Download

NextFix™ 1.0.0. Free and open source under the Apache 2.0 licence. One file per platform; no Node, npm or internet connection needed to start it. About 100 MB.

Files

Every platform

PlatformFileNotes
WindowsNextFix-Setup-1.0.0.exePer-user installer, signed by GRCSAC. Adds nextfix to the PATH and a Start Menu entry, “NextFix dashboards”.
Windows, portablenextfix-1.0.0-win32-x64.exeA single executable. Unsigned, so SmartScreen may ask once; the installer carries a signed copy.
macOS, Apple siliconnextfix-1.0.0-darwin-arm64chmod +x, then run. macOS keeps a downloaded program in quarantine until you allow it once: right-click and choose Open, or xattr -d com.apple.quarantine nextfix.
macOS, Intelnextfix-1.0.0-darwin-x64Same as above.
Linux, x64nextfix-1.0.0-linux-x64chmod +x, then run.
Linux, arm64nextfix-1.0.0-linux-arm64Graviton, Raspberry Pi 4 and 5, Ampere.
Dockerghcr.io/grcsac/nextfix:1.0.0Signed with cosign. Runs as a non-root user, keeps everything under /data, and has syft built in for image scans. The image's own SBOM is attached to the release.
ChecksumsSHA256SUMSEvery file above.

Package managers, once each release is approved there: winget install GRCSAC.NextFix and choco install nextfix.

Docker

One line for a server the team shares

docker run -d --name nextfix -p 8790:8790 -v nextfix-data:/data \
  -v /var/run/docker.sock:/var/run/docker.sock ghcr.io/grcsac/nextfix:1.0.0
docker exec -it nextfix nextfix user add admin --role admin

The Docker socket is only needed for scanning images that live on that machine; leave it out otherwise. Use 127.0.0.1:8790:8790 to keep the dashboards local behind a reverse proxy.

Verify

Check a download before you run it

Linux and macOS

V=1.0.0
curl -fsSLO "https://github.com/GRCSAC/nextfix/releases/download/v$V/nextfix-$V-linux-x64"
curl -fsSLO "https://github.com/GRCSAC/nextfix/releases/download/v$V/SHA256SUMS"
sha256sum --check --ignore-missing SHA256SUMS   # macOS: shasum -a 256 --check --ignore-missing SHA256SUMS

Windows (PowerShell)

(Get-FileHash .\NextFix-Setup-1.0.0.exe -Algorithm SHA256).Hash.ToLower()
# compare with the matching line in SHA256SUMS

Docker image

cosign verify ghcr.io/grcsac/nextfix:1.0.0 \
  --certificate-identity-regexp '^https://github.com/GRCSAC/nextfix/' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

First run

Open the dashboards, create the administrator

nextfix serve          # dashboards at http://127.0.0.1:8790, opens the browser
nextfix scan ./my-app  # decisions on the terminal

The first visit to the dashboards creates the administrator account. Until that account exists, the server answers only the machine it runs on. Everything NextFix keeps lives in one folder, ~/.nextfix (C:\Users\<you>\.nextfix on Windows), which makes backup a copy and upgrade a file swap.

Installing, upgrading, backup and restore, and running behind a reverse proxy are all in the install guide.

Only run NextFix on code you own or have permission to assess.