AcquiCode diligence
Free · runs where your code lives

The AcquiCode CLI

The same analysis engine the hosted service runs, as a single file. It reads your repository with git, writes the dossier to disk, and sends nothing anywhere unless you ask it to.

Version 0.1.0, rules 2026.09.1. Requires Node.js 22 or newer and git.

Install

curl -fsSL https://acquicode.infinityore.com/cli/acquicode.mjs -o acquicode.mjs
echo "e9627db7241f47056d99e8af376dba29ec480b1642e464c127bfee10dd395c07  acquicode.mjs" \
  | shasum -a 256 -c -

The checksum confirms the download is intact. acquicode.mjs.sha256

Analyse a repository

cd your-repo
# writes acquicode-out/dossier.{html,json} and a CycloneDX SBOM
node acquicode.mjs scan .
open acquicode-out/dossier.html

Add --osv to check public dependencies against OSV.dev (sends package names and versions only). Declarations live in acquicode.yml in the repository; see the sample dossier for what the output covers.

Sign it, and let anyone verify it

node acquicode.mjs keygen --out .acquicode-keys
node acquicode.mjs scan . \
  --sign-key .acquicode-keys/acquicode-signing.key.pem

# anyone with the same commits and your public key:
node acquicode.mjs verify acquicode-out/dossier.json \
  --envelope acquicode-out/dossier.dsse.json \
  --key .acquicode-keys/acquicode-signing.pub.pem \
  --reproduce .

Reproduction re-runs the analysis and must produce the identical digest. Signed dossiers can also be checked on the verify page.

Deliver it without sharing code

node acquicode.mjs push acquicode-out/dossier.json \
  --server https://acquicode.infinityore.com --token "$ACQUICODE_TOKEN" \
  --envelope acquicode-out/dossier.dsse.json \
  --key .acquicode-keys/acquicode-signing.pub.pem

The token comes from your workspace settings, or from a buyer's dossier request. Tokens can only upload dossiers; they cannot read anything.

In CI (GitHub Actions)

- uses: actions/checkout@v5
  with: { fetch-depth: 0 }  # ownership and AI evidence need history
- run: git fetch origin 'refs/notes/*:refs/notes/*' || true
- run: |
    curl -fsSL https://acquicode.infinityore.com/cli/acquicode.mjs -o "$RUNNER_TEMP/acquicode.mjs"
    echo "e9627db7241f47056d99e8af376dba29ec480b1642e464c127bfee10dd395c07  $RUNNER_TEMP/acquicode.mjs" \
      | sha256sum -c -  # pinned: update it when you upgrade
    node "$RUNNER_TEMP/acquicode.mjs" scan . --osv --fail-on blocked
- uses: actions/upload-artifact@v4
  if: always()
  with: { name: acquicode-dossier, path: acquicode-out }

--fail-on blocked fails the job when the dossier is BLOCKED (a live credential, for example), so the issue is caught before a buyer sees it.