Updatecli
Description
The updatecli crawler looks recursively for Updatecli compose files and updates the version of each policy they reference.
Two file names are scanned by default:
updatecli-compose.yamlupdate-compose.yaml, the deprecated name
Override them with the files parameter.
Policies are OCI artifacts, so a compose file such as the following has its policy version bumped:
policies:
- name: Update Golang
policy: ghcr.io/updatecli/policies/autodiscovery/golang:0.4.0This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest.
The automatic discovery behavior can be tuned by providing a YAML manifest with an updatecli crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.
Generated manifests
Each policy produces a dockerimage source for the latest version, a dockerdigest source resolving the digest behind it, and a yaml target writing the reference back into the compose file.
Authentication
Use auths to reach a private policy registry, keyed by registry URL without a scheme, accepting either a token or a username/password pair. When it is empty Updatecli falls back to the ambient OCI credentials, such as those written by docker login.
Manifest
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| auths | object | Auths provides a map of registry credentials where the key is the registry URL without scheme | |
| password | string | password specifies the container registry password to use for authentication. Not compatible with token compatible: * source * condition * target default:
by default credentials are fetch from the local environment such as remark: Not compatible with token | |
| token | string | token specifies the container registry token to use for authentication. compatible: * source * condition * target default:
by default credentials are fetch from the local environment such as remark: Not compatible with username/password | |
| username | string | username specifies the container registry username to use for authentication. compatible: * source * condition * target default:
by default credentials are fetch from the local environment such as remark: Not compatible with token | |
| files | array | Files allows to specify a list of Files to analyze. The pattern syntax is: Match requires pattern to match all of name, not just a substring. The only possible returned error is ErrBadPattern, when pattern is malformed. On Windows, escaping is disabled. Instead, | |
| ignore | array | Ignore allows to specify rule to ignore autodiscovery a specific Updatecli based on a rule | |
| path | string | Path specifies a Updatecli compose filepath pattern, the pattern requires to match all of name, not just a subpart of the path. | |
| policies | object | Policies specifies a Updatecli policy | |
| only | array | Only allows to specify rule to only autodiscovery manifest for a specific Updatecli based on a rule | |
| path | string | Path specifies a Updatecli compose filepath pattern, the pattern requires to match all of name, not just a subpart of the path. | |
| policies | object | Policies specifies a Updatecli policy | |
| rootdir | string | rootdir defines the root directory used to recursively search for Updatecli manifest | |
| versionfilter | object |
kind - semver
versionfilter of kind kind - regex
versionfilter of kind example: and its type like regex, semver, or just latest. More examples can be found at https://www.updatecli.io/docs/core/versionfilter/ | |
| kind | string | specifies the version kind such as semver, regex, or latest | |
| pattern | string | specifies the version pattern according the version kind for semver, it is a semver constraint for regex, it is a regex pattern for time, it is a date format | |
| regex | string | specifies the regex pattern, used for regex/semver and regex/time. Output of the first capture group will be used. | |
| replaceall | object | replaceAll applies a regex replacement to version strings before filtering. This is useful for transforming versions (e.g., curl-8_15_0 to curl-8.15.0) before regex extraction. | |
| pattern | string | Pattern specifies the regex pattern to match for replacement | |
| replacement | string | Replacement specifies the replacement string (supports $1, $2, etc. for captured groups) | |
| strict | boolean | strict enforce strict versioning rule. Only used for semantic versioning at this time |
Example
# updatecli.d/default.yaml
name: "Updatecli Autodiscovery"
scms:
default:
kind: git
spec:
url: https://github.com/updatecli/website.git
branch: master
autodiscovery:
scmid: default
crawlers:
updatecli:
versionfilter:
kind: semver
pattern: majoronly