Install
Vulkro is a single self-contained binary. There is nothing to compile and no runtime to install.
Install in one line
macOS and Linux:
curl -fsSL https://dist.vulkro.com/install.sh | bash
Windows (PowerShell):
iwr -useb https://dist.vulkro.com/install.ps1 | iex
The installer picks the right binary for your machine, checks its signature,
installs it to /usr/local/bin (or ~/.local/bin if that is not writable),
and downloads the latest CVE data so dependency scanning works right away.
Connect your account
You need a free account to run scans. After installing, sign in:
vulkro login
Your first sign-in on a machine starts a 14-day trial of the full product, no card required. After that, the CLI keeps a signed license that refreshes about once a day in the background, so short spells offline (travel, flaky Wi-Fi) never interrupt your work. The check only ever confirms your license and counts usage. It never sees your code, your file paths, or your findings.
When the trial ends, request a license from our team at
license@vulkro.com. Vulkro is licensed per seat.
Running vulkro buy opens a pre-filled request email; we reply with a license
file you install using vulkro activate <file.lic>.
For the full account model, see Accounts and licensing.
Air-gapped install
If the machine cannot reach the internet, ask us for an offline bundle (the binary plus a signed CVE bundle) and a license file. On the target machine:
# apply the signed CVE bundle
vulkro update --bundle ./vulkro-cve-<date>.vkbundle
# install the license (replaces `vulkro login` on air-gapped machines)
vulkro activate ./your-team.lic
Set VULKRO_OFFLINE=1 and Vulkro makes no network calls at all. The license
file satisfies the account requirement with no internet access.
Staying up to date
Vulkro never checks for updates behind your back. A plain vulkro scan makes no
network request and shows no update notice. When you want to update:
vulkro update
This checks for a newer version, offers to install it, and then refreshes your CVE data. In CI the prompt is skipped automatically, so pipelines are never blocked.
Installer options
Set these before running the installer to change its behavior:
| Variable | Effect |
|---|---|
VULKRO_VERSION=v0.3.0 | Install a specific version. |
VULKRO_BIN_DIR=/opt/bin | Install somewhere else. |
VULKRO_OFFLINE=1 | Make no network calls, including the first-run CVE download. |
VULKRO_NO_ANALYTICS=1 | Skip the anonymous install ping (product, OS, and version only). |
Scanning Salesforce?
Salesforce code and orgs use a separate product, vulkro-sf, with its own
installer:
curl -fsSL https://dist.vulkro.com/install-sf.sh | bash
See the Vulkro for Salesforce install guide for the full walk-through.