vlt / docs

  • PricingBenchmarks (opens in new window)Community (opens in new window)Feedback
  • Overview
  • bugs
  • build
  • cache
  • ci
  • config
  • create
  • docs
  • exec-cache
  • exec-local
  • exec
  • help
  • init
  • install
  • list
  • login
  • logout
  • outdated
  • pack
  • ping
  • pkg
  • publish
  • query
  • registry
  • repo
  • run-exec
  • run
  • setup
  • token
  • uninstall
  • version
  • whoami
  • Examples
  • Output
  • Options
  • target
  • workspace
  • workspace-group
  • view
  1. Client
  2. /
  3. Commands
  4. /
  5. outdated

vlt outdated

Usage:

Terminal
$ vlt outdated
$ vlt outdated [package-names...]
$ vlt outdated [--target=<query>] [--workspace=<path>]
$ vlt outdated [--view=human | json | count]

List dependencies that have newer versions available, and what is keeping them from being upgraded.

For every registry dependency, the installed version is compared against the highest version that satisfies the declared range (wanted) and against the registry's latest dist-tag (latest). Only dependencies that are missing or behind on either count are reported.

Each report goes beyond the version numbers:

  • the size of the jump (major, minor, patch)
  • whether the installed version is deprecated
  • security scores and alerts for the installed, wanted and latest versions, so an upgrade that fixes a vulnerability or one that introduces a flagged version stands out
  • other dependents whose ranges hold the package back
  • engine and peer dependency requirements of the latest version that this project does not meet
  • the command that performs the upgrade

By default the direct dependencies of the project root and its workspaces are checked; --workspace and --workspace-group narrow that to the given workspaces. The --target option accepts a DSS query selector instead, which can reach any dependency in the graph. Package names given as positional arguments filter either selection.

The installed versions come from the graph built by vlt install, so the project must be installed by vlt first. Dependencies that do not resolve against a registry (git, file, remote tarball or workspace specs) are not checked. Catalog specs are checked against the range the catalog resolves them to.

Examples

Report outdated direct dependencies of the project and all its workspaces

Terminal
$ vlt outdated

Only check the dependencies named react and react-dom

Terminal
$ vlt outdated react react-dom

Only check the dependencies of a single workspace

Terminal
$ vlt outdated --workspace=packages/app

Check every dependency in the graph, transitive ones included

Terminal
$ vlt outdated --target="*"

Only check the dev dependencies of the project root

Terminal
$ vlt outdated --target=":root > *:dev"

Only check dependencies with known vulnerabilities

Terminal
$ vlt outdated --target="*:vuln"

Print the report as JSON

Terminal
$ vlt outdated --view=json

Output

The human-readable view is a table with one row per dependency and dependent. The Why column summarizes the jump size, deprecation, security changes between the installed version and the wanted or latest one (high and critical severity alerts fixed or added, and score drops), the dependents holding a transitive package back, and the engine or peer requirements of the latest version that are not met. The commands that perform the upgrades follow the table: vlt update for versions within the declared ranges, vlt install with new ranges for the rest, and the catalog entries to edit.

The JSON view is an array of entries with these fields:

  • name, spec, type: the dependency as declared by its dependent
  • current, wanted, latest: the installed version (absent when missing), the highest version satisfying the spec, and the registry's latest
  • dependent, location: the importer name, or name@version of a transitive dependent, and its location
  • kind: missing, major, minor, patch or prerelease
  • inRange: whether vlt update picks up a newer version
  • deprecated: the deprecation message of the installed version
  • heldBy: transitive dependents whose ranges do not admit latest
  • requires: the node engine range and peers ranges of latest that this project does not satisfy
  • security: score (0 to 100) and alerts for current, wanted and latest, for the versions the security archive has reports on
  • action: the command that performs the upgrade, for dependencies of an importer

Options

target

DSS query selector choosing the dependencies to check, in place of the direct dependencies of the selected importers.

Text
--target=<query>

workspace

Limit the report to the dependencies of the given workspace(s).

Text
--workspace=<path>

workspace-group

Limit the report to the dependencies of the workspaces in the given group(s).

Text
--workspace-group=<name>

view

Output format. Defaults to human-readable or json if no tty. count outputs the number of outdated dependencies.

Text
--view=[human | json | count]

PreviouslogoutNextpack

On this page

  • Examples
  • Output
  • Options
  • target
  • workspace
  • workspace-group
  • view
Edit this page

Deploy your package on vlt.io

Publish scoped and private packages, manage organizations and access, and give every developer and CI environment a consistent source for public and private JavaScript dependencies.

Publish now