The AcquiCode CLI
The same analysis engine the hosted service runs, as a single file. It reads your repository with git, writes the dossier to disk, and sends nothing anywhere unless you ask it to.
Version 0.1.0, rules 2026.09.1. Requires Node.js 22 or newer and git.
Install
curl -fsSL https://acquicode.infinityore.com/cli/acquicode.mjs -o acquicode.mjs echo "e9627db7241f47056d99e8af376dba29ec480b1642e464c127bfee10dd395c07 acquicode.mjs" \ | shasum -a 256 -c -
The checksum confirms the download is intact. acquicode.mjs.sha256
Analyse a repository
cd your-repo
# writes acquicode-out/dossier.{html,json} and a CycloneDX SBOM
node acquicode.mjs scan .
open acquicode-out/dossier.htmlAdd --osv to check public dependencies against OSV.dev (sends package names and versions only). Declarations live in acquicode.yml in the repository; see the sample dossier for what the output covers.
Sign it, and let anyone verify it
node acquicode.mjs keygen --out .acquicode-keys node acquicode.mjs scan . \ --sign-key .acquicode-keys/acquicode-signing.key.pem # anyone with the same commits and your public key: node acquicode.mjs verify acquicode-out/dossier.json \ --envelope acquicode-out/dossier.dsse.json \ --key .acquicode-keys/acquicode-signing.pub.pem \ --reproduce .
Reproduction re-runs the analysis and must produce the identical digest. Signed dossiers can also be checked on the verify page.
Deliver it without sharing code
node acquicode.mjs push acquicode-out/dossier.json \ --server https://acquicode.infinityore.com --token "$ACQUICODE_TOKEN" \ --envelope acquicode-out/dossier.dsse.json \ --key .acquicode-keys/acquicode-signing.pub.pem
The token comes from your workspace settings, or from a buyer's dossier request. Tokens can only upload dossiers; they cannot read anything.
In CI (GitHub Actions)
- uses: actions/checkout@v5
with: { fetch-depth: 0 } # ownership and AI evidence need history
- run: git fetch origin 'refs/notes/*:refs/notes/*' || true
- run: |
curl -fsSL https://acquicode.infinityore.com/cli/acquicode.mjs -o "$RUNNER_TEMP/acquicode.mjs"
echo "e9627db7241f47056d99e8af376dba29ec480b1642e464c127bfee10dd395c07 $RUNNER_TEMP/acquicode.mjs" \
| sha256sum -c - # pinned: update it when you upgrade
node "$RUNNER_TEMP/acquicode.mjs" scan . --osv --fail-on blocked
- uses: actions/upload-artifact@v4
if: always()
with: { name: acquicode-dossier, path: acquicode-out }--fail-on blocked fails the job when the dossier is BLOCKED (a live credential, for example), so the issue is caught before a buyer sees it.