Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Installation

Arbitraitor offers two installation methods. Nightly binaries are the fastest option; building from source is available for development.

Pre-built binaries are published every night from the latest main commit. They are available for Linux on x86_64 and aarch64, and for macOS on aarch64 (Apple Silicon).

Download

Fetch the latest binary for your platform from the nightly release page:

PlatformFile
Linux x86_64arbitraitor-x86_64-unknown-linux-gnu.tar.gz
Linux aarch64arbitraitor-aarch64-unknown-linux-gnu.tar.gz
macOS aarch64 (Apple Silicon)arbitraitor-aarch64-apple-darwin.tar.gz

Install

# Download and extract
curl -fsSL https://github.com/arbsec/arbitraitor/releases/download/nightly/arbitraitor-x86_64-unknown-linux-gnu.tar.gz | tar xz

# Move to a directory on your PATH
sudo mv arbitraitor /usr/local/bin/

# Verify
arbitraitor --version

On macOS, substitute the file name with arbitraitor-aarch64-apple-darwin.tar.gz.

Warning: Pre-alpha. Nightly binaries are built from unreleased code. The CLI, config format, and schemas change between commits. Do not use in production.

Build from source

Building from source is required for development or if you need a platform without pre-built binaries (e.g. Windows).

Prerequisites

Rust 1.96+ (Rust 2024 edition). Install via rustup:

curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh

You also need pkg-config and OpenSSL development headers.

Ubuntu/Debian:

sudo apt install pkg-config libssl-dev

macOS:

brew install pkg-config openssl@3

The project uses mise to pin the exact Rust toolchain and supporting tools. If you have mise installed:

mise install

This installs the Rust version pinned in .mise.toml, plus lefthook (git hooks), cocogitto (conventional commits), and rumdl (markdown linter).

Build and install

git clone https://github.com/arbsec/arbitraitor.git
cd arbitraitor
cargo install --path crates/arbitraitor-cli

This compiles the CLI and all its dependencies. Expect 5–15 minutes depending on your machine and whether dependencies are cached.

The binary installs to ~/.cargo/bin/arbitraitor.

Verify the installation

arbitraitor --version
arbitraitor --help

You should see the version string and the list of subcommands:

Commands:
  inspect   Retrieve and analyze an artifact without executing it
  run       Execute the full pipeline with approval flow
  scan      Scan a local file or stdin for threats
  explain   Explain a verdict from a receipt file
  store     Manage content-addressed storage
  policy    Validate a policy file
  doctor    Check scanner and integration health
  version   Show version and build provenance
  daemon    Unix socket daemon with background queue
  unpack    Unpack an archive to a directory for inspection
  intel     Manage local threat-intelligence feeds
  status    Show system health and configured detectors
  wrappers  Manage curl/wget wrapper shims
  mcp       Start MCP server over stdio (JSON-RPC 2.0)

Troubleshooting

Build fails with OpenSSL errors: Ensure pkg-config and libssl-dev (or openssl@3 on macOS) are installed. On macOS, you may need to set OPENSSL_DIR:

export OPENSSL_DIR=$(brew --prefix openssl@3)

arbitraitor command not found: Ensure the binary is on your PATH:

echo 'export PATH="$HOME/.cargo/bin:$PATH"' >> ~/.bashrc
source ~/.bashrc

Out of memory during build: The workspace is large. Try building with reduced parallelism:

cargo install --path crates/arbitraitor-cli -j 2