Skip to main content

Aposlop

Aposlop

CI status crates.io version PyPI version License


Aposlop is a fast command-line tool. It finds duplicate code and calculates cyclomatic complexity.

Aposlop supports Rust, Python, TypeScript, and TSX. Aposlop uses Tree-sitter to parse each supported language.

Documentation: https://aposlop.ezygang.digital/

Source Code: https://github.com/EzyGang/aposlop

Issues: https://github.com/EzyGang/aposlop/issues


Table of Contents


Why Aposlop?

Aposlop exists to find code slop from coding agents.

Coding agents can generate duplicate code and add complex control flow. These changes can enter a project faster than a reviewer can find them.

Text comparison does not find a duplicate after an agent renames identifiers or changes literals. A linter does not find repeated logic in different files or languages. A complexity limit does not identify repeated logic.

Aposlop uses exact, normalized, and verified near-miss duplicate detection. It also calculates cyclomatic complexity for each code block.

Aposlop is fast enough for an agent validation loop. You can configure thresholds for each language and file extension. You can also exclude paths or accept specific findings. These controls let a project accept known findings and continue development.

Feature Result
Type-1 detection Finds exact duplicates
Type-2 detection Finds duplicates after identifier or literal changes
Type-3 detection Finds verified near-miss duplicates
Complexity analysis Calculates complexity for each code block
Terminal code view Shows both source ranges with line numbers
JSON output Provides stable data for other tools
CI command Returns failure when findings remain
Local cache Reuses analysis for unchanged files
Update check Warns interactive users when a new release is available
How Aposlop works
  • Parse once. Tree-sitter providers extract blocks, identifiers, literals, comments, and complexity decisions.
  • Type-1. XXH3 groups exact token streams before complete equality verification.
  • Type-2. The same process compares streams with normalized identifiers and literals.
  • Type-3. Five-token shingles feed a prefix-filtered similarity join. Length and position filters prune candidates before Jaccard verification.
  • Complexity. Each block starts at 1 and adds unique language-specific decision captures. Nested blocks have independent scores.
  • Cache. Versioned bincode data reuses unchanged analysis. File metadata and schema versions invalidate stale entries before atomic replacement.

Installation

Install script on Linux or macOS

Install cosign. Then run the installer:

curl -fsSLo install.sh https://github.com/EzyGang/aposlop/releases/latest/download/install.sh
sh install.sh

Install script on Windows

Install cosign. Then run the installer:

Invoke-WebRequest https://github.com/EzyGang/aposlop/releases/latest/download/install.ps1 -OutFile install.ps1
powershell -ExecutionPolicy Bypass -File .\install.ps1

Both scripts verify the archive checksum and Sigstore signatures.

Cargo

Install Aposlop from crates.io:

cargo install aposlop --locked

PyPI with uv

Install Aposlop as a global tool:

uv tool install aposlop

Run Aposlop without installing it:

uvx aposlop --help

Homebrew

Install Aposlop from the EzyGang Homebrew tap:

brew install EzyGang/tap/aposlop

From source

Install Aposlop from source. A stable Rust toolchain must support edition 2024.

git clone https://github.com/EzyGang/aposlop.git
cd aposlop
cargo install --path . --locked

Verify the installation:

aposlop --version
aposlop --help

Agent skill

Install the Aposlop skill for supported coding agents:

npx skills@latest add EzyGang/aposlop --skill aposlop

The skill teaches agents how to configure Aposlop, inspect findings, and add Aposlop to validation workflows. The skill does not install the Aposlop binary.

Update checks

Aposlop checks for a new GitHub release during interactive runs. It performs a network request at most once every 24 hours. It stores the latest result in the user cache directory. Non-interactive commands do not perform this check.

Set this environment variable to disable the check:

APOSLOP_NO_UPDATE_CHECK=1 aposlop .

Quick Start

Analyze the current directory:

aposlop .

Show the source for each duplicate:

aposlop . --terminal-output code

Run CI validation:

aposlop ci .

The ci command returns exit code 1 when a finding remains.

Write the complete report as JSON:

aposlop . --format json > aposlop-report.json

Read the full quick-start guide.


Core Features

Duplicate Detection

A block enters analysis when it meets the line and named-node limits.

Aposlop classifies duplicate findings in this order:

  1. Type-1 requires identical canonical syntax.
  2. Type-2 allows different identifiers and literals.
  3. Type-3 requires a Jaccard similarity at or above the configured threshold.

Aposlop reports each block pair one time. A TypeScript block can match a TSX block.

Read the duplicate model.

Cyclomatic Complexity

Each valid block has an initial complexity score of 1. Aposlop adds one for each language-specific decision. Decisions include branches, loops, alternatives, exception paths, conditional expressions, and short-circuit operations.

A nested block has an independent score. Nested blocks include functions, closures, lambdas, field initializers, and static blocks.

A violation requires:

score > complexity_threshold

Read the complexity model.

Language Support

Language Extensions
Rust .rs
Python .py
TypeScript .ts
TSX .tsx

Aposlop ignores unsupported extensions. Aposlop follows standard ignore files such as .gitignore.

Read the language guides.

Output Formats

The terminal report is the default. It contains duplicate findings, complexity findings, diagnostics, and a summary.

aposlop . --format terminal

The JSON report contains the complete report and its schema version.

aposlop . --format json

The ci command shows only the status and finding counts.

aposlop ci .

Read the output guide.

Manual Exclusions

Aposlop assigns a deterministic five-character ID to each duplicate or complexity finding.

Add a finding to the manual exclusions:

aposlop allow aB7_x

The command writes the ID to .aposlopignore. Delete the ID from that file to restore the finding.


Configuration

Aposlop reads <PATH>/.aposlop.toml. Aposlop uses built-in values when this file does not exist.

[core]
min_lines = 5
min_nodes = 30
exclude = ["tests/", "vendor/", "node_modules/", "target/"]
use_cache = true

[duplicates_detection]
type_1 = true
type_2 = true
type_3 = true
type_3_threshold = 0.85

[metrics]
calculate_complexity = true
complexity_threshold = 15

Language and extension tables can override the core values. Command-line values override all configuration-file values.

Read the configuration guide.


CLI Quick Reference

Command or option Purpose
aposlop ci [PATH] Print a concise finding summary and fail when findings exist
aposlop allow <FINDING> [PATH] Add a finding to the target's manual exclusions
--format <terminal|json> Select the report format
--terminal-output <locations|code> Select terminal duplicate detail
--min-lines <N> Override the minimum block line count
--min-nodes <N> Override the minimum named-node count
--exclude <PATH> Replace configured exclusions
--use-cache <BOOL> Enable or disable the analysis cache
--type-1 <BOOL> Enable or disable Type-1 findings
--type-2 <BOOL> Enable or disable Type-2 findings
--type-3 <BOOL> Enable or disable Type-3 findings
--type-3-threshold <RATIO> Override the Type-3 threshold
--calculate-complexity <BOOL> Enable or disable complexity findings
--complexity-threshold <N> Override the complexity threshold

Read the complete CLI reference.


Contributing

Open a GitHub issue to discuss a large change. Then open a pull request.

Run these checks before you submit the pull request:

cargo fmt --all -- --check
cargo clippy --workspace --all-targets --all-features -- -D warnings
cargo test --workspace --all-features
cargo run -- --help

License

You can use Aposlop under either license:

Metadata

Release files for aposlop 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for aposlop 1.0.0
File
aposlop-1.0.0-py3-none-win_arm64.whl Python 3 none Windows ARM64 Details
aposlop-1.0.0-py3-none-win_amd64.whl Python 3 none Windows x86-64 Details
aposlop-1.0.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Python 3 none Linux glibc 2.17+ x86-64 Details
aposlop-1.0.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl Python 3 none Linux glibc 2.17+ ARM64 Details
aposlop-1.0.0-py3-none-macosx_11_0_arm64.whl Python 3 none macOS 11.0+ ARM64 Details
aposlop-1.0.0-py3-none-macosx_10_12_x86_64.whl Python 3 none macOS 10.12+ x86-64 Details

Total release size: 20.7 MB

Release files / aposlop-1.0.0-py3-none-win_arm64.whl

Download URL aposlop-1.0.0-py3-none-win_arm64.whl
Size 3.2 MB
Tags Python 3 Windows ARM64
SHA-256 checksum
How to use checksums
f4b8f6fe5377efc77c8bb6d81f6588a288b8ee018099636324941d3d9f3ed963
BLAKE2b-256 checksum
How to use checksums
166b47bd586e252171be941733d7419582d94152c89d1e92b07f18538b3b83bf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.

Transparency log

Release files / aposlop-1.0.0-py3-none-win_amd64.whl

Download URL aposlop-1.0.0-py3-none-win_amd64.whl
Size 3.3 MB
Tags Python 3 Windows x86-64
SHA-256 checksum
How to use checksums
a9d6d01ae39b264920773e5fe3dc680a8c31f7de3449dc5951a247427041e4e5
BLAKE2b-256 checksum
How to use checksums
42dd4329026a416d9bdacfe379a4aab6a6c3b241896c158b93dc447b8ef40cc7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.

Transparency log

Release files / aposlop-1.0.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL aposlop-1.0.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 3.7 MB
Tags Linux glibc 2.17+ x86-64 Python 3
SHA-256 checksum
How to use checksums
e6cb52cbe2caecc51f84da2bc3cfac293d07034bb6f259a535296504abdf44b8
BLAKE2b-256 checksum
How to use checksums
113476d4f224a29552deed4ba0cadbefbfcd507d6cb7e4bbf067f6824a85353a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.

Transparency log

Release files / aposlop-1.0.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl

Download URL aposlop-1.0.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Size 3.5 MB
Tags Linux glibc 2.17+ ARM64 Python 3
SHA-256 checksum
How to use checksums
d95f390ec4ea2091206e0f8ed41650df5e7bbaf570f2d04113a0542d8a9c8d4f
BLAKE2b-256 checksum
How to use checksums
c851ebd476ae0c18ecf69696ba1ed8b82c4bbf0473b33e056006309c0f646e26
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.

Transparency log

Release files / aposlop-1.0.0-py3-none-macosx_11_0_arm64.whl

Download URL aposlop-1.0.0-py3-none-macosx_11_0_arm64.whl
Size 3.4 MB
Tags Python 3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
44c0523e727a66e76186b97f23607e5b1b474f59e67e1be34a10a5e7d04f7030
BLAKE2b-256 checksum
How to use checksums
2359b34b0f4366ec2fa376d8c5f45b0e878e45f9dfa83a5258649006efc25ffd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.

Transparency log

Release files / aposlop-1.0.0-py3-none-macosx_10_12_x86_64.whl

Download URL aposlop-1.0.0-py3-none-macosx_10_12_x86_64.whl
Size 3.6 MB
Tags Python 3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
bbe76053c7c422800dcd4415d2d54edc34b6b97a22d6d6c34d21e0493079e8ae
BLAKE2b-256 checksum
How to use checksums
1f23c076bfad4fa2335020f88c06f22599bb2d0015539aed5eb96e200791765a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.

Transparency log

Release history Release notifications | RSS feed

1.2.2

6 release files

1.2.1

6 release files

1.2.0

6 release files

1.1.3

6 release files

1.1.2

6 release files

1.1.1

6 release files

1.1.0

6 release files

This release

1.0.0 This release

6 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page