Skip to main content

Aposlop

Aposlop

CI status crates.io version PyPI version License


Aposlop is a fast command-line tool. It finds duplicate code and calculates cyclomatic complexity.

Aposlop supports Rust, Python, TypeScript, and TSX. Aposlop uses Tree-sitter to parse each supported language.

Documentation: https://aposlop.ezygang.digital/

Source Code: https://github.com/EzyGang/aposlop

Issues: https://github.com/EzyGang/aposlop/issues


Table of Contents


Why Aposlop?

Aposlop exists to find code slop from coding agents.

Coding agents can generate duplicate code and add complex control flow. These changes can enter a project faster than a reviewer can find them.

Text comparison does not find a duplicate after an agent renames identifiers or changes literals. A linter does not find repeated logic in different files or languages. A complexity limit does not identify repeated logic.

Aposlop uses exact, normalized, and verified near-miss duplicate detection. It also calculates cyclomatic complexity for each code block.

Aposlop is fast enough for an agent validation loop. You can configure thresholds for each language and file extension. You can also exclude paths or accept specific findings. These controls let a project accept known findings and continue development.

Feature Result
Type-1 detection Finds exact duplicates
Type-2 detection Finds duplicates after identifier or literal changes
Type-3 detection Finds verified near-miss duplicates
Complexity analysis Calculates complexity for each code block
Terminal code view Shows every group instance with line numbers
JSON output Provides stable data for other tools
CI command Returns failure when findings remain
Local cache Reuses analysis for unchanged files
Update check Warns interactive users when a new release is available
How Aposlop works
  • Parse once. Tree-sitter providers extract blocks, identifiers, literals, comments, and complexity decisions.
  • Type-1. XXH3 groups exact token streams before complete equality verification.
  • Type-2. The same process compares streams with normalized identifiers and literals.
  • Type-3. Five-token shingles feed a prefix-filtered similarity join. Length and position filters prune candidates before Jaccard verification.
  • Grouping. Connected duplicate relations become one deterministic group with every source instance.
  • Complexity. Each block starts at 1 and adds unique language-specific decision captures. Nested blocks have independent scores.
  • Cache. Versioned bincode data reuses unchanged analysis. File metadata and schema versions invalidate stale entries before atomic replacement.

Installation

Install script on Linux or macOS

Install cosign. Then run the installer:

curl -fsSLo install.sh https://github.com/EzyGang/aposlop/releases/latest/download/install.sh
sh install.sh

Install script on Windows

Install cosign. Then run the installer:

Invoke-WebRequest https://github.com/EzyGang/aposlop/releases/latest/download/install.ps1 -OutFile install.ps1
powershell -ExecutionPolicy Bypass -File .\install.ps1

Both scripts verify the archive checksum and Sigstore signatures.

Cargo

Install Aposlop from crates.io:

cargo install aposlop --locked

PyPI with uv

Install Aposlop as a global tool:

uv tool install aposlop

Run Aposlop without installing it:

uvx aposlop --help

Homebrew

Install Aposlop from the EzyGang Homebrew tap:

brew install EzyGang/tap/aposlop

From source

Install Aposlop from source. A stable Rust toolchain must support edition 2024.

git clone https://github.com/EzyGang/aposlop.git
cd aposlop
cargo install --path . --locked

Verify the installation:

aposlop --version
aposlop --help

Agent skill

Install the Aposlop skill for supported coding agents:

npx skills@latest add EzyGang/aposlop --skill aposlop

The skill teaches agents how to configure Aposlop, inspect findings, and add Aposlop to validation workflows. The skill does not install the Aposlop binary.

Update checks

Aposlop checks for a new GitHub release during interactive runs. It performs a network request at most once every 24 hours. It stores the latest result in the user cache directory. Non-interactive commands do not perform this check.

Set this environment variable to disable the check:

APOSLOP_NO_UPDATE_CHECK=1 aposlop .

Quick Start

Analyze the current directory:

aposlop .

Show the source for each duplicate:

aposlop . --terminal-output code

Run CI validation:

aposlop ci .

The ci command returns exit code 1 when a finding remains.

Write the complete report as JSON:

aposlop . --format json > aposlop-report.json

Read the full quick-start guide.


Core Features

Duplicate Detection

A block enters analysis when it meets the line and named-node limits.

Aposlop classifies block relations in this order:

  1. Type-1 requires identical canonical syntax.
  2. Type-2 allows different identifiers and literals.
  3. Type-3 requires a Jaccard similarity at or above the configured threshold.

Aposlop reports each connected set of duplicate relations as one group. A TypeScript block can match a TSX block.

Read the duplicate model.

Cyclomatic Complexity

Each valid block has an initial complexity score of 1. Aposlop adds one for each language-specific decision. Decisions include branches, loops, alternatives, exception paths, conditional expressions, and short-circuit operations.

A nested block has an independent score. Nested blocks include functions, closures, lambdas, field initializers, and static blocks.

A violation requires:

score > complexity_threshold

Read the complexity model.

Language Support

Language Extensions
Rust .rs
Python .py
TypeScript .ts
TSX .tsx

Aposlop ignores unsupported extensions. Aposlop follows standard ignore files such as .gitignore.

Read the language guides.

Output Formats

The terminal report is the default. It contains duplicate groups, complexity findings, diagnostics, and a summary.

aposlop . --format terminal

The JSON report contains the complete report and its schema version.

aposlop . --format json

The ci command shows only the status and finding counts.

aposlop ci .

Read the output guide.

Manual Exclusions

Aposlop assigns a deterministic five-character ID to each duplicate group or complexity finding.

Add a finding to the manual exclusions:

aposlop allow aB7_x

The command writes the ID to .aposlopignore. Delete the ID from that file to restore the finding. Aposlop reports valid IDs that match no current finding as unused ignores at the end of each report. Unused ignores do not change the process exit code.


Configuration

Aposlop reads <PATH>/.aposlop.toml. Aposlop uses built-in values when this file does not exist.

[core]
min_lines = 5
min_nodes = 30
exclude = ["tests/", "vendor/", "node_modules/", "target/"]
use_cache = true

[duplicates_detection]
type_1 = true
type_2 = true
type_3 = true
type_3_threshold = 0.85

[metrics]
calculate_complexity = true
complexity_threshold = 15

Language and extension tables can override the core values. Command-line values override all configuration-file values.

Read the configuration guide.


CLI Quick Reference

Command or option Purpose
aposlop ci [PATH] Print a concise finding summary and fail when findings exist
aposlop allow <FINDING> [PATH] Add a finding to the target's manual exclusions
--format <terminal|json> Select the report format
--terminal-output <locations|code> Select terminal duplicate detail
--min-lines <N> Override the minimum block line count
--min-nodes <N> Override the minimum named-node count
--exclude <PATH> Replace configured exclusions
--use-cache <BOOL> Enable or disable the analysis cache
--type-1 <BOOL> Enable or disable Type-1 findings
--type-2 <BOOL> Enable or disable Type-2 findings
--type-3 <BOOL> Enable or disable Type-3 findings
--type-3-threshold <RATIO> Override the Type-3 threshold
--calculate-complexity <BOOL> Enable or disable complexity findings
--complexity-threshold <N> Override the complexity threshold

Read the complete CLI reference.


Contributing

Open a GitHub issue to discuss a large change. Then open a pull request.

Run these checks before you submit the pull request:

cargo fmt --all -- --check
cargo clippy --workspace --all-targets --all-features -- -D warnings
cargo test --workspace --all-features
cargo run -- --help

License

You can use Aposlop under either license:

Metadata

Release files for aposlop 1.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for aposlop 1.1.0
File
aposlop-1.1.0-py3-none-win_arm64.whl Python 3 none Windows ARM64 Details
aposlop-1.1.0-py3-none-win_amd64.whl Python 3 none Windows x86-64 Details
aposlop-1.1.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Python 3 none Linux glibc 2.17+ x86-64 Details
aposlop-1.1.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl Python 3 none Linux glibc 2.17+ ARM64 Details
aposlop-1.1.0-py3-none-macosx_11_0_arm64.whl Python 3 none macOS 11.0+ ARM64 Details
aposlop-1.1.0-py3-none-macosx_10_12_x86_64.whl Python 3 none macOS 10.12+ x86-64 Details

Total release size: 20.7 MB

Release files / aposlop-1.1.0-py3-none-win_arm64.whl

Download URL aposlop-1.1.0-py3-none-win_arm64.whl
Size 3.2 MB
Tags Python 3 Windows ARM64
SHA-256 checksum
How to use checksums
c6dfcad52da6b4fb2873d433ad01b3ff52f3739d8461d4487273f3a868aa79a0
BLAKE2b-256 checksum
How to use checksums
e1ec33be4039829c6b44934edd6d59e95666f9b9bd705d0ec5188ed7451d85e1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release files / aposlop-1.1.0-py3-none-win_amd64.whl

Download URL aposlop-1.1.0-py3-none-win_amd64.whl
Size 3.3 MB
Tags Python 3 Windows x86-64
SHA-256 checksum
How to use checksums
b8168c170673831c99fc119461ad37c206cfd2f6c468d01d4bdb6728c596e0fc
BLAKE2b-256 checksum
How to use checksums
96a627e2169e8316053b27c3c7454b58d5d3c9df885a579c819128833fe6dba6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release files / aposlop-1.1.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL aposlop-1.1.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 3.7 MB
Tags Linux glibc 2.17+ x86-64 Python 3
SHA-256 checksum
How to use checksums
f7f345d99e2cceae544c94ef4df0c35698ca7fef4ae041c753121306a37f11ce
BLAKE2b-256 checksum
How to use checksums
0f7069c90852a71649a025ba7e11e91d8f99ddc6f10117e2559f1441f3696702
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release files / aposlop-1.1.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl

Download URL aposlop-1.1.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Size 3.5 MB
Tags Linux glibc 2.17+ ARM64 Python 3
SHA-256 checksum
How to use checksums
6fb21721a2f7bce449d41d36a265c51c2d4bac082f9c4c1204b592b759b29c92
BLAKE2b-256 checksum
How to use checksums
9768c3154c4977bd98870c96b197b7384aa563e7ae6268a4ad2d415b1858280b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release files / aposlop-1.1.0-py3-none-macosx_11_0_arm64.whl

Download URL aposlop-1.1.0-py3-none-macosx_11_0_arm64.whl
Size 3.4 MB
Tags Python 3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
c1829e1823ea0b44f3d0c3516d2ed0ba0f41ca31fd3e63b94a9802ba8b7ede79
BLAKE2b-256 checksum
How to use checksums
9af36e98c5c7ba628a0f63e560192b5d3f398ca98e16dda71bc84bed83bd7d7f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release files / aposlop-1.1.0-py3-none-macosx_10_12_x86_64.whl

Download URL aposlop-1.1.0-py3-none-macosx_10_12_x86_64.whl
Size 3.6 MB
Tags Python 3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
7d7e864e6345782125fb6a1e2a1090f0fa15bfcea9852fc53da806ba794d8816
BLAKE2b-256 checksum
How to use checksums
58ee2416608797d36dec9907c0a8306a90c820cf9836001fa80f7ecfbf5560fc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release history Release notifications | RSS feed

1.2.2

6 release files

1.2.1

6 release files

1.2.0

6 release files

1.1.3

6 release files

1.1.2

6 release files

1.1.1

6 release files

This release

1.1.0 This release

6 release files

1.0.0

6 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page