devguard

Commands

Every devguard command, its flags, and how connection settings resolve.

The binary is installed as devguard. Every command exits with 0 on success and a non-zero code on failure.

Global flags

Global flags are read by every command.

FlagMeaning
--url <url>API base url. Default https://app.devguard.ch.
--key [key]API key (dvg_...). With no value, devguard login --key prompts for one with echo suppressed (the valueless form has to follow the command name, because before it the next word is read as the key). Absent, login uses your browser.
--config <path>Path to the configuration file. Default devguard.yml.
--org <organizationId>Organization id. Overrides organization: in the configuration and the login default.
--versionPrint the CLI version.
--helpPrint usage for the program or a command.

devguard login

devguard login [--org <organizationId|slug>] [--no-browser] [--timeout <ms>] [--key [key]]

Opens your browser to sign in to devguard, lets you pick the organization this machine may act in, and stores the resulting login for the target url in ~/.devguard/config.json. Nothing is pasted: the CLI is a public OAuth client, keeps a short-lived token it refreshes on its own, and holds no permanent secret. --org preselects an organization (id or slug) on the sign-in page. --no-browser skips opening a browser; the sign-in URL is printed either way. The browser still has to reach this machine's loopback address, so over SSH use a key. The login waits two minutes for the browser; --timeout <ms> changes that (default 120000).

A login is bound to one organization. --org or organization: naming another one is refused; run devguard login --org <id> to switch. The login is revoked from Account → Connected apps, or stops on its own after seven days without use; the next command then says to run devguard login again.

--key keeps the key path for CI and for hosts without a browser: with a value (or DEVGUARD_API_KEY), the key is verified and stored; with no value, the CLI prompts for one. The prompting form goes after the command name — devguard login --key. Written before it, --key takes the command as its value, and the CLI says so instead of running. A key carries the full permissions of your account in every organization, and the organization picker runs as before.

devguard logout

devguard logout

Revokes this machine's login for the target url and forgets it, along with any stored key for that url.

devguard init

devguard init [--force]

Interactive wizard that writes a first configuration file. It runs only in a terminal; in CI, commit a devguard.yml instead. It writes to the path given by --config (default devguard.yml) and refuses to overwrite an existing file unless --force is set.

The wizard signs in through your browser when nothing is stored for the target url, picks an organization in the same order as login, proposes an npm-audit collector when a package-lock.json is present and a uses: scan collector when a supported scanner is installed, and then accepts any number of custom command collectors. It binds only to evidence records that already exist; it never creates one. It also offers to add the .devguard/ staging folder to your .gitignore.

devguard scan

devguard scan --evidence <shortId> [--scanner <id>] [--expires <duration>] [--org <organizationId>] [--allow-secrets]

Runs an installed vulnerability scanner and pushes its report into one evidence record, without a configuration file.

FlagMeaning
--evidence <shortId>Required. 42 or EV-42. The record must already exist.
--scanner <id>Force trivy, osv-scanner, grype, or npm-audit. Default: the first scanner found on the machine.
--expires <duration>Freshness window stamped on the file. Default 30d.
--org <organizationId>Organization id, when no configuration or login default names one.
--allow-secretsDo not block the push on secret findings.

The report uploads under the collector name scan-<scanner> with a 30 minute timeout and replaces that collector's previous file. When a devguard.yml is present, its organization: is read; nothing else in the file is used.

devguard evidence validate

devguard evidence validate

Read-only preflight. It parses the configuration, checks that every uses: scan collector has an installed scanner, verifies your credentials, and confirms that every referenced evidence record resolves in the organization. It prints one line per record, runs no collector commands, and uploads nothing.

devguard evidence push

devguard evidence push [--dry-run] [--allow-secrets]

The whole pipeline: runs every collector, scans each artifact for secrets, uploads, and supersedes that collector's previous file. It prints one line per collector and exits non-zero when any collector fails. A failed collector uploads nothing; its previous file stays in place.

FlagMeaning
--dry-runRun everything, including the secret scan, and upload nothing.
--allow-secretsDo not block on secret findings for this run. Prefer the per-collector allowSecrets field, which stays visible in review.

Connection and organization

Connection settings resolve highest first:

  1. The --url and --key flags.
  2. DEVGUARD_API_URL and DEVGUARD_API_KEY.
  3. The login keystore (~/.devguard/config.json), where a browser login is stored as a grant entry and a key as key: the grant comes first.
  4. https://app.devguard.ch.

The organization resolves highest first:

  1. The --org flag.
  2. organization: in the configuration file.
  3. The default stored by devguard login for the resolved url.

With a browser login, the organization must be the one the login is bound to.

For push, validate, and scan the value must be the organization id. The slug is accepted only by login and init. devguard login prints the id.

Environment variables

VariableMeaning
DEVGUARD_API_URLAPI base url, for example http://localhost:3000 for a local instance.
DEVGUARD_API_KEYAPI key. The usual way to authenticate in CI; when set, it wins over a stored login.

How is this guide?

On this page