Skip to main content
Or download a static binary for macOS, Linux or Windows from Releases.

Integrity

Every release ships SHA-256 checksums and an SPDX SBOM per archive. The npm package verifies the archive it downloads against the checksums and is published with provenance from the repository’s release workflow.

What gets installed

aspex is the front door and routes every command. It ships alongside aspex-scan, aspex-trace and aspex-attack; you never need to know which binary owns a command. Every command →

Uninstall

State Aspex writes: scan logs and environment snapshots under your user cache directory (~/Library/Caches/aspex/ on macOS, ~/.cache/aspex/ on Linux), an optional .aspex.yaml policy and .aspex.lock in your project, and the trace baseline under ~/.config/aspex/ if you learn one.