Direct binary downloads attached to each GitHub Release. The same binaries back the Homebrew formula; use this page if you don't want a package manager.
Examples assume version 0.1.0 — substitute the version you want.
| Platform | Asset |
|---|---|
| macOS arm64 (Apple Silicon) | darnit-0.1.0-macos-arm64 |
| Linux arm64 | darnit-0.1.0-linux-arm64 |
| Linux amd64 | darnit-0.1.0-linux-amd64 |
Intel Macs are not supported. Apple has fully transitioned to Apple Silicon; we don't build a
macos-amd64binary. If you're on an Intel Mac, usepip install/pipxor run the Linux amd64 container image under emulation.
# macOS arm64
curl -LO https://github.com/kusari-oss/darnit/releases/download/v0.1.0/darnit-0.1.0-macos-arm64
chmod +x darnit-0.1.0-macos-arm64
sudo mv darnit-0.1.0-macos-arm64 /usr/local/bin/darnit
darnit --versionSubstitute the darnit-0.1.0-<os>-<arch> filename for your platform.
The binary is a shiv zipapp. Python 3.11 or 3.12 must be on PATH when you run it the first time so shiv can extract its bundled site-packages into a per-user cache. Subsequent runs are cached and fast.
If you don't have Python on the host, use the container image or install via pipx.
Every binary asset is signed with cosign keyless OIDC, bound to the canonical release.yml workflow in kusari-oss/darnit. Download the .sigstore bundle alongside the binary:
curl -LO https://github.com/kusari-oss/darnit/releases/download/v0.1.0/darnit-0.1.0-macos-arm64.sigstore
cosign verify-blob \
--bundle darnit-0.1.0-macos-arm64.sigstore \
--certificate-identity-regexp '^https://github\.com/kusari-oss/darnit/\.github/workflows/release\.yml@' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
darnit-0.1.0-macos-arm64A passing verification proves:
- The binary bytes match exactly what was signed.
- The signer was the
release.ymlworkflow inkusari-oss/darnit. - The OIDC issuer was GitHub Actions.
Each binary ships with an SPDX-JSON SBOM as a sibling file (darnit-<...>.sbom.spdx.json) and a GitHub Artifact Attestation that binds the SBOM to the binary.
Download the SBOM directly:
curl -LO https://github.com/kusari-oss/darnit/releases/download/v0.1.0/darnit-0.1.0-macos-arm64.sbom.spdx.jsonVerify the attestation via gh:
gh attestation verify \
--repo kusari-oss/darnit \
darnit-0.1.0-macos-arm64- Python 3.11/3.12 — must be present on the host (prerequisite above).
gitandghCLIs — some darnit controls invoke them at runtime. If you only have the binary, installgitand the GitHub CLI separately, or use the container image which bundles them.- Windows support — Windows binaries are not produced (out of scope; darnit's controls assume POSIX tooling).
- Linux musl/Alpine — tree-sitter native bindings don't build cleanly on musl; use the container image or
pip installinstead.
| Symptom | Cause |
|---|---|
bash: ./darnit-0.1.0-...: No such file or directory (on Linux) |
The shiv shebang points at python3.11. Confirm python3.11 is on PATH (which python3.11). |
| First run takes 10+ seconds | Expected — shiv is extracting site-packages into ~/.shiv/ on first run. Subsequent runs are fast. |
cosign verify-blob fails with "no matching signatures" |
Wrong binary or wrong .sigstore bundle. Both files must be from the same release. |
Audit complains about missing git or gh |
The binary doesn't bundle them. Install them via your platform's package manager. |