Skip to content

Installation

Install the capa CLI once on your machine, then use it in any project. The binary is what you upgrade later with capa upgrade.

Terminal window
curl -LsSf https://capa.sh/install.sh | sh

The script downloads the latest capa binary, checks it against the release’s SHA256SUMS.txt, installs it to ~/.local/bin/capa, and adds that directory to PATH in your shell profile.

Terminal window
powershell -ExecutionPolicy ByPass -c "irm https://capa.sh/install.ps1 | iex"

The script checks the binary against SHA256SUMS.txt, installs to %LOCALAPPDATA%\Programs\capa\capa.exe, and updates your user PATH.

Both installers read the same environment variables:

VariableEffect
CAPA_VERSIONInstall a specific release (e.g. 2.2.1 or v2.2.1) instead of the latest
CAPA_INSTALL_DIRInstall to a custom directory
CAPA_NO_MODIFY_PATHSet to 1 to skip PATH changes
CAPA_UNMANAGED_INSTALLSet for CI / unmanaged installs (also skips PATH changes)
CAPA_PRINT_VERBOSE / CAPA_PRINT_QUIETSet to 1 for verbose or quiet output

Pin a version:

Terminal window
curl -LsSf https://capa.sh/install.sh | CAPA_VERSION=2.2.1 sh
Terminal window
$env:CAPA_VERSION="2.2.1"; irm https://capa.sh/install.ps1 | iex

Prefer a manual binary? Download the build for your OS from the capa GitHub releases page, place it somewhere on your PATH, and rename it to capa (or capa.exe on Windows).

Binaries are named by target: capa-x86_64-unknown-linux-gnu, capa-aarch64-unknown-linux-gnu, capa-x86_64-apple-darwin, capa-aarch64-apple-darwin, and capa-x86_64-pc-windows-msvc.exe (also used on Windows ARM64).

Every release also publishes:

  • SHA256SUMS.txt: SHA-256 checksums for each binary, install.sh, and install.ps1
  • install.sh and install.ps1: the installers for that exact tag
  • GitHub build provenance attestations for SHA256SUMS.txt, install.sh, and install.ps1
Terminal window
V=v2.2.1
curl -fsSL -O https://github.com/infragate/capa/releases/download/$V/install.sh
curl -fsSL -O https://github.com/infragate/capa/releases/download/$V/SHA256SUMS.txt
# Optional: confirm both files were produced by capa's release workflow
gh attestation verify SHA256SUMS.txt --repo infragate/capa
gh attestation verify install.sh --repo infragate/capa
sha256sum -c SHA256SUMS.txt --ignore-missing # macOS: shasum -a 256 -c SHA256SUMS.txt --ignore-missing
CAPA_VERSION=$V bash ./install.sh

The same checksum command verifies a manually downloaded binary: keep it next to SHA256SUMS.txt under its release name and run the check before renaming it.

Terminal window
capa --version

You should see the installed version printed. If the command is not found, restart the terminal or add the install directory to your PATH.

Keep the CLI current with:

Terminal window
capa upgrade

capa upgrade downloads the latest release’s tagged installer, verifies it against SHA256SUMS.txt, and runs the verified local copy; see upgrade. Re-run the install script or replace the binary from GitHub releases if you installed outside the usual layout.

With capa on your PATH, initialize a project in the managed quick start, or jump to wrap if you already have a capabilities.yaml.