Skip to content

Latest commit

 

History

History
312 lines (200 loc) · 31.8 KB

File metadata and controls

312 lines (200 loc) · 31.8 KB

@codacy/codacy-cloud-cli

1.13.0

Minor Changes

  • #58 a06a95b Thanks @pedrobpereira! - images now shows how many tags each image holds, and the organization's image tag usage against its limit. --output json includes tagCount per image. The image --delete --keep-latest warning now uses the organization's actual tag limit instead of assuming 1,000.

  • #57 891564b Thanks @pedrobpereira! - Show dependency import chains on codacy issue/codacy issues for SCA issues, matching what codacy finding/codacy findings already show. --output json gains dependencyChains on the issue payload.

1.12.1

Patch Changes

  • #55 3e55d0f Thanks @claudiacodacy! - Escape path parameters per segment, so a namespaced image name reaches the right endpoint. codacy image gh my-org my-org/my-service and every other image subcommand failed with Error: The requested resource could not be found. (HTTP 404) against any image whose name carries a slash — which is the usual shape, and was every image in our own organization.

    The generated client falls back to encodeURI when OpenAPI.ENCODE_PATH is unset, and encodeURI leaves / alone because it is meant for whole URLs rather than the pieces they are built from. codacy/codacy-website therefore expanded into two path segments and hit a route that does not exist. The entry point now sets encodePathSegment (encodeURIComponent), which escapes separators as a single segment requires.

    This affects every command, not only image: the same encoder handles branch names and file paths, which can carry slashes for the same reason. No currently shipped command sent one as a path parameter, so nothing else changes shape.

1.12.0

Minor Changes

  • #50 4dfa3dd Thanks @claudiacodacy! - Add codacy image <provider> <org> <image> --tag <tag> --upload <file> to upload an SBOM (SPDX or CycloneDX) for a container image tag.

    -e, --environment <name> and -r, --repository <name> optionally record where the image is deployed and which repository it belongs to. The file is checked before the request, so a wrong path or an empty file fails immediately.

  • #49 a389153 Thanks @claudiacodacy! - Add images and image commands for container images with SBOMs uploaded to an organization.

    codacy images <provider> <org> lists images with their latest tag and last upload/generation dates.

    codacy image <provider> <org> <image> lists that image's tags (environment, repository, generated/uploaded/last-analysed dates), shows a single one with -t, --tag <tag>, and deletes with -D, --delete — the whole image on its own, or just one tag when combined with --tag. Under --output json a declined confirmation reports itself as {"deleted": false, "aborted": true} rather than a prose line, so stdout stays parseable. Deletes confirm first (-y, --skip-confirmation bypasses it for CI).

    Both commands require an account API token.

  • #52 260b59a Thanks @claudiacodacy! - Add codacy image <provider> <org> <image> --delete --keep-latest <n> to clean up old image tags, keeping the n most recently uploaded and deleting the rest. Intended as the cleanup step of a release pipeline, which runs before the SBOM upload.

    --dry-run shows exactly which tags would be kept and deleted without deleting anything.

    Under --output json the command emits one object after every delete has been attempted: deleted lists the tags that actually went and failures the ones that did not, and the exit code is non-zero when there are any. Deletes run one at a time and continue past failures, so a partial cleanup still frees space; the exit code is non-zero if any tag failed.

    Confirmation applies in every output mode, including --output json — -y, --skip-confirmation is how a pipeline says yes ahead of time, and a declined prompt emits {"deleted": [], "aborted": true}. An empty or whitespace-only --keep-latest is rejected rather than read as 0, so --keep-latest "$KEEP_COUNT" with the variable unset fails loudly instead of deleting every tag.

    Because the organization tag cap counts image-and-tag pairs while --keep-latest applies per image, the command warns when keeping n tags across every image in the organization would exceed the default 1,000-tag cap, and says what the cap allows per image instead.

Patch Changes

  • #52 260b59a Thanks @claudiacodacy! - Show the error message Codacy actually returned instead of a generic status name. Failures that used to print Error: Not Found now print what went wrong — for example Error: Could not find repository gh/my-org/my-repo (HTTP 404), Error: Bad credentials (HTTP 401), or Error: SBOM tag mismatch: expected 9.9.9, found 3.20 (HTTP 400). This affects every command. Where the API sends no explanation, the output is unchanged.

    Only a body that plausibly is a message is used: not every error response is JSON, so a proxy or load balancer answering with an HTML error page falls back to the status name (Error: Bad Gateway) rather than dumping the page into the terminal. The same applies to image --delete --keep-latest, whose per-tag failure list reported Bad Request for every failure because it formats errors at its own call site.

  • #49 a389153 Thanks @claudiacodacy! - Confirmation prompts are now written to stderr instead of stdout.

    --output json promises that stdout carries exactly one JSON document, and process.stdin.isTTY is still true when stdout is a pipe — so codacy image gh my-org my-service --tag 1.2.3 --delete --output json | jq sent the question and the echoed keystroke into jq, which failed on them. The prompt is interaction, not program output, so it now goes to stderr alongside the spinners and error lines, for every command that confirms (image --delete, issues --ignore, tools --import). Interactive runs look the same; piped ones no longer break.

1.11.0

Minor Changes

  • #48 e58f17a Thanks @alerizzo! - Show the repository's coverage status, not just its percentage.

    Codacy now reports whether a repository's coverage is up to date, still waiting on a report, has stopped receiving them, or was never set up — and the CLI can tell those apart:

    • codacy repos marks a repository whose latest commit has no report yet with a dim ⋯ after its last known value, and shows a dim ⊘ instead of a number for one that has stopped receiving reports. A legend under the table explains only the states actually present in the listing.
    • codacy repo's Metrics section spells the same states out, with the date and commit of the last report, and notes when a stopped repository's coverage gate is no longer being enforced. A repository that never had coverage now reads Not set up rather than a bare N/A.
    • codacy repo's Analysis row reads coverage state from the API's own status field instead of inferring it from a separate request. This fixes repositories that were reported as healthy while showing a stale percentage, drops one request per run, and makes the coverage state available under a repository token for the first time.

    --output json gains coverage.status, coverage.lastCommitWithCoverage, coverage.statusUpdatedAt and coverage.valueUpdatedAt on both commands. Under a repository token, codacy repo's unavailable array is now ["pullRequests"] only.

  • #45 e21f321 Thanks @alerizzo! - New -k, --matches-stack [value] filter on codacy patterns, which narrows a tool's code patterns to those that do (or don't) match the repository's detected stack.

    It's a tri-state flag, the same shape as issues --false-positives:

    codacy patterns eslint9 --matches-stack          # only patterns matching the repo stack
    codacy patterns eslint9 --matches-stack true     # same
    codacy patterns eslint9 --matches-stack false    # only patterns that don't match
    codacy patterns eslint9                          # unfiltered

    The filter applies in bulk mode too, so --enable-all / --disable-all can be scoped to the stack:

    codacy patterns eslint9 --disable-all --matches-stack false

    The summary printed after a bulk update still reports counts for the whole tool, not just the updated subset.

    Only true and false are accepted as values. Because Commander's optional-value syntax consumes the next token, a lax parser would let codacy patterns gh org repo --matches-stack eslint silently swallow the tool name and then fail with a confusing positional-count error; the flag now rejects non-boolean values with a message that says what to do instead.

1.10.0

Minor Changes

  • #43 3b215b3 Thanks @alerizzo! - Add HTTP/HTTPS proxy and TLS support, so the CLI works behind a corporate proxy (#40).

    Every command now honors the standard environment variables:

    • HTTPS_PROXY / HTTP_PROXY (and lowercase) — proxy URL per scheme; a bare host:port is accepted
    • NO_PROXY / no_proxy — hosts that bypass the proxy (*, .suffix), matched per request
    • SSL_CERT_FILE / NODE_EXTRA_CA_CERTS — PEM CA bundle for a TLS-intercepting proxy
    • CODACY_CLI_INSECURE — disable TLS verification as a last resort (warns on stderr)

    These are the same variable names the Codacy Analysis CLI and the Codacy VS Code extension use, so one environment configures all of them. The implementation is the shared configureProxy() from @codacy/tooling rather than a local reimplementation, which is what keeps the behavior identical across the tools. Misconfiguration fails immediately rather than silently doing something else: an unreadable or non-PEM CA bundle reports the path instead of quietly falling back to the default trust store, and a malformed proxy URL reports which variable was wrong and why (with any proxy password redacted) instead of a bare Invalid URL.

    Nothing changes when no proxy variable is set — the proxy dependency is loaded lazily, so an unproxied run has no measurable overhead.

    Thanks to @rattalur for reporting the gap and for the initial implementation in #39.

1.9.0

Minor Changes

  • #37 402edd8 Thanks @alerizzo! - Add repository (project) token support

    You can now authenticate with a repository token — scoped to a single repository — instead of a personal account API token that reaches every organization and repository you can see. This is the right credential for CI and for the auto-configuration agent: if it leaks, the blast radius is one repository.

    codacy tools --repository-token <your-repository-token>
    # or, for a whole CI job:
    export CODACY_PROJECT_TOKEN=<your-repository-token>

    Get one from Codacy > Repository > Settings > Integrations > Project API token. The new --repository-token <token> flag is accepted by every command, and CODACY_PROJECT_TOKEN is picked up automatically.

    Token precedence (identical to the Codacy Analysis CLI): --repository-token > CODACY_PROJECT_TOKEN > CODACY_API_TOKEN > stored codacy login. An explicit --repository-token wins outright, so a deliberately scoped run is never silently widened. Note that CODACY_PROJECT_TOKEN outranks CODACY_API_TOKEN — unset it if you want your account token used.

    Not every command accepts a repository token, because Codacy only honours them on a limited set of repository-scoped operations:

    • Fully supported: tools, tool, patterns, pattern, issues (including --overview), tools --import, repository --reanalyze / --reanalyze-and-wait.
    • Partially supported: repository works but omits the pull request and coverage sections. In --output json, pullRequests stays an empty array and a new unavailable: ["pullRequests"] field marks what couldn't be fetched. Output under an account token is unchanged.
    • Account token required: info, repositories, ls, directories, pull-request, pull-requests, issue, findings, finding, issues --ignore/--ignored, tools --import --force, and repository's --add/--remove/--follow/--unfollow/--link-standard/--unlink-standard.

    Unsupported combinations now fail immediately with a message naming the operation, why a repository token can't perform it, and which token is in use — instead of sending a request that comes back as a bare Unauthorized.

    codacy login continues to store account tokens only; repository tokens are passed per command or via the environment.

    Also fixed: codacy repository no longer loses the entire dashboard when the pull request lookup fails, and codacy login no longer reports a repository token as "invalid" when it is rejected for being the wrong kind of token.

1.8.0

Minor Changes

  • #35 72a4d3b Thanks @pedrobpereira! - New pull-requests (prs) command: lists pull requests for a repository, with the same analysis-gated columns as repository's "Open Pull Requests" table. -q, --search and -B, --base filter by free text (title/author handle) and target branch, mapping to the API's textQuery/targetBranch params; -S, --state filters by open (default) or closed.

Patch Changes

  • #35 72a4d3b Thanks @pedrobpereira! - Fix findings's pagination warning silently not firing when the API response omits pagination.total: the guard now also checks for a remaining cursor, so a trailing page of results is no longer hidden from the --limit hint.

  • #35 72a4d3b Thanks @pedrobpereira! - formatStandards() (used by repository's Open Pull Requests table, pull-request's Up to Standards row, and pull-requests' ✓ column) now shows a dim ⋯ while a pull request is still being analysed, instead of falling through to a hard ✗ on gate data that isn't final yet.

  • #35 72a4d3b Thanks @pedrobpereira! - Fix PR complexity showing as no data, and polish the pull-requests table. Complexity is now read from the API's nested quality object, which is where the pull-request endpoints actually return it — pull-requests, pull-request and repository all previously rendered it as empty. The pull-requests table now leads with the up-to-standards column, orders metrics the same way repositories does (issues, complexity, duplication, coverage), hides the Coverage column when no listed PR has coverage data, shows - instead of N/A for metrics with no value, and no longer signs a zero issue count (0 instead of -0). --output json now includes the quality and coverage resultReasons, so consumers can see which gates passed or failed.

1.7.0

Minor Changes

  • #34 c26ff79 Thanks @pedrobpereira! - issue, issues, pull-request --issue, finding, and findings now show vulnerable/affected functions for SCA issues and findings with a linked OSV advisory (CommitIssue.advisoryInformation / SrmItem.advisoryInformation). Card views show a compact one-line summary; detail views show the full list with advisory ID and published date. Included in --output json for all five commands.

Patch Changes

  • #30 12c1a33 Thanks @alerizzo! - Neutralize terminal control characters in human-readable output (CWE-150). Repository-derived values shown by the CLI — PR and finding titles, author names, branches, file paths, diff and file content, issue messages, and package names — are now stripped of ANSI/OSC escape and other control bytes before being printed, so a crafted pull request can no longer repaint or hide findings, spoof gate status, or trigger terminal side effects (e.g. clipboard writes) when you run the CLI against it. Offending bytes are shown in visible caret notation (e.g. ^[) instead of being interpreted. --output json is unaffected — it still returns the original values, escaped by JSON encoding.

  • #34 c26ff79 Thanks @pedrobpereira! - Sanitize vulnerable/affected function names and the advisory ID (CommitIssue.advisoryInformation / SrmItem.advisoryInformation) before printing them in issue, issues, pull-request --issue, finding, and findings. These values come from the linked OSV advisory, so — like other repository-derived output — they are now passed through sanitizeText() to strip ANSI/OSC control bytes (CWE-150) instead of being printed raw.

1.6.0

Minor Changes

  • #28 440a57f Thanks @claudiacodacy! - codacy issues --ignore now asks for confirmation before bulk-ignoring. It prints how many issues match the current filters and only proceeds when you answer y, guarding against a mistyped or too-broad filter ignoring far more issues than intended. Pass --skip-confirmation (-y) to bypass the prompt in CI or scripts; in a non-interactive shell without that flag the command aborts without ignoring anything.

  • #28 440a57f Thanks @claudiacodacy! - Add codacy issues --ignored (-i) to list issues that were marked as ignored on Codacy. Without the flag, codacy issues behaves exactly as before; pass --ignored to see the ignored ones instead. The ignored listing accepts all the same filters as the normal search (--branch, --severities, --categories, --tools, --patterns, --languages, --tags, --authors, --limit, and --false-positives), and each ignored issue shows who ignored it, when, the reason, and any comment. It cannot be combined with --overview or --ignore. --output json emits an ignoredIssues array. Unignoring individual issues stays with codacy issue <id> --unignore.

1.5.0

Minor Changes

  • #26 bf903e4 Thanks @alerizzo! - Add ls and directories commands to browse a repository's tree with quality metrics. ls lists the directories and files at a path — showing Grade, Issues, Complexity, Duplication, and Coverage per row — and directories (alias dirs) lists folders only, with --plus-children to also show one level of sub-directories as a └─ tree. Both auto-detect the provider/organization/repository from the git remote and the path from your current directory (relative to the repo root); override with positional args, --path, and --branch. Sort with --sort <field> (name, issues, grade, duplication, complexity, coverage) and --direction asc|desc. codacy ls --search <term> finds files at any depth under the path. Folders and files are marked with ▸ and · (no emojis). Both commands fetch every page of results, so nothing is truncated.

  • #24 bf527ad Thanks @alerizzo! - Add an npm-style "update available" notice. When a newer version is published, the CLI prints a one-time upgrade hint to stderr — it never auto-updates. The notice only shows with the default --output table in an interactive terminal; it is suppressed for --output json, when piped, in CI, and under npx/npm scripts, so machine-readable stdout stays byte-clean. The version lookup runs in a non-blocking background process (at most once a day) and never affects timing or exit codes. Opt out via CODACY_DISABLE_UPDATE_CHECK, NO_UPDATE_NOTIFIER, or --no-update-notifier. A package.json overrides entry pins update-notifier's transitive got/package-json to patched, still-CommonJS versions to avoid CVE-2022-33987.

Patch Changes

  • #27 c5c9af5 Thanks @alerizzo! - Stop issues --overview from suggesting noise reduction on repositories that aren't actually noisy. The "Suggested actions to reduce noise" section now requires two absolute floors before anything is suggested: the repository must have at least 200 issues in total, and an individual pattern must produce at least 100 issues on its own. The per-pattern floor matters because a repository with a long tail of tiny patterns pulls the median issues-per- pattern very low, which previously made a pattern with only a handful of issues look disproportionate — now a rule has to genuinely flood the repo before it's flagged. On top of those floors, a pattern must still show a relative signal: the "dominant share" rule (≥10% of all issues) only applies when there are at least 11 distinct patterns (an even split of N patterns only drops below 10% once N is above 10, so 8-10 balanced patterns would otherwise all be flagged), and the "disproportionate count" rule now compares each pattern against the median issues-per-pattern instead of the mean, so a single huge pattern can no longer inflate the baseline and hide smaller-but-still-disproportionate ones.

1.4.0

Minor Changes

  • #20 cbf62d5 Thanks @alerizzo! - codacy findings and codacy finding now show the vulnerable dependency's import chain for SCA findings that carry the new dependencyChains field. Each finding is labelled Direct (Update <pkg> to <fixedVersion>) or Transitive (<pkg> → … → <pkg> (Fixed in <fixedVersion>)), and chains with 4+ packages collapse their middle to <first> → ... N more ... → <last>. The list shows the first chain plus ... and X more; the detail lists every chain aligned under a single label. dependencyChains is also included in --output json.

1.3.1

Patch Changes

  • #18 7b09b5b Thanks @manufacturist! - Fix --version flag reporting hardcoded 1.0.0 instead of the actual package version. The CLI now reads the version dynamically from package.json at runtime via require, so the reported version stays in sync with every release automatically.

1.3.0

Minor Changes

  • #16 8f86866 Thanks @manufacturist! - codacy repo --output json now includes a fileCount field on the repository object, plucked from coverage.numberTotalFiles on the existing getRepositoryWithAnalysis response. The field is present even on repos without coverage data, so no extra API call is needed. Lets consumers (e.g. the configure-codacy-cloud skill) read repo size without a separate roundtrip.

1.2.1

Patch Changes

1.2.0

Minor Changes

  • #11 12ad8a3 Thanks @alerizzo! - Auto-detect provider, organization, and repository from the git remote origin URL. All repository-scoped commands now work without explicitly passing <provider> <organization> <repository> — just run them inside a git repo with an origin remote pointing at GitHub, GitLab, or Bitbucket.

  • #13 f039b39 Thanks @alerizzo! - Improve issues --overview. The False Positives table now uses human-friendly labels ("Not a False Positive" / "Potential False Positive") instead of the raw belowThreshold / equalOrAboveThreshold API bucket names. The overview also adds a "Suggested actions to reduce noise" section that flags noisy patterns — those accounting for at least 10% of all issues, or at least 3× the average issues-per-pattern — and prints a ready-to-run codacy pattern <tool> <patternId> --disable command for each (the owning tool is resolved automatically; suggestions whose tool can't be resolved are omitted). --output json output is unchanged.

  • #13 f039b39 Thanks @alerizzo! - Make the pattern commands aware of local configuration files and coding standards.

    • pattern <tool> <patternId> with no action flag now shows the pattern's information (same card as the patterns command, with --output json support). Since there's no single-pattern endpoint, it searches by ID and keeps the exact match.
    • When a tool is driven by a local configuration file, patterns (list) and pattern (info) print <tool> is using a local configuration file. and skip fetching patterns; patterns --enable-all/--disable-all and pattern --enable/--disable/--parameter refuse with Tool uses a local configuration file, can't be updated.
    • pattern --enable/--disable/--parameter also refuses patterns enforced by a coding standard with Pattern enforced by <standard> coding standard, can't be modified.
    • issues --overview noise suggestions now adapt per pattern: a runnable codacy pattern … --disable command when possible, otherwise a manual step — Update your local <tool> configuration file to disable the pattern or Update <coding standard> to disable the pattern.
  • #13 f039b39 Thanks @alerizzo! - Add a --reanalyze-and-wait (-w) variant to the repository and pull-request commands. Unlike --reanalyze (which triggers analysis and exits), this blocking variant captures a baseline of the current issues, triggers the reanalysis, polls until it finishes (every 10s, up to 20 minutes), and then prints how long the analysis took and what changed — issue deltas by pattern, severity, and category. Supports --output json.

1.1.1

Patch Changes

  • #9 a973363 Thanks @alerizzo! - Fix tools import to preserve cloud-only tools (only disable tools the local CLI supports), handle config-file mode correctly (skip pattern reset when useLocalConfigurationFile is set), and surface structured API error details on import failures.

1.1.0

Minor Changes

  • #6 0280af1 Thanks @alerizzo! - ### Changes since v1.0.5

    • --tools filter for issues command (#4): Added --tools option to filter issues by the tool/pattern that detected them. Includes new formatting utilities for tool name display.

    • Filter and bulk-ignore for false positives (#5): Added --category and --severity filters to the issues command. Introduced bulk-ignore functionality to ignore multiple issues matching filter criteria, streamlining false-positive triage workflows.

    • Pin GitHub Actions to SHA hashes (#2): Pinned all GitHub Actions workflow dependencies to commit SHAs for improved supply-chain security.

    • Adopt changesets for automated versioning and publishing (#6): Replaced the manual publish workflow with a changesets-based release pipeline. PRs now require a changeset file, and merging to main triggers automated version bumps and npm publishing with provenance.