-
Notifications
You must be signed in to change notification settings - Fork 0
CI integration
depsmith-docs-bot[bot] edited this page Sep 29, 2026
·
1 revision
In CI, depsmith runs without prompts, resolves and applies in one job, and reports through exit statuses and JSON. Committing the result and opening a pull request belong to your pipeline.
depsmith check --root "$PROJECT_DIR" --all --non-interactive --json > "$REPORT_DIR/check.json"
depsmith update --root "$PROJECT_DIR" --all --apply --yes --non-interactive --json > "$REPORT_DIR/update.json"- Select targets explicitly (
--target,--all, or a saved selection); ambiguity is an error. - Keep reports outside the project while preparing and applying, so writing a report does not change the inputs the proposal was prepared from.
-
--jsonkeeps stdout valid JSON and sends diagnostics to stderr;--markdowngives a readable summary with diffs, for example for a job summary. - A proposal cannot be carried between jobs: prepare and apply in the same job.
- Scanning is opt-in: install Grype and add
--scanand the policy flags.
| Exit | Meaning |
|---|---|
| 0 | Success; check found nothing pending |
| 1 |
check found pending changes |
| 2 | Invalid arguments, configuration or selection |
| 3 | Package manager, validation, scanner or application failure |
| 4 | Policy rejection (vulnerability gate) |
| 5 | Partial success |
| 130 | Interrupted |
- GitHub Actions check: treats exit 1 as available updates and fails on other errors. Full Git history is fetched so SCM-derived versions work.
-
Provider-neutral shell job:
sh update.sh /path/to/project /outside/reports check|apply.