@getappz/appz-linux-arm64
v0.2.0
Published
Detect toolchains, wire up mise, and run install/build/dev/test/lint/format/doctor for any project.
Readme
Zero-config toolchains, mise, and deploy.
appz
appz detects your stack (Node, Rust, Python, ...), wires up
mise with cached, incremental tasks instead of a
hand-rolled build cache, and drives install/build/dev/test/lint/format/deploy
through one command — no config to write by hand.
- Zero-config detection — reads your project, not a config file, to know how to build it (96+ frameworks, mise tool versions, output dirs).
- mise-native, not another task runner — generates
[tools]+[tasks]withsources/outputs, so mise's own cache — not a second one — decides what to skip. - Unified deploy —
appz deploydrives each platform's own CLI (Vercel, Netlify, ...) instead of competing with them. - Built for agents too —
appz mcpexposes detect/build/deploy as MCP tools, so an AI agent can drive the same pipeline a human does.
appz init # detect toolchains, scaffold appz.jsonc + mise.toml
appz install # mise + package manager install
appz build # mise run build (skips when inputs are unchanged)
appz dev # start the dev server
appz test # run tests
appz lint # run the linter
appz format # run the formatter
appz deploy # deploy via the target platform's own CLI
appz doctor # diagnose project stack, config, and suggestions
appz mcp # stdio MCP server exposing detect/doctor/run to AI agentsInstall
Linux/macOS (downloads a prebuilt binary and verifies it against the
release's SHA256SUMS when sha256sum/shasum is available, otherwise warns
and skips; builds from source instead if run from inside a clone):
curl -fsSL https://raw.githubusercontent.com/getappz/cli/main/install.sh | shWindows, build from source (no unsigned prebuilt binary to trip an AV heuristic):
git clone https://github.com/getappz/cli
cd cli
.\install.ps1Windows, Scoop (prebuilt binary — not Authenticode-signed, so Defender/SmartScreen false-positives are possible; verify with cosign/SLSA instead, see "Verifying release binaries" below; report an issue if hit):
scoop bucket add appz https://github.com/getappz/cli
scoop install appznpm:
npm install -g @getappz/cliDocker (pin a version — latest isn't tied to a specific verifiable
release):
docker run --rm ghcr.io/getappz/cli:v0.1.0 appz --versionAny platform with Rust, no clone needed (builds from source, no checksum applicable):
cargo install --git https://github.com/getappz/cli appzUninstall (curl install only — for the others: scoop uninstall appz,
npm uninstall -g @getappz/cli, cargo uninstall appz, or remove the
Docker image):
curl -fsSL https://raw.githubusercontent.com/getappz/cli/main/install.sh | sh -s -- --uninstallVerifying release binaries
The curl installer verifies SHA-256 checksums against the release's
SHA256SUMS when sha256sum/shasum is available — enough to catch a
corrupted download, not a substituted one. Scoop verifies its manifest's own
hash field (sourced from the same SHA256SUMS); npm, Docker, and
cargo install don't consume SHA256SUMS at all. For higher-assurance
environments, verify the cryptographic signature and build provenance
before running the binary.
cosign (signing identity)
Every release archive (.tar.gz/.zip) is signed in CI using
cosign keyless signing via the
GitHub OIDC token — the certificate is issued by Fulcio and bound to this
repo's release.yml workflow, so verifiers pin to the workflow identity
instead of a long-lived key.
VERSION=v0.x.x
FILE=appz-x86_64-unknown-linux-gnu.tar.gz
curl -fL -o "$FILE" "https://github.com/getappz/cli/releases/download/${VERSION}/${FILE}"
curl -fL -o "${FILE}.cosign.bundle" "https://github.com/getappz/cli/releases/download/${VERSION}/${FILE}.cosign.bundle"
cosign verify-blob \
--bundle "${FILE}.cosign.bundle" \
--certificate-identity-regexp "^https://github\.com/getappz/cli/\.github/workflows/release\.yml@refs/tags/${VERSION}\$" \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
"$FILE"SLSA L3 provenance (build process)
cosign proves this repo's CI signed it; SLSA provenance proves how it was
built — which commit, workflow, and inputs. Releases include a
<tag>.intoto.jsonl attestation generated by the
SLSA GitHub generator.
Verify with slsa-verifier:
curl -fL -o "${VERSION}.intoto.jsonl" "https://github.com/getappz/cli/releases/download/${VERSION}/${VERSION}.intoto.jsonl"
slsa-verifier verify-artifact \
--provenance-path "${VERSION}.intoto.jsonl" \
--source-uri github.com/getappz/cli \
--source-tag "${VERSION}" \
"$FILE"MCP server
appz mcp speaks the Model Context Protocol
over stdio so AI agents can drive appz directly. Tools:
detect— JSON toolchain report for a directorydoctor— JSON diagnosis + suggestionsrun— execute a lifecycle command (install/build/test/lint/format) and return its output
Point an MCP client at appz mcp (e.g. {"command": "appz", "args": ["mcp"]}).
GitHub Action
- uses: getappz/[email protected]
with:
command: deploy # init/install/build/dev/test/lint/format/deploy/doctor
# version: latest
# working-directory: .
# args: ""appz deploy shells out to each target platform's own CLI (Vercel, Netlify,
...), so set that platform's native env vars/secrets (e.g. VERCEL_TOKEN)
directly on the step or job — the action doesn't take platform-specific
inputs.
devcontainer Feature
"features": {
"ghcr.io/getappz/cli/appz:1": {
"version": "latest",
"autoInstall": false
}
}autoInstall runs appz install once, after the workspace is created, via the
Feature's own postCreateCommand — if your own devcontainer.json also sets
postCreateCommand, both run (the Feature's first), it doesn't override
yours.
Layout
crates/appz— the CLI binarycrates/appz-core— toolchain detection,mise.tomlgeneration, and the doctor/report logicappzruns on top ofcrates/appz-deploy— theDeployProvidertrait + per-platform CLIscrates/command— shell-free process execution (arg-vector, timeouts)
Build
cargo build --release -p appz