Skip to content

Fix dependency navigation scroll alignment in list view - #26

Merged
JosephMaynard merged 4 commits into
masterfrom
feat/improve-scroll-to-dependency
Mar 18, 2026
Merged

JosephMaynard merged 4 commits into
masterfrom
feat/improve-scroll-to-dependency

Conversation

@JosephMaynard

@JosephMaynard JosephMaynard commented Mar 18, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • align dependency scrolling so opened items land just below the sticky filter bar
  • use the same list-view scroll behavior for graph-to-list navigation and in-list dependency links
  • hide root/package provenance fields for direct dependencies to avoid redundant self-parent context

Testing

  • Not run (not requested)

Summary by CodeRabbit

  • Documentation

    • Clarified CLI output labels for improved readability.
    • Enhanced privacy documentation with explicit details on collected environment data and excluded information.
    • Standardized terminology across documentation.
  • UI/UX Improvements

    • Improved scrolling and navigation when viewing dependency details in the report interface.
    • Refined conditional display of dependency relationship information.

@coderabbitai

coderabbitai Bot commented Mar 18, 2026 •

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

This PR updates terminology and wording across documentation and CLI output for consistency (e.g., "deps" to "dependencies", "Licence" to "License"). It refactors UI scrolling behavior in the report interface by introducing helper functions for sticky filter bar offsets and smooth dependency scrolling, and conditionally renders dependency relationship details based on usage type.

Changes

Cohort / File(s) Summary
Documentation and terminology standardization
README.md
Updated terminology ("deps" to "dependencies", "Licence" to "License"), revised CLI output examples and summary descriptions, and reorganized privacy/environment data notes.
CLI output label updates
src/cli.ts, src/cli.test.ts
Renamed CLI summary output labels ("Direct deps scanned" → "Direct dependencies scanned", "Unused installed deps" → "Dependencies with no static import reference") with corresponding test assertion updates.
UI refactoring and scrolling behavior
report-ui/main.ts
Added helper functions getStickyFilterBarOffset and scrollDependencyIntoView for improved scroll handling; refactored dependency detail rendering to conditionally show relationship fields based on usage type; replaced direct scrollIntoView calls with new helper function.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

Poem

🐰 The words dance clearer now, so bright,
"Dependencies" shines, no more abbreviated night,
Scroll helpers leap and bound with grace,
Sticky bars find their rightful place,
Each usage type knows its own way—hopping forward in the fray! 🌟

🚥 Pre-merge checks | ✅ 1 | ❌ 2

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Title check ❓ Inconclusive The PR title focuses on scroll alignment for dependency navigation, but the changeset includes substantial README updates (terminology changes: 'Licence' to 'License', 'deps' to 'dependencies', new privacy/environment notes) and conditional UI logic for hiding root/package fields that are not mentioned in the title. Clarify whether the scroll alignment feature is the primary change, or if documentation/terminology updates should be reflected in a more comprehensive title.
✅ Passed checks (1 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/improve-scroll-to-dependency
📝 Coding Plan
  • Generate coding plan for human review comments

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@README.md`:
- Line 7: Change the over-absolute privacy claims in the README by softening the
two statements "Nothing leaves your machine." and "No ... paths ... are
collected." to accurately reflect documented behavior: acknowledge that the tool
performs registry lookups (for audit/outdated checks) and that local path fields
may be included in outputs, and rephrase to something like "No personal data is
transmitted except for package registry lookups required for audit/outdated
checks; local file paths may be included in outputs." Update both the line
containing "Nothing leaves your machine." and the line containing "No ... paths
... are collected." to this clarified language so the README is consistent with
registry lookups and local path reporting.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 85ad49b4-4517-4fe3-bd53-05b2010bd931

📥 Commits

Reviewing files that changed from the base of the PR and between 5a44957 and ee7dfef.

⛔ Files ignored due to path filters (3)
  • dist/cli.js is excluded by !**/dist/**
  • dist/report-assets.js is excluded by !**/dist/**
  • report-ui/dist/report.iife.js is excluded by !**/dist/**
📒 Files selected for processing (5)
  • README.md
  • report-ui/main.ts
  • src/cli.test.ts
  • src/cli.ts
  • src/report-assets.ts

Comment thread README.md
Unlike basic audit tools, it builds the graph from lockfiles, understands PNPM workspaces, validates declared vs inferred licences, and highlights structural risks before they become production problems.

No accounts. No uploads. Runs entirely on your machine.
No accounts. No uploads. Nothing leaves your machine.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

Privacy wording is currently over-absolute and can mislead users.

Line 7 (“Nothing leaves your machine.”) and Line 609 (“No ... paths ... are collected.”) conflict with other documented behavior (registry lookups for audit/outdated and path fields in local output). This should be softened to avoid privacy/compliance ambiguity.

✏️ Proposed wording adjustment
-No accounts. No uploads. Nothing leaves your machine.
+No accounts. No source-code uploads. Dependency Radar runs locally by default.
-- Environment data includes Node.js version, OS platform, CPU architecture, and package manager versions.
-- No personal information, usernames, paths, or environment variables are collected.
+- Environment data includes Node.js version, OS platform, CPU architecture, and package manager versions.
+- No personal information or environment-variable values are collected.
+- Scan outputs may include local project path metadata (for example, project-relative paths), and audit/outdated commands can contact package registries unless `--offline` is used.

Also applies to: 608-609

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@README.md` at line 7, Change the over-absolute privacy claims in the README
by softening the two statements "Nothing leaves your machine." and "No ... paths
... are collected." to accurately reflect documented behavior: acknowledge that
the tool performs registry lookups (for audit/outdated checks) and that local
path fields may be included in outputs, and rephrase to something like "No
personal data is transmitted except for package registry lookups required for
audit/outdated checks; local file paths may be included in outputs." Update both
the line containing "Nothing leaves your machine." and the line containing "No
... paths ... are collected." to this clarified language so the README is
consistent with registry lookups and local path reporting.

@JosephMaynard
JosephMaynard merged commit 2fe1815 into master Mar 18, 2026
1 check passed
@JosephMaynard
JosephMaynard deleted the feat/improve-scroll-to-dependency branch March 18, 2026 17:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant