Skip to content

CLI reference

depsmith-docs-bot[bot] edited this page Oct 5, 2026 · 5 revisions

CLI reference

Every option is global: it may be given before or after the command. Exit statuses: 0 success or nothing pending, 1 updates pending (check), 2 invalid request, 3 tool or scanner failure, 4 policy rejection, 5 partial success, 130 interrupted.

depsmith

Review and apply dependency updates across package managers

Usage: depsmith [OPTIONS] <COMMAND>

Commands:
  init      Choose targets and save them to depsmith.toml, offer to install each missing native tool they use (pinned, sha256-verified) into the tool cache, and report what their adapters support; exit 3 when a used tool is still missing
  discover  List the targets found under the root
  doctor    Report adapter capabilities and whether native tools are available
  check     Prepare a proposal without writing; exit 1 when updates are pending
  update    Prepare a proposal, preview it, and apply it when confirmed
  scan      Scan the current locks for known vulnerabilities without updating
  recover   Restore the files of an interrupted apply
  help      Print this message or the help of the given subcommand(s)

Options:
      --root <ROOT>
          Repository root to work in [default: .]
      --json
          Print a JSON report on stdout; diagnostics go to stderr
      --markdown
          Print a Markdown summary, for example for a CI job summary
      --non-interactive
          Never prompt; fail when a choice would be needed
      --target <TARGET>
          Target to work on, as `manager:path` (repeatable); see `discover`
      --all
          Select every discovered target
      --package <PACKAGE>
          Update only this direct dependency (repeatable)
      --accept <NAME[=REQUIREMENT]>
          Accept a suggestion: NAME (same style, evidenced version; for GitHub Actions the newest major, else a commit pin) or NAME=REQUIREMENT
      --upgrade
          Allow the selected packages' declared constraints to change (requires --package)
      --refresh-git
          Allow Git pins to move to newer commits
      --scan
          Scan the baseline and candidate for known vulnerabilities with Grype
      --install
          Also install the candidate's default environment on this host
      --fail-on <FAIL_ON>
          Reject the proposal on findings of at least this severity (negligible, low, medium, high, critical); requires --scan
      --only-new
          Apply --fail-on only to findings the update introduces
      --cooldown-days <COOLDOWN_DAYS>
          Minimum release age in days; rejected where the package manager cannot enforce it
      --timeout-seconds <TIMEOUT_SECONDS>
          Time limit for each package manager or scanner process [default: 300]
      --tool <NAME=PATH>
          Path of a native tool, as NAME=PATH (repeatable), for example `--tool pixi=/opt/pixi/bin/pixi`; `doctor` lists the tool names
      --pixi <PIXI>
          Deprecated: use `--tool pixi=PATH`
      --grype <GRYPE>
          Deprecated: use `--tool grype=PATH`
  -h, --help
          Print help
  -V, --version
          Print version

depsmith discover

List the targets found under the root

Usage: depsmith discover [OPTIONS]

Options:
      --root <ROOT>
          Repository root to work in [default: .]
      --json
          Print a JSON report on stdout; diagnostics go to stderr
      --markdown
          Print a Markdown summary, for example for a CI job summary
      --non-interactive
          Never prompt; fail when a choice would be needed
      --target <TARGET>
          Target to work on, as `manager:path` (repeatable); see `discover`
      --all
          Select every discovered target
      --package <PACKAGE>
          Update only this direct dependency (repeatable)
      --accept <NAME[=REQUIREMENT]>
          Accept a suggestion: NAME (same style, evidenced version; for GitHub Actions the newest major, else a commit pin) or NAME=REQUIREMENT
      --upgrade
          Allow the selected packages' declared constraints to change (requires --package)
      --refresh-git
          Allow Git pins to move to newer commits
      --scan
          Scan the baseline and candidate for known vulnerabilities with Grype
      --install
          Also install the candidate's default environment on this host
      --fail-on <FAIL_ON>
          Reject the proposal on findings of at least this severity (negligible, low, medium, high, critical); requires --scan
      --only-new
          Apply --fail-on only to findings the update introduces
      --cooldown-days <COOLDOWN_DAYS>
          Minimum release age in days; rejected where the package manager cannot enforce it
      --timeout-seconds <TIMEOUT_SECONDS>
          Time limit for each package manager or scanner process [default: 300]
      --tool <NAME=PATH>
          Path of a native tool, as NAME=PATH (repeatable), for example `--tool pixi=/opt/pixi/bin/pixi`; `doctor` lists the tool names
      --pixi <PIXI>
          Deprecated: use `--tool pixi=PATH`
      --grype <GRYPE>
          Deprecated: use `--tool grype=PATH`
  -h, --help
          Print help

depsmith doctor

Report adapter capabilities and whether native tools are available

Usage: depsmith doctor [OPTIONS]

Options:
      --root <ROOT>
          Repository root to work in [default: .]
      --json
          Print a JSON report on stdout; diagnostics go to stderr
      --markdown
          Print a Markdown summary, for example for a CI job summary
      --non-interactive
          Never prompt; fail when a choice would be needed
      --target <TARGET>
          Target to work on, as `manager:path` (repeatable); see `discover`
      --all
          Select every discovered target
      --package <PACKAGE>
          Update only this direct dependency (repeatable)
      --accept <NAME[=REQUIREMENT]>
          Accept a suggestion: NAME (same style, evidenced version; for GitHub Actions the newest major, else a commit pin) or NAME=REQUIREMENT
      --upgrade
          Allow the selected packages' declared constraints to change (requires --package)
      --refresh-git
          Allow Git pins to move to newer commits
      --scan
          Scan the baseline and candidate for known vulnerabilities with Grype
      --install
          Also install the candidate's default environment on this host
      --fail-on <FAIL_ON>
          Reject the proposal on findings of at least this severity (negligible, low, medium, high, critical); requires --scan
      --only-new
          Apply --fail-on only to findings the update introduces
      --cooldown-days <COOLDOWN_DAYS>
          Minimum release age in days; rejected where the package manager cannot enforce it
      --timeout-seconds <TIMEOUT_SECONDS>
          Time limit for each package manager or scanner process [default: 300]
      --tool <NAME=PATH>
          Path of a native tool, as NAME=PATH (repeatable), for example `--tool pixi=/opt/pixi/bin/pixi`; `doctor` lists the tool names
      --pixi <PIXI>
          Deprecated: use `--tool pixi=PATH`
      --grype <GRYPE>
          Deprecated: use `--tool grype=PATH`
  -h, --help
          Print help

depsmith check

Prepare a proposal without writing; exit 1 when updates are pending

Usage: depsmith check [OPTIONS]

Options:
      --root <ROOT>
          Repository root to work in [default: .]
      --json
          Print a JSON report on stdout; diagnostics go to stderr
      --markdown
          Print a Markdown summary, for example for a CI job summary
      --non-interactive
          Never prompt; fail when a choice would be needed
      --target <TARGET>
          Target to work on, as `manager:path` (repeatable); see `discover`
      --all
          Select every discovered target
      --package <PACKAGE>
          Update only this direct dependency (repeatable)
      --accept <NAME[=REQUIREMENT]>
          Accept a suggestion: NAME (same style, evidenced version; for GitHub Actions the newest major, else a commit pin) or NAME=REQUIREMENT
      --upgrade
          Allow the selected packages' declared constraints to change (requires --package)
      --refresh-git
          Allow Git pins to move to newer commits
      --scan
          Scan the baseline and candidate for known vulnerabilities with Grype
      --install
          Also install the candidate's default environment on this host
      --fail-on <FAIL_ON>
          Reject the proposal on findings of at least this severity (negligible, low, medium, high, critical); requires --scan
      --only-new
          Apply --fail-on only to findings the update introduces
      --cooldown-days <COOLDOWN_DAYS>
          Minimum release age in days; rejected where the package manager cannot enforce it
      --timeout-seconds <TIMEOUT_SECONDS>
          Time limit for each package manager or scanner process [default: 300]
      --tool <NAME=PATH>
          Path of a native tool, as NAME=PATH (repeatable), for example `--tool pixi=/opt/pixi/bin/pixi`; `doctor` lists the tool names
      --pixi <PIXI>
          Deprecated: use `--tool pixi=PATH`
      --grype <GRYPE>
          Deprecated: use `--tool grype=PATH`
  -h, --help
          Print help

depsmith update

Prepare a proposal, preview it, and apply it when confirmed

Usage: depsmith update [OPTIONS]

Options:
      --apply
          Apply the proposal (noninteractively also needs --yes)
      --yes
          Confirm applying without a prompt
      --allow-partial
          Apply the successful targets even if others failed
      --root <ROOT>
          Repository root to work in [default: .]
      --json
          Print a JSON report on stdout; diagnostics go to stderr
      --markdown
          Print a Markdown summary, for example for a CI job summary
      --non-interactive
          Never prompt; fail when a choice would be needed
      --target <TARGET>
          Target to work on, as `manager:path` (repeatable); see `discover`
      --all
          Select every discovered target
      --package <PACKAGE>
          Update only this direct dependency (repeatable)
      --accept <NAME[=REQUIREMENT]>
          Accept a suggestion: NAME (same style, evidenced version; for GitHub Actions the newest major, else a commit pin) or NAME=REQUIREMENT
      --upgrade
          Allow the selected packages' declared constraints to change (requires --package)
      --refresh-git
          Allow Git pins to move to newer commits
      --scan
          Scan the baseline and candidate for known vulnerabilities with Grype
      --install
          Also install the candidate's default environment on this host
      --fail-on <FAIL_ON>
          Reject the proposal on findings of at least this severity (negligible, low, medium, high, critical); requires --scan
      --only-new
          Apply --fail-on only to findings the update introduces
      --cooldown-days <COOLDOWN_DAYS>
          Minimum release age in days; rejected where the package manager cannot enforce it
      --timeout-seconds <TIMEOUT_SECONDS>
          Time limit for each package manager or scanner process [default: 300]
      --tool <NAME=PATH>
          Path of a native tool, as NAME=PATH (repeatable), for example `--tool pixi=/opt/pixi/bin/pixi`; `doctor` lists the tool names
      --pixi <PIXI>
          Deprecated: use `--tool pixi=PATH`
      --grype <GRYPE>
          Deprecated: use `--tool grype=PATH`
  -h, --help
          Print help

depsmith scan

Scan the current locks for known vulnerabilities without updating

Usage: depsmith scan [OPTIONS]

Options:
      --root <ROOT>
          Repository root to work in [default: .]
      --json
          Print a JSON report on stdout; diagnostics go to stderr
      --markdown
          Print a Markdown summary, for example for a CI job summary
      --non-interactive
          Never prompt; fail when a choice would be needed
      --target <TARGET>
          Target to work on, as `manager:path` (repeatable); see `discover`
      --all
          Select every discovered target
      --package <PACKAGE>
          Update only this direct dependency (repeatable)
      --accept <NAME[=REQUIREMENT]>
          Accept a suggestion: NAME (same style, evidenced version; for GitHub Actions the newest major, else a commit pin) or NAME=REQUIREMENT
      --upgrade
          Allow the selected packages' declared constraints to change (requires --package)
      --refresh-git
          Allow Git pins to move to newer commits
      --scan
          Scan the baseline and candidate for known vulnerabilities with Grype
      --install
          Also install the candidate's default environment on this host
      --fail-on <FAIL_ON>
          Reject the proposal on findings of at least this severity (negligible, low, medium, high, critical); requires --scan
      --only-new
          Apply --fail-on only to findings the update introduces
      --cooldown-days <COOLDOWN_DAYS>
          Minimum release age in days; rejected where the package manager cannot enforce it
      --timeout-seconds <TIMEOUT_SECONDS>
          Time limit for each package manager or scanner process [default: 300]
      --tool <NAME=PATH>
          Path of a native tool, as NAME=PATH (repeatable), for example `--tool pixi=/opt/pixi/bin/pixi`; `doctor` lists the tool names
      --pixi <PIXI>
          Deprecated: use `--tool pixi=PATH`
      --grype <GRYPE>
          Deprecated: use `--tool grype=PATH`
  -h, --help
          Print help

depsmith recover

Restore the files of an interrupted apply

Usage: depsmith recover [OPTIONS]

Options:
      --root <ROOT>
          Repository root to work in [default: .]
      --json
          Print a JSON report on stdout; diagnostics go to stderr
      --markdown
          Print a Markdown summary, for example for a CI job summary
      --non-interactive
          Never prompt; fail when a choice would be needed
      --target <TARGET>
          Target to work on, as `manager:path` (repeatable); see `discover`
      --all
          Select every discovered target
      --package <PACKAGE>
          Update only this direct dependency (repeatable)
      --accept <NAME[=REQUIREMENT]>
          Accept a suggestion: NAME (same style, evidenced version; for GitHub Actions the newest major, else a commit pin) or NAME=REQUIREMENT
      --upgrade
          Allow the selected packages' declared constraints to change (requires --package)
      --refresh-git
          Allow Git pins to move to newer commits
      --scan
          Scan the baseline and candidate for known vulnerabilities with Grype
      --install
          Also install the candidate's default environment on this host
      --fail-on <FAIL_ON>
          Reject the proposal on findings of at least this severity (negligible, low, medium, high, critical); requires --scan
      --only-new
          Apply --fail-on only to findings the update introduces
      --cooldown-days <COOLDOWN_DAYS>
          Minimum release age in days; rejected where the package manager cannot enforce it
      --timeout-seconds <TIMEOUT_SECONDS>
          Time limit for each package manager or scanner process [default: 300]
      --tool <NAME=PATH>
          Path of a native tool, as NAME=PATH (repeatable), for example `--tool pixi=/opt/pixi/bin/pixi`; `doctor` lists the tool names
      --pixi <PIXI>
          Deprecated: use `--tool pixi=PATH`
      --grype <GRYPE>
          Deprecated: use `--tool grype=PATH`
  -h, --help
          Print help

Clone this wiki locally