CLI reference

A curated OMG command guide for packages, runtimes, audits, environments, and maintenance, with useful options and limits.

How to read the command line

The CLI has one parser for package operations, runtime managers, project tasks, environment records, and team or enterprise workflows. `omg --help` shows the public command list. Add `--all-commands` to include advanced commands, and add `--help` after any command or subcommand for its exact arguments.

Package commands use the native backend of the host: ALPM and the AUR on Arch, APT on Debian or Ubuntu, DNF and RPM on Fedora, and Homebrew on Apple Silicon macOS. Native Windows has no backend; use OMG inside WSL so the Linux guest supplies the backend. Runtime and audit coverage still varies by provider and platform.

`omg completions` supports Bash, Zsh, Fish, PowerShell (`pwsh`), and Elvish. The directory-change PATH hook currently emits Bash, Zsh, and Fish scripts; PowerShell and Elvish are completion-only values and return an unsupported-shell error when passed to `omg hook`.

A safe first pass Nothing here changes the machine until the fourth step, and that step asks for confirmation first.
A safe first passA safe first pass. Steps in reading order: omg --help (the public list); omg search <query> (find the package); Preview install (omg install ripgrep --dry-run); omg install <package> (now it changes); omg doctor (reads exit status). Connections: omg --help to omg search <query>; omg search <query> to Preview install; Preview install to omg install <package>; omg install <package> to omg doctor.omg --helpthe public listomg search <query>find the packagePreview installomg install ripgrep --dry-runomg install <package>now it changesomg doctorreads exit status

Start here

omg --help
omg --all-commands --help
omg doctor --network --eol
omg status

Global options

OptionEffect
-v, --verbose (repeatable)Increase detail; package build output is streamed live
-q, --quietSuppress non-essential logs and fast-path banners; command results still print
--jsonRequest JSON where that command implements it; do not assume one stable schema across commands
--all-commandsInclude advanced commands in top-level help
-h, --help / -V, --versionPrint command help or the installed OMG version

Nested parser options

Command familyExact nested arguments and options
hooks and workspace`hooks install --force`; `hooks run <hook>`; `workspace add <path> --name`; `workspace run <command> [-- <args...>] --parallel --filter --yes`; `workspace diff [branch]` defaults to `main`
config, privacy, and env`config reset --yes`; `privacy export --output`; `env share --description --public`; `env sync <url-or-id>`
audit`sbom --output`; `secrets --path`; `log --limit --severity --export`; `slsa <package> --certificate-identity <identity>`; `licenses --format --export --filter --check-policy`; `fix --dry-run --yes --min-severity`; `export --framework --period --output`
snapshots, CI, and migration`snapshot create --message`; `restore <id> --dry-run --yes`; `ci init <provider> --advanced`; `migrate export --output`; `migrate import <manifest> --dry-run`
team`team init <team-id> --name`; `golden-path create <name> --node --python --packages`; `compliance --export --enforce`; `activity --days`
containers`run <image> [-- <command...>] --name --detach --interactive --env --volume --workdir`; `shell --image --workdir --env --volume`; `build --dockerfile --tag --no-cache --build-arg --target`; `init --base`
account and enterprise`account link --token-stdin`; `enterprise reports --report-type`; `policy show --scope`; `audit-export --framework --period --output`; `license-scan --export`
hidden shell helpers`hook-env --shell` is called by generated hooks; `complete --shell --current --last [--full]` powers dynamic completion

Package management

Every package command

CommandPurpose and important options
omg search <query> (s)Search configured repositories; --detailed, --no-aur, and --limit control source detail and result count
omg install [packages] (i)Install packages or open the interactive picker; --yes, --dry-run, --review, and --allow-local-file
omg remove <packages> (r)Remove packages; --recursive is Arch-only, with --yes and --dry-run
omg update (u)Update packages; --check, --yes, --dry-run, --review, --no-sync, --aur-only, --fast, and --turbo
omg info <package>Show package metadata from the active backend
omg why <package>Show dependency parents; --reverse shows dependents
omg outdatedList packages with available updates
omg sizeShow package disk usage; --tree <package> and --limit <n> refine it
omg blame <package>Show when and why a package was installed
omg cleanRemove orphans or caches; --orphans, --cache, --aur, --all, --dry-run, --yes
omg explicitList explicitly installed packages; --count prints only the count
omg sync (sy)Refresh package databases from mirrors

Safe package workflow

omg search ripgrep --detailed
omg install ripgrep --dry-run
omg install ripgrep --yes
omg history --search ripgrep

Runtime management

Runtime commands

CommandPurpose and options
omg use <runtime> [version]Install or select a version; omit the version to use a detected project pin, or pass --uninstall to remove it
omg list [runtime]List installed versions; --available or -a lists downloadable versions
omg which <runtime>Report the version selected for the current directory
omg hook <shell>Print or install the directory-change hook; --uninstall removes the managed hook

Native runtime managers

RuntimeNames, pins, and exposed tools
nodeAlias nodejs; .node-version, .nvmrc, .tool-versions, and package.json; node, npm, npx
pythonAlias python3; .python-version, pyproject.toml, and .tool-versions; python3, pip
goAlias golang; .go-version, go.mod, and .tool-versions; go, gofmt
rustAlias rustlang; rust-toolchain, rust-toolchain.toml, and .tool-versions; rustc, cargo
ruby.ruby-version and .tool-versions; ruby, gem
java.java-version and .tool-versions; java, javac
bunAlias bunjs; .bun-version, .tool-versions, and package.json; bun
pi.tool-versions; pi
deno.deno-version, .dvmrc, and .tool-versions; deno
zigAlias ziglang; .zig-version and .tool-versions; zig
dotnetglobal.json and .tool-versions; dotnet
erlang.tool-versions; erl, erlc
php.php-version and .tool-versions; php
swift.swift-version and .tool-versions; swift, swiftc

The exact 54 registry tools

RegistryNames
GitHub-release toolsripgrep, fd, bat, eza, fzf, zoxide, starship, just, task, jq, yq, gh, lazygit, delta, neovim, helix, zellij, helm, k9s, terraform, opentofu, vault, consul, minikube, kind, kustomize, tilt, skaffold, lazydocker, glow, pandoc, shellcheck, shfmt, hadolint, actionlint, hyperfine, tokei, dust, duf, procs, ruff, uv, fnm, protoc, terragrunt, packer, dive, golangci-lint, delve, stylua, kotlin, scala, elixir, ghcup

The hook walks from the current directory toward its parents; the nearest explicit pin wins. It also reads `mise.toml`, `.mise.toml`, and `package.json` where the native parser supports them. Unknown runtime names fail explicitly instead of invoking another version manager.

Shell integration, Git hooks, and workspaces

Shell and monorepo commands

CommandPurpose and options
omg completions <shell>Install completions for bash, zsh, fish, powershell/pwsh, or elvish; --stdout prints instead
omg hooks installInstall environment-sync Git hooks; --force overwrites existing hooks
omg hooks uninstall / statusRemove hooks or show their status
omg hooks run <hook>Run pre-commit, post-checkout, or post-merge manually
omg workspace init <name>Create a workspace definition
omg workspace add <path>Add a project; --name overrides the directory name
omg workspace remove <project> / listRemove a project or list workspace members
omg workspace run <command>Run across projects; --parallel, --filter, and --yes control execution
omg workspace diff [branch]Compare workspace environments with a branch (default main)
omg workspace check / statusCheck project environments or show workspace state

Shell setup examples

eval "$(omg hook bash)"
eval "$(omg hook zsh)"
omg hook fish | source
omg completions powershell

Status, health, and security

Health and diagnostics

CommandPurpose and options
omg statusShow package totals, updates, orphans, vulnerabilities, and cached runtimes; --fast uses counts only
omg doctorCheck network, backend, daemon, PATH, and shell hook; --network tests mirrors, --eol checks Node.js, Python, Rust, Go, Ruby, Java, Bun, and Deno, --turbo primes sudo
omg audit [scan]Scan installed packages for advisories; v0.1.223 needs omgd, while current main has a direct fallback. Findings are reported without a failure exit status
omg audit sbomWrite a CycloneDX system-package inventory; v0.1.223 succeeds on Arch, while current main also supports Debian, Ubuntu, and Fedora. -o/--output selects the file
omg audit secretsScan a directory for credentials; -p/--path selects it
omg audit logRead or export audit entries; --limit, --severity, and --export filter output
omg audit verify / policyCheck local audit-chain consistency or show policy status
omg audit slsa <package>Verify supported artifact signatures against the required --certificate-identity value; this does not establish a SLSA level
omg audit licensesReport installed-package licenses on Arch; --format, --export, --filter, and --check-policy. Violations currently print without a failure exit status
omg audit fixUpgrade vulnerable Arch packages when updates are available; --dry-run, --yes, and --min-severity
omg audit exportExport SOC 2 evidence on a supported backend; other accepted framework names are not implemented. --period records metadata rather than filtering events
omg audit eolCheck end-of-life dates for installed Node.js, Python, Rust, Go, Ruby, Java, Bun, and Deno

Tasks, tools, and project setup

Development commands

CommandPurpose and options
omg run <task>Run a detected project task; --watch, --parallel, --using <ecosystem>, and --all are mutually exclusive modes
omg new <stack> <name>Scaffold rust, react, node, python, or go projects; alias create
omg tool install <name>Install a registry developer tool from supported sources
omg tool list / remove <name>Inspect or remove managed tools
omg tool update <name>Update one tool or use the special name all
omg tool search <query> / registrySearch or list the curated tool registry
omg initRun first setup; --defaults or a non-interactive terminal applies defaults and captures omg.lock; --skip-shell and --skip-daemon skip those setup actions

Task detection

Project fileNative command family
package.jsonnpm, yarn, pnpm, or bun scripts
deno.jsondeno task
Cargo.toml / Makefile / Taskfile.ymlcargo, make, or task
pyproject.toml / Pipfilepoetry or pipenv
composer.json / pom.xml / build.gradlecomposer, Maven, or Gradle
mise.toml / .mise.tomlOMG reads supported tasks, tools, and environment entries

Environments, snapshots, history, and rollback

Environment state commands

CommandPurpose and options
omg env captureWrite explicit package names and selected runtime versions to omg.lock on Arch, Debian, or Ubuntu
omg env checkReport drift against omg.lock on those backends without changing the machine
omg env sharePublish a GitHub Gist; --description and --public control metadata and visibility
omg env sync <url-or-id>Fetch and check a shared environment record
omg diff <to>Compare the current lock or --from <file> with another lock file
omg snapshot create / listCreate a state snapshot with optional --message or list snapshots
omg snapshot restore <id>Preview or restore a snapshot with --dry-run and --yes
omg snapshot delete <id>Delete one snapshot
omg migrate exportWrite a portable manifest; -o/--output defaults to omg-manifest.json
omg migrate import <manifest>Map and install from a manifest; --dry-run previews changes

History and rollback

CommandPurpose and options
omg historyShow transactions; --limit, --search, --type, --from, and --to filter entries
omg rollback [id]Restore a previous package state; omit the id for the newest transaction and use --yes in non-interactive shells

Team, container, and account commands

Team workflows

CommandPurpose and options
omg team init <team-id>Create a team workspace; --name sets its display name
omg team join <url>Join a team from a GitHub Gist URL or ID
omg team status / membersShow sync state or members
omg team push / pullPublish local state or fetch team state
omg team dashboardOpen the interactive team TUI
omg team roles listList available roles
omg team golden-path create <name>Create a template with --node, --python, and --packages
omg team golden-path list / delete <name>Inspect or delete templates
omg team complianceReport that local compliance scoring is unavailable; --enforce warns without enforcing, and --export fails because no evaluated report exists
omg team activityShow activity; --days sets the lookback window

Containers and dashboard account

CommandPurpose and options
omg container statusCheck Docker or Podman
omg container run <image>Run a command; --name, --detach, --interactive, --env, --volume, and --workdir
omg container shellOpen a project-mounted shell; --image, --workdir, --env, and --volume
omg container buildBuild an image from the current directory; --dockerfile, --tag, --no-cache, --build-arg, and --target. In v0.1.223, pass a relative -f path because the default path is rejected; the newer checkout fixes that default
omg container list / images / pull <image>Inspect containers, images, or download an image
omg container stop <container> / exec <container>Stop or execute in a running container
omg container initGenerate Dockerfile.omg; --base selects the image. Build with omg container build -f Dockerfile.omg -t myapp. Omit the unsupported trailing dot printed by v0.1.223
omg account link / status / unlinkOptional dashboard link; --token-stdin avoids putting the token in shell history

Configuration and privacy

Configuration commands

CommandPurpose
omg config get <key> / set <key> <value>Read or change a setting
omg config list / validateList effective settings or validate syntax and values
omg config resetRestore defaults; --yes skips confirmation
omg config pathPrint the active configuration path
omg privacy statusShow local privacy settings and policy summary
omg privacy exportExport local OMG data; -o/--output selects a file
omg privacy opt-out / opt-inDisable or re-enable telemetry collection

Configuration paths follow XDG on Linux and WSL and Application Support on macOS. `OMG_DATA_DIR`, `OMG_CONFIG_DIR`, and `OMG_SOCKET_PATH` can override the active locations. Review exported data before sharing it.

CI, daemon, dashboard, and enterprise

CI and lifecycle commands

CommandPurpose and options
omg ci init <provider>Generate GitHub, GitLab, or CircleCI configuration; --advanced adds matrices and audit steps
omg ci validate / cacheCheck CI expectations or print recommended cache paths
omg daemon [--foreground]Start omgd on Unix; --foreground keeps it attached
omg daemon-statusShow daemon health and socket details (Unix)
omg metricsPrint Prometheus-style system metrics (Unix)
omg dash (d)Open the interactive system dashboard
omg statsShow usage statistics
omg self-update (up)Update the paired omg and omgd binaries; --force or --version selects the update
omg generate-manGenerate man pages; -o/--output changes the destination

Fleet and enterprise commands

CommandPurpose and options
omg fleet statusShow fleet status across machines
omg enterprise reportsCreate monthly, quarterly, or custom executive reports with --report-type
omg enterprise policy showShow policies, optionally scoped with --scope
omg enterprise audit-exportExport generic evidence with --framework, --period, and --output
omg enterprise license-scanScan license compliance; --export accepts json or csv

Reviewed against omg-cli/omg/docs/cli.md at commit c43c8ff on 2026-09-22. This page was checked against the CLI code and documentation at that commit.