Download both the Linux archive and its SHA-256 checksum into one directory.

```sh
sha256sum -c githerald-linux-x64-glibc.tar.gz.sha256
tar -xzf githerald-linux-x64-glibc.tar.gz
cd githerald-linux-x64-glibc-*
```

# GitHerald local package

This archive is a single-user GitHerald app for **Linux x64 with glibc**. It contains the built SvelteKit web UI, API, and locked runtime JavaScript and native SQLite addon. Use the Node version named in `MANIFEST.json` for this exact archive. The same manifest records the native addon's minimum GLIBC and GLIBCXX symbol versions (`nativeGlibcMin` and `nativeGlibcxxMin`); the target system must provide compatible glibc and libstdc++. Building from source requires Node.js 22.12 or newer.

GitHerald needs a GitHub OAuth App and a key for one supported AI provider. No key or user database is included in this archive. Configure the GitHub OAuth App callback URL as `http://127.0.0.1:5550/api/auth/github/callback` (replace the port only if you deliberately set `GITHERALD_LOCAL_PORT`). Do not use the source development URL `localhost:5550` for this package's OAuth App.

From the extracted archive, choose an **absolute directory** for private GitHerald data. Keep using the same directory on every run:

```bash
node bin/githerald.mjs init --data-dir /absolute/private/githerald
# Edit /absolute/private/githerald/app.env with GITHUB_CLIENT_ID,
# GITHUB_CLIENT_SECRET, LLM_PROVIDER and its matching provider API key.
node bin/githerald.mjs check --data-dir /absolute/private/githerald
node bin/githerald.mjs start --data-dir /absolute/private/githerald
```

Open `http://127.0.0.1:5550`. The app binds only to loopback. `init` creates the chosen data directory with mode 0700 and `app.env` with mode 0600; it does not create or reset the database. The first app database access creates `githerald.db`. Repeating `init` preserves existing config and database bytes. `check` validates permissions, required configuration and the bundled SQLite addon without starting a listener or changing the database. An existing database is never silently replaced or migrated by these package commands; the application retains its reviewed legacy session-expiry migration when opened.

`app.env` supports `GITHUB_CLIENT_ID`, `GITHUB_CLIENT_SECRET`, `LLM_PROVIDER`, `LLM_MODEL`, `ANTHROPIC_API_KEY`, `OPENAI_API_KEY`, `GOOGLE_GENERATIVE_AI_API_KEY`, and `OPENROUTER_API_KEY`. Choose a provider and configure its key. Keep `app.env` private. The launcher sets `GITHERALD_DB_PATH`, `GITHERALD_APP_ORIGIN`, `HOST` and `PORT` from the selected directory and loopback port. `GITHERALD_LOCAL_PORT` may be set to an integer from 1024 to 65535; update the GitHub callback URL to the same port. Running two copies against the same SQLite file is not a supported multi-instance deployment.

The web app reads private GitHub repositories through the signed-in user's OAuth token. Generation calls the configured AI provider and can incur provider charges; reviewing and publishing are separate actions. This package runs a single-user local instance; public or multi-user hosting requires a separate deployment configuration.
