deps-cli 2.0.0

CLI for running deps-lsp's dependency-health checks in CI, pre-commit, and shell workflows
Documentation
[package]
name = "deps-cli"
version.workspace = true
edition.workspace = true
rust-version.workspace = true
authors.workspace = true
license.workspace = true
repository.workspace = true
description = "CLI for running deps-lsp's dependency-health checks in CI, pre-commit, and shell workflows"
publish = true

[lints]
workspace = true

[[bin]]
name = "deps-cli"
path = "src/main.rs"

[lib]
name = "deps_cli"
path = "src/lib.rs"

[features]
default = [
    "cargo",
    "npm",
    "pypi",
    "go",
    "bundler",
    "dart",
    "maven",
    "gradle",
    "swift",
    "composer",
    "nuget",
    "deno",
    "github-actions",
    "gitlab-ci",
]
cargo = ["deps-engine/cargo"]
npm = ["deps-engine/npm"]
pypi = ["deps-engine/pypi"]
go = ["deps-engine/go"]
bundler = ["deps-engine/bundler"]
dart = ["deps-engine/dart"]
maven = ["deps-engine/maven"]
gradle = ["deps-engine/gradle"]
swift = ["deps-engine/swift"]
composer = ["deps-engine/composer"]
nuget = ["deps-engine/nuget"]
github-actions = ["deps-engine/github-actions"]
gitlab-ci = ["deps-engine/gitlab-ci"]
# Pulls in deps-npm transitively (DenoRegistry delegates npm: specifiers to it) even when
# the "npm" feature itself is disabled — mirrors deps-lsp/deps-engine's identical carve-out.
deno = ["deps-engine/deno"]

# Exposes `config::fuzz_parse_config` for the `fuzz/` cargo-fuzz workspace's
# `deps_cli_config` target (#1404) — never enabled by this crate's own default feature
# set, so `config::parse` stays out of the normal public API surface. Mirrors
# `deps-gradle`/`deps-npm`'s identical `fuzzing` feature.
fuzzing = []

[dependencies]
deps-core = { workspace = true }
deps-engine = { workspace = true }
clap = { workspace = true, features = ["derive"] }
ignore = { workspace = true }
serde = { workspace = true, features = ["derive"] }
serde-sarif = { workspace = true }
serde_json = { workspace = true }
thiserror = { workspace = true }
tokio = { workspace = true, features = ["macros", "rt-multi-thread", "sync", "time"] }
toml-span = { workspace = true, features = ["serde"] }
tracing = { workspace = true }
tracing-subscriber = { workspace = true, features = ["env-filter"] }
url = { workspace = true }
urlencoding = { workspace = true }

[dev-dependencies]
# `deps_core::test_util::test_uri` is used directly by the tier-3 license parity/regression
# tests in `tests/check_integration.rs` (issue #1133). This dependency also exists so
# deps-core's `test-util` feature is reachable in *this* crate's dev-dependency tree, which
# CI's "Guard against test-util leaking into the release dependency tree" step
# (.github/workflows/ci.yml) requires as a positive control proving its grep-based leak
# detector actually works — mirroring the identical, genuinely-used pattern in deps-engine's
# and deps-lsp's own `[dev-dependencies]`. Do not remove as "unused" without also removing
# deps-cli's block from that CI guard.
deps-core = { workspace = true, features = ["test-util"] }
# `deps_engine::test_util::TestTier3Ecosystem` — a network-free tier-3 `Ecosystem` test
# double used by `check_integration.rs`'s `tier3_wiring_regression` test (issue #1133 critic
# S2) to prove `check_manifest` actually reaches `prefetch_tier3_licenses`, so deleting that
# call site fails this test instead of leaving the suite silently green. The `cargo` feature
# also re-exports `deps_engine::setup::CargoFormatter` — the real semver-backed formatter used by
# `update::security`'s regression test proving Cargo's actual matcher (not a mock) returns
# `Some(false)` for a compound requirement/fix pair (issue #1578) — deps-cli must reach it
# through deps-engine's ecosystem registry, never link deps-cargo directly.
deps-engine = { workspace = true, features = ["test-util", "cargo"] }
insta = { workspace = true, features = ["json", "redactions"] }
jsonschema = { workspace = true }
# `check_integration.rs`'s `gossip_prefetch_wiring_regression` module (issue #1521 item 2) —
# a `mockito`-backed `DepsDevClient::for_test` to prove `analyze_manifest` actually reaches
# `fetch_gossip_findings_batch`'s ecosystem/offline/opt-in gates, mirroring `deps-core`'s own
# `mock_client()` test helper for the same endpoint.
mockito = { workspace = true }
tempfile = { workspace = true }