viv audit
Run this before a release to check for known security advisories and abandoned packages among your installed or locked dependencies.
Usage
Check installed (or locked) packages for security vulnerability advisories and abandoned packages
Usage: viv audit [OPTIONS]
Options:
--no-dev
Disables auditing of `require-dev` packages
-v, --verbose
Raise logging to debug
--cache-dir <CACHE_DIR>
Store location (default `$XDG_CACHE_HOME/vivace`, or `~/.cache/vivace`)
-f, --format <FORMAT>
Output format [default: table] [possible values: table, plain, json, summary]
--locked
Audit `composer.lock` instead of the installed packages (`vendor/composer/installed.json`)
--offline
Fail fast on any request instead of connecting: install errors, naming every package not already in the store; update solves from cached repository metadata only, erroring on an uncached package. Also set by `COMPOSER_DISABLE_NETWORK` (any value but unset, empty or `0`; Composer's own git-priming `prime` value is not special-cased here, since neither `install` nor `update` touch a git source)
--abandoned <ABANDONED>
Behaviour on abandoned packages: `ignore`, `report`, or `fail` (Composer default: `fail`, overriding `config.audit.abandoned`)
--ignore-severity <IGNORE_SEVERITY>
Ignore advisories at these severity levels (`low`, `medium`, `high`, `critical`)
-d, --project-dir <PROJECT_DIR>
Project directory holding `composer.json`/`composer.lock` [default: .]
-h, --help
Print help
Reads and writes
- Reads:
composer.json,vendor/composer/installed.json(orcomposer.lockwith--locked),auth.json, and fetches each repository's security-advisories endpoint over the network (unless--offline); reads the store under$XDG_CACHE_HOME/vivacefor cached repository metadata. - Writes: nothing to disk; prints its report.
Exit codes
0— clean: no active advisory and no failing abandoned package.1— an active advisory or a failing abandoned package was found, or no installed packages were found at all when the project declares dependencies.
viv audit never uses 2: a genuine failure to audit (no lock, no
network, a malformed composer.json) is a plain error, not a finding, and
still exits 1.