Cobra
github.com/spf13/cobra
Command trees, flags and shell completion for CLI applications
Reviewed 2026-09-30 · Package source
Recorded facts
Metadata fetched: 2026-09-30T18:11:16.669Z · Freshness: current. This is a dated snapshot; check the linked sources before adopting a package.
- Version
- v1.10.2
- Minimum Go version
- 1.15
- Licenses
- Apache-2.0
- Import path
- github.com/spf13/cobra
- Capabilities
- subcommands, flags
- Dependencies recorded
- 4
- Metadata source 1: https://proxy.golang.org/github.com/spf13/cobra/@latest
- Metadata source 2: https://proxy.golang.org/github.com/spf13/cobra/@v/v1.10.2.mod
- Metadata source 3: https://api.deps.dev/v3/systems/go/packages/github.com%2Fspf13%2Fcobra/versions/v1.10.2
Vulnerability evidence
Status: checked. Checked: 2026-09-30T18:11:16.669Z.
No advisories reported by this check.
Version advisories do not establish whether a vulnerability is reachable in your application.
Vulnerability sourceTradeoffs
- Configuration-file loading is a separate concern.
Install and import
go get github.com/spf13/[email protected]import "github.com/spf13/cobra"
Authored example
Verification status: passed · Checked: 2026-09-30T18:16:20.347Z
Package version: v1.10.2 · Go toolchain: go1.27.1
Targets: linux/amd64, windows/amd64 · CGO: disabled
Compilation checks only this displayed example. It does not verify runtime behavior, all package features or vulnerability reachability.
package main
import (
"fmt"
"log"
"github.com/spf13/cobra"
)
func main() {
var name string
command := &cobra.Command{
Use: "hello",
RunE: func(cmd *cobra.Command, args []string) error {
_, err := fmt.Fprintln(cmd.OutOrStdout(), "hello", name)
return err
},
}
command.Flags().StringVar(&name, "name", "Go", "Name to greet")
if err := command.Execute(); err != nil {
log.Fatal(err)
}
}
Compile verification covers this example only. It does not test runtime behavior or every optional feature.
Reproduce the compilation with pinned dependencies
Save the example as main.go alongside these files in a new directory. Use the recorded Go toolchain and CGO_ENABLED=0 to compile for a recorded target.
go.mod
module example.com/discovery/cobra
go 1.27.1
require github.com/spf13/cobra v1.10.2
require (
github.com/inconshreveable/mousetrap v1.1.0 // indirect
github.com/spf13/pflag v1.0.9 // indirect
)
go.sum
github.com/cpuguy83/go-md2man/v2 v2.0.6/go.mod h1:oOW0eioCTA6cOiMLiUPZOpcVxMig6NIQQ7OS05n1F4g=
github.com/inconshreveable/mousetrap v1.1.0 h1:wN+x4NVGpMsO7ErUn/mUI3vEoE6Jt13X2s0bqwp9tc8=
github.com/inconshreveable/mousetrap v1.1.0/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw=
github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM=
github.com/spf13/cobra v1.10.2 h1:DMTTonx5m65Ic0GOoRY2c16WCbHxOOw6xxezuLaBpcU=
github.com/spf13/cobra v1.10.2/go.mod h1:7C1pvHqHw5A4vrJfjNwvOdzYu0Gml16OCs2GRiTUUS4=
github.com/spf13/pflag v1.0.9 h1:9exaQaMOCwffKiiiYk6/BndUBv+iRViNW+4lEMi0PvY=
github.com/spf13/pflag v1.0.9/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg=
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=