Skip to content

Repository files navigation

osaat

Audit and back up installed applications on macOS, Linux, and Unix. Produces a structured inventory plus a restoration manifest you can run on a new machine.

The binary is osaat.

Install

Homebrew (macOS, Linux):

brew install simtabi/tap/osaat

Go (any supported platform):

go install github.com/simtabi/osaat/cmd/osaat@latest

Direct binary: see the latest release. Pre-built binaries cover macOS (Intel + Apple Silicon), Linux (amd64, arm64, 386, armv7), Windows (amd64, arm64, 386), and FreeBSD (amd64, arm64, 386).

Zero-dep Bash fallback (macOS only): for the cold-start case where Go and Homebrew aren't installed yet, use scripts/bash-fallback.sh. It produces a JSON report compatible with the Go binary's schema. See docs/tools/bash-fallback.md.

Quick start

# Interactive wizard — auto-opens when stdin is a TTY and no flags are passed
osaat scan

# Headless
osaat scan --os macos --format pdf,markdown,txt,json --out ~/backup/

The wizard collects every setting, runs the scan, and prints the equivalent non-interactive command at the end. Wizard answers can be saved as named profiles (osaat scan --profile <name>).

What gets captured

For every detected app: name, author, vendor URL, installation source (App Store / Homebrew / pkg / DMG / direct download / system / sandbox / unknown), original download URL, version, install date, last-used date, size on disk, signing status, Apple Silicon compatibility (macOS), and a reinstall command.

License keys, when detectable, go to a separate secrets.json — unredacted and grouped by category — never to the audit report. Optional age encryption is supported via --age-recipient.

File locations

What Where
Generated audit outputs <Documents>/osaat/<YYYY-MM-DD>/ by default (overridable via --out or the wizard)
Daily log file (mode 600) ~/.config/osaat/logs/osaat-<YYYY-MM-DD>.log
Named profiles (mode 600) ~/.config/osaat/profiles/<name>.toml
Secrets file (mode 600) <output>/secrets.json or <output>/secrets.json.age
Output integrity checksums <output>/SHA256SUMS

The Documents folder is auto-detected per OS:

  • macOS / Windows: $HOME/Documents/osaat (or %USERPROFILE%\Documents\osaat).
  • Linux / BSD: $XDG_DOCUMENTS_DIR/osaat, falling back to $HOME/Documents/osaat.

Privacy

osaat never sends data over the network. Logs are written to disk with $HOME paths replaced by ~ and hostname-shaped attributes redacted, so a stolen log file doesn't identify the machine.

Output formats

Format File Use
PDF report.pdf Print-ready, paginated. Default.
Markdown report.md Renders cleanly on GitHub or in editors. Default.
Plain text report.txt grep-friendly, no rendering deps. Default.
JSON report.json Machine-readable. Required for osaat diff. Default.
CSV report.csv Spreadsheet imports.
HTML report.html Self-contained file with sortable table + filter input.

Documentation

End-user documentation for osaat. Project-internal design notes live in .design/ and are not shipped with releases.

Document What it covers
Installation How to install on macOS, Linux, BSD
Configuration Config file format, environment variables, profiles
Architecture What the tool does and how it does it, at a level useful for contributors
Release process How a release is cut and how the Homebrew tap is updated
Migration / shipping checklist Step-by-step migration runbook

Per-command reference:

Command Doc
osaat scan tools/scan.md
osaat diff tools/diff.md
osaat restore-help tools/restore-help.md
osaat install-schedule tools/install-schedule.md
osaat backup tools/backup.md
bash-fallback.sh tools/bash-fallback.md

Each document records its current status in its header. Documents are filled in as the feature they cover ships; the skeletons were created in Phase 0.

License

MIT — see LICENSE. Copyright © 2026 Simtabi LLC.

About

Audit and back up installed applications on macOS, Linux, and Unix.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages