| title | `glab dependency-firewall package` |
|---|---|
| stage | AI Coding |
| group | Code Review |
| info | To determine the technical writer assigned to the Stage/Group associated with this page, see <https://handbook.gitlab.com/handbook/product/ux/technical-writing/#assignments> |
Check a package against the GitLab Dependency Firewall. (EXPERIMENTAL)
Check a single package coordinate against the GitLab Dependency Firewall policy for the current project and report the outcome (allow, warning, blocked). No package manager binary is required.
Supported package URL (PURL) types are npm, pypi, maven, and gem. The PURL must include a version, for example pkg:npm/left-pad@1.3.0.
This command does not write to the CI log at .gitlab/df/ci-log.json, so glab dependency-firewall ci-summary does not include its result.
Exit codes:
| Exit code | Meaning |
|---|---|
0 |
Allow or warning. |
1 |
Misconfiguration or transport error. |
3 |
Blocked. |
This feature is an experiment and is not ready for production use. It might be unstable or removed at any time. For more information, see https://docs.gitlab.com/policy/development_stages_support/.
glab dependency-firewall package <purl> [flags]
# Check an npm package version
glab dependency-firewall package pkg:npm/left-pad@1.3.0
# Check a PyPI package version
glab dependency-firewall package pkg:pypi/requests@2.31.0
# Check a Maven package version
glab dependency-firewall package pkg:maven/org.slf4j/slf4j-api@2.0.13
# Check a RubyGems package version
glab dependency-firewall package pkg:gem/rails@7.1.3
-h, --help Show help for this command.