Skip to content

Repository files navigation

DEEPBOM Desktop

Inspect AI model artifacts locally, with a desktop interface and native file exports. The application bundles DEEPBOM 1.103.0 and its runtime. Node.js, Python, an AI subscription, and a DEEPBOM account are not required on the user's computer.

DEEPBOM Desktop artifact overview

Downloads

Download the current preview or visit the download page.

System Package
Windows x64 / ARM64 Setup .exe (current-user installation)
macOS Apple Silicon / Intel .dmg and application .zip
Linux x64 / ARM64 .deb and AppImage
Linux x64 Experimental strictly confined .snap

This is an initial preview. Windows installers are not Authenticode-signed and macOS builds are not Developer ID-signed or notarized. They may be blocked or warned about by operating-system security controls. Code signing is a separate release step; unsigned downloads are not represented as trusted store builds. Keep normal operating-system security settings enabled.

Ubuntu / Debian package

Download the .deb matching your architecture and, from its download directory:

sudo apt install ./DEEPBOM-Desktop-0.1.1-linux-amd64.deb
deepbom-desktop

Use the arm64 file on ARM Linux. apt installs any required system libraries.

Signed APT repository

After the release workflow deploys the repository, configure it once:

curl -fsSLo /tmp/deepbom-desktop.gpg https://junhwan-kwon.github.io/deepbom-desktop/apt/deepbom-desktop.gpg
gpg --show-keys --with-fingerprint /tmp/deepbom-desktop.gpg
sudo install -m 0644 /tmp/deepbom-desktop.gpg /usr/share/keyrings/deepbom-desktop.gpg
echo 'deb [signed-by=/usr/share/keyrings/deepbom-desktop.gpg] https://junhwan-kwon.github.io/deepbom-desktop/apt stable main' | sudo tee /etc/apt/sources.list.d/deepbom-desktop.list
sudo apt update
sudo apt install deepbom-desktop

The signing-key fingerprint is recorded in APT_KEY_FINGERPRINT.txt. Compare it before trusting the key. Updates use sudo apt update and sudo apt upgrade. The stable APT suite currently contains the explicitly labeled desktop preview; it does not imply mature-release certification or Ubuntu archive inclusion.

AppImage

chmod +x DEEPBOM-Desktop-0.1.1-linux-x86_64.AppImage
./DEEPBOM-Desktop-0.1.1-linux-x86_64.AppImage

Use the ARM64 AppImage on ARM Linux. FUSE is required by the AppImage launcher; the .deb package is the recommended Ubuntu path, including systems whose AppArmor policy restricts uninstalled Chromium applications.

Snap preview

The release contains a locally installable experimental Snap:

sudo snap install --dangerous ./DEEPBOM-Desktop-0.1.1-linux-amd64.snap
snap run deepbom-desktop

Here --dangerous means the file lacks Snap Store assertions; it does not switch off strict confinement. The Snap can read normal files under your home directory. Hidden directories are restricted by the home interface. Reading external drives requires sudo snap connect deepbom-desktop:removable-media.

The application is not yet published in the Snap Store. A bare sudo snap install deepbom-desktop is not offered until the publisher registers the name and uploads an approved build. See publishing.

Windows and macOS

On Windows, run the downloaded Setup .exe for x64 or ARM64 and use the Start menu entry. On macOS, open the matching .dmg and drag DEEPBOM Desktop into Applications. The .zip contains the same application bundle.

Inspect and export

  1. Open or drop one .onnx, .tflite, .gguf, .safetensors, .mlmodel, .pte, or .ptd file.
  2. Choose Automatic or Full inspection, then Inspect artifact.
  3. Review Overview, Structure, Visualization, and Findings.
  4. Save evidence JSON, CycloneDX 1.7, SPDX 2.3, architecture SVG/PNG, or a ZIP of canonical model views. Each save opens the operating system's Save dialog.
  5. Use Compare with another model for a second artifact in the same format.

Artifacts and reports are held locally. The renderer blocks network requests; the CLI uses --offline. No telemetry, accounts, automatic update requests, or hosted endpoints are used. Downloading/installing the software and APT updates do of course use the network.

The inspector never executes model code. Formats have different static evidence coverage. Storage containers do not acquire a fabricated execution graph. MAC counts are not latency measurements; static checks do not establish model accuracy, safety, clinical validity, or regulatory compliance.

Scope of this release

  • Single-file inspection is supported. Sharded directories, .mlpackage, and explicit external-data root selection remain CLI workflows in this preview.
  • Model operation rows are paginated and searchable; all findings are retained.
  • Large reports are capped at 96 MiB and a parser task at ten minutes; exceeding a limit produces an explicit error. The CLI's format-specific memory limits still apply. This does not promise inspection of arbitrarily large files.
  • Exports that re-read a file verify its SHA-256 against the inspected artifact. Evidence JSON and comparison JSON are saved snapshots and retain their hashes.
  • The GUI provides static artifact inspection and comparison. The hosted web workbench's account, research, and optional runtime features are not included.
  • AI-host integrations are separate packages. This app itself does not connect to ChatGPT, Claude, or Antigravity.

Development

Node.js 22+ is required for development only:

npm ci
npm test
npm start
npm run build:linux

Run npm run build:windows on Windows, npm run build:mac on macOS, and npm run build:snap on Linux x64. Snap builds require tar and squashfs-tools (sudo apt install squashfs-tools). GitHub Actions builds and exercises the packaged application on six native OS/architecture runners before publishing.

GUI checks: npm run test:desktop, or xvfb-run -a npm run test:desktop in Linux CI. The optional DESKTOP_TEST_NO_SANDBOX=1 belongs exclusively to the CI test harness on hosts where user namespaces are unavailable; DEB and AppImage launchers do not add that flag. The strict Snap uses electron-builder's standard launcher, which disables Chromium's inner sandbox and relies on Snap's outer confinement. Renderer context isolation, Node integration disabled, IPC sender validation, navigation blocking, and permission denial remain on.

Licensed under Apache-2.0. See NOTICE and vendor/provenance.json for the public engine and projection sources. Support: https://github.com/JunHwan-Kwon/deepbom-desktop/issues.

About

Offline desktop inspection of AI model artifacts for Windows, macOS, and Linux

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages