Check what you downloaded
Compare the printed hash with the one on the build. If they differ, don't run it.
Every build lists its SHA-256 — check it before you run it. That's true of software from anyone, including me.
Compare the printed hash with the one on the build. If they differ, don't run it.
Use apt, not dpkg -i — it pulls the
dependencies. As root the launcher adds --no-sandbox for you;
as a normal user it runs fully sandboxed.
Settings → Providers. Paste an API key — it's encrypted into the OS credential store, not a dotfile. Or skip it entirely: if Ollama is running locally, REX finds it on its own.
New session, then pick a folder. Every file and shell operation is scoped to it, and the status bar shows you which folder is live.
"Find where we verify JWTs and fix anything unsafe." REX greps, reads, proposes a diff, and waits for you before it writes a byte.
Every build here is published with its SHA-256. Check it before you run anything — including this.
Node 20+, one npm install, and npm start
builds and launches the app.