Skip to main content

Aposlop

Aposlop

CI status crates.io version PyPI version License


Apos, the Slopbreaker

Slop always rolls downhill. Aposlop helps to push back.

Aposlop is a fast command-line tool. It finds duplicate code and calculates cyclomatic complexity.

Aposlop supports Go, Rust, Python, TypeScript, and TSX. Aposlop uses Tree-sitter to parse each supported language.

Documentation: https://aposlop.ezygang.digital/

Source Code: https://github.com/EzyGang/aposlop

Issues: https://github.com/EzyGang/aposlop/issues


Table of Contents


Why Aposlop?

Aposlop exists to find code slop from coding agents.

Coding agents can generate duplicate code and add complex control flow. These changes can enter a project faster than a reviewer can find them.

Text comparison does not find a duplicate after an agent renames identifiers or changes literals. A linter does not find repeated logic in different files or languages. A complexity limit does not identify repeated logic.

Aposlop uses exact, normalized, and verified near-miss duplicate detection. It also calculates cyclomatic complexity for each code block.

Aposlop is fast enough for an agent validation loop. You can configure thresholds for each language and file extension. You can also exclude paths or accept specific findings. These controls let a project accept known findings and continue development.

Feature Result
Type-1 detection Finds exact duplicates
Type-2 detection Finds duplicates after identifier or literal changes
Type-3 detection Finds verified near-miss duplicates
Complexity analysis Calculates complexity for each code block
Terminal code view Shows every group instance with line numbers
JSON output Provides stable data for other tools
CI command Returns failure when findings remain
Local cache Reuses analysis for unchanged files
Update check Warns interactive users when a new release is available
How Aposlop works
  • Parse once. Tree-sitter providers extract blocks, identifiers, literals, comments, and complexity decisions.
  • Type-1. XXH3 groups exact token streams before complete equality verification.
  • Type-2. The same process compares streams with normalized identifiers and literals.
  • Type-3. Five-token shingles feed a prefix-filtered similarity join. Length and position filters prune candidates before Jaccard verification.
  • Grouping. Connected duplicate relations become one deterministic group with every source instance.
  • Complexity. Each block starts at 1 and adds unique language-specific decision captures. Nested blocks have independent scores.
  • Cache. Versioned bincode data reuses unchanged analysis. File metadata and schema versions invalidate stale entries before atomic replacement.

Installation

Install script on Linux or macOS

Install cosign. Then run the installer:

curl -fsSLo install.sh https://github.com/EzyGang/aposlop/releases/latest/download/install.sh
sh install.sh

Install script on Windows

Install cosign. Then run the installer:

Invoke-WebRequest https://github.com/EzyGang/aposlop/releases/latest/download/install.ps1 -OutFile install.ps1
powershell -ExecutionPolicy Bypass -File .\install.ps1

Both scripts verify the archive checksum and Sigstore signatures.

Cargo

Install Aposlop from crates.io:

cargo install aposlop --locked

PyPI with uv

Install Aposlop as a global tool:

uv tool install aposlop

Run Aposlop without installing it:

uvx aposlop --help

Homebrew

Install Aposlop from the EzyGang Homebrew tap:

brew install EzyGang/tap/aposlop

From source

Install Aposlop from source. A stable Rust toolchain must support edition 2024.

git clone https://github.com/EzyGang/aposlop.git
cd aposlop
cargo install --path . --locked

Verify the installation:

aposlop --version
aposlop --help

Agent skill

Install the Aposlop skill for supported coding agents:

npx skills@latest add EzyGang/aposlop --skill aposlop

The skill teaches agents how to configure Aposlop, inspect findings, and add Aposlop to validation workflows. The skill does not install the Aposlop binary.

Update checks

Aposlop checks for a new GitHub release during interactive runs. It performs a network request at most once every 24 hours. It stores the latest result in the user cache directory. Non-interactive commands do not perform this check.

Set this environment variable to disable the check:

APOSLOP_NO_UPDATE_CHECK=1 aposlop .

Quick Start

Analyze the current directory:

aposlop .

Show the source for each duplicate:

aposlop . --terminal-output code

Run CI validation:

aposlop ci .

The ci command returns exit code 1 when a finding remains.

Write the complete report as JSON:

aposlop . --format json > aposlop-report.json

Read the full quick-start guide.


Core Features

Duplicate Detection

A block enters analysis when it meets the line and named-node limits.

Aposlop classifies block relations in this order:

  1. Type-1 requires identical canonical syntax.
  2. Type-2 allows different identifiers and literals.
  3. Type-3 requires a Jaccard similarity at or above the configured threshold.

Aposlop reports each connected set of duplicate relations as one group. A TypeScript block can match a TSX block.

Read the duplicate model.

Cyclomatic Complexity

Each valid block has an initial complexity score of 1. Aposlop adds one for each language-specific decision. Decisions include branches, loops, alternatives, exception paths, conditional expressions, and short-circuit operations.

A nested block has an independent score. Nested blocks include functions, closures, lambdas, field initializers, and static blocks.

A violation requires:

score > complexity_threshold

Read the complexity model.

Language Support

Language Extensions
Go .go
Rust .rs
Python .py
TypeScript .ts
TSX .tsx

Aposlop ignores unsupported extensions. Aposlop follows standard ignore files such as .gitignore.

Read the language guides.

Output Formats

The terminal report is the default. It contains duplicate groups, complexity findings, diagnostics, and a summary.

aposlop . --format terminal

The JSON report contains the complete report and its schema version.

aposlop . --format json

The ci command shows only the status and finding counts.

aposlop ci .

Read the output guide.

Manual Exclusions

Aposlop assigns a deterministic five-character ID to each duplicate group or complexity finding.

Add a finding to the manual exclusions:

aposlop allow aB7_x

The command writes the ID to .aposlopignore. Delete the ID from that file to restore the finding. Aposlop reports valid IDs that match no current finding as unused ignores at the end of each report. Unused ignores do not change the process exit code.


Configuration

Aposlop reads <PATH>/.aposlop.toml. Aposlop uses built-in values when this file does not exist.

[core]
min_lines = 5
min_nodes = 30
exclude = ["tests/", "vendor/", "node_modules/", "target/"]
use_cache = true

[duplicates_detection]
type_1 = true
type_2 = true
type_3 = true
type_3_threshold = 0.85

[metrics]
calculate_complexity = true
complexity_threshold = 15

Each exclude value uses the same pattern syntax as one .gitignore line. A directory pattern such as tests/ matches that directory name at any depth. Patterns can use / for root anchoring and ** for recursive directory matching.

Language and extension tables can override the core values. Command-line values override all configuration-file values.

Read the configuration guide.


CLI Quick Reference

Command or option Purpose
aposlop ci [PATH] Print a concise finding summary and fail when findings exist
aposlop allow <FINDING> [PATH] Add a finding to the target's manual exclusions
--format <terminal|json> Select the report format
--terminal-output <locations|code> Select terminal duplicate detail
--min-lines <N> Override the minimum block line count
--min-nodes <N> Override the minimum named-node count
--exclude <GLOB> Replace configured gitignore-style exclusion patterns
--use-cache <BOOL> Enable or disable the analysis cache
--type-1 <BOOL> Enable or disable Type-1 findings
--type-2 <BOOL> Enable or disable Type-2 findings
--type-3 <BOOL> Enable or disable Type-3 findings
--type-3-threshold <RATIO> Override the Type-3 threshold
--calculate-complexity <BOOL> Enable or disable complexity findings
--complexity-threshold <N> Override the complexity threshold

Read the complete CLI reference.


Contributing

Open a GitHub issue to discuss a large change. Then open a pull request.

Run these checks before you submit the pull request:

cargo fmt --all -- --check
cargo clippy --workspace --all-targets --all-features -- -D warnings
cargo test --workspace --all-features
cargo run -- --help

License

You can use Aposlop under either license:

Metadata

Release files for aposlop 1.1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for aposlop 1.1.2
File
aposlop-1.1.2-py3-none-win_arm64.whl Python 3 none Windows ARM64 Details
aposlop-1.1.2-py3-none-win_amd64.whl Python 3 none Windows x86-64 Details
aposlop-1.1.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Python 3 none Linux glibc 2.17+ x86-64 Details
aposlop-1.1.2-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl Python 3 none Linux glibc 2.17+ ARM64 Details
aposlop-1.1.2-py3-none-macosx_11_0_arm64.whl Python 3 none macOS 11.0+ ARM64 Details
aposlop-1.1.2-py3-none-macosx_10_12_x86_64.whl Python 3 none macOS 10.12+ x86-64 Details

Total release size: 21.0 MB

Release files / aposlop-1.1.2-py3-none-win_arm64.whl

Download URL aposlop-1.1.2-py3-none-win_arm64.whl
Size 3.2 MB
Tags Python 3 Windows ARM64
SHA-256 checksum
How to use checksums
8c55b75929bb9955b8abf40b0cbba8a01b124dcdd92ad9f503381ce2dd94b256
BLAKE2b-256 checksum
How to use checksums
b9d4b33889b6699d8cf9b7b5d03ab0ef69db37588df309c9bb2a60a7b90f5602
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release files / aposlop-1.1.2-py3-none-win_amd64.whl

Download URL aposlop-1.1.2-py3-none-win_amd64.whl
Size 3.3 MB
Tags Python 3 Windows x86-64
SHA-256 checksum
How to use checksums
ddf2064f0a0440200c85eeec88ceaf927de8b49b5c575fa9080914e54dcdd42f
BLAKE2b-256 checksum
How to use checksums
0107c50bd6e90098e2fe7fcd41ef33cf0e634ce096e1667a8185eb1cde12da77
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release files / aposlop-1.1.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL aposlop-1.1.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 3.8 MB
Tags Linux glibc 2.17+ x86-64 Python 3
SHA-256 checksum
How to use checksums
a4ba7c9daa7b73428498ea10b53ce277662b9229ef8647eb547cb5533fee3c3c
BLAKE2b-256 checksum
How to use checksums
a2250421d279f2982f9855b6fb94a7f5481f36ccb44864afa9dc98064f1b1403
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release files / aposlop-1.1.2-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl

Download URL aposlop-1.1.2-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Size 3.5 MB
Tags Linux glibc 2.17+ ARM64 Python 3
SHA-256 checksum
How to use checksums
21fb8f1aee532bb1e7324ebfeab744a141795f58d9dc0f72be0d943f5da95ed1
BLAKE2b-256 checksum
How to use checksums
0fcaef74ce1123ed2a025d2f57f358ada1ed67cd981c7c575302d64819ba1bf1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release files / aposlop-1.1.2-py3-none-macosx_11_0_arm64.whl

Download URL aposlop-1.1.2-py3-none-macosx_11_0_arm64.whl
Size 3.5 MB
Tags Python 3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
b9b8224326e12dbc5aeecb3896a93c73b119f5b4352d30de8493367f30f5c48a
BLAKE2b-256 checksum
How to use checksums
dd0cf7593c14d538bcdcd28602837db5d686d5cae56f7c014d3c678def666ef3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release files / aposlop-1.1.2-py3-none-macosx_10_12_x86_64.whl

Download URL aposlop-1.1.2-py3-none-macosx_10_12_x86_64.whl
Size 3.7 MB
Tags Python 3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
25f3340a7fcb146d9f1dc5813afd87cd791bbdc7978be342ca30aac5e79a7951
BLAKE2b-256 checksum
How to use checksums
7b7432646f4d50bf589bbb1d09bfb7b35e60b8bb932d6134295f29c23e842227
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release history Release notifications | RSS feed

1.2.2

6 release files

1.2.1

6 release files

1.2.0

6 release files

1.1.3

6 release files

This release

1.1.2 This release

6 release files

1.1.1

6 release files

1.1.0

6 release files

1.0.0

6 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page