• Reference
  • Version · 6.0
  • Change Automation Reference

checks run

Last updated: September 29, 2026

The checks run command executes the policy checks in your checks settings file, or in a Change Governance assignment, against a changelog, a database, or both. Policy checks support XML, SQL, YAML, and JSON changelog formats, and all the Liquibase Secure-certified databases.

Uses

The checks run command executes the policy checks you have enabled. Set --checks-scope to changelog, database, or changelog,database to choose what they run against. It defaults to changelog, and a database-scoped run takes a snapshot of your database to run the checks against.

By default the command reads the enabled changelog checks from your checks settings file, which can be in the default location or one you specify. If your files are not stored in the Liquibase working directory, give the relative path to them. How Liquibase finds files covers the search order it uses.

To run checks for a specific package, pass --checks-packages with the name of a default or custom package.

checks run also executes any Liquibase Secure custom policy checks you have written.

Note: To view a list of available checks, run liquibase checks show.

Pull checks settings from a Change Governance assignment

Instead of reading a local checks settings file, checks run can pull the checks settings for one or more assignments configured in Change Governance. Pass an assignment's UUID with --assignment-id, or its alias --assn-id:

liquibase checks run --assignment-id=3f9a1c2e-7b04-4d8a-9c2e-17b04d8a9c2e

To run several assignments together, pass a comma-separated list of up to 50 UUIDs. Liquibase merges them into one set of checks settings, so a check that more than one of those assignments references appears once, enabled if any of them enables it:

liquibase checks run --assignment-id=3f9a1c2e-7b04-4d8a-9c2e-17b04d8a9c2e,8c14e07d-52f9-4a3b-8e07-d52f9a3b8e07

--assignment-id takes precedence over both --checks-settings-file and --checks-packages. When you pass them together the assignment wins and the local file is never read, so it does not have to exist. Liquibase logs which file it skipped, naming the path you supplied or the default liquibase.checks-settings.conf when you supplied none. The assignments Liquibase pulled from appear in the console output, so the source of the settings is never a guess.

Note: Liquibase holds the pulled settings in memory for the length of the command and never writes them to disk, so every run reflects the assignment's current state. It does not back them up, upgrade them, or add newly discovered local checks to them, the way it does for a local checks settings file.

Run checks with a policy assignment covers creating an assignment and connecting the CLI to your Liquibase Secure server.

Syntax

Run the command specifying your values. Each example assumes changelogFile or url is set in your defaults file. Pass --changelog-file or --url on the command line if it is not.

liquibase checks run

Note: If you have a checks settings file customized for a specific environment or project, pass it with --checks-settings-file. Without that parameter Liquibase uses the default settings file, liquibase.checks-settings.conf.

liquibase checks run --checks-settings-file=prod.checks-settings.conf

To pull the checks settings from a Change Governance assignment instead of a local file, pass the assignment's UUID with --assignment-id:

liquibase checks run --assignment-id=3f9a1c2e-7b04-4d8a-9c2e-17b04d8a9c2e

To execute checks that require a database connection, you must also include connection attributes such as the database url.

Parameters

Global parameters

Parameter

Definition

Requirement

--license-key=<string>

Your Liquibase Secure license key

Required

Command parameters

Parameter

Description

Requirement

--changelog-file=<string>

The changelog file against which you execute checks when running liquibase checks run.

Required (either this or --url)

--url=<string>

The JDBC database connection URL. How do I connect to my database? covers the URL format for each database.

Required (either this or --changelog-file)

--assignment-id=<string>

Liquibase Secure 6.0 and later. One assignment UUID, or a comma-separated list of up to 50, configured in Change Governance. Liquibase pulls the merged checks settings for those assignments instead of reading a local checks settings file. Requires liquibase.platform.apiUrl and liquibase.platform.apiKey to be set. Takes precedence over --checks-settings-file.

Optional

--auto-enable-new-checks=<true|false>

Automatically enable new policy checks in the liquibase.checks-settings.conf file when they are available. Default: false.

Optional

--auto-update=<string>

Allows automatic backup and updating of the liquibase.checks-settings.conf file when new policy checks are available. Valid values are ON and OFF. Default: OFF.

Optional

--cache-changelog-file-contents=<true|false>

If true, sqlFile Change Type contents are cached in memory to improve performance, at the cost of higher memory usage. To reduce memory usage, set this to false. Default: true

Optional

--changeset-filter=<string>

Specifies whether policy checks run on ALL changesets or only PENDING (undeployed) changesets. Only applies to checks with the changelog scope. Default: ALL.

Optional

--check-name=<string>

The name of the check(s) you want to target. Comma-separated list of one or more enabled checks.

Checks to exclude can be prefixed with the ! character. In bash or zsh, single-quote any token containing ! (for example, '!shortname3') to prevent shell history expansion; double quotes do not work.

If no checks are specified, all enabled checks are targeted.

For example: --check-name=shortname1,shortname2,'!shortname3'

To skip multiple checks: --check-name='!skipMe1','!skipMe2'

Optional

--check-rollbacks=<true|false>

Allow changeset's rollback code to be analyzed for compliance with currently enabled policy checks. Default: false

Optional

--check-timeout=<seconds>

Sets a timeout in seconds for each built-in policy check. If a check takes longer than the specified time, it is terminated. Default: 0 (disabled).

Optional

--check-validity-fail-severity=<string>

The severity that a check which fails because of a validation error exits with. If not set, the check is skipped instead. Valid values are the return codes 0, 1, 2, 3, and 4.

Optional

--checks-output=<string>

Specify which parts of the checks run output should be shown. Options:

all: show all sections

issues: show the triggered checks

issues0: show the issues with severity 0

issues1: show the issues with severity 1

issues2: show the issues with severity 2

issues3: show the issues with severity 3

issues4: show the issues with severity 4

validated: show the section that starts with "Changesets Validated"

checksrun: show the section that starts with "Checks run against each changeset"

sqlparserfails: show the section that starts with "Changeset SQL not parsed in..."

skippedchecks: show the section that starts with "Changelogs Checks Skipped Due to unsupported changeset..." (such as checks skipped due to version incompatibility)

nonapplicablechecks: show chained checks which cannot be evaluated due to their configurations conflicting (such as a chained check that evaluates

TableColumnLimit & ObjectNameMustMatch, where TableColumnLimit only evaluates tables and ObjectNameMustMatch is configured to only evaluate indexes).

Default: all

Optional

--checks-packages=<string>

If using a checks packages file, optionally specify which packages should be run from the file as a comma-separated list.

Optional

--checks-scope=<string>

The Liquibase component to run checks against, which can be a comma-separated list. Valid values are changelog and database. Default: changelog.

Optional

--checks-scripts-enabled=<true|false>

Allow execution of the Liquibase Secure custom policy checks you have written. Default: false.

Optional

--checks-scripts-path=<string>

Only allow custom scripts found in the specified directories to execute. If not set, Liquibase allows custom scripts from any location to execute.

Optional

--checks-scripts-python-path=<string>

Additional directories to add to the Python import path, so custom policy check scripts can import shared utility modules. Separate multiple directories with the system path separator. Relative paths are resolved to absolute paths automatically. The script's own directory is added for you, so a check script can import from sibling .py files without setting this parameter.

Optional

--checks-settings-file=<string>

Specifies the checks settings file to use with policy checks commands. Write the relative path of the settings file that you want to read from or modify. Use the checks settings file covers its contents.

Optional

--context-filter=<string>

Specifies the changeset contexts to match. Contexts are tags you can add to changesets to control which changesets are executed in any particular migration run.

Optional

--custom-check-timeout=<seconds>

Sets a timeout in seconds for each custom policy check. If a check takes longer than the specified time, it is terminated. Default: 0 (disabled).

Optional

--default-catalog-name=<string>

Name of the default catalog to use for the database connection

Optional

--default-schema-name=<string>

Name of the default schema to use for the database connection. If defaultSchemaName is set, then objects do not have to be fully qualified. This means you can refer to just mytable instead of myschema.mytable.

Note: You can use mixed-case schema names if you set --preserve-schema-case to true.

Optional

--driver=<string>

The JDBC driver class

Optional

--driver-properties-file=<string>

The JDBC driver properties file

Optional

--format=<string>

Sets the format of the check output to text or JSON. Valid values are TXT and JSON. Default: TXT.

Policy checks JSON object describes the JSON structure.

Optional

--label-filter=<string>

Specifies the changeset labels to match. Labels are tags you can add to changesets to control which changesets will be executed in any migration run.

Optional

--conditions-filter=<string>

Liquibase Secure 6.0 and later. Specifies the changeset conditions to match. conditions is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match.

Optional

--keywords-filter=<string>

Liquibase Secure 6.0 and later. Specifies the changeset keywords to match. keywords is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match.

Optional

--releases-filter=<string>

Liquibase Secure 6.0 and later. Specifies the changeset releases to match. releases is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match.

Optional

--teams-filter=<string>

Liquibase Secure 6.0 and later. Specifies the changeset teams to match. teams is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match.

Optional

--max-affected-fail-severity=<string>

The severity returned when a MaxAffected* check cannot run against the given script, or cannot determine a result, and so performs no operation. If not set, the severity of the configured check is returned. Valid values are the return codes 0, 1, 2, 3, and 4.

Optional

--password=<string>

Password to connect to the target database.

Optional

--property-substitution-enabled=<true|false>

If set to true, changesets are evaluated by checks run after property substitution. If set to false, changesets are evaluated by checks run before property substitution, meaning the names of the "property substitution tokens" are evaluated. Default: true.

Optional

--report-enabled=<true|false>

Enables a report at the command level. Overrides the global parameter --reports-enabled. Default: true.

Optional

--report-name=<string>

Specifies the name of the report file at the command level. Overrides the global parameter --reports-name. By default, Liquibase generates a new report file labeled with a timestamp (user's local time). If you set a custom name, Liquibase overwrites the existing file every time you generate a new report. Default: report-<DD-Mon-YYYY-HHmmss>.html.

Optional

--report-path=<string>

Specifies the file path to the report file at the command level. Overrides the global parameter --reports-path. Default: ./.

Optional

--report-suppress-exception=<true|false>

Specifies whether to hide exceptions (which may contain SQL) from the operation report at the command level. Overrides the global parameter --reports-suppress-exception. Default: false. However:

If --report-suppress-exception is not set and --report-suppress-sql=true, Liquibase suppresses all SQL, including exception SQL.

If --report-suppress-exception=false and --report-suppress-sql=true, Liquibase suppresses most SQL but shows exception SQL.

Optional

--report-suppress-skipped=<true|false>

Liquibase Secure 6.0 and later. Specifies whether to hide the detail rows for skipped (filtered out) changesets in operation reports at the command level. The report still displays the total number of skipped changesets in its summary. Overrides the global parameter --reports-suppress-skipped. Default: false.

Optional

--report-suppress-sql=<true|false>

Specifies whether to hide changeset SQL in operation reports at the command level. Overridden by the global parameter --reports-suppress-sql. Default: false.

Optional

--schemas=<string>

The schemas to check when --checks-scope contains database.

Optional

--skip-bulk-data=<true|false>

Skip regex pattern matching on bulk data load statements (INSERT/UPDATE with large VALUES clauses). Multi-value INSERTs are split automatically for efficient pattern matching, so this parameter is typically not needed. Set it to true to skip bulk data entirely. Default: false.

Optional

--sql-parser-fail-severity=<string>

Specifies the severity value returned when a check fails due to a SQL parse error. Valid values are the following return codes:

0 is INFO

1 is MINOR

2 is MAJOR

3 is CRITICAL

4 is BLOCKER

Default: severity of the executed check

Optional

--targeting-file=<string>

Specifies the checks targeting file to apply to this run. Checks Targeting rules apply only when you name the file with this parameter. There is no default file lookup, so a run that omits it applies no rules.

Optional

--username=<string>

Username to connect to the target database.

Optional

--verbose=<true|false>

Specifies the detail level of the command's output. Default: false.

Optional

Global parameters

Parameter

Definition

Requirement

globalArgs: { license-key: "<string>" }

Your Liquibase Secure license key

Required

Command parameters

Parameter

Description

Requirement

cmdArgs: { changelog-file: "<string>" }

The changelog file against which you execute checks when running liquibase checks run.

Required (either this or --url)

cmdArgs: { url: "<string>" }

The JDBC database connection URL. How do I connect to my database? covers the URL format for each database.

Required (either this or --changelog-file)

cmdArgs: { assignment-id: "<string>" }

Liquibase Secure 6.0 and later. One assignment UUID, or a comma-separated list of up to 50, configured in Change Governance. Liquibase pulls the merged checks settings for those assignments instead of reading a local checks settings file. Requires liquibase.platform.apiUrl and liquibase.platform.apiKey to be set. Takes precedence over --checks-settings-file.

Optional

cmdArgs: { auto-enable-new-checks: "<true|false>" }

Automatically enable new policy checks in the liquibase.checks-settings.conf file when they are available. Default: false.

Optional

cmdArgs: { auto-update: "<string>" }

Allows automatic backup and updating of the liquibase.checks-settings.conf file when new policy checks are available. Valid values are ON and OFF. Default: OFF.

Optional

cmdArgs: { cache-changelog-file-contents: "<true|false>" }

If true, sqlFile Change Type contents are cached in memory to improve performance, at the cost of higher memory usage. To reduce memory usage, set this to false. Default: true

Optional

cmdArgs: { changeset-filter: "<string>" }

Specifies whether policy checks run on ALL changesets or only PENDING (undeployed) changesets. Only applies to checks with the changelog scope. Default: ALL.

Optional

cmdArgs: { check-name: "<string>" }

The name of the check(s) you want to target. Comma-separated list of one or more enabled checks. Checks to exclude can be prefixed with the ! character. If no checks are specified, all enabled checks are targeted. For example: --check-name=shortname1,shortname2,!shortname3

Optional

cmdArgs: { check-rollbacks: "<true|false>" }

Allow changeset's rollback code to be analyzed for compliance with currently enabled policy checks. Default: false

Optional

cmdArgs: { check-timeout: "<seconds>" }

Sets a timeout in seconds for each built-in policy check. If a check takes longer than the specified time, it is terminated. Default: 0 (disabled).

Optional

cmdArgs: { check-validity-fail-severity: "<string>" }

The severity that a check which fails because of a validation error exits with. If not set, the check is skipped instead. Valid values are the return codes 0, 1, 2, 3, and 4.

Optional

cmdArgs: { checks-output: "<string>" }

Specify which parts of the checks run output should be shown. Options:

all: show all sections

issues: show the triggered checks

issues0: show the issues with severity 0

issues1: show the issues with severity 1

issues2: show the issues with severity 2

issues3: show the issues with severity 3

issues4: show the issues with severity 4

validated: show the section that starts with "Changesets Validated"

checksrun: show the section that starts with "Checks run against each changeset"

sqlparserfails: show the section that starts with "Changeset SQL not parsed in..."

skippedchecks: show the section that starts with "Changelogs Checks Skipped Due to unsupported changeset..." (such as checks skipped due to version incompatibility)

nonapplicablechecks: show chained checks which cannot be evaluated due to their configurations conflicting (such as a chained check that evaluates

TableColumnLimit & ObjectNameMustMatch, where TableColumnLimit only evaluates tables and ObjectNameMustMatch is configured to only evaluate indexes).

Default: all

Optional

cmdArgs: { checks-packages: "<string>" }

If using a checks packages file, optionally specify which packages should be run from the file as a comma-separated list.

Optional

cmdArgs: { checks-scope: "<string>" }

The Liquibase component to run checks against, which can be a comma-separated list. Valid values are changelog and database. Default: changelog.

Optional

cmdArgs: { checks-scripts-enabled: "<true|false>" }

Allow execution of the Liquibase Secure custom policy checks you have written. Default: false.

Optional

cmdArgs: { checks-scripts-path: "<string>" }

Only allow custom scripts found in the specified directories to execute. If not set, Liquibase allows custom scripts from any location to execute.

Optional

cmdArgs: { checks-scripts-python-path: "<string>" }

Additional directories to add to the Python import path, so custom policy check scripts can import shared utility modules. Separate multiple directories with the system path separator. Relative paths are resolved to absolute paths automatically. The script's own directory is added for you, so a check script can import from sibling .py files without setting this parameter.

Optional

cmdArgs: { checks-settings-file: "<string>" }

Specifies the checks settings file to use with policy checks commands. Write the relative path of the settings file that you want to read from or modify. Use the checks settings file covers its contents.

Optional

cmdArgs: { context-filter: "<string>" }

Specifies the changeset contexts to match. Contexts are tags you can add to changesets to control which changesets are executed in any particular migration run.

Optional

cmdArgs: { custom-check-timeout: "<seconds>" }

Sets a timeout in seconds for each custom policy check. If a check takes longer than the specified time, it is terminated. Default: 0 (disabled).

Optional

cmdArgs: { default-catalog-name: "<string>" }

Name of the default catalog to use for the database connection

Optional

cmdArgs: { default-schema-name: "<string>" }

Name of the default schema to use for the database connection. If defaultSchemaName is set, then objects do not have to be fully qualified. This means you can refer to just mytable instead of myschema.mytable.

Note: You can use mixed-case schema names if you set --preserve-schema-case to true.

Optional

cmdArgs: { driver: "<string>" }

The JDBC driver class

Optional

cmdArgs: { driver-properties-file: "<string>" }

The JDBC driver properties file

Optional

cmdArgs: { format: "<string>" }

Sets the format of the check output to text or JSON. Valid values are TXT and JSON. Default: TXT.

Policy checks JSON object describes the JSON structure.

Optional

cmdArgs: { label-filter: "<string>" }

Specifies the changeset labels to match. Labels are tags you can add to changesets to control which changesets will be executed in any migration run.

Optional

cmdArgs: { conditions-filter: "<string>" }

Liquibase Secure 6.0 and later. Specifies the changeset conditions to match. conditions is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match.

Optional

cmdArgs: { keywords-filter: "<string>" }

Liquibase Secure 6.0 and later. Specifies the changeset keywords to match. keywords is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match.

Optional

cmdArgs: { releases-filter: "<string>" }

Liquibase Secure 6.0 and later. Specifies the changeset releases to match. releases is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match.

Optional

cmdArgs: { teams-filter: "<string>" }

Liquibase Secure 6.0 and later. Specifies the changeset teams to match. teams is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match.

Optional

cmdArgs: { max-affected-fail-severity: "<string>" }

The severity returned when a MaxAffected* check cannot run against the given script, or cannot determine a result, and so performs no operation. If not set, the severity of the configured check is returned. Valid values are the return codes 0, 1, 2, 3, and 4.

Optional

cmdArgs: { password: "<string>" }

Password to connect to the target database.

Optional

cmdArgs: { property-substitution-enabled: "<true|false>" }

If set to true, changesets are evaluated by checks run after property substitution. If set to false, changesets are evaluated by checks run before property substitution, meaning the names of the "property substitution tokens" are evaluated. Default: true.

Optional

cmdArgs: { report-enabled: "<true|false>" }

Enables a report at the command level. Overrides the global parameter --reports-enabled. Default: true.

Optional

cmdArgs: { report-name: "<string>" }

Specifies the name of the report file at the command level. Overrides the global parameter --reports-name. By default, Liquibase generates a new report file labeled with a timestamp (user's local time). If you set a custom name, Liquibase overwrites the existing file every time you generate a new report. Default: report-<DD-Mon-YYYY-HHmmss>.html.

Optional

cmdArgs: { report-path: "<string>" }

Specifies the file path to the report file at the command level. Overrides the global parameter --reports-path. Default: ./.

Optional

cmdArgs: { report-suppress-exception: "<true|false>" }

Specifies whether to hide exceptions (which may contain SQL) from the operation report at the command level. Overrides the global parameter --reports-suppress-exception. Default: false. However:

If --report-suppress-exception is not set and --report-suppress-sql=true, Liquibase suppresses all SQL, including exception SQL.

If --report-suppress-exception=false and --report-suppress-sql=true, Liquibase suppresses most SQL but shows exception SQL.

Optional

cmdArgs: { report-suppress-skipped: "<true|false>" }

Liquibase Secure 6.0 and later. Specifies whether to hide the detail rows for skipped (filtered out) changesets in operation reports at the command level. The report still displays the total number of skipped changesets in its summary. Overrides the global parameter --reports-suppress-skipped. Default: false.

Optional

cmdArgs: { report-suppress-sql: "<true|false>" }

Specifies whether to hide changeset SQL in operation reports at the command level. Overridden by the global parameter --reports-suppress-sql. Default: false.

Optional

cmdArgs: { schemas: "<string>" }

The schemas to check when --checks-scope contains database.

Optional

cmdArgs: { skip-bulk-data: "<true|false>" }

Skip regex pattern matching on bulk data load statements (INSERT/UPDATE with large VALUES clauses). Multi-value INSERTs are split automatically for efficient pattern matching, so this parameter is typically not needed. Set it to true to skip bulk data entirely. Default: false.

Optional

cmdArgs: { sql-parser-fail-severity: "<string>" }

Specifies the severity value returned when a check fails due to a SQL parse error. Valid values are the following return codes:

0 is INFO

1 is MINOR

2 is MAJOR

3 is CRITICAL

4 is BLOCKER

Default: severity of the executed check

Optional

cmdArgs: { targeting-file: "<string>" }

Specifies the checks targeting file to apply to this run. Checks Targeting rules apply only when you name the file with this parameter. There is no default file lookup, so a run that omits it applies no rules.

Optional

cmdArgs: { username: "<string>" }

Username to connect to the target database.

Optional

cmdArgs: { verbose: "<true|false>" }

Specifies the detail level of the command's output. Default: false.

Optional

Global parameters

Parameter

Definition

Requirement

liquibase.licenseKey: <string>

Your Liquibase Secure license key

Required

Command parameters

Parameter

Description

Requirement

liquibase.command.changelogFile: <string>

liquibase.command.checks.run.changelogFile: <string>

The changelog file against which you execute checks when running liquibase checks run.

Required (either this or --url)

liquibase.command.url: <string>

liquibase.command.checks.run.url: <string>

The JDBC database connection URL. How do I connect to my database? covers the URL format for each database.

Required (either this or --changelog-file)

liquibase.command.assignmentId: <string>liquibase.command.checks.run.assignmentId: <string>

Liquibase Secure 6.0 and later. One assignment UUID, or a comma-separated list of up to 50, configured in Change Governance. Liquibase pulls the merged checks settings for those assignments instead of reading a local checks settings file. Requires liquibase.platform.apiUrl and liquibase.platform.apiKey to be set. Takes precedence over --checks-settings-file.

Optional

liquibase.command.autoEnableNewChecks: <true|false>

liquibase.command.checks.run.autoEnableNewChecks: <true|false>

Automatically enable new policy checks in the liquibase.checks-settings.conf file when they are available. Default: false.

Optional

liquibase.command.autoUpdate: <string>

liquibase.command.checks.run.autoUpdate: <string>

Allows automatic backup and updating of the liquibase.checks-settings.conf file when new policy checks are available. Valid values are ON and OFF. Default: OFF.

Optional

liquibase.command.cacheChangelogFileContents: <true|false>

liquibase.command.checks.run.cacheChangelogFileContents: <true|false>

If true, sqlFile Change Type contents are cached in memory to improve performance, at the cost of higher memory usage. To reduce memory usage, set this to false. Default: true

Optional

liquibase.command.changesetFilter: <string>

liquibase.command.checks.run.changesetFilter: <string>

Specifies whether policy checks run on ALL changesets or only PENDING (undeployed) changesets. Only applies to checks with the changelog scope. Default: ALL.

Optional

liquibase.command.checkName: <string>

liquibase.command.checks.run.checkName: <string>

The name of the check(s) you want to target. Comma-separated list of one or more enabled checks. Checks to exclude can be prefixed with the ! character. If no checks are specified, all enabled checks are targeted. For example: --check-name=shortname1,shortname2,!shortname3

Optional

liquibase.command.checkRollbacks: <true|false>

liquibase.command.checks.run.checkRollbacks: <true|false>

Allow changeset's rollback code to be analyzed for compliance with currently enabled policy checks. Default: false

Optional

liquibase.command.checkTimeout: <seconds>

liquibase.command.checks.run.checkTimeout: <seconds>

Sets a timeout in seconds for each built-in policy check. If a check takes longer than the specified time, it is terminated. Default: 0 (disabled).

Optional

liquibase.command.checkValidityFailSeverity: <string> liquibase.command.checks.run.checkValidityFailSeverity: <string>

The severity that a check which fails because of a validation error exits with. If not set, the check is skipped instead. Valid values are the return codes 0, 1, 2, 3, and 4.

Optional

liquibase.command.checksOutput: <string>

liquibase.command.checks.run.checksOutput: <string>

Specify which parts of the checks run output should be shown. Options:

all: show all sections

issues: show the triggered checks

issues0: show the issues with severity 0

issues1: show the issues with severity 1

issues2: show the issues with severity 2

issues3: show the issues with severity 3

issues4: show the issues with severity 4

validated: show the section that starts with "Changesets Validated"

checksrun: show the section that starts with "Checks run against each changeset"

sqlparserfails: show the section that starts with "Changeset SQL not parsed in..."

skippedchecks: show the section that starts with "Changelogs Checks Skipped Due to unsupported changeset..." (such as checks skipped due to version incompatibility)

nonapplicablechecks: show chained checks which cannot be evaluated due to their configurations conflicting (such as a chained check that evaluates

TableColumnLimit & ObjectNameMustMatch, where TableColumnLimit only evaluates tables and ObjectNameMustMatch is configured to only evaluate indexes).

Default: all

Optional

liquibase.command.checksPackages: <string>

liquibase.command.checks.run.checksPackages: <string>

If using a checks packages file, optionally specify which packages should be run from the file as a comma-separated list.

Optional

liquibase.command.checksScope: <string>

liquibase.command.checks.run.checksScope: <string>

The Liquibase component to run checks against, which can be a comma-separated list. Valid values are changelog and database. Default: changelog.

Optional

liquibase.command.checksScriptsEnabled: <true|false>

liquibase.command.checks.run.checksScriptsEnabled: <true|false>

Allow execution of the Liquibase Secure custom policy checks you have written. Default: false.

Optional

liquibase.command.checksScriptsPath: <string>

liquibase.command.checks.run.checksScriptsPath: <string>

Only allow custom scripts found in the specified directories to execute. If not set, Liquibase allows custom scripts from any location to execute.

Optional

liquibase.command.checksScriptsPythonPath: <string>

liquibase.command.checks.run.checksScriptsPythonPath: <string>

Additional directories to add to the Python import path, so custom policy check scripts can import shared utility modules. Separate multiple directories with the system path separator. Relative paths are resolved to absolute paths automatically. The script's own directory is added for you, so a check script can import from sibling .py files without setting this parameter.

Optional

liquibase.command.checksSettingsFile: <string>

liquibase.command.checks.run.checksSettingsFile: <string>

Specifies the checks settings file to use with policy checks commands. Write the relative path of the settings file that you want to read from or modify. Use the checks settings file covers its contents.

Optional

liquibase.command.contextFilter: <string>

liquibase.command.checks.run.contextFilter: <string>

Specifies the changeset contexts to match. Contexts are tags you can add to changesets to control which changesets are executed in any particular migration run.

Optional

liquibase.command.customCheckTimeout: <seconds>

liquibase.command.checks.run.customCheckTimeout: <seconds>

Sets a timeout in seconds for each custom policy check. If a check takes longer than the specified time, it is terminated. Default: 0 (disabled).

Optional

liquibase.command.defaultCatalogName: <string>

liquibase.command.checks.run.defaultCatalogName: <string>

Name of the default catalog to use for the database connection

Optional

liquibase.command.defaultSchemaName: <string>

liquibase.command.checks.run.defaultSchemaName: <string>

Name of the default schema to use for the database connection. If defaultSchemaName is set, then objects do not have to be fully qualified. This means you can refer to just mytable instead of myschema.mytable.

Note: You can use mixed-case schema names if you set --preserve-schema-case to true.

Optional

liquibase.command.driver: <string>

liquibase.command.checks.run.driver: <string>

The JDBC driver class

Optional

liquibase.command.driverPropertiesFile: <string>

liquibase.command.checks.run.driverPropertiesFile: <string>

The JDBC driver properties file

Optional

liquibase.command.format: <string>

liquibase.command.checks.run.format: <string>

Sets the format of the check output to text or JSON. Valid values are TXT and JSON. Default: TXT.

Policy checks JSON object describes the JSON structure.

Optional

liquibase.command.labelFilter: <string>

liquibase.command.checks.run.labelFilter: <string>

Specifies the changeset labels to match. Labels are tags you can add to changesets to control which changesets will be executed in any migration run.

Optional

liquibase.command.conditionsFilter: <string>

liquibase.command.checks.run.conditionsFilter: <string>

Liquibase Secure 6.0 and later. Specifies the changeset conditions to match. conditions is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match.

Optional

liquibase.command.keywordsFilter: <string>

liquibase.command.checks.run.keywordsFilter: <string>

Liquibase Secure 6.0 and later. Specifies the changeset keywords to match. keywords is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match.

Optional

liquibase.command.releasesFilter: <string>

liquibase.command.checks.run.releasesFilter: <string>

Liquibase Secure 6.0 and later. Specifies the changeset releases to match. releases is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match.

Optional

liquibase.command.teamsFilter: <string>

liquibase.command.checks.run.teamsFilter: <string>

Liquibase Secure 6.0 and later. Specifies the changeset teams to match. teams is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match.

Optional

liquibase.command.maxAffectedFailSeverity: <string> liquibase.command.checks.run.maxAffectedFailSeverity: <string>

The severity returned when a MaxAffected* check cannot run against the given script, or cannot determine a result, and so performs no operation. If not set, the severity of the configured check is returned. Valid values are the return codes 0, 1, 2, 3, and 4.

Optional

liquibase.command.password: <string>

liquibase.command.checks.run.password: <string>

Password to connect to the target database.

Optional

liquibase.command.propertySubstitutionEnabled: <true|false>

liquibase.command.checks.run.propertySubstitutionEnabled: <true|false>

If set to true, changesets are evaluated by checks run after property substitution. If set to false, changesets are evaluated by checks run before property substitution, meaning the names of the "property substitution tokens" are evaluated. Default: true.

Optional

liquibase.command.reportEnabled: <true|false>

liquibase.command.checks.run.reportEnabled: <true|false>

Enables a report at the command level. Overrides the global parameter --reports-enabled. Default: true.

Optional

liquibase.command.reportName: <string>

liquibase.command.checks.run.reportName: <string>

Specifies the name of the report file at the command level. Overrides the global parameter --reports-name. By default, Liquibase generates a new report file labeled with a timestamp (user's local time). If you set a custom name, Liquibase overwrites the existing file every time you generate a new report. Default: report-<DD-Mon-YYYY-HHmmss>.html.

Optional

liquibase.command.reportPath: <string>

liquibase.command.checks.run.reportPath: <string>

Specifies the file path to the report file at the command level. Overrides the global parameter --reports-path. Default: ./.

Optional

liquibase.command.reportSuppressException: <true|false>

liquibase.command.checks.run.reportSuppressException: <true|false>

Specifies whether to hide exceptions (which may contain SQL) from the operation report at the command level. Overrides the global parameter --reports-suppress-exception. Default: false. However:

If --report-suppress-exception is not set and --report-suppress-sql=true, Liquibase suppresses all SQL, including exception SQL.

If --report-suppress-exception=false and --report-suppress-sql=true, Liquibase suppresses most SQL but shows exception SQL.

Optional

liquibase.command.reportSuppressSkipped: <true|false> liquibase.command.checks.run.reportSuppressSkipped: <true|false>

Liquibase Secure 6.0 and later. Specifies whether to hide the detail rows for skipped (filtered out) changesets in operation reports at the command level. The report still displays the total number of skipped changesets in its summary. Overrides the global parameter --reports-suppress-skipped. Default: false.

Optional

liquibase.command.reportSuppressSql: <true|false>

liquibase.command.checks.run.reportSuppressSql: <true|false>

Specifies whether to hide changeset SQL in operation reports at the command level. Overridden by the global parameter --reports-suppress-sql. Default: false.

Optional

liquibase.command.schemas: <string>

liquibase.command.checks.run.schemas: <string>

The schemas to check when --checks-scope contains database.

Optional

liquibase.command.skipBulkData: <true|false>

liquibase.command.checks.run.skipBulkData: <true|false>

Skip regex pattern matching on bulk data load statements (INSERT/UPDATE with large VALUES clauses). Multi-value INSERTs are split automatically for efficient pattern matching, so this parameter is typically not needed. Set it to true to skip bulk data entirely. Default: false.

Optional

liquibase.command.sqlParserFailSeverity: <string>

liquibase.command.checks.run.sqlParserFailSeverity: <string>

Specifies the severity value returned when a check fails due to a SQL parse error. Valid values are the following return codes:

0 is INFO

1 is MINOR

2 is MAJOR

3 is CRITICAL

4 is BLOCKER

Default: severity of the executed check

Optional

liquibase.command.targetingFile: <string>

liquibase.command.checks.run.targetingFile: <string>

Specifies the checks targeting file to apply to this run. Checks Targeting rules apply only when you name the file with this parameter. There is no default file lookup, so a run that omits it applies no rules.

Optional

liquibase.command.username: <string>

liquibase.command.checks.run.username: <string>

Username to connect to the target database.

Optional

liquibase.command.verbose: <true|false>

liquibase.command.checks.run.verbose: <true|false>

Specifies the detail level of the command's output. Default: false.

Optional

Global parameters

Parameter

Definition

Requirement

JAVA_OPTS=-Dliquibase.licenseKey=<string>

Your Liquibase Secure license key

Required

Command parameters

Parameter

Description

Requirement

JAVA_OPTS=-Dliquibase.command.changelogFile=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.changelogFile=<string>

The changelog file against which you execute checks when running liquibase checks run.

Required (either this or --url)

JAVA_OPTS=-Dliquibase.command.url=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.url=<string>

The JDBC database connection URL. How do I connect to my database? covers the URL format for each database.

Required (either this or --changelog-file)

JAVA_OPTS=-Dliquibase.command.assignmentId=<string>JAVA_OPTS=-Dliquibase.command.checks.run.assignmentId=<string>

Liquibase Secure 6.0 and later. One assignment UUID, or a comma-separated list of up to 50, configured in Change Governance. Liquibase pulls the merged checks settings for those assignments instead of reading a local checks settings file. Requires liquibase.platform.apiUrl and liquibase.platform.apiKey to be set. Takes precedence over --checks-settings-file.

Optional

JAVA_OPTS=-Dliquibase.command.autoEnableNewChecks=<true|false>

JAVA_OPTS=-Dliquibase.command.checks.run.autoEnableNewChecks=<true|false>

Automatically enable new policy checks in the liquibase.checks-settings.conf file when they are available. Default: false.

Optional

JAVA_OPTS=-Dliquibase.command.autoUpdate=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.autoUpdate=<string>

Allows automatic backup and updating of the liquibase.checks-settings.conf file when new policy checks are available. Valid values are ON and OFF. Default: OFF.

Optional

JAVA_OPTS=-Dliquibase.command.cacheChangelogFileContents=<true|false>

JAVA_OPTS=-Dliquibase.command.checks.run.cacheChangelogFileContents=<true|false>

If true, sqlFile Change Type contents are cached in memory to improve performance, at the cost of higher memory usage. To reduce memory usage, set this to false. Default: true

Optional

JAVA_OPTS=-Dliquibase.command.changesetFilter=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.changesetFilter=<string>

Specifies whether policy checks run on ALL changesets or only PENDING (undeployed) changesets. Only applies to checks with the changelog scope. Default: ALL.

Optional

JAVA_OPTS=-Dliquibase.command.checkName=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.checkName=<string>

The name of the check(s) you want to target. Comma-separated list of one or more enabled checks. Checks to exclude can be prefixed with the ! character. If no checks are specified, all enabled checks are targeted. For example: --check-name=shortname1,shortname2,!shortname3

Optional

JAVA_OPTS=-Dliquibase.command.checkRollbacks=<true|false>

JAVA_OPTS=-Dliquibase.command.checks.run.checkRollbacks=<true|false>

Allow changeset's rollback code to be analyzed for compliance with currently enabled policy checks. Default: false

Optional

JAVA_OPTS=-Dliquibase.command.checkTimeout=<seconds>

JAVA_OPTS=-Dliquibase.command.checks.run.checkTimeout=<seconds>

Sets a timeout in seconds for each built-in policy check. If a check takes longer than the specified time, it is terminated. Default: 0 (disabled).

Optional

JAVA_OPTS=-Dliquibase.command.checkValidityFailSeverity=<string> JAVA_OPTS=-Dliquibase.command.checks.run.checkValidityFailSeverity=<string>

The severity that a check which fails because of a validation error exits with. If not set, the check is skipped instead. Valid values are the return codes 0, 1, 2, 3, and 4.

Optional

JAVA_OPTS=-Dliquibase.command.checksOutput=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.checksOutput=<string>

Specify which parts of the checks run output should be shown. Options:

all: show all sections

issues: show the triggered checks

issues0: show the issues with severity 0

issues1: show the issues with severity 1

issues2: show the issues with severity 2

issues3: show the issues with severity 3

issues4: show the issues with severity 4

validated: show the section that starts with "Changesets Validated"

checksrun: show the section that starts with "Checks run against each changeset"

sqlparserfails: show the section that starts with "Changeset SQL not parsed in..."

skippedchecks: show the section that starts with "Changelogs Checks Skipped Due to unsupported changeset..." (such as checks skipped due to version incompatibility)

nonapplicablechecks: show chained checks which cannot be evaluated due to their configurations conflicting (such as a chained check that evaluates

TableColumnLimit & ObjectNameMustMatch, where TableColumnLimit only evaluates tables and ObjectNameMustMatch is configured to only evaluate indexes).

Default: all

Optional

JAVA_OPTS=-Dliquibase.command.checksPackages=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.checksPackages=<string>

If using a checks packages file, optionally specify which packages should be run from the file as a comma-separated list.

Optional

JAVA_OPTS=-Dliquibase.command.checksScope=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.checksScope=<string>

The Liquibase component to run checks against, which can be a comma-separated list. Valid values are changelog and database. Default: changelog.

Optional

JAVA_OPTS=-Dliquibase.command.checksScriptsEnabled=<true|false>

JAVA_OPTS=-Dliquibase.command.checks.run.checksScriptsEnabled=<true|false>

Allow execution of the Liquibase Secure custom policy checks you have written. Default: false.

Optional

JAVA_OPTS=-Dliquibase.command.checksScriptsPath=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.checksScriptsPath=<string>

Only allow custom scripts found in the specified directories to execute. If not set, Liquibase allows custom scripts from any location to execute.

Optional

JAVA_OPTS=-Dliquibase.command.checksScriptsPythonPath=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.checksScriptsPythonPath=<string>

Additional directories to add to the Python import path, so custom policy check scripts can import shared utility modules. Separate multiple directories with the system path separator. Relative paths are resolved to absolute paths automatically. The script's own directory is added for you, so a check script can import from sibling .py files without setting this parameter.

Optional

JAVA_OPTS=-Dliquibase.command.checksSettingsFile=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.checksSettingsFile=<string>

Specifies the checks settings file to use with policy checks commands. Write the relative path of the settings file that you want to read from or modify. Use the checks settings file covers its contents.

Optional

JAVA_OPTS=-Dliquibase.command.contextFilter=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.contextFilter=<string>

Specifies the changeset contexts to match. Contexts are tags you can add to changesets to control which changesets are executed in any particular migration run.

Optional

JAVA_OPTS=-Dliquibase.command.customCheckTimeout=<seconds>

JAVA_OPTS=-Dliquibase.command.checks.run.customCheckTimeout=<seconds>

Sets a timeout in seconds for each custom policy check. If a check takes longer than the specified time, it is terminated. Default: 0 (disabled).

Optional

JAVA_OPTS=-Dliquibase.command.defaultCatalogName=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.defaultCatalogName=<string>

Name of the default catalog to use for the database connection

Optional

JAVA_OPTS=-Dliquibase.command.defaultSchemaName=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.defaultSchemaName=<string>

Name of the default schema to use for the database connection. If defaultSchemaName is set, then objects do not have to be fully qualified. This means you can refer to just mytable instead of myschema.mytable.

Note: You can use mixed-case schema names if you set --preserve-schema-case to true.

Optional

JAVA_OPTS=-Dliquibase.command.driver=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.driver=<string>

The JDBC driver class

Optional

JAVA_OPTS=-Dliquibase.command.driverPropertiesFile=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.driverPropertiesFile=<string>

The JDBC driver properties file

Optional

JAVA_OPTS=-Dliquibase.command.format=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.format=<string>

Sets the format of the check output to text or JSON. Valid values are TXT and JSON. Default: TXT.

Policy checks JSON object describes the JSON structure.

Optional

JAVA_OPTS=-Dliquibase.command.labelFilter=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.labelFilter=<string>

Specifies the changeset labels to match. Labels are tags you can add to changesets to control which changesets will be executed in any migration run.

Optional

JAVA_OPTS=-Dliquibase.command.conditionsFilter=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.conditionsFilter=<string>

Liquibase Secure 6.0 and later. Specifies the changeset conditions to match. conditions is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match.

Optional

JAVA_OPTS=-Dliquibase.command.keywordsFilter=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.keywordsFilter=<string>

Liquibase Secure 6.0 and later. Specifies the changeset keywords to match. keywords is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match.

Optional

JAVA_OPTS=-Dliquibase.command.releasesFilter=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.releasesFilter=<string>

Liquibase Secure 6.0 and later. Specifies the changeset releases to match. releases is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match.

Optional

JAVA_OPTS=-Dliquibase.command.teamsFilter=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.teamsFilter=<string>

Liquibase Secure 6.0 and later. Specifies the changeset teams to match. teams is a tag you can add to changesets to control which changesets will be executed in any migration run. Matching is a straight string comparison. Prefix the value with the @ operator to match strictly, so that only changesets with the exact value match.

Optional

JAVA_OPTS=-Dliquibase.command.maxAffectedFailSeverity=<string> JAVA_OPTS=-Dliquibase.command.checks.run.maxAffectedFailSeverity=<string>

The severity returned when a MaxAffected* check cannot run against the given script, or cannot determine a result, and so performs no operation. If not set, the severity of the configured check is returned. Valid values are the return codes 0, 1, 2, 3, and 4.

Optional

JAVA_OPTS=-Dliquibase.command.password=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.password=<string>

Password to connect to the target database.

Optional

JAVA_OPTS=-Dliquibase.command.propertySubstitutionEnabled=<true|false>

JAVA_OPTS=-Dliquibase.command.checks.run.propertySubstitutionEnabled=<true|false>

If set to true, changesets are evaluated by checks run after property substitution. If set to false, changesets are evaluated by checks run before property substitution, meaning the names of the "property substitution tokens" are evaluated. Default: true.

Optional

JAVA_OPTS=-Dliquibase.command.reportEnabled=<true|false>

JAVA_OPTS=-Dliquibase.command.checks.run.reportEnabled=<true|false>

Enables a report at the command level. Overrides the global parameter --reports-enabled. Default: true.

Optional

JAVA_OPTS=-Dliquibase.command.reportName=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.reportName=<string>

Specifies the name of the report file at the command level. Overrides the global parameter --reports-name. By default, Liquibase generates a new report file labeled with a timestamp (user's local time). If you set a custom name, Liquibase overwrites the existing file every time you generate a new report. Default: report-<DD-Mon-YYYY-HHmmss>.html.

Optional

JAVA_OPTS=-Dliquibase.command.reportPath=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.reportPath=<string>

Specifies the file path to the report file at the command level. Overrides the global parameter --reports-path. Default: ./.

Optional

JAVA_OPTS=-Dliquibase.command.reportSuppressException=<true|false>

JAVA_OPTS=-Dliquibase.command.checks.run.reportSuppressException=<true|false>

Specifies whether to hide exceptions (which may contain SQL) from the operation report at the command level. Overrides the global parameter --reports-suppress-exception. Default: false. However:

If --report-suppress-exception is not set and --report-suppress-sql=true, Liquibase suppresses all SQL, including exception SQL.

If --report-suppress-exception=false and --report-suppress-sql=true, Liquibase suppresses most SQL but shows exception SQL.

Optional

JAVA_OPTS=-Dliquibase.command.reportSuppressSkipped=<true|false> JAVA_OPTS=-Dliquibase.command.checks.run.reportSuppressSkipped=<true|false>

Liquibase Secure 6.0 and later. Specifies whether to hide the detail rows for skipped (filtered out) changesets in operation reports at the command level. The report still displays the total number of skipped changesets in its summary. Overrides the global parameter --reports-suppress-skipped. Default: false.

Optional

JAVA_OPTS=-Dliquibase.command.reportSuppressSql=<true|false>

JAVA_OPTS=-Dliquibase.command.checks.run.reportSuppressSql=<true|false>

Specifies whether to hide changeset SQL in operation reports at the command level. Overridden by the global parameter --reports-suppress-sql. Default: false.

Optional

JAVA_OPTS=-Dliquibase.command.schemas=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.schemas=<string>

The schemas to check when --checks-scope contains database.

Optional

JAVA_OPTS=-Dliquibase.command.skipBulkData=<true|false>

JAVA_OPTS=-Dliquibase.command.checks.run.skipBulkData=<true|false>

Skip regex pattern matching on bulk data load statements (INSERT/UPDATE with large VALUES clauses). Multi-value INSERTs are split automatically for efficient pattern matching, so this parameter is typically not needed. Set it to true to skip bulk data entirely. Default: false.

Optional

JAVA_OPTS=-Dliquibase.command.sqlParserFailSeverity=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.sqlParserFailSeverity=<string>

Specifies the severity value returned when a check fails due to a SQL parse error. Valid values are the following return codes:

0 is INFO

1 is MINOR

2 is MAJOR

3 is CRITICAL

4 is BLOCKER

Default: severity of the executed check

Optional

JAVA_OPTS=-Dliquibase.command.targetingFile=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.targetingFile=<string>

Specifies the checks targeting file to apply to this run. Checks Targeting rules apply only when you name the file with this parameter. There is no default file lookup, so a run that omits it applies no rules.

Optional

JAVA_OPTS=-Dliquibase.command.username=<string>

JAVA_OPTS=-Dliquibase.command.checks.run.username=<string>

Username to connect to the target database.

Optional

JAVA_OPTS=-Dliquibase.command.verbose=<true|false>

JAVA_OPTS=-Dliquibase.command.checks.run.verbose=<true|false>

Specifies the detail level of the command's output. Default: false.

Optional

Output

A run that finds issues in a changelog reports each triggered check, the changesets it validated, the checks it ran against every changeset, and the exit code it returns:

loading

Checks Targeting information in the output

When a run names a targeting file with --targeting-file, the block for a triggered check that a targeting rule affected carries extra lines naming the file, the rule that applied, and the rule’s reason and expiration when it has them:

loading

Targeting Rule is EXEMPT, RESTRICT, or both when one changeset matches a rule of each kind, and it notes a count such as (+1 more rule matched) when more than one rule of the same type matched the changeset. Targeting Expiry is then the latest expiration across all of them. What is Checks Targeting? covers what the rules do, how they select changesets, and how the output reads when several rules match or both kinds apply.