Checking Catalog Alignment
If you are using a Tidelift catalog, you can check alignment (i.e. if a repository is using only approved package releases) quickly using Tidelift CLI. Unlike a scan, using
tidelift align does not save a record of the repository's current alignment. It is intended to be used as part of your developer workflow rather than during your CI/CD process.
- To check for your catalog alignment, you will first need to have a user API key to authenticate to the API. Be sure to note your team name when downloading your API key.
- From your repository's root directory run
tidelift align --repository REPO_NAME --team TEAM_NAME. REPO_NAME is the name of the repository as set up in Tidelift.
- From your repository's root directory, run
- Once the alignment check completes, you will see the percent of package releases in the current repository that are approved in the organization's catalog.
- If any package releases are not available, you will see if you should request them using
tidelift request --alland/or why they were previously denied.