can be held at several versions in one tree; the listing reports one entry per rock. |
|
✅ |
|
|
||
|
✅ |
Results are reduced to one entry per rock, the tool printing one row per version and per form. Exact and extended search backfilled by |
|
✅ |
|
|
✅ |
|
|
✅ |
No native |
|
✅ |
|
|
❌ |
Nothing refreshes the manifest without also downloading. |
|
❌ |
The |
|
Configuration¶
Ignore
luarockson thempmCLI by passing the--no-luarocksoption.Ignore it for every run in your configuration:
[mpm] luarocks = false
Raise the timeout of all
luarockscalls:[mpm.overrides.luarocks] timeout = 900
Run
mpm config-template luarocksto print all overridable settings for your configuration file:[mpm.overrides.luarocks] cli_names = [ "luarocks", ] cli_search_path = [] dry_run = false ignore_auto_updates = true plan = false post_args = [] pre_args = [ "--no-project", ] pre_cmds = [] requirement = ">=3.9.1" stop_on_error = false unmaintained = false version_cli_options = [ "--version", ] version_regexes = [ "luarocks(?:\\.exe)?[ \\t]+(?P<version>\\d+\\.\\d+(?:\\.\\d+)?)", ]
The arguments and environment variables listed in the box atop this page are forced on every luarocks call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.
Recipes¶
A few jobs you would otherwise script around luarocks, one mpm command each:
Snapshot and clone a machine:
mpm --luarocks dump luarocks.toml, thenmpm restore luarocks.tomlon the next one.Export a compliance SBOM:
mpm --luarocks sbom(CycloneDX by default,--spdxfor SPDX).
Privilege escalation¶
mpm runs this manager as the current user and never prepends sudo by default. Flip the policy for its privileged operations with --sudo or the per-manager sudo override.
None of its operations is privileged.
See privilege escalation for the full policy.
Cooldown¶
State of LuaRocks’s release-age gating, from the cooldown support table:
Status: ❌ None
A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:
Registry: LuaRocks (
pkg:luarocks)Retraction: Deletion, not retraction: luarocks.org is the single host and its site application exposes owner and administrator delete paths (
modules.moon), with no yank or unlist concept, so a withdrawn version simply stops existing in the manifestPublish date: ❌ the manifest the client downloads maps module to version to
archand carries no timestamp of any kind, so a release-age gate would have nothing client-side to filter on
With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.
Reference traces¶
A collection of raw native outputs captured from the manager’s own CLI and recorded in the manager source. If you know LuaRocks well and a transcript below looks wrong, or a newer release changed its output format, report it.
$ luarocks --no-project list --porcelain
inspect 3.1.2-0 installed /Users/kde/.luarocks/lib/luarocks/rocks-5.5
say 1.4.1-3 installed /Users/kde/.luarocks/lib/luarocks/rocks-5.5
$ luarocks --no-project list --outdated --porcelain
inspect 3.1.2-0 3.1.3-0 https://luarocks.org
Version check¶
The version is probed by running:
$ luarocks --version
/opt/homebrew/bin/luarocks 3.13.0
LuaRocks main command-line interface
and extracted with:
r"luarocks(?:\.exe)?[ \t]+(?P<version>\d+\.\d+(?:\.\d+)?)"
Upstream project¶
Metrics |
|
|---|---|
Activity |
|
Popularity |
|
Metadata |
|
Changelog¶
8.0.0(2026-09-20)Add the LuaRocks package manager with
installed,outdated,search,install,upgradeandremovesupport, every call forced--no-projectso the inventory answers for the machine.