Skip to content

Render unusual supply-chain signals in dependency details - #29

Merged
JosephMaynard merged 8 commits into
masterfrom
feat/code-tidy
May 1, 2026
Merged

JosephMaynard merged 8 commits into
masterfrom
feat/code-tidy

Conversation

@JosephMaynard

@JosephMaynard JosephMaynard commented Apr 30, 2026 •

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

  • New Features

    • Supply-chain source signals displayed per dependency in reports.
    • New CLI --timestamp option to append timestamps to generated report filenames.
  • Bug Fixes

    • Stricter CLI argument validation with clearer errors for missing or unknown options.
  • Tests

    • Added CLI tests covering error handling and timestamped output behavior.
  • Chores

    • Updated package metadata, adjusted build minification, and added a JS sanitization step.
  • Documentation

    • README updated to document the --timestamp flag.

@coderabbitai

coderabbitai Bot commented Apr 30, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: b218c79e-2d90-463e-8f13-3b265d3aae39

📥 Commits

Reviewing files that changed from the base of the PR and between 88cd515 and a817413.

⛔ Files ignored due to path filters (3)
  • dist/cli.js is excluded by !**/dist/**
  • dist/report-assets.js is excluded by !**/dist/**
  • report-ui/dist/report.iife.js is excluded by !**/dist/**
📒 Files selected for processing (2)
  • report-ui/main.ts
  • src/report-assets.ts

📝 Walkthrough

Walkthrough

Updates package metadata; adds supply-chain signal indexing and rendering to the report UI; tightens CLI parsing with a new --timestamp flag and fail-fast behavior; removes Vite/Terser beautify option; adds post-build JS sanitization; and expands CLI tests for error and timestamp behaviors.

Changes

Cohort / File(s) Summary
Package metadata
package.json
Set author to "Joseph Maynard" and updated homepage to https://www.dependency-radar.com.
Supply-chain signals UI
report-ui/main.ts
Added buildSupplyChainSignalIndex() resolving report.supplyChain.signals to dependency keys (order: packageId, packageName@packageVersion, name-only). Added helpers to render a "Supply chain source" subsection and integrated per-dependency signals into lazy renderDepDetails.
Build config
report-ui/vite.config.ts
Removed Terser format.beautify: true from production minify config.
Post-build sanitizer
scripts/build-report.ts
Added post-build sanitization of minified JS (inserts space in ambiguous ?.<digit>-like tokens) and writes sanitized report.iife.js used for embedding.
CLI parsing & behavior
src/cli.ts
Added --timestamp option; filename rewriting to append local YYYY-MM-DD_HH-MM-SS before extension; stricter fail-fast arg parsing (unknown options, missing option values, unexpected positional args) via takeOptionValue.
CLI tests
src/cli.test.ts
Added tests asserting exit code 1 and specific stderr for unknown options/missing values; added tests validating timestamped output filenames and JSON schema version.
Docs
README.md
Documented the new --timestamp flag and its filename behavior; updated CLI pipeline docs.

Sequence Diagram(s)

sequenceDiagram
    autonumber
    participant Builder as Builder (scripts/build-report.ts)
    participant Assets as Report Assets (report.iife.js)
    participant Browser as Report UI (report-ui/main.ts)
    participant User as User (browser)

    Builder->>Builder: Read minified report.iife.js
    Builder->>Builder: Sanitize ambiguous tokens (e.g., "?.<digit>" → "? .<digit>")
    Builder->>Assets: Write sanitized report.iife.js (embedded JS_CONTENT)

    Browser->>Assets: Load report assets (sanitized JS)
    Browser->>Browser: init()\nbuildSupplyChainSignalIndex()
    User->>Browser: Open dependency detail
    Browser->>Browser: Lookup dependency key in index\nAttach supplyChainSignals to detail render
    Browser-->>User: Render dependency detail with "Supply chain source"
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Poem

🐇 I nibbled through minified lines with care,
I placed a tiny space to make tokens fair,
Signals now hop into each dependency view,
CLI timestamps mark the files anew,
A merry rabbit twitches — build, render, share.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Title check ⚠️ Warning The PR title focuses on rendering supply-chain signals in dependency details, which is addressed in report-ui/main.ts. However, the changeset includes substantial changes across multiple files: package.json metadata updates, Vite config minification settings, build script sanitization, CLI timestamp functionality, and comprehensive test coverage. The title captures only one aspect of a multi-faceted changeset. Consider a more comprehensive title that reflects the primary changes, such as 'Add supply-chain signals UI and timestamp CLI feature' or separate this into focused PRs by feature area.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Docstring Coverage ✅ Passed Docstring coverage is 85.19% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/code-tidy

Review rate limit: 4/5 reviews remaining, refill in 12 minutes.

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@report-ui/main.ts`:
- Around line 953-982: buildSupplyChainSignalIndex can add the same
SupplyChainSignal multiple times when both candidate keys resolve to the same
dep; update the loop that iterates candidates in buildSupplyChainSignalIndex so
that after a successful resolve via resolveDepLinkTarget you call add(depKey,
signal) once and break out of the candidate loop (or alternatively dedupe
resolved depKey values before calling add), ensuring you still fall back to
resolveDepKeyByNameFromSet only if no candidate matched; reference the inner
variables candidates, depKey, matched, the add helper, and the functions
resolveDepLinkTarget / resolveDepKeyByNameFromSet when making the change.

In `@src/cli.ts`:
- Around line 1229-1236: takeOptionValue currently rejects any value beginning
with "-" which breaks path-valued options; change takeOptionValue(args:
string[], option: string, allowLeadingDash = false) to only enforce the
startsWith("-") check when allowLeadingDash is false, and return the shifted
value otherwise, and update any call sites that parse filesystem paths to call
takeOptionValue(..., true) (leave existing flag callers unchanged).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 3840b101-5cf4-4287-9a4e-d4d0d0d949fe

📥 Commits

Reviewing files that changed from the base of the PR and between 0fba91e and c7b79c6.

⛔ Files ignored due to path filters (4)
  • dist/cli.js is excluded by !**/dist/**
  • dist/report-assets.js is excluded by !**/dist/**
  • dist/report.js is excluded by !**/dist/**
  • report-ui/dist/report.iife.js is excluded by !**/dist/**
📒 Files selected for processing (7)
  • package.json
  • report-ui/main.ts
  • report-ui/vite.config.ts
  • scripts/build-report.ts
  • src/cli.test.ts
  • src/cli.ts
  • src/report-assets.ts
💤 Files with no reviewable changes (1)
  • report-ui/vite.config.ts

Comment thread report-ui/main.ts
Comment thread src/cli.ts Outdated
@coderabbitai

coderabbitai Bot commented May 1, 2026 •

Copy link
Copy Markdown
Contributor

Note

Docstrings generation - SUCCESS
Generated docstrings and committed to branch feat/code-tidy (commit: 88cd515f88b4ba23005d0ca2e9641b9e717317a9)

Docstrings generation was requested by @JosephMaynard.

The following files were modified:

* `report-ui/main.ts`
* `scripts/build-report.ts`
* `src/cli.ts`

These files were ignored:
* `src/cli.test.ts`

These file types are not supported:
* `README.md`
* `package.json`

@coderabbitai coderabbitai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@report-ui/main.ts`:
- Around line 997-1015: The current loop uses resolveDepLinkTarget which may
fall back to name-only matches and thus attach exact-version signals to the
wrong package; implement and use a strict resolver (e.g.,
resolveExactDepLinkTarget as described) that only returns an exact depKey or npm
alias and does not perform name-only fallbacks, call that resolver when
iterating candidates (replace resolveDepLinkTarget(candidate, linkableKeys,
keysByName) with resolveExactDepLinkTarget(candidate, linkableKeys)) and keep
the existing fallback to resolveDepKeyByNameFromSet(signal.packageName,
linkableKeys, keysByName) only for the unmatched case so exact-match phases
remain exact.
🪄 Autofix (Beta)

✅ Autofix completed


ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 941d69d4-ce21-4b95-84af-26a4bd26cdb3

📥 Commits

Reviewing files that changed from the base of the PR and between fbac9db and 88cd515.

📒 Files selected for processing (3)
  • report-ui/main.ts
  • scripts/build-report.ts
  • src/cli.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • scripts/build-report.ts

Comment thread report-ui/main.ts
@coderabbitai

coderabbitai Bot commented May 1, 2026 •

Copy link
Copy Markdown
Contributor

Note

Autofix is a beta feature. Expect some limitations and changes as we gather feedback and continue to improve it.

Fixes Applied Successfully

Fixed 5 file(s) based on 1 unresolved review comment.

Files modified:

  • dist/cli.js
  • dist/report-assets.js
  • report-ui/dist/report.iife.js
  • report-ui/main.ts
  • src/report-assets.ts

Commit: 675d9946ac12a01e34679d409c4c863b0f2a2991

The changes have been pushed to the feat/code-tidy branch.

Time taken: 2m 23s

Fixed 5 file(s) based on 1 unresolved review comment.

Co-authored-by: CodeRabbit <noreply@coderabbit.ai>

@coderabbitai coderabbitai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@report-ui/main.ts`:
- Around line 1050-1058: The JSDoc block above the renderRootPackageList
function is missing its closing "*/", which causes the function declaration to
be commented out; fix this by adding the terminating "*/" immediately before the
"function renderRootPackageList(" line so the JSDoc is properly closed and
renderRootPackageList (and its params like packages, maxShow, linkableKeys,
keysByName) are parsed as code.
🪄 Autofix (Beta)

✅ Autofix completed


ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 65a5c908-a06e-444c-bd86-0c09934bce85

📥 Commits

Reviewing files that changed from the base of the PR and between 88cd515 and 675d994.

⛔ Files ignored due to path filters (3)
  • dist/cli.js is excluded by !**/dist/**
  • dist/report-assets.js is excluded by !**/dist/**
  • report-ui/dist/report.iife.js is excluded by !**/dist/**
📒 Files selected for processing (2)
  • report-ui/main.ts
  • src/report-assets.ts

Comment thread report-ui/main.ts
@coderabbitai

coderabbitai Bot commented May 1, 2026 •

Copy link
Copy Markdown
Contributor

Note

Autofix is a beta feature. Expect some limitations and changes as we gather feedback and continue to improve it.

Fixes Applied Successfully

Fixed 4 file(s) based on 1 unresolved review comment.

Files modified:

  • dist/report-assets.js
  • report-ui/dist/report.iife.js
  • report-ui/main.ts
  • src/report-assets.ts

Commit: 8ae484df670cc7cff12cb3c78ac676c7bec40b04

The changes have been pushed to the feat/code-tidy branch.

Time taken: 1m 50s

Fixed 4 file(s) based on 1 unresolved review comment.

Co-authored-by: CodeRabbit <noreply@coderabbit.ai>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

♻️ Duplicate comments (1)
report-ui/main.ts (1)

1041-1043: ⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Keep versioned signals out of the name-only fallback.

If signal.packageVersion is present but the exact name@version candidate misses, this branch can still pin the signal to a different dependency with the same name. That puts a version-specific warning on the wrong card. Restrict this fallback to versionless signals or leave the signal unassigned.

Suggested fix
-    if (!matched && signal.packageName) {
+    if (!matched && signal.packageName && !signal.packageVersion) {
       const depKey = resolveDepKeyByNameFromSet(signal.packageName, linkableKeys, keysByName);
       if (depKey) add(depKey, signal);
     }
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@report-ui/main.ts` around lines 1041 - 1043, The current fallback assigns a
signal by name even when signal.packageVersion exists, which can pin a versioned
signal to the wrong dependency; in the block using resolveDepKeyByNameFromSet
and add, restrict the fallback to only versionless signals by changing the
condition to require that signal.packageVersion is falsy (e.g., if (!matched &&
signal.packageName && !signal.packageVersion) { ... }), so
resolveDepKeyByNameFromSet(linkableKeys, keysByName) is only used for name-only
signals and versioned signals remain unassigned when their exact name@version
candidate misses.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Duplicate comments:
In `@report-ui/main.ts`:
- Around line 1041-1043: The current fallback assigns a signal by name even when
signal.packageVersion exists, which can pin a versioned signal to the wrong
dependency; in the block using resolveDepKeyByNameFromSet and add, restrict the
fallback to only versionless signals by changing the condition to require that
signal.packageVersion is falsy (e.g., if (!matched && signal.packageName &&
!signal.packageVersion) { ... }), so resolveDepKeyByNameFromSet(linkableKeys,
keysByName) is only used for name-only signals and versioned signals remain
unassigned when their exact name@version candidate misses.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 6ffd4ca5-7799-414b-8808-6de3a65b5ffe

📥 Commits

Reviewing files that changed from the base of the PR and between 88cd515 and 8ae484d.

⛔ Files ignored due to path filters (3)
  • dist/cli.js is excluded by !**/dist/**
  • dist/report-assets.js is excluded by !**/dist/**
  • report-ui/dist/report.iife.js is excluded by !**/dist/**
📒 Files selected for processing (2)
  • report-ui/main.ts
  • src/report-assets.ts

@JosephMaynard
JosephMaynard merged commit b988a6a into master May 1, 2026
1 check passed
@JosephMaynard
JosephMaynard deleted the feat/code-tidy branch May 1, 2026 12:50
@coderabbitai coderabbitai Bot mentioned this pull request Jul 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant