Repository navigation
Fix dependency navigation scroll alignment in list view - #26
Conversation
📝 WalkthroughWalkthroughThis PR updates terminology and wording across documentation and CLI output for consistency (e.g., "deps" to "dependencies", "Licence" to "License"). It refactors UI scrolling behavior in the report interface by introducing helper functions for sticky filter bar offsets and smooth dependency scrolling, and conditionally renders dependency relationship details based on usage type. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 1 | ❌ 2❌ Failed checks (1 warning, 1 inconclusive)
✅ Passed checks (1 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
📝 Coding Plan
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@README.md`:
- Line 7: Change the over-absolute privacy claims in the README by softening the
two statements "Nothing leaves your machine." and "No ... paths ... are
collected." to accurately reflect documented behavior: acknowledge that the tool
performs registry lookups (for audit/outdated checks) and that local path fields
may be included in outputs, and rephrase to something like "No personal data is
transmitted except for package registry lookups required for audit/outdated
checks; local file paths may be included in outputs." Update both the line
containing "Nothing leaves your machine." and the line containing "No ... paths
... are collected." to this clarified language so the README is consistent with
registry lookups and local path reporting.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 85ad49b4-4517-4fe3-bd53-05b2010bd931
⛔ Files ignored due to path filters (3)
dist/cli.jsis excluded by!**/dist/**dist/report-assets.jsis excluded by!**/dist/**report-ui/dist/report.iife.jsis excluded by!**/dist/**
📒 Files selected for processing (5)
README.mdreport-ui/main.tssrc/cli.test.tssrc/cli.tssrc/report-assets.ts
| Unlike basic audit tools, it builds the graph from lockfiles, understands PNPM workspaces, validates declared vs inferred licences, and highlights structural risks before they become production problems. | ||
|
|
||
| No accounts. No uploads. Runs entirely on your machine. | ||
| No accounts. No uploads. Nothing leaves your machine. |
There was a problem hiding this comment.
Privacy wording is currently over-absolute and can mislead users.
Line 7 (“Nothing leaves your machine.”) and Line 609 (“No ... paths ... are collected.”) conflict with other documented behavior (registry lookups for audit/outdated and path fields in local output). This should be softened to avoid privacy/compliance ambiguity.
✏️ Proposed wording adjustment
-No accounts. No uploads. Nothing leaves your machine.
+No accounts. No source-code uploads. Dependency Radar runs locally by default.-- Environment data includes Node.js version, OS platform, CPU architecture, and package manager versions.
-- No personal information, usernames, paths, or environment variables are collected.
+- Environment data includes Node.js version, OS platform, CPU architecture, and package manager versions.
+- No personal information or environment-variable values are collected.
+- Scan outputs may include local project path metadata (for example, project-relative paths), and audit/outdated commands can contact package registries unless `--offline` is used.Also applies to: 608-609
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@README.md` at line 7, Change the over-absolute privacy claims in the README
by softening the two statements "Nothing leaves your machine." and "No ... paths
... are collected." to accurately reflect documented behavior: acknowledge that
the tool performs registry lookups (for audit/outdated checks) and that local
path fields may be included in outputs, and rephrase to something like "No
personal data is transmitted except for package registry lookups required for
audit/outdated checks; local file paths may be included in outputs." Update both
the line containing "Nothing leaves your machine." and the line containing "No
... paths ... are collected." to this clarified language so the README is
consistent with registry lookups and local path reporting.
Summary
Testing
Summary by CodeRabbit
Documentation
UI/UX Improvements