vlt outdated
Usage:
$ vlt outdated
$ vlt outdated [package-names...]
$ vlt outdated [--target=<query>] [--workspace=<path>]
$ vlt outdated [--view=human | json | count]List dependencies that have newer versions available, and what is keeping them from being upgraded.
For every registry dependency, the installed version is compared
against the highest version that satisfies the declared range (wanted)
and against the registry's latest dist-tag (latest). Only
dependencies that are missing or behind on either count are reported.
Each report goes beyond the version numbers:
- the size of the jump (major, minor, patch)
- whether the installed version is deprecated
- security scores and alerts for the installed, wanted and latest versions, so an upgrade that fixes a vulnerability or one that introduces a flagged version stands out
- other dependents whose ranges hold the package back
- engine and peer dependency requirements of the latest version that this project does not meet
- the command that performs the upgrade
By default the direct dependencies of the project root and its
workspaces are checked; --workspace and --workspace-group narrow
that to the given workspaces. The --target option accepts a
DSS query selector instead, which can reach any
dependency in the graph. Package names given as positional arguments
filter either selection.
The installed versions come from the graph built by vlt install, so
the project must be installed by vlt first. Dependencies that do not
resolve against a registry (git, file, remote tarball or workspace
specs) are not checked. Catalog specs are checked against the range
the catalog resolves them to.
Examples
Report outdated direct dependencies of the project and all its workspaces
$ vlt outdatedOnly check the dependencies named react and react-dom
$ vlt outdated react react-domOnly check the dependencies of a single workspace
$ vlt outdated --workspace=packages/appCheck every dependency in the graph, transitive ones included
$ vlt outdated --target="*"Only check the dev dependencies of the project root
$ vlt outdated --target=":root > *:dev"Only check dependencies with known vulnerabilities
$ vlt outdated --target="*:vuln"Print the report as JSON
$ vlt outdated --view=jsonOutput
The human-readable view is a table with one row per dependency and
dependent. The Why column summarizes the jump size, deprecation,
security changes between the installed version and the wanted or
latest one (high and critical severity alerts fixed or added, and
score drops), the dependents holding a transitive package back, and
the engine or peer requirements of the latest version that are not
met. The commands that perform the upgrades follow the table:
vlt update for versions within the declared ranges, vlt install
with new ranges for the rest, and the catalog entries to edit.
The JSON view is an array of entries with these fields:
name,spec,type: the dependency as declared by its dependentcurrent,wanted,latest: the installed version (absent when missing), the highest version satisfying the spec, and the registry'slatestdependent,location: the importer name, orname@versionof a transitive dependent, and its locationkind:missing,major,minor,patchorprereleaseinRange: whethervlt updatepicks up a newer versiondeprecated: the deprecation message of the installed versionheldBy: transitive dependents whose ranges do not admitlatestrequires: thenodeengine range andpeersranges oflatestthat this project does not satisfysecurity:score(0 to 100) andalertsforcurrent,wantedandlatest, for the versions the security archive has reports onaction: the command that performs the upgrade, for dependencies of an importer
Options
target
DSS query selector choosing the dependencies to check, in place of the direct dependencies of the selected importers.
--target=<query>workspace
Limit the report to the dependencies of the given workspace(s).
--workspace=<path>workspace-group
Limit the report to the dependencies of the workspaces in the given group(s).
--workspace-group=<name>view
Output format. Defaults to human-readable or json if no tty. count
outputs the number of outdated dependencies.
--view=[human | json | count]