Preview 0.1.1 Out now for Apple silicon Macs and Windows x64. Google sign-in is open; installers aren't signed yet. Here's what's tested and what isn't →

A desktop app for macOS & Windows · Free and open source

Know what a repo needs before you run it.

Paste a public GitHub or GitLab link. Reporun reads the project's manifest files, compares them with what's installed on your computer, and gives you a plain list of what's missing — with the exact commands to fix it, shown to you before anything runs.

Version 0.1.1 preview · macOS (Apple silicon) and Windows (x64) · Free

Reporun showing a sample check of acme/studio: Git and Node.js compatible, pnpm and Docker not installed, Python version mismatch, and an install plan for Python waiting for confirmation.

Reporun

01 The problem

"Just run npm install."

Most READMEs assume your computer is set up like the author's. When it isn't, you find out one error at a time: the wrong package manager, a runtime that's too new, a tool you never installed.

Each fix takes a search, and each search turns up the next problem. In the example on the right, it takes four commands to discover three issues — and nothing works yet.

With Reporun you'd see all three in one list before cloning anything, each with the command that fixes it.
~/code — zsh

          

02 How it works

Four steps, in this order.
You approve the last one.

  1. 01

    Paste a link

    Any public repository on github.com or gitlab.com. Reporun checks the current default branch and pins the result to that exact commit, so the check and the download always match.

    https://github.com/acme/studio→ pinned to a1b2c3d
  2. 02

    Read the manifests

    It fetches only the files that describe requirements — package.json, pyproject.toml, Cargo.toml, go.mod, Dockerfiles and so on. Nothing is cloned at this point.

    Up to 35 files · 5 folders deep · 150 KB each
  3. 03

    Compare with your computer

    Installed versions are checked against the ranges the project declares. Anything missing, too old or too new is listed with the file it came from and a short explanation.

    Python 3.13.2needs >=3.10 <3.13 → mismatch
  4. 04

    Review, then run

    Every install, download and launch is shown as the exact command first. Output streams live, you can stop a job at any time, and an unused plan expires after five minutes.

    brew install python@3.10waiting for you

03 What it reads

Eight languages, plus Docker
and environment files.

The full list. If a file or version format isn't supported, Reporun says so in the report instead of guessing.

EcosystemFiles it readsWhat it can set up or launch
JavaScript / TypeScriptpackage.json (engines, packageManager), Volta, .nvmrc, .node-version, lockfile namesnpm, pnpm, Yarn or Bun install; any script in package.json
Pythonpyproject.toml, requirements.txt, .python-version, Pipfileuv, Poetry, or an isolated .venv with pip; launch follows the README
RustCargo.toml, rust-toolchain.tomlcargo fetch, cargo run
Gogo.modgo mod download, go run .
Javapom.xml, build.gradle(.kts)Maven dependencies or Gradle build; launch follows the README
RubyGemfile, .ruby-versionbundle install; launch follows the README
PHPcomposer.jsoncomposer install; launch follows the README
.NETglobal.json, .csprojdotnet restore, dotnet run
ContainersDockerfile, Compose service namesChecks the Docker CLI and daemon; you start containers yourself
Environment.tool-versions, .env.example, .env.sampleVariable names only — never values

Missing tools are installed through Homebrew on macOS or winget on Windows, from a curated list. Package-manager versions are installed with npm, with lifecycle scripts turned off.

04 Who it's for

Anyone setting up
code they didn't write.

Students and new developers

Get a course or tutorial repo running without a day lost to setup.

Developers trying a tool

See what a project will change on your computer before you clone it.

Maintainers and teachers

See your project the way a fresh computer sees it, and catch setup gaps before your users do.

Teams onboarding people

New laptop, new hire, old service. Compare what the repo expects with what's installed.

05 Safety

It reads first,
and asks before it runs.

Reporun was built around one rule: you should see every command before it touches your computer.

Worth knowing: installing or starting a project runs that project's own code (and its dependencies') after you confirm. Reporun shows you exactly what will run, but it doesn't sandbox the project itself. Only run code you trust.
  • GitHub token optionalChecks use public APIs by default. A read-only GitHub token raises your rate limit; it's validated, encrypted on your computer, sent only to GitHub's API and never synced.
  • Plans run once, then expireCommands are prepared by the app itself, tied to your session, and expire after five minutes. The interface can't submit its own commands.
  • Careful downloadsRepositories are fetched over HTTPS with inherited Git hooks and config turned off. Git LFS files and submodules aren't fetched automatically.
  • No install scriptsPackage managers installed through npm use --ignore-scripts.
  • Secrets stay localSign-in tokens use your operating system's secure storage. Environment values, local paths and logs are never uploaded.

06 Limits

What it won't do
(at least not yet).

07 Build status

Where things stand.

v0.1.1 Development preview

New in this version

  • Hit a GitHub or GitLab rate limit and you get a live countdown to the retry time from the provider's own headers. If it doesn't send one, Reporun says so instead of guessing.
  • Rate limits, access denied (403) and invalid credentials (401) now get separate explanations.
  • No repeat requests during a known cooldown. A scan that gets throttled while reading manifests stops instead of handing you a half-finished report.
  • Optional GitHub token in Settings for a higher allowance, checked with GitHub before it's saved, removable any time.
  • Unchanged commits reuse cached files for ten minutes. Repository visibility, the branch's latest commit and your installed tools are checked fresh every time.

Tested

  • 59 engine tests, 6 interface tests and the production build pass
  • The countdown worked against a real GitHub rate limit in the packaged Mac app
  • On a Mac: the app launches, Google sign-in works, history syncs, and both persist after a restart
  • Google sign-in is published for all Google accounts
  • Packaged app files match a fresh build of the published source
  • SHA-256 checksums published for both installers

Still being verified

  • Signed and notarized macOS installer
  • Windows signing and a full run on real Windows hardware (the installer is cross-built and hasn't been tested on Windows yet)
  • Intel Mac and Windows ARM64 installers
  • Installing and launching real third-party projects, end to end
v0.1.0 First preview: public GitHub/GitLab checks, local compatibility checks, reviewed install and run plans, Google sign-in and account history.

Release notes and checksums · Full changelog

08 Download

Get Reporun.

Pick your platform below.

Version 0.1.1 is a development preview. The installers aren't code-signed yet and the Mac app isn't notarized, so your system may warn you or block it; please don't turn off its security protections to get around that. Signed builds will follow. Intel Mac, Windows ARM64 and Linux builds aren't available yet. You don't need Node.js or anything else installed to open the app. Release notes and checksums

09 FAQ

Questions people ask.

Is it free?

Yes. Reporun is free and open source under the MIT license.

Do I need Node.js or other tools installed first?

No. The app runs on its own. It tells you which tools a particular repository needs, and can install them through Homebrew (macOS) or winget (Windows) if you have those.

Which repositories can it check?

Public repositories on github.com and gitlab.com, on their default branch. Private repositories aren't supported, even with a token.

Will it install or run anything without asking?

No. Every action is shown as a command preview first. A plan can only run once and expires after five minutes.

Do I have to sign in?

Yes, to check repositories. Sign-in is with Google and keeps your 100 most recent checks across devices. Google sign-in is open to all Google accounts. You can explore the sample report and see what's installed on your computer before signing in. What syncs: repository details, the requirements found, the relevant installed versions, and your OS name and architecture. Full tool lists, local paths, environment values, logs and GitHub tokens stay on your computer.

What happens if I hit a rate limit?

GitHub and GitLab limit how many API requests you can make without an account. When you reach the limit, Reporun shows a live countdown and the local time you can try again, taken from the provider's response. It won't keep retrying in the background. For more headroom, add a fine-grained, read-only GitHub token under Settings → GitHub connection. It's only sent to GitHub's API, never to GitLab or the account service.

Can I trust a "ready" result completely?

Treat it as a strong starting point. Reporun reads what a project declares. Undocumented steps, credentials and external services are outside what it can see, and the report tells you when a file couldn't be read or a version format isn't supported.

Paste a link.
See what's missing.

Download Reporun