vera — the Vera CLI
Scan your app for App Store / Google Play compliance issues from the terminal.
A standalone client for the Vera service: it talks to the same /api/* surface
as the dashboard and complements the MCP server (which cannot upload a local
project).
vera login # sign in through your browser
vera init # create a project (+ short questionnaire)
vera scan # zip this folder, upload, watch the audit live
vera audits list # recent runs
vera audits show latest
Install
The distribution on PyPI is vera-audit; the command you type is vera.
(vera and vera-cli belong to an unrelated project, and PyPI rejects
vera-scan as too similar to the existing verascan — it ignores -, _
and . when comparing names.)
uv tool install vera-audit # recommended: uv fetches its own Python
pipx install vera-audit # if you already use pipx (needs Python 3.12+)
Or the one-liner, which installs uv first if the machine does not have it:
curl -fsSL https://98.80.215.12.sslip.io/install.sh | sh
The one-liner is served by
veracode-clientatGET /install.sh. It only works once the server has a real TLS certificate — today nginx serves a self-signed cert, socurlrefuses the connection. Useuv tool installuntil the domain + certbot change ships, and do not paste acurl -kversion: piping an unverified script into a shell is exactly the thing TLS is there to prevent.
VERA_VERSION=0.1.0 pins a version; VERA_PACKAGE overrides the distribution.
uv tool upgrade vera-audit # update
uv tool uninstall vera-audit # remove
Configuration
Precedence: flag > environment > ~/.config/vera/config.json > default.
| Setting | Flag | Env | Default |
|---|---|---|---|
| Server URL | --base-url |
VERA_BASE_URL |
https://98.80.215.12.sslip.io |
| Skip TLS verify | --insecure |
VERA_INSECURE=1 |
on for the default host only (self-signed cert) |
vera config prints the effective values; vera config set base-url …
persists one. Credentials live in ~/.config/vera/credentials.json (0600),
one entry per server.
Exit codes
| Code | Meaning |
|---|---|
| 0 | Success; a completed audit with no error-severity findings |
| 1 | Unexpected error (network, API) |
| 2 | Usage error |
| 3 | Not signed in / session expired |
| 4 | Audit failed or timed out |
| 5 | Audit completed with error-severity findings (CI-friendly) |
What vera scan uploads
The CLI packages the directory with the same exclusion policy the server
enforces on extraction (src/veracode/server/scan/sanitize.py): dependency
and build folders (node_modules, Pods, .git, DerivedData, …), secrets
(.env*, keys, certificates), nested archives, binaries, and files over
10 MB never leave your machine. The zip is deterministic, so re-scanning an
unchanged project reuses the previous audit (--force re-runs it).
Server operator setup (required for vera login)
The login flow opens the browser to Supabase and catches the redirect on
http://127.0.0.1:8976/callback (falling back to ports 8977/8978). Those URLs
must be added to the Supabase project's Auth → URL Configuration → Redirect
URLs allowlist:
http://127.0.0.1:8976/callback
http://127.0.0.1:8977/callback
http://127.0.0.1:8978/callback
Until that is configured, browser sign-in cannot return to the CLI (the paste-the-redirect-URL fallback is offered, but Supabase may reject the redirect outright).
Smoke test against the deployed server
uv run vera login
uv run vera init --yes --label smoke
uv run vera scan tests/fixtures/tiny-app
API documentation
cli/openapi.yaml documents the /api/* surface this CLI consumes. It is
hand-written; update it in the same PR as any /api/* change.
Development
cd cli
uv sync
uv run vera --help
uv run pytest
uv run ruff check .
uv tool install --force . # install this checkout on your PATH
Releasing
CI: .github/workflows/release-cli.yml builds, tests, and publishes to PyPI
with trusted publishing (OIDC — no API token stored).
# 1. bump both (a test asserts they match):
# cli/pyproject.toml → project.version
# cli/src/vera_cli/__init__.py → __version__
# 2. merge to main, then:
git tag cli-v0.1.0
git push origin cli-v0.1.0
The workflow refuses to publish if the tag and pyproject.toml version
disagree. Actions → Release CLI → Run workflow does a build-only dry run.
One-time setup, both required before the first tag:
- PyPI trusted publisher — on PyPI, create the
vera-auditproject (or add a pending publisher at https://pypi.org/manage/account/publishing/) with ownerReef-Inc, repositoryveracode, workflowrelease-cli.yml, environmentpypi. - GitHub environment — repo Settings → Environments → New environment
named
pypi(add required reviewers if publishing should need approval).
Note that PyPI is public: publishing ships the CLI source (an sdist anyone can
download) even though this repository is private. The CLI holds no secrets, but
it does disclose the /api/* surface it calls.
Release files for vera-audit 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vera_audit-0.1.0.tar.gz | 24.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vera_audit-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 59.2 kB
Release files / vera_audit-0.1.0.tar.gz
| Download URL | vera_audit-0.1.0.tar.gz |
|---|---|
| Size | 24.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
8e837ed537f80e69dd3d4498bd494c452fd62a22279ee2ae1a8f4f72a7e5f4e3
|
|
BLAKE2b-256 checksum How to use checksums |
30e9972a9b291d636ce86a8259faf3873659f25993ab389557cc4ceed59c7eb9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.17 {"installer":{"name":"uv","version":"0.12.17","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / vera_audit-0.1.0-py3-none-any.whl
| Download URL | vera_audit-0.1.0-py3-none-any.whl |
|---|---|
| Size | 34.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f02487ae6aa91d1de0d23a11dd5fe6cacf655c7556b22b4c8e54a97bd17359bb
|
|
BLAKE2b-256 checksum How to use checksums |
a763348c6689417305dd236d378d645f0acf51ee700945951f527acd349ce3d9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.17 {"installer":{"name":"uv","version":"0.12.17","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|