Repository navigation
Add explain and quiet CLI modes - #25
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
📝 WalkthroughWalkthroughAdds a new explain command and a --quiet CLI flag, refactors CLI flow to return richer analysis results, introduces explain rendering/filtering utilities, expands tests for explain and quiet behavior, and updates README with usage and CI guidance. Changes
Sequence Diagram(s)sequenceDiagram
participant User as User / CLI
participant CLI as CLI Handler
participant Analysis as executeAnalysis
participant Formatter as Output Formatter
Note over User,Formatter: Scan Command Flow
User->>CLI: run(['scan'], cwd)
CLI->>Analysis: executeAnalysis(options)
Analysis->>Analysis: Run full pipeline (ls, audit, reports)
Analysis->>Formatter: Generate report artifacts (HTML/JSON)
Formatter->>CLI: Return AnalysisExecutionResult
CLI->>User: Print progress, summary, open report
sequenceDiagram
participant User as User / CLI
participant CLI as CLI Handler
participant Analysis as executeAnalysis
participant Filter as findDependenciesByPackageName
participant Formatter as formatExplainOutput
Note over User,Formatter: Explain Command Flow
User->>CLI: run(['explain','pkg-name'], cwd)
CLI->>Analysis: executeAnalysis(options with reports disabled)
Analysis->>CLI: Return AnalysisExecutionResult
CLI->>Filter: findDependenciesByPackageName(aggregated, 'pkg-name')
Filter->>CLI: Return matches (sorted)
CLI->>Formatter: formatExplainOutput('pkg-name', matches, context)
Formatter->>CLI: Return formatted text
CLI->>User: Print explain output (exit non-zero if no matches)
Estimated code review effort🎯 4 (Complex) | ⏱️ ~45 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 2 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
📝 Coding Plan
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🧹 Nitpick comments (2)
README.md (1)
288-289: Clarify “same pipeline” scope to avoid confusion with scan-only options.Since Line 288 references the scan pipeline, consider explicitly noting that
explainreuses collectors but suppresses report writing/output generation. This avoids readers inferring identical option/output behavior across commands.🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@README.md` around lines 288 - 289, Update the README sentence about the explain command to explicitly state its scope: clarify that the explain command reuses the same scan pipeline collectors (e.g., artifact collectors, metadata collectors) but suppresses report writing and any output-generation steps, and that scan-only options which control report formats or storage are not applied; mention that explain filters the in-memory model to a single package for terminal output rather than producing the full report.src/cli.ts (1)
1094-1110: Argument parsing for explain command has a subtle issue with positional argument handling.The current logic at lines 1108-1110 checks
!arg.startsWith("-")to capture the package name, but this happens inside thewhileloop after the command has been shifted. If a user runsdependency-radar explain --offline lodash, the--offlineflag will be processed first, butlodashwill only be captured ifopts.packageNameis still falsy.However, there's a control flow concern: the
else ifchain means that once a non-flag argument is encountered for explain, subsequent flags won't be processed correctly if the user places the package name before flags.Consider validating the argument order or documenting that package name must come immediately after
explain.📝 Suggested documentation clarification in printHelp
function printHelp(): void { console.log(`dependency-radar [scan] [options] -dependency-radar explain <package-name> [options] +dependency-radar explain <package-name> [options] + +Note: For \`explain\`, <package-name> must be the first argument after the command.🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@src/cli.ts` around lines 1094 - 1110, The explain command's positional package handling (in the args loop using args, command, and opts.packageName) currently lives inside an else-if chain that prevents subsequent flags from being processed if a non-flag argument appears first; change the loop so that when a non-flag is seen and opts.command === "explain" and opts.packageName is unset you set opts.packageName immediately but do not block further flag processing (i.e., don't use an else-if that swallows later flag branches) — either handle the positional case before the flag checks or set opts.packageName and continue the loop so later iterations still match flag handlers for options like --offline. Ensure you reference the same variables/operators (args, arg, command, opts.command, opts.packageName) when applying the fix.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@README.md`:
- Around line 113-114: The README claim that `explain` “does not fetch registry
metadata” is misleading; update the phrasing around the `explain` feature to
state that it reuses the normal local scan model and therefore may trigger
registry lookups in the same situations as `audit`/`outdated` (unless run with
`--offline`), and clarify it still filters results in memory and does not
generate `dependency-radar.html`; reference the `explain`, `audit`, and
`outdated` commands and the `--offline` flag so readers understand network
behavior is dependent on the underlying scan mode rather than guaranteed absent.
---
Nitpick comments:
In `@README.md`:
- Around line 288-289: Update the README sentence about the explain command to
explicitly state its scope: clarify that the explain command reuses the same
scan pipeline collectors (e.g., artifact collectors, metadata collectors) but
suppresses report writing and any output-generation steps, and that scan-only
options which control report formats or storage are not applied; mention that
explain filters the in-memory model to a single package for terminal output
rather than producing the full report.
In `@src/cli.ts`:
- Around line 1094-1110: The explain command's positional package handling (in
the args loop using args, command, and opts.packageName) currently lives inside
an else-if chain that prevents subsequent flags from being processed if a
non-flag argument appears first; change the loop so that when a non-flag is seen
and opts.command === "explain" and opts.packageName is unset you set
opts.packageName immediately but do not block further flag processing (i.e.,
don't use an else-if that swallows later flag branches) — either handle the
positional case before the flag checks or set opts.packageName and continue the
loop so later iterations still match flag handlers for options like --offline.
Ensure you reference the same variables/operators (args, arg, command,
opts.command, opts.packageName) when applying the fix.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 26d49235-25b1-41b8-a837-b37c3c66832d
⛔ Files ignored due to path filters (2)
dist/cli.jsis excluded by!**/dist/**dist/explain.jsis excluded by!**/dist/**
📒 Files selected for processing (5)
README.mdsrc/cli.test.tssrc/cli.tssrc/explain.test.tssrc/explain.ts
Summary
dependency-radar explain <package>to print existing scan insights for a single dependency in the terminal--quietto suppress scan progress/info output while keeping summaries and policy failures visiblescanflow continues to behave as beforeTesting
npx tsc --noEmitnpm run test:unitSummary by CodeRabbit
New Features
Documentation
Tests