Skip to content

Feat: Update Report and README - #51

Merged
JosephMaynard merged 10 commits into
masterfrom
feat/update-report-styles-and-README
May 15, 2026
Merged

JosephMaynard merged 10 commits into
masterfrom
feat/update-report-styles-and-README

Conversation

@JosephMaynard

@JosephMaynard JosephMaynard commented May 15, 2026 •

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

  • Documentation

    • Expanded README guidance on pre-run evaluation, offline behavior, CLI access, report sharing options, and releases/changelog publishing.
  • New Features

    • Enhanced report details: clearer overall risk, key points, status chips, and explicit upgrade-blocker messaging.
  • Style

    • Refreshed report UI spacing, typography, cards, status pills, tables, and detail layouts for improved readability.
  • Tests

    • Added unit tests covering risk calculation, key-point generation, and vulnerability totals.

Review Change Stack

@coderabbitai

coderabbitai Bot commented May 15, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 96b7e14d-ca7b-4464-ab13-a9a7c0daafb6

📥 Commits

Reviewing files that changed from the base of the PR and between 63975b3 and d2c95e4.

⛔ Files ignored due to path filters (2)
  • dist/report-assets.js is excluded by !**/dist/**
  • report-ui/dist/report.css is excluded by !**/dist/**
📒 Files selected for processing (3)
  • README.md
  • report-ui/style.css
  • src/report-assets.ts
✅ Files skipped from review due to trivial changes (1)
  • README.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • report-ui/style.css

📝 Walkthrough

Walkthrough

This PR extracts security/risk reporting calculations into shared helpers, refactors the dependency detail UI to use those helpers, redesigns styling for new visual components, and updates documentation to clarify tool capabilities and data access patterns.

Changes

Security Risk Reporting and Dependency UI Enhancements

Layer / File(s) Summary
Security and risk reporting helpers
src/reportDetailRules.ts, src/reportDetailRules.test.ts
New SecuritySummary type and exported functions (reportVulnerabilityTotal, reportAllExecutionSignals, buildReportOverallRisk, buildReportKeyPoints) compute vulnerability totals, derive overall risk combining install/supply-chain/maintenance signals via priority rules, and build deduplicated key report points with fallback healthy states when no issues exist.
UI integration of reporting helpers
report-ui/main.ts
Imports and uses new reporting helpers; removes local getHighestRisk; refactors dependency card rendering to compute data-risk via buildReportOverallRisk(...); adds status-chip and key-points HTML builders; rewrites dependency "Overview" section with description and grid layout; updates "Vulnerabilities" and "Risk & Compliance" sections to use shared functions; refactors upgrade-blockers rendering with explicit "no blockers" state.
Dependency detail styling system
report-ui/style.css
Adds --radius-sm CSS variable; introduces new "section cards" system (.section*, .status-chip*, .key-points*) and KV grid/card variants; reworks dependency card, subsection, detail list, declared dependency table, vulnerability table, and raw-data UI with updated spacing, typography, borders, and hover behaviors.
Sample data and documentation updates
report-ui/sample-data.json, README.md
Sample data updates schema to 1.4 and expands execution/supply-chain signal metadata for esbuild and tinyexec; documentation clarifies tool scope as review/triage utility, distinguishes free local CLI from optional premium service, improves "Before you run" messaging with capability/network/offline behavior table, and updates release notes guidance.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

  • JosephMaynard/dependency-radar#2: Both PRs modify report-ui/main.ts’s dependency rendering logic—main PR refactors risk/vulnerability calculations to use src/reportDetailRules.ts helpers (buildReportOverallRisk, reportVulnerabilityTotal, key points), while the retrieved PR changes how those same license/vulnerability values and the dependency micro-summary are rendered (including optional package description).
  • JosephMaynard/dependency-radar#29: Both PRs modify report-ui/main.ts’s dependency detail rendering—especially renderDep/renderDepDetails and the “Risk & Compliance” section—to incorporate supply-chain signal data into the UI.

Poem

🐰 With helpers shared and signals bright,
The risk reveals its true delight.
Cards restyled in section grace,
Key points dance in proper place—
A CLI that clearly shows the way!

🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 17.39% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Title check ❓ Inconclusive The title is overly broad and vague—'Update Report and README' doesn't convey the specific nature of the changes, which include refactored report UI components, new security rules module, CSS styling updates, and documentation improvements. Use a more specific title that captures the primary change, such as 'Refactor report UI with shared helpers and security rules' or 'Add security-focused report detail rules and UI improvements'.
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/update-report-styles-and-README

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint skipped: no ESLint configuration detected in root package.json. To enable, add eslint to devDependencies.

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@README.md`:
- Line 23: Replace the non-descriptive link text "here" in the README line
containing the URL to the Dependency Radar example with descriptive link text
like "Dependency Radar example report" (i.e., change "You can see an example
report [here](https://www.dependency-radar.com/examples/dependency-radar.html)."
to use descriptive text), so screen readers and users scanning links know the
destination; update the markdown link text accordingly.

In `@report-ui/style.css`:
- Around line 1936-1941: Remove the deprecated CSS declaration "word-break:
break-word" wherever it appears (e.g., in the .kv-value rule shown) at the three
reported locations so stylelint won't fail; keep the existing "overflow-wrap:
anywhere" and "word-break" should be deleted from those rules (the occurrences
at the three reported spots are the only changes required).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 5733f3c6-1d93-460b-811d-70d3562f5bc5

📥 Commits

Reviewing files that changed from the base of the PR and between 766a285 and 63975b3.

⛔ Files ignored due to path filters (7)
  • dist/report-assets.js is excluded by !**/dist/**
  • dist/reportDetailRules.js is excluded by !**/dist/**
  • docs/screenshot-01.jpg is excluded by !**/*.jpg
  • docs/screenshot-02.jpg is excluded by !**/*.jpg
  • docs/screenshot-03.jpg is excluded by !**/*.jpg
  • report-ui/dist/report.css is excluded by !**/dist/**
  • report-ui/dist/report.iife.js is excluded by !**/dist/**
📒 Files selected for processing (7)
  • README.md
  • report-ui/main.ts
  • report-ui/sample-data.json
  • report-ui/style.css
  • src/report-assets.ts
  • src/reportDetailRules.test.ts
  • src/reportDetailRules.ts

Comment thread README.md Outdated
Comment thread report-ui/style.css
@JosephMaynard
JosephMaynard merged commit b648f36 into master May 15, 2026
5 checks passed
@JosephMaynard
JosephMaynard deleted the feat/update-report-styles-and-README branch May 15, 2026 15:30
@coderabbitai coderabbitai Bot mentioned this pull request Jul 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant