-
Notifications
You must be signed in to change notification settings - Fork 0
Configuration
Repository defaults live in depsmith.toml at the repository root:
targets = ["pixi:pixi.toml", "github-actions:.github/workflows/ci.yml"]
[options]
timeout_seconds = 300
upgrade = false-
targetsis the saved selection, used when no--target/--all(CLI) ortargets=(Python) is given. -
[options]accepts the fields ofUpdateOptions(see the Python API); unknown fields are an error. - Explicit CLI flags and Python options override the file.
- Native package-manager configuration stays authoritative for ecosystem
behaviour. Native Pixi configuration in
.pixi/config.tomlis staged even when.pixi/is ignored.
Each adapter declares the native tools it runs; depsmith doctor lists them
by name. Point one at a specific executable with [options.tools], the
repeatable --tool NAME=PATH flag, or UpdateOptions(tools={...}) in Python:
[options.tools]
pixi = "/opt/pixi/bin/pixi"
grype = "/usr/local/bin/grype"
conda = "/opt/micromamba/bin/micromamba" # the solver conda-lock drives--pixi and --grype (and the matching option fields) still work as
deprecated aliases.
depsmith init chooses targets and saves them as targets: it offers the
discovered targets a package manager at a time (then file by file when a
group is declined), or takes --all / --target, and appends the choice.
Saved targets are never removed; a saved target that is no longer found is
reported and skipped. --no-save leaves the file alone. The rest of the file
and its comments are kept.
When no targets are configured, an interactive check or update asks in the
same way and then offers to save the selection (default no).
--non-interactive and the Python API never prompt or save.
--cooldown-days asks for a minimum release age. An adapter that cannot
enforce it rejects the request (exit 2) rather than ignoring it, because
ignoring it would relax your policy. For Pixi, set the native release-age
cutoff (exclude-newer) in the manifest instead; depsmith respects it (see
Pixi adapter).
Identity mappings and suppressions are configured as
[[options.identity_mappings]] and [[options.suppressions]]; see
Vulnerability scanning.