Installation
Install the capa CLI once on your machine, then use it in any project. The binary is what you upgrade later with capa upgrade.
Install
Section titled “Install”macOS and Linux
Section titled “macOS and Linux”curl -LsSf https://capa.sh/install.sh | shThe script downloads the latest capa binary, checks it against the release’s SHA256SUMS.txt, installs it to ~/.local/bin/capa, and adds that directory to PATH in your shell profile.
Windows
Section titled “Windows”powershell -ExecutionPolicy ByPass -c "irm https://capa.sh/install.ps1 | iex"The script checks the binary against SHA256SUMS.txt, installs to %LOCALAPPDATA%\Programs\capa\capa.exe, and updates your user PATH.
Installer options
Section titled “Installer options”Both installers read the same environment variables:
| Variable | Effect |
|---|---|
CAPA_VERSION | Install a specific release (e.g. 2.2.1 or v2.2.1) instead of the latest |
CAPA_INSTALL_DIR | Install to a custom directory |
CAPA_NO_MODIFY_PATH | Set to 1 to skip PATH changes |
CAPA_UNMANAGED_INSTALL | Set for CI / unmanaged installs (also skips PATH changes) |
CAPA_PRINT_VERBOSE / CAPA_PRINT_QUIET | Set to 1 for verbose or quiet output |
Pin a version:
curl -LsSf https://capa.sh/install.sh | CAPA_VERSION=2.2.1 sh$env:CAPA_VERSION="2.2.1"; irm https://capa.sh/install.ps1 | iexGitHub releases
Section titled “GitHub releases”Prefer a manual binary? Download the build for your OS from the capa GitHub releases page, place it somewhere on your PATH, and rename it to capa (or capa.exe on Windows).
Binaries are named by target: capa-x86_64-unknown-linux-gnu, capa-aarch64-unknown-linux-gnu, capa-x86_64-apple-darwin, capa-aarch64-apple-darwin, and capa-x86_64-pc-windows-msvc.exe (also used on Windows ARM64).
Verify the download
Section titled “Verify the download”Every release also publishes:
SHA256SUMS.txt: SHA-256 checksums for each binary,install.sh, andinstall.ps1install.shandinstall.ps1: the installers for that exact tag- GitHub build provenance attestations for
SHA256SUMS.txt,install.sh, andinstall.ps1
V=v2.2.1curl -fsSL -O https://github.com/infragate/capa/releases/download/$V/install.shcurl -fsSL -O https://github.com/infragate/capa/releases/download/$V/SHA256SUMS.txt
# Optional: confirm both files were produced by capa's release workflowgh attestation verify SHA256SUMS.txt --repo infragate/capagh attestation verify install.sh --repo infragate/capa
sha256sum -c SHA256SUMS.txt --ignore-missing # macOS: shasum -a 256 -c SHA256SUMS.txt --ignore-missingCAPA_VERSION=$V bash ./install.shThe same checksum command verifies a manually downloaded binary: keep it next to SHA256SUMS.txt under its release name and run the check before renaming it.
Verify
Section titled “Verify”capa --versionYou should see the installed version printed. If the command is not found, restart the terminal or add the install directory to your PATH.
Upgrade
Section titled “Upgrade”Keep the CLI current with:
capa upgradecapa upgrade downloads the latest release’s tagged installer, verifies it against SHA256SUMS.txt, and runs the verified local copy; see upgrade. Re-run the install script or replace the binary from GitHub releases if you installed outside the usual layout.
Next steps
Section titled “Next steps”With capa on your PATH, initialize a project in the managed quick start, or jump to wrap if you already have a capabilities.yaml.