Skip to main content

Install the CLI

Add @scoutui/cli to a repo so you can run scout there. You need Node.js 24 or later.

1. Add the package​

In the repo root, add the CLI as a dev dependency with your package manager:

npm install --save-dev @scoutui/cli
# or: yarn add -D @scoutui/cli
# or: pnpm add -D @scoutui/cli
warning

The scan needs all of the repo's dependencies installed, not just the CLI. Without them, it can't find the components those packages provide, and scan refuses with:

Error: Couldn't upload the scan: some dependencies aren't installed. Install them and try again.

In a fresh clone or a CI job, run your package manager's install (npm ci, yarn install or pnpm install) before you scan.

2. Switch Yarn off Plug'n'Play​

Skip this step if you use npm, pnpm, or Yarn 1.

Scout needs a node_modules folder. Yarn 2 and later use Plug'n'Play instead unless .yarnrc.yml says otherwise, and a scan there stops with:

Error: Scout can't read packages installed with Yarn Plug'n'Play. Set nodeLinker: node-modules in .yarnrc.yml, run yarn install, and scan again.

To fix it:

  1. Set nodeLinker in .yarnrc.yml:

    .yarnrc.yml
    nodeLinker: node-modules
  2. Reinstall so Yarn writes node_modules:

    yarn install

If the scan still stops with the same error, delete any .pnp.cjs or .pnp.loader.mjs left in the folder that holds scout.config.json.

3. Check the command runs​

npx scout --version
# or: yarn scout --version
# or: pnpm exec scout --version

It prints the installed version, for example:

0.1.0

Check what the CLI contains​

The package ships a CycloneDX software bill of materials at node_modules/@scoutui/cli/dist/sbom.cdx.json. It lists the third-party packages bundled into the CLI and the packages it installs, so your dependency scanner can check them. A few packages that @vue/compiler-sfc builds into its own files, such as postcss-selector-parser, are covered by its entry rather than listed on their own. Each CLI release on GitHub Releases has the same file attached.

Next​