viv audit

Run this before a release to check for known security advisories and abandoned packages among your installed or locked dependencies.

Usage

Check installed (or locked) packages for security vulnerability advisories and abandoned packages

Usage: viv audit [OPTIONS]

Options:
      --no-dev
          Disables auditing of `require-dev` packages
  -v, --verbose
          Raise logging to debug
      --cache-dir <CACHE_DIR>
          Store location (default `$XDG_CACHE_HOME/vivace`, or `~/.cache/vivace`)
  -f, --format <FORMAT>
          Output format [default: table] [possible values: table, plain, json, summary]
      --locked
          Audit `composer.lock` instead of the installed packages (`vendor/composer/installed.json`)
      --offline
          Fail fast on any request instead of connecting: install errors, naming every package not already in the store; update solves from cached repository metadata only, erroring on an uncached package. Also set by `COMPOSER_DISABLE_NETWORK` (any value but unset, empty or `0`; Composer's own git-priming `prime` value is not special-cased here, since neither `install` nor `update` touch a git source)
      --abandoned <ABANDONED>
          Behaviour on abandoned packages: `ignore`, `report`, or `fail` (Composer default: `fail`, overriding `config.audit.abandoned`)
      --ignore-severity <IGNORE_SEVERITY>
          Ignore advisories at these severity levels (`low`, `medium`, `high`, `critical`)
  -d, --project-dir <PROJECT_DIR>
          Project directory holding `composer.json`/`composer.lock` [default: .]
  -h, --help
          Print help

Reads and writes

  • Reads: composer.json, vendor/composer/installed.json (or composer.lock with --locked), auth.json, and fetches each repository's security-advisories endpoint over the network (unless --offline); reads the store under $XDG_CACHE_HOME/vivace for cached repository metadata.
  • Writes: nothing to disk; prints its report.

Exit codes

  • 0 — clean: no active advisory and no failing abandoned package.
  • 1 — an active advisory or a failing abandoned package was found, or no installed packages were found at all when the project declares dependencies.

viv audit never uses 2: a genuine failure to audit (no lock, no network, a malformed composer.json) is a plain error, not a finding, and still exits 1.

See also

viv outdated