Public/Update-PSDependLock.ps1

function Update-PSDependLock {
    <#
    .SYNOPSIS
        Resolve a DependencyFile's full dependency graph and write a lock file.
 
    .DESCRIPTION
        Resolve a DependencyFile's full dependency graph and write a lock file
 
        Works like npm's package-lock.json: every dependency whose DependencyType
        supports Resolve is resolved to the highest version satisfying Version,
        and its dependencies are resolved recursively. Gallery, NuGet and
        Chocolatey types accept NuGet ranges; Npm accepts npm semver ranges.
 
        One version is locked per DependencyType::Name. Resolution is greedy:
        child constraints are intersected, but PSDepend does not backtrack to an
        older parent version. Narrow a parent range when an older version is
        required. Incompatible constraints fail the update.
 
        The result is written next to the DependencyFile as <name>.lock.json
        (requirements.psd1 -> requirements.lock.json). Invoke-PSDepend and
        Get-Dependency then use it automatically. A changed Dependency, Version,
        resolution Source, or DependencyScript parameter makes the lock stale.
 
        DependencyTypes without Resolve (Git, GitHub, FileDownload, ...) are
        recorded for drift detection but install exactly as declared. Lock files
        should be committed and reviewed like code; format version 1 validates
        exact versions but does not contain package content hashes.
 
        See Get-Help about_PSDepend for more information.
 
    .PARAMETER Path
        Path to a specific depend.psd1 file, or to a folder that we recursively search for *.depend.psd1 and requirements.psd1 files
 
        Defaults to the current path
 
    .PARAMETER Recurse
        If path is a folder, whether to recursively search for *.depend.psd1 and requirements.psd1 files under that folder
 
        Defaults to $True
 
    .PARAMETER PSDependTypePath
        Specify a PSDependMap.psd1 file that maps DependencyTypes to their scripts.
 
        This defaults to the PSDependMap.psd1 in the PSDepend module folder
 
    .PARAMETER Credentials
        Specifies a hashtable of PSCredentials to use for each dependency that is served from a private feed. The key of the hashtable must match the Credential property value in the dependency.
 
    .PARAMETER PassThru
        Return the path of each lock file that was written
 
    .EXAMPLE
        Update-PSDependLock -Path .\requirements.psd1
 
        # Resolve every dependency (and their dependencies) in requirements.psd1 and write requirements.lock.json
 
    .EXAMPLE
        Update-PSDependLock -Path C:\Project -Recurse $false
 
        # Write a lock for each *.depend.psd1 and requirements.psd1 directly under C:\Project
 
    .LINK
        https://github.com/PowerShellOrg/PSDepend
    #>

    [CmdletBinding(SupportsShouldProcess = $True)]
    [OutputType([string])]
    param(
        [validatescript( { Test-Path -Path $_ -ErrorAction Stop })]
        [parameter( Position = 0,
            ValueFromPipeline = $True,
            ValueFromPipelineByPropertyName = $True)]
        [string[]]$Path = '.',

        [bool]$Recurse = $True,

        [validatescript( { Test-Path -Path $_ -PathType Leaf -ErrorAction Stop })]
        [string]$PSDependTypePath = $(Join-Path $ModuleRoot PSDependMap.psd1),

        [hashtable]$Credentials,

        [switch]$PassThru
    )
    process {
        foreach ($PathItem in $Path) {
            $DependencyFiles = @( Resolve-DependScripts -Path $PathItem -Recurse $Recurse )
            if ($DependencyFiles.Count -eq 0) {
                Write-Warning "No *.depend.psd1 or requirements.psd1 files found under [$PathItem]"
                continue
            }

            foreach ($DependencyFile in $DependencyFiles) {
                $GetParams = @{ Path = $DependencyFile; IgnoreLock = $true }
                if ($null -ne $Credentials) {
                    $GetParams.Add('Credentials', $Credentials)
                }
                $Dependencies = @( Get-Dependency @GetParams -ErrorAction Stop | Where-Object { $_ } )
                $LockPath = Get-PSDependLockPath -DependencyFile $DependencyFile

                Write-Verbose "Resolving [$($Dependencies.Count)] dependencies from [$DependencyFile]"
                $Lock = Resolve-PSDependLock -Dependency $Dependencies -PSDependTypePath $PSDependTypePath

                if ($PSCmdlet.ShouldProcess($LockPath, "Write lock for '$DependencyFile'")) {
                    Export-PSDependLock -Lock $Lock -Path $LockPath
                    Write-Verbose "Wrote lock with [$($Lock.packages.Count)] packages to [$LockPath]"
                    if ($PassThru) {
                        $LockPath
                    }
                }
            }
        }
    }
}