Inspect security evidence next to the code.
The editor surface exposes findings, evidence, verification state, policy, remediation state, and persistent project security context without collapsing them into one score.
Install from MarketplaceDevelopers
The shortest supported path is the VS Code extension. Aegis manages the developer-facing runtime integration around the editor while the underlying trust model remains available through the GitHub Action and local CLI/API surfaces.
Quick start
No repository clone, Python environment, or manually started web server is part of the public VS Code install path described by this release.
Use the Marketplace or the VS Code CLI command below.
The extension is the primary developer surface for the packaged Aegis workflow.
Inspect claims, evidence, verification state, remediation, and policy from the supported product surface.
Platform support is stated before installation so macOS and Windows users are not surprised after the extension is installed.
Product surfaces
The capture below comes from the repository’s launch asset. GitHub Action and CLI details are described as capabilities rather than dressed up as fake product screens.
The editor surface exposes findings, evidence, verification state, policy, remediation state, and persistent project security context without collapsing them into one score.
Install from MarketplaceThe public GitHub Action is a thin integration surface for the versioned Aegis runtime and machine-readable verification artifacts. The proprietary runtime core stays separate.
Inspect the public repositoryCLI and local API workflows use the same trust model. The current packaged runtime target published by this repository is Linux x64.
Read the developer contractA security decision should carry the checks and evidence that contributed to it, including missing or incomplete steps.
Analysis does not imply permission to execute. Controlled validation remains separately authorized and constrained.
A patch proposal and a post-change verification result are distinct lifecycle states.
The public repository contains the developer integration surface, release contracts, and security policy. The proprietary runtime core is distributed separately rather than published merely to make installation easier.