- Reference
- Version · 6.0
- Change Automation Reference
checks run
Last updated: September 29, 2026
The checks run command executes the policy checks in your checks settings file, or in a Change Governance assignment, against a changelog, a database, or both. Policy checks support XML, SQL, YAML, and JSON changelog formats, and all the Liquibase Secure-certified databases.
Uses
The checks run command executes the policy checks you have enabled. Set --checks-scope to changelog, database, or changelog,database to choose what they run against. It defaults to changelog, and a database-scoped run takes a snapshot of your database to run the checks against.
By default the command reads the enabled changelog checks from your checks settings file, which can be in the default location or one you specify. If your files are not stored in the Liquibase working directory, give the relative path to them. How Liquibase finds files covers the search order it uses.
To run checks for a specific package, pass --checks-packages with the name of a default or custom package.
checks run also executes any Liquibase Secure custom policy checks you have written.
Note: To view a list of available checks, run liquibase checks show.
Pull checks settings from a Change Governance assignment
Instead of reading a local checks settings file, checks run can pull the checks settings for one or more assignments configured in Change Governance. Pass an assignment's UUID with --assignment-id, or its alias --assn-id:
liquibase checks run --assignment-id=3f9a1c2e-7b04-4d8a-9c2e-17b04d8a9c2e
To run several assignments together, pass a comma-separated list of up to 50 UUIDs. Liquibase merges them into one set of checks settings, so a check that more than one of those assignments references appears once, enabled if any of them enables it:
liquibase checks run --assignment-id=3f9a1c2e-7b04-4d8a-9c2e-17b04d8a9c2e,8c14e07d-52f9-4a3b-8e07-d52f9a3b8e07
--assignment-id takes precedence over both --checks-settings-file and --checks-packages. When you pass them together the assignment wins and the local file is never read, so it does not have to exist. Liquibase logs which file it skipped, naming the path you supplied or the default liquibase.checks-settings.conf when you supplied none. The assignments Liquibase pulled from appear in the console output, so the source of the settings is never a guess.
Note: Liquibase holds the pulled settings in memory for the length of the command and never writes them to disk, so every run reflects the assignment's current state. It does not back them up, upgrade them, or add newly discovered local checks to them, the way it does for a local checks settings file.
Run checks with a policy assignment covers creating an assignment and connecting the CLI to your Liquibase Secure server.
Syntax
Run the command specifying your values. Each example assumes changelogFile or url is set in your defaults file. Pass --changelog-file or --url on the command line if it is not.
liquibase checks run
Note: If you have a checks settings file customized for a specific environment or project, pass it with --checks-settings-file. Without that parameter Liquibase uses the default settings file, liquibase.checks-settings.conf.
liquibase checks run --checks-settings-file=prod.checks-settings.conf
To pull the checks settings from a Change Governance assignment instead of a local file, pass the assignment's UUID with --assignment-id:
liquibase checks run --assignment-id=3f9a1c2e-7b04-4d8a-9c2e-17b04d8a9c2e
To execute checks that require a database connection, you must also include connection attributes such as the database url.
Parameters
Global parameters
Parameter | Definition | Requirement |
| Your Liquibase Secure license key | Required |
Command parameters
Parameter | Description | Requirement |
| The changelog file against which you execute checks when running | Required (either this or |
| The JDBC database connection URL. How do I connect to my database? covers the URL format for each database. | Required (either this or |
| Liquibase Secure 6.0 and later. One assignment UUID, or a comma-separated list of up to 50, configured in Change Governance. Liquibase pulls the merged checks settings for those assignments instead of reading a local checks settings file. Requires | Optional |
| Automatically enable new policy checks in the | Optional |
| Allows automatic backup and updating of the | Optional |
| If | Optional |
| Specifies whether policy checks run on | Optional |
| The name of the check(s) you want to target. Comma-separated list of one or more enabled checks. Checks to exclude can be prefixed with the If no checks are specified, all enabled checks are targeted. For example: To skip multiple checks: | Optional |
| Allow changeset's rollback code to be analyzed for compliance with currently enabled policy checks. Default: | Optional |
| Sets a timeout in seconds for each built-in policy check. If a check takes longer than the specified time, it is terminated. Default: | Optional |
| The severity that a check which fails because of a validation error exits with. If not set, the check is skipped instead. Valid values are the return codes | Optional |
| Specify which parts of the checks run output should be shown. Options:
Default: | Optional |
| If using a checks packages file, optionally specify which packages should be run from the file as a comma-separated list. | Optional |
| The Liquibase component to run checks against, which can be a comma-separated list. Valid values are | Optional |
| Allow execution of the Liquibase Secure custom policy checks you have written. Default: | Optional |
| Only allow custom scripts found in the specified directories to execute. If not set, Liquibase allows custom scripts from any location to execute. | Optional |
| Additional directories to add to the Python import path, so custom policy check scripts can import shared utility modules. Separate multiple directories with the system path separator. Relative paths are resolved to absolute paths automatically. The script's own directory is added for you, so a check script can import from sibling | Optional |
| Specifies the checks settings file to use with policy checks commands. Write the relative path of the settings file that you want to read from or modify. Use the checks settings file covers its contents. | Optional |
| Specifies the changeset contexts to match. Contexts are tags you can add to changesets to control which changesets are executed in any particular migration run. | Optional |
| Sets a timeout in seconds for each custom policy check. If a check takes longer than the specified time, it is terminated. Default: | Optional |
| Name of the default catalog to use for the database connection | Optional |
| Name of the default schema to use for the database connection. If Note: You can use mixed-case schema names if you set | Optional |
| The JDBC driver class | Optional |
| The JDBC driver properties file | Optional |
| Sets the format of the check output to text or JSON. Valid values are Policy checks JSON object describes the JSON structure. | Optional |
| Specifies the changeset labels to match. Labels are tags you can add to changesets to control which changesets will be executed in any migration run. | Optional |
| Liquibase Secure 6.0 and later. Specifies the changeset conditions to match. conditions is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match. | Optional |
| Liquibase Secure 6.0 and later. Specifies the changeset keywords to match. keywords is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match. | Optional |
| Liquibase Secure 6.0 and later. Specifies the changeset releases to match. releases is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match. | Optional |
| Liquibase Secure 6.0 and later. Specifies the changeset teams to match. teams is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match. | Optional |
| The severity returned when a | Optional |
| Password to connect to the target database. | Optional |
| If set to | Optional |
| Enables a report at the command level. Overrides the global parameter | Optional |
| Specifies the name of the report file at the command level. Overrides the global parameter | Optional |
| Specifies the file path to the report file at the command level. Overrides the global parameter | Optional |
| Specifies whether to hide exceptions (which may contain SQL) from the operation report at the command level. Overrides the global parameter If If | Optional |
| Liquibase Secure 6.0 and later. Specifies whether to hide the detail rows for skipped (filtered out) changesets in operation reports at the command level. The report still displays the total number of skipped changesets in its summary. Overrides the global parameter | Optional |
| Specifies whether to hide changeset SQL in operation reports at the command level. Overridden by the global parameter | Optional |
| The schemas to check when | Optional |
| Skip regex pattern matching on bulk data load statements (INSERT/UPDATE with large VALUES clauses). Multi-value INSERTs are split automatically for efficient pattern matching, so this parameter is typically not needed. Set it to | Optional |
| Specifies the severity value returned when a check fails due to a SQL parse error. Valid values are the following return codes:
Default: severity of the executed check | Optional |
| Specifies the checks targeting file to apply to this run. Checks Targeting rules apply only when you name the file with this parameter. There is no default file lookup, so a run that omits it applies no rules. | Optional |
| Username to connect to the target database. | Optional |
| Specifies the detail level of the command's output. Default: | Optional |
Global parameters
Parameter | Definition | Requirement |
| Your Liquibase Secure license key | Required |
Command parameters
Parameter | Description | Requirement |
| The changelog file against which you execute checks when running | Required (either this or --url) |
| The JDBC database connection URL. How do I connect to my database? covers the URL format for each database. | Required (either this or |
| Liquibase Secure 6.0 and later. One assignment UUID, or a comma-separated list of up to 50, configured in Change Governance. Liquibase pulls the merged checks settings for those assignments instead of reading a local checks settings file. Requires | Optional |
| Automatically enable new policy checks in the | Optional |
| Allows automatic backup and updating of the | Optional |
| If | Optional |
| Specifies whether policy checks run on | Optional |
| The name of the check(s) you want to target. Comma-separated list of one or more enabled checks. Checks to exclude can be prefixed with the | Optional |
| Allow changeset's rollback code to be analyzed for compliance with currently enabled policy checks. Default: | Optional |
| Sets a timeout in seconds for each built-in policy check. If a check takes longer than the specified time, it is terminated. Default: | Optional |
| The severity that a check which fails because of a validation error exits with. If not set, the check is skipped instead. Valid values are the return codes | Optional |
| Specify which parts of the checks run output should be shown. Options: all: show all sections issues: show the triggered checks issues0: show the issues with severity 0 issues1: show the issues with severity 1 issues2: show the issues with severity 2 issues3: show the issues with severity 3 issues4: show the issues with severity 4 validated: show the section that starts with "Changesets Validated" checksrun: show the section that starts with "Checks run against each changeset" sqlparserfails: show the section that starts with "Changeset SQL not parsed in..." skippedchecks: show the section that starts with "Changelogs Checks Skipped Due to unsupported changeset..." (such as checks skipped due to version incompatibility) nonapplicablechecks: show chained checks which cannot be evaluated due to their configurations conflicting (such as a chained check that evaluates TableColumnLimit & ObjectNameMustMatch, where TableColumnLimit only evaluates tables and ObjectNameMustMatch is configured to only evaluate indexes). Default: all | Optional |
| If using a checks packages file, optionally specify which packages should be run from the file as a comma-separated list. | Optional |
| The Liquibase component to run checks against, which can be a comma-separated list. Valid values are | Optional |
| Allow execution of the Liquibase Secure custom policy checks you have written. Default: | Optional |
| Only allow custom scripts found in the specified directories to execute. If not set, Liquibase allows custom scripts from any location to execute. | Optional |
| Additional directories to add to the Python import path, so custom policy check scripts can import shared utility modules. Separate multiple directories with the system path separator. Relative paths are resolved to absolute paths automatically. The script's own directory is added for you, so a check script can import from sibling | Optional |
| Specifies the checks settings file to use with policy checks commands. Write the relative path of the settings file that you want to read from or modify. Use the checks settings file covers its contents. | Optional |
| Specifies the changeset contexts to match. Contexts are tags you can add to changesets to control which changesets are executed in any particular migration run. | Optional |
| Sets a timeout in seconds for each custom policy check. If a check takes longer than the specified time, it is terminated. Default: | Optional |
| Name of the default catalog to use for the database connection | Optional |
| Name of the default schema to use for the database connection. If Note: You can use mixed-case schema names if you set | Optional |
| The JDBC driver class | Optional |
| The JDBC driver properties file | Optional |
| Sets the format of the check output to text or JSON. Valid values are Policy checks JSON object describes the JSON structure. | Optional |
| Specifies the changeset labels to match. Labels are tags you can add to changesets to control which changesets will be executed in any migration run. | Optional |
| Liquibase Secure 6.0 and later. Specifies the changeset conditions to match. conditions is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match. | Optional |
| Liquibase Secure 6.0 and later. Specifies the changeset keywords to match. keywords is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match. | Optional |
| Liquibase Secure 6.0 and later. Specifies the changeset releases to match. releases is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match. | Optional |
| Liquibase Secure 6.0 and later. Specifies the changeset teams to match. teams is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match. | Optional |
| The severity returned when a | Optional |
| Password to connect to the target database. | Optional |
| If set to | Optional |
| Enables a report at the command level. Overrides the global parameter | Optional |
| Specifies the name of the report file at the command level. Overrides the global parameter | Optional |
| Specifies the file path to the report file at the command level. Overrides the global parameter | Optional |
| Specifies whether to hide exceptions (which may contain SQL) from the operation report at the command level. Overrides the global parameter If --report-suppress-exception is not set and --report-suppress-sql=true, Liquibase suppresses all SQL, including exception SQL. If --report-suppress-exception=false and --report-suppress-sql=true, Liquibase suppresses most SQL but shows exception SQL. | Optional |
| Liquibase Secure 6.0 and later. Specifies whether to hide the detail rows for skipped (filtered out) changesets in operation reports at the command level. The report still displays the total number of skipped changesets in its summary. Overrides the global parameter | Optional |
| Specifies whether to hide changeset SQL in operation reports at the command level. Overridden by the global parameter | Optional |
| The schemas to check when | Optional |
| Skip regex pattern matching on bulk data load statements (INSERT/UPDATE with large VALUES clauses). Multi-value INSERTs are split automatically for efficient pattern matching, so this parameter is typically not needed. Set it to | Optional |
| Specifies the severity value returned when a check fails due to a SQL parse error. Valid values are the following return codes: 0 is INFO 1 is MINOR 2 is MAJOR 3 is CRITICAL 4 is BLOCKER Default: severity of the executed check | Optional |
| Specifies the checks targeting file to apply to this run. Checks Targeting rules apply only when you name the file with this parameter. There is no default file lookup, so a run that omits it applies no rules. | Optional |
| Username to connect to the target database. | Optional |
| Specifies the detail level of the command's output. Default: | Optional |
Global parameters
Parameter | Definition | Requirement |
| Your Liquibase Secure license key | Required |
Command parameters
Parameter | Description | Requirement |
| The changelog file against which you execute checks when running | Required (either this or --url) |
| The JDBC database connection URL. How do I connect to my database? covers the URL format for each database. | Required (either this or |
| Liquibase Secure 6.0 and later. One assignment UUID, or a comma-separated list of up to 50, configured in Change Governance. Liquibase pulls the merged checks settings for those assignments instead of reading a local checks settings file. Requires | Optional |
| Automatically enable new policy checks in the | Optional |
| Allows automatic backup and updating of the | Optional |
| If | Optional |
| Specifies whether policy checks run on | Optional |
| The name of the check(s) you want to target. Comma-separated list of one or more enabled checks. Checks to exclude can be prefixed with the | Optional |
| Allow changeset's rollback code to be analyzed for compliance with currently enabled policy checks. Default: | Optional |
| Sets a timeout in seconds for each built-in policy check. If a check takes longer than the specified time, it is terminated. Default: | Optional |
| The severity that a check which fails because of a validation error exits with. If not set, the check is skipped instead. Valid values are the return codes | Optional |
| Specify which parts of the checks run output should be shown. Options: all: show all sections issues: show the triggered checks issues0: show the issues with severity 0 issues1: show the issues with severity 1 issues2: show the issues with severity 2 issues3: show the issues with severity 3 issues4: show the issues with severity 4 validated: show the section that starts with "Changesets Validated" checksrun: show the section that starts with "Checks run against each changeset" sqlparserfails: show the section that starts with "Changeset SQL not parsed in..." skippedchecks: show the section that starts with "Changelogs Checks Skipped Due to unsupported changeset..." (such as checks skipped due to version incompatibility) nonapplicablechecks: show chained checks which cannot be evaluated due to their configurations conflicting (such as a chained check that evaluates TableColumnLimit & ObjectNameMustMatch, where TableColumnLimit only evaluates tables and ObjectNameMustMatch is configured to only evaluate indexes). Default: all | Optional |
| If using a checks packages file, optionally specify which packages should be run from the file as a comma-separated list. | Optional |
| The Liquibase component to run checks against, which can be a comma-separated list. Valid values are | Optional |
| Allow execution of the Liquibase Secure custom policy checks you have written. Default: | Optional |
| Only allow custom scripts found in the specified directories to execute. If not set, Liquibase allows custom scripts from any location to execute. | Optional |
| Additional directories to add to the Python import path, so custom policy check scripts can import shared utility modules. Separate multiple directories with the system path separator. Relative paths are resolved to absolute paths automatically. The script's own directory is added for you, so a check script can import from sibling | Optional |
| Specifies the checks settings file to use with policy checks commands. Write the relative path of the settings file that you want to read from or modify. Use the checks settings file covers its contents. | Optional |
| Specifies the changeset contexts to match. Contexts are tags you can add to changesets to control which changesets are executed in any particular migration run. | Optional |
| Sets a timeout in seconds for each custom policy check. If a check takes longer than the specified time, it is terminated. Default: | Optional |
| Name of the default catalog to use for the database connection | Optional |
| Name of the default schema to use for the database connection. If Note: You can use mixed-case schema names if you set | Optional |
| The JDBC driver class | Optional |
| The JDBC driver properties file | Optional |
| Sets the format of the check output to text or JSON. Valid values are Policy checks JSON object describes the JSON structure. | Optional |
| Specifies the changeset labels to match. Labels are tags you can add to changesets to control which changesets will be executed in any migration run. | Optional |
| Liquibase Secure 6.0 and later. Specifies the changeset conditions to match. conditions is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match. | Optional |
| Liquibase Secure 6.0 and later. Specifies the changeset keywords to match. keywords is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match. | Optional |
| Liquibase Secure 6.0 and later. Specifies the changeset releases to match. releases is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match. | Optional |
| Liquibase Secure 6.0 and later. Specifies the changeset teams to match. teams is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match. | Optional |
| The severity returned when a | Optional |
| Password to connect to the target database. | Optional |
| If set to | Optional |
| Enables a report at the command level. Overrides the global parameter | Optional |
| Specifies the name of the report file at the command level. Overrides the global parameter | Optional |
| Specifies the file path to the report file at the command level. Overrides the global parameter | Optional |
| Specifies whether to hide exceptions (which may contain SQL) from the operation report at the command level. Overrides the global parameter If --report-suppress-exception is not set and --report-suppress-sql=true, Liquibase suppresses all SQL, including exception SQL. If --report-suppress-exception=false and --report-suppress-sql=true, Liquibase suppresses most SQL but shows exception SQL. | Optional |
| Liquibase Secure 6.0 and later. Specifies whether to hide the detail rows for skipped (filtered out) changesets in operation reports at the command level. The report still displays the total number of skipped changesets in its summary. Overrides the global parameter | Optional |
| Specifies whether to hide changeset SQL in operation reports at the command level. Overridden by the global parameter | Optional |
| The schemas to check when | Optional |
| Skip regex pattern matching on bulk data load statements (INSERT/UPDATE with large VALUES clauses). Multi-value INSERTs are split automatically for efficient pattern matching, so this parameter is typically not needed. Set it to | Optional |
| Specifies the severity value returned when a check fails due to a SQL parse error. Valid values are the following return codes: 0 is INFO 1 is MINOR 2 is MAJOR 3 is CRITICAL 4 is BLOCKER Default: severity of the executed check | Optional |
| Specifies the checks targeting file to apply to this run. Checks Targeting rules apply only when you name the file with this parameter. There is no default file lookup, so a run that omits it applies no rules. | Optional |
| Username to connect to the target database. | Optional |
| Specifies the detail level of the command's output. Default: | Optional |
Global parameters
Parameter | Definition | Requirement |
| Your Liquibase Secure license key | Required |
Command parameters
Parameter | Description | Requirement |
| The changelog file against which you execute checks when running | Required (either this or --url) |
| The JDBC database connection URL. How do I connect to my database? covers the URL format for each database. | Required (either this or |
| Liquibase Secure 6.0 and later. One assignment UUID, or a comma-separated list of up to 50, configured in Change Governance. Liquibase pulls the merged checks settings for those assignments instead of reading a local checks settings file. Requires | Optional |
| Automatically enable new policy checks in the | Optional |
| Allows automatic backup and updating of the | Optional |
| If | Optional |
| Specifies whether policy checks run on | Optional |
| The name of the check(s) you want to target. Comma-separated list of one or more enabled checks. Checks to exclude can be prefixed with the | Optional |
| Allow changeset's rollback code to be analyzed for compliance with currently enabled policy checks. Default: | Optional |
| Sets a timeout in seconds for each built-in policy check. If a check takes longer than the specified time, it is terminated. Default: | Optional |
| The severity that a check which fails because of a validation error exits with. If not set, the check is skipped instead. Valid values are the return codes | Optional |
| Specify which parts of the checks run output should be shown. Options: all: show all sections issues: show the triggered checks issues0: show the issues with severity 0 issues1: show the issues with severity 1 issues2: show the issues with severity 2 issues3: show the issues with severity 3 issues4: show the issues with severity 4 validated: show the section that starts with "Changesets Validated" checksrun: show the section that starts with "Checks run against each changeset" sqlparserfails: show the section that starts with "Changeset SQL not parsed in..." skippedchecks: show the section that starts with "Changelogs Checks Skipped Due to unsupported changeset..." (such as checks skipped due to version incompatibility) nonapplicablechecks: show chained checks which cannot be evaluated due to their configurations conflicting (such as a chained check that evaluates TableColumnLimit & ObjectNameMustMatch, where TableColumnLimit only evaluates tables and ObjectNameMustMatch is configured to only evaluate indexes). Default: all | Optional |
| If using a checks packages file, optionally specify which packages should be run from the file as a comma-separated list. | Optional |
| The Liquibase component to run checks against, which can be a comma-separated list. Valid values are | Optional |
| Allow execution of the Liquibase Secure custom policy checks you have written. Default: | Optional |
| Only allow custom scripts found in the specified directories to execute. If not set, Liquibase allows custom scripts from any location to execute. | Optional |
| Additional directories to add to the Python import path, so custom policy check scripts can import shared utility modules. Separate multiple directories with the system path separator. Relative paths are resolved to absolute paths automatically. The script's own directory is added for you, so a check script can import from sibling | Optional |
| Specifies the checks settings file to use with policy checks commands. Write the relative path of the settings file that you want to read from or modify. Use the checks settings file covers its contents. | Optional |
| Specifies the changeset contexts to match. Contexts are tags you can add to changesets to control which changesets are executed in any particular migration run. | Optional |
| Sets a timeout in seconds for each custom policy check. If a check takes longer than the specified time, it is terminated. Default: | Optional |
| Name of the default catalog to use for the database connection | Optional |
| Name of the default schema to use for the database connection. If Note: You can use mixed-case schema names if you set | Optional |
| The JDBC driver class | Optional |
| The JDBC driver properties file | Optional |
| Sets the format of the check output to text or JSON. Valid values are Policy checks JSON object describes the JSON structure. | Optional |
| Specifies the changeset labels to match. Labels are tags you can add to changesets to control which changesets will be executed in any migration run. | Optional |
| Liquibase Secure 6.0 and later. Specifies the changeset conditions to match. conditions is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match. | Optional |
| Liquibase Secure 6.0 and later. Specifies the changeset keywords to match. keywords is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match. | Optional |
| Liquibase Secure 6.0 and later. Specifies the changeset releases to match. releases is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match. | Optional |
| Liquibase Secure 6.0 and later. Specifies the changeset teams to match. teams is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match. | Optional |
| The severity returned when a | Optional |
| Password to connect to the target database. | Optional |
| If set to | Optional |
| Enables a report at the command level. Overrides the global parameter | Optional |
| Specifies the name of the report file at the command level. Overrides the global parameter | Optional |
| Specifies the file path to the report file at the command level. Overrides the global parameter | Optional |
| Specifies whether to hide exceptions (which may contain SQL) from the operation report at the command level. Overrides the global parameter If --report-suppress-exception is not set and --report-suppress-sql=true, Liquibase suppresses all SQL, including exception SQL. If --report-suppress-exception=false and --report-suppress-sql=true, Liquibase suppresses most SQL but shows exception SQL. | Optional |
| Liquibase Secure 6.0 and later. Specifies whether to hide the detail rows for skipped (filtered out) changesets in operation reports at the command level. The report still displays the total number of skipped changesets in its summary. Overrides the global parameter | Optional |
| Specifies whether to hide changeset SQL in operation reports at the command level. Overridden by the global parameter | Optional |
| The schemas to check when | Optional |
| Skip regex pattern matching on bulk data load statements (INSERT/UPDATE with large VALUES clauses). Multi-value INSERTs are split automatically for efficient pattern matching, so this parameter is typically not needed. Set it to | Optional |
| Specifies the severity value returned when a check fails due to a SQL parse error. Valid values are the following return codes: 0 is INFO 1 is MINOR 2 is MAJOR 3 is CRITICAL 4 is BLOCKER Default: severity of the executed check | Optional |
| Specifies the checks targeting file to apply to this run. Checks Targeting rules apply only when you name the file with this parameter. There is no default file lookup, so a run that omits it applies no rules. | Optional |
| Username to connect to the target database. | Optional |
| Specifies the detail level of the command's output. Default: | Optional |
Output
A run that finds issues in a changelog reports each triggered check, the changesets it validated, the checks it ran against every changeset, and the exit code it returns:
Checks Targeting information in the output
When a run names a targeting file with --targeting-file, the block for a triggered check that a targeting rule affected carries extra lines naming the file, the rule that applied, and the rule’s reason and expiration when it has them:
Targeting Rule is EXEMPT, RESTRICT, or both when one changeset matches a rule of each kind, and it notes a count such as (+1 more rule matched) when more than one rule of the same type matched the changeset. Targeting Expiry is then the latest expiration across all of them. What is Checks Targeting? covers what the rules do, how they select changesets, and how the output reads when several rules match or both kinds apply.