Skip to content

Configuration

depsmith-docs-bot[bot] edited this page Oct 5, 2026 · 4 revisions

Configuration

Repository defaults live in depsmith.toml at the repository root:

targets = ["pixi:pixi.toml", "github-actions:.github/workflows/ci.yml"]

[options]
timeout_seconds = 300
upgrade = false
  • targets is the saved selection, used when no --target/--all (CLI) or targets= (Python) is given.
  • [options] accepts the fields of UpdateOptions (see the Python API); unknown fields are an error.
  • Explicit CLI flags and Python options override the file.
  • Native package-manager configuration stays authoritative for ecosystem behaviour. Native Pixi configuration in .pixi/config.toml is staged even when .pixi/ is ignored.

Native tool paths

Each adapter declares the native tools it runs; depsmith doctor lists them by name. Point one at a specific executable with [options.tools], the repeatable --tool NAME=PATH flag, or UpdateOptions(tools={...}) in Python:

[options.tools]
pixi = "/opt/pixi/bin/pixi"
grype = "/usr/local/bin/grype"
conda = "/opt/micromamba/bin/micromamba"  # the solver conda-lock drives

--pixi and --grype (and the matching option fields) still work as deprecated aliases.

Saving a selection

depsmith init chooses targets and saves them as targets: it offers the discovered targets a package manager at a time (then file by file when a group is declined), or takes --all / --target, and appends the choice. Saved targets are never removed; a saved target that is no longer found is reported and skipped. --no-save leaves the file alone. The rest of the file and its comments are kept.

When no targets are configured, an interactive check or update asks in the same way and then offers to save the selection (default no). --non-interactive and the Python API never prompt or save.

Cooldown

--cooldown-days asks for a minimum release age. An adapter that cannot enforce it rejects the request (exit 2) rather than ignoring it, because ignoring it would relax your policy. For Pixi, set the native release-age cutoff (exclude-newer) in the manifest instead; depsmith respects it (see Pixi adapter).

Scanning options

Identity mappings and suppressions are configured as [[options.identity_mappings]] and [[options.suppressions]]; see Vulnerability scanning.

Clone this wiki locally