Download
NextFix™ 1.0.0. Free and open source under the Apache 2.0 licence. One file per platform; no Node, npm or internet connection needed to start it. About 100 MB.
Files
Every platform
| Platform | File | Notes |
|---|---|---|
| Windows | NextFix-Setup-1.0.0.exe | Per-user installer, signed by GRCSAC. Adds nextfix to the PATH and a Start Menu entry, “NextFix dashboards”. |
| Windows, portable | nextfix-1.0.0-win32-x64.exe | A single executable. Unsigned, so SmartScreen may ask once; the installer carries a signed copy. |
| macOS, Apple silicon | nextfix-1.0.0-darwin-arm64 | chmod +x, then run. macOS keeps a downloaded program in quarantine until you allow it once: right-click and choose Open, or xattr -d com.apple.quarantine nextfix. |
| macOS, Intel | nextfix-1.0.0-darwin-x64 | Same as above. |
| Linux, x64 | nextfix-1.0.0-linux-x64 | chmod +x, then run. |
| Linux, arm64 | nextfix-1.0.0-linux-arm64 | Graviton, Raspberry Pi 4 and 5, Ampere. |
| Docker | ghcr.io/grcsac/nextfix:1.0.0 | Signed with cosign. Runs as a non-root user, keeps everything under /data, and has syft built in for image scans. The image's own SBOM is attached to the release. |
| Checksums | SHA256SUMS | Every file above. |
Package managers, once each release is approved there:
winget install GRCSAC.NextFix and
choco install nextfix.
Docker
One line for a server the team shares
docker run -d --name nextfix -p 8790:8790 -v nextfix-data:/data \ -v /var/run/docker.sock:/var/run/docker.sock ghcr.io/grcsac/nextfix:1.0.0 docker exec -it nextfix nextfix user add admin --role admin
The Docker socket is only needed for scanning images that live on that
machine; leave it out otherwise. Use 127.0.0.1:8790:8790 to
keep the dashboards local behind a reverse proxy.
Verify
Check a download before you run it
Linux and macOS
V=1.0.0 curl -fsSLO "https://github.com/GRCSAC/nextfix/releases/download/v$V/nextfix-$V-linux-x64" curl -fsSLO "https://github.com/GRCSAC/nextfix/releases/download/v$V/SHA256SUMS" sha256sum --check --ignore-missing SHA256SUMS # macOS: shasum -a 256 --check --ignore-missing SHA256SUMS
Windows (PowerShell)
(Get-FileHash .\NextFix-Setup-1.0.0.exe -Algorithm SHA256).Hash.ToLower() # compare with the matching line in SHA256SUMS
Docker image
cosign verify ghcr.io/grcsac/nextfix:1.0.0 \ --certificate-identity-regexp '^https://github.com/GRCSAC/nextfix/' \ --certificate-oidc-issuer https://token.actions.githubusercontent.com
First run
Open the dashboards, create the administrator
nextfix serve # dashboards at http://127.0.0.1:8790, opens the browser nextfix scan ./my-app # decisions on the terminal
The first visit to the dashboards creates the administrator account.
Until that account exists, the server answers only the machine it runs
on. Everything NextFix keeps lives in one folder, ~/.nextfix
(C:\Users\<you>\.nextfix on Windows), which makes
backup a copy and upgrade a file swap.
Installing, upgrading, backup and restore, and running behind a reverse proxy are all in the install guide.
Only run NextFix on code you own or have permission to assess.