-
Notifications
You must be signed in to change notification settings - Fork 0
CLI reference
depsmith-docs-bot[bot] edited this page Oct 5, 2026
·
5 revisions
Every option is global: it may be given before or after the command.
Exit statuses: 0 success or nothing pending, 1 updates pending (check),
2 invalid request, 3 tool or scanner failure, 4 policy rejection,
5 partial success, 130 interrupted.
Review and apply dependency updates across package managers
Usage: depsmith [OPTIONS] <COMMAND>
Commands:
init Choose targets and save them to depsmith.toml, offer to install each missing native tool they use (pinned, sha256-verified) into the tool cache, and report what their adapters support; exit 3 when a used tool is still missing
discover List the targets found under the root
doctor Report adapter capabilities and whether native tools are available
check Prepare a proposal without writing; exit 1 when updates are pending
update Prepare a proposal, preview it, and apply it when confirmed
scan Scan the current locks for known vulnerabilities without updating
recover Restore the files of an interrupted apply
help Print this message or the help of the given subcommand(s)
Options:
--root <ROOT>
Repository root to work in [default: .]
--json
Print a JSON report on stdout; diagnostics go to stderr
--markdown
Print a Markdown summary, for example for a CI job summary
--non-interactive
Never prompt; fail when a choice would be needed
--target <TARGET>
Target to work on, as `manager:path` (repeatable); see `discover`
--all
Select every discovered target
--package <PACKAGE>
Update only this direct dependency (repeatable)
--accept <NAME[=REQUIREMENT]>
Accept a suggestion: NAME (same style, evidenced version; for GitHub Actions the newest major, else a commit pin) or NAME=REQUIREMENT
--upgrade
Allow the selected packages' declared constraints to change (requires --package)
--refresh-git
Allow Git pins to move to newer commits
--scan
Scan the baseline and candidate for known vulnerabilities with Grype
--install
Also install the candidate's default environment on this host
--fail-on <FAIL_ON>
Reject the proposal on findings of at least this severity (negligible, low, medium, high, critical); requires --scan
--only-new
Apply --fail-on only to findings the update introduces
--cooldown-days <COOLDOWN_DAYS>
Minimum release age in days; rejected where the package manager cannot enforce it
--timeout-seconds <TIMEOUT_SECONDS>
Time limit for each package manager or scanner process [default: 300]
--tool <NAME=PATH>
Path of a native tool, as NAME=PATH (repeatable), for example `--tool pixi=/opt/pixi/bin/pixi`; `doctor` lists the tool names
--pixi <PIXI>
Deprecated: use `--tool pixi=PATH`
--grype <GRYPE>
Deprecated: use `--tool grype=PATH`
-h, --help
Print help
-V, --version
Print version
List the targets found under the root
Usage: depsmith discover [OPTIONS]
Options:
--root <ROOT>
Repository root to work in [default: .]
--json
Print a JSON report on stdout; diagnostics go to stderr
--markdown
Print a Markdown summary, for example for a CI job summary
--non-interactive
Never prompt; fail when a choice would be needed
--target <TARGET>
Target to work on, as `manager:path` (repeatable); see `discover`
--all
Select every discovered target
--package <PACKAGE>
Update only this direct dependency (repeatable)
--accept <NAME[=REQUIREMENT]>
Accept a suggestion: NAME (same style, evidenced version; for GitHub Actions the newest major, else a commit pin) or NAME=REQUIREMENT
--upgrade
Allow the selected packages' declared constraints to change (requires --package)
--refresh-git
Allow Git pins to move to newer commits
--scan
Scan the baseline and candidate for known vulnerabilities with Grype
--install
Also install the candidate's default environment on this host
--fail-on <FAIL_ON>
Reject the proposal on findings of at least this severity (negligible, low, medium, high, critical); requires --scan
--only-new
Apply --fail-on only to findings the update introduces
--cooldown-days <COOLDOWN_DAYS>
Minimum release age in days; rejected where the package manager cannot enforce it
--timeout-seconds <TIMEOUT_SECONDS>
Time limit for each package manager or scanner process [default: 300]
--tool <NAME=PATH>
Path of a native tool, as NAME=PATH (repeatable), for example `--tool pixi=/opt/pixi/bin/pixi`; `doctor` lists the tool names
--pixi <PIXI>
Deprecated: use `--tool pixi=PATH`
--grype <GRYPE>
Deprecated: use `--tool grype=PATH`
-h, --help
Print help
Report adapter capabilities and whether native tools are available
Usage: depsmith doctor [OPTIONS]
Options:
--root <ROOT>
Repository root to work in [default: .]
--json
Print a JSON report on stdout; diagnostics go to stderr
--markdown
Print a Markdown summary, for example for a CI job summary
--non-interactive
Never prompt; fail when a choice would be needed
--target <TARGET>
Target to work on, as `manager:path` (repeatable); see `discover`
--all
Select every discovered target
--package <PACKAGE>
Update only this direct dependency (repeatable)
--accept <NAME[=REQUIREMENT]>
Accept a suggestion: NAME (same style, evidenced version; for GitHub Actions the newest major, else a commit pin) or NAME=REQUIREMENT
--upgrade
Allow the selected packages' declared constraints to change (requires --package)
--refresh-git
Allow Git pins to move to newer commits
--scan
Scan the baseline and candidate for known vulnerabilities with Grype
--install
Also install the candidate's default environment on this host
--fail-on <FAIL_ON>
Reject the proposal on findings of at least this severity (negligible, low, medium, high, critical); requires --scan
--only-new
Apply --fail-on only to findings the update introduces
--cooldown-days <COOLDOWN_DAYS>
Minimum release age in days; rejected where the package manager cannot enforce it
--timeout-seconds <TIMEOUT_SECONDS>
Time limit for each package manager or scanner process [default: 300]
--tool <NAME=PATH>
Path of a native tool, as NAME=PATH (repeatable), for example `--tool pixi=/opt/pixi/bin/pixi`; `doctor` lists the tool names
--pixi <PIXI>
Deprecated: use `--tool pixi=PATH`
--grype <GRYPE>
Deprecated: use `--tool grype=PATH`
-h, --help
Print help
Prepare a proposal without writing; exit 1 when updates are pending
Usage: depsmith check [OPTIONS]
Options:
--root <ROOT>
Repository root to work in [default: .]
--json
Print a JSON report on stdout; diagnostics go to stderr
--markdown
Print a Markdown summary, for example for a CI job summary
--non-interactive
Never prompt; fail when a choice would be needed
--target <TARGET>
Target to work on, as `manager:path` (repeatable); see `discover`
--all
Select every discovered target
--package <PACKAGE>
Update only this direct dependency (repeatable)
--accept <NAME[=REQUIREMENT]>
Accept a suggestion: NAME (same style, evidenced version; for GitHub Actions the newest major, else a commit pin) or NAME=REQUIREMENT
--upgrade
Allow the selected packages' declared constraints to change (requires --package)
--refresh-git
Allow Git pins to move to newer commits
--scan
Scan the baseline and candidate for known vulnerabilities with Grype
--install
Also install the candidate's default environment on this host
--fail-on <FAIL_ON>
Reject the proposal on findings of at least this severity (negligible, low, medium, high, critical); requires --scan
--only-new
Apply --fail-on only to findings the update introduces
--cooldown-days <COOLDOWN_DAYS>
Minimum release age in days; rejected where the package manager cannot enforce it
--timeout-seconds <TIMEOUT_SECONDS>
Time limit for each package manager or scanner process [default: 300]
--tool <NAME=PATH>
Path of a native tool, as NAME=PATH (repeatable), for example `--tool pixi=/opt/pixi/bin/pixi`; `doctor` lists the tool names
--pixi <PIXI>
Deprecated: use `--tool pixi=PATH`
--grype <GRYPE>
Deprecated: use `--tool grype=PATH`
-h, --help
Print help
Prepare a proposal, preview it, and apply it when confirmed
Usage: depsmith update [OPTIONS]
Options:
--apply
Apply the proposal (noninteractively also needs --yes)
--yes
Confirm applying without a prompt
--allow-partial
Apply the successful targets even if others failed
--root <ROOT>
Repository root to work in [default: .]
--json
Print a JSON report on stdout; diagnostics go to stderr
--markdown
Print a Markdown summary, for example for a CI job summary
--non-interactive
Never prompt; fail when a choice would be needed
--target <TARGET>
Target to work on, as `manager:path` (repeatable); see `discover`
--all
Select every discovered target
--package <PACKAGE>
Update only this direct dependency (repeatable)
--accept <NAME[=REQUIREMENT]>
Accept a suggestion: NAME (same style, evidenced version; for GitHub Actions the newest major, else a commit pin) or NAME=REQUIREMENT
--upgrade
Allow the selected packages' declared constraints to change (requires --package)
--refresh-git
Allow Git pins to move to newer commits
--scan
Scan the baseline and candidate for known vulnerabilities with Grype
--install
Also install the candidate's default environment on this host
--fail-on <FAIL_ON>
Reject the proposal on findings of at least this severity (negligible, low, medium, high, critical); requires --scan
--only-new
Apply --fail-on only to findings the update introduces
--cooldown-days <COOLDOWN_DAYS>
Minimum release age in days; rejected where the package manager cannot enforce it
--timeout-seconds <TIMEOUT_SECONDS>
Time limit for each package manager or scanner process [default: 300]
--tool <NAME=PATH>
Path of a native tool, as NAME=PATH (repeatable), for example `--tool pixi=/opt/pixi/bin/pixi`; `doctor` lists the tool names
--pixi <PIXI>
Deprecated: use `--tool pixi=PATH`
--grype <GRYPE>
Deprecated: use `--tool grype=PATH`
-h, --help
Print help
Scan the current locks for known vulnerabilities without updating
Usage: depsmith scan [OPTIONS]
Options:
--root <ROOT>
Repository root to work in [default: .]
--json
Print a JSON report on stdout; diagnostics go to stderr
--markdown
Print a Markdown summary, for example for a CI job summary
--non-interactive
Never prompt; fail when a choice would be needed
--target <TARGET>
Target to work on, as `manager:path` (repeatable); see `discover`
--all
Select every discovered target
--package <PACKAGE>
Update only this direct dependency (repeatable)
--accept <NAME[=REQUIREMENT]>
Accept a suggestion: NAME (same style, evidenced version; for GitHub Actions the newest major, else a commit pin) or NAME=REQUIREMENT
--upgrade
Allow the selected packages' declared constraints to change (requires --package)
--refresh-git
Allow Git pins to move to newer commits
--scan
Scan the baseline and candidate for known vulnerabilities with Grype
--install
Also install the candidate's default environment on this host
--fail-on <FAIL_ON>
Reject the proposal on findings of at least this severity (negligible, low, medium, high, critical); requires --scan
--only-new
Apply --fail-on only to findings the update introduces
--cooldown-days <COOLDOWN_DAYS>
Minimum release age in days; rejected where the package manager cannot enforce it
--timeout-seconds <TIMEOUT_SECONDS>
Time limit for each package manager or scanner process [default: 300]
--tool <NAME=PATH>
Path of a native tool, as NAME=PATH (repeatable), for example `--tool pixi=/opt/pixi/bin/pixi`; `doctor` lists the tool names
--pixi <PIXI>
Deprecated: use `--tool pixi=PATH`
--grype <GRYPE>
Deprecated: use `--tool grype=PATH`
-h, --help
Print help
Restore the files of an interrupted apply
Usage: depsmith recover [OPTIONS]
Options:
--root <ROOT>
Repository root to work in [default: .]
--json
Print a JSON report on stdout; diagnostics go to stderr
--markdown
Print a Markdown summary, for example for a CI job summary
--non-interactive
Never prompt; fail when a choice would be needed
--target <TARGET>
Target to work on, as `manager:path` (repeatable); see `discover`
--all
Select every discovered target
--package <PACKAGE>
Update only this direct dependency (repeatable)
--accept <NAME[=REQUIREMENT]>
Accept a suggestion: NAME (same style, evidenced version; for GitHub Actions the newest major, else a commit pin) or NAME=REQUIREMENT
--upgrade
Allow the selected packages' declared constraints to change (requires --package)
--refresh-git
Allow Git pins to move to newer commits
--scan
Scan the baseline and candidate for known vulnerabilities with Grype
--install
Also install the candidate's default environment on this host
--fail-on <FAIL_ON>
Reject the proposal on findings of at least this severity (negligible, low, medium, high, critical); requires --scan
--only-new
Apply --fail-on only to findings the update introduces
--cooldown-days <COOLDOWN_DAYS>
Minimum release age in days; rejected where the package manager cannot enforce it
--timeout-seconds <TIMEOUT_SECONDS>
Time limit for each package manager or scanner process [default: 300]
--tool <NAME=PATH>
Path of a native tool, as NAME=PATH (repeatable), for example `--tool pixi=/opt/pixi/bin/pixi`; `doctor` lists the tool names
--pixi <PIXI>
Deprecated: use `--tool pixi=PATH`
--grype <GRYPE>
Deprecated: use `--tool grype=PATH`
-h, --help
Print help