Releases: codacy/codacy-cloud-cli
Release list
v1.11.0
Minor Changes
-
#48
e58f17aThanks @alerizzo! - Show the repository's coverage status, not just its percentage.Codacy now reports whether a repository's coverage is up to date, still waiting
on a report, has stopped receiving them, or was never set up — and the CLI can
tell those apart:codacy reposmarks a repository whose latest commit has no report yet with a
dim⋯after its last known value, and shows a dim⊘instead of a number
for one that has stopped receiving reports. A legend under the table explains
only the states actually present in the listing.codacy repo's Metrics section spells the same states out, with the date and
commit of the last report, and notes when a stopped repository's coverage gate
is no longer being enforced. A repository that never had coverage now reads
Not set uprather than a bareN/A.codacy repo's Analysis row reads coverage state from the API's own status
field instead of inferring it from a separate request. This fixes repositories
that were reported as healthy while showing a stale percentage, drops one
request per run, and makes the coverage state available under a repository
token for the first time.
--output jsongainscoverage.status,coverage.lastCommitWithCoverage,
coverage.statusUpdatedAtandcoverage.valueUpdatedAton both commands. Under
a repository token,codacy repo'sunavailablearray is now["pullRequests"]
only. -
#45
e21f321Thanks @alerizzo! - New-k, --matches-stack [value]filter oncodacy patterns, which narrows a tool's code patterns to those that do (or don't) match the repository's detected stack.It's a tri-state flag, the same shape as
issues --false-positives:codacy patterns eslint9 --matches-stack # only patterns matching the repo stack codacy patterns eslint9 --matches-stack true # same codacy patterns eslint9 --matches-stack false # only patterns that don't match codacy patterns eslint9 # unfiltered
The filter applies in bulk mode too, so
--enable-all/--disable-allcan be scoped to the stack:codacy patterns eslint9 --disable-all --matches-stack falseThe summary printed after a bulk update still reports counts for the whole tool, not just the updated subset.
Only
trueandfalseare accepted as values. Because Commander's optional-value syntax consumes the next token, a lax parser would letcodacy patterns gh org repo --matches-stack eslintsilently swallow the tool name and then fail with a confusing positional-count error; the flag now rejects non-boolean values with a message that says what to do instead.
v1.10.0
Minor Changes
-
#43
3b215b3Thanks @alerizzo! - Add HTTP/HTTPS proxy and TLS support, so the CLI works behind a corporate proxy (#40).Every command now honors the standard environment variables:
HTTPS_PROXY/HTTP_PROXY(and lowercase) — proxy URL per scheme; a barehost:portis acceptedNO_PROXY/no_proxy— hosts that bypass the proxy (*,.suffix), matched per requestSSL_CERT_FILE/NODE_EXTRA_CA_CERTS— PEM CA bundle for a TLS-intercepting proxyCODACY_CLI_INSECURE— disable TLS verification as a last resort (warns on stderr)
These are the same variable names the Codacy Analysis CLI and the Codacy VS Code extension use, so one environment configures all of them. The implementation is the shared
configureProxy()from@codacy/toolingrather than a local reimplementation, which is what keeps the behavior identical across the tools. Misconfiguration fails immediately rather than silently doing something else: an unreadable or non-PEM CA bundle reports the path instead of quietly falling back to the default trust store, and a malformed proxy URL reports which variable was wrong and why (with any proxy password redacted) instead of a bareInvalid URL.Nothing changes when no proxy variable is set — the proxy dependency is loaded lazily, so an unproxied run has no measurable overhead.
Thanks to @rattalur for reporting the gap and for the initial implementation in #39.
v1.9.0
Minor Changes
-
#37
402edd8Thanks @alerizzo! - Add repository (project) token supportYou can now authenticate with a repository token — scoped to a single repository — instead of a personal account API token that reaches every organization and repository you can see. This is the right credential for CI and for the auto-configuration agent: if it leaks, the blast radius is one repository.
codacy tools --repository-token <your-repository-token> # or, for a whole CI job: export CODACY_PROJECT_TOKEN=<your-repository-token>
Get one from Codacy > Repository > Settings > Integrations > Project API token. The new
--repository-token <token>flag is accepted by every command, andCODACY_PROJECT_TOKENis picked up automatically.Token precedence (identical to the Codacy Analysis CLI):
--repository-token>CODACY_PROJECT_TOKEN>CODACY_API_TOKEN> storedcodacy login. An explicit--repository-tokenwins outright, so a deliberately scoped run is never silently widened. Note thatCODACY_PROJECT_TOKENoutranksCODACY_API_TOKEN— unset it if you want your account token used.Not every command accepts a repository token, because Codacy only honours them on a limited set of repository-scoped operations:
- Fully supported:
tools,tool,patterns,pattern,issues(including--overview),tools --import,repository --reanalyze/--reanalyze-and-wait. - Partially supported:
repositoryworks but omits the pull request and coverage sections. In--output json,pullRequestsstays an empty array and a newunavailable: ["pullRequests"]field marks what couldn't be fetched. Output under an account token is unchanged. - Account token required:
info,repositories,ls,directories,pull-request,pull-requests,issue,findings,finding,issues --ignore/--ignored,tools --import --force, andrepository's--add/--remove/--follow/--unfollow/--link-standard/--unlink-standard.
Unsupported combinations now fail immediately with a message naming the operation, why a repository token can't perform it, and which token is in use — instead of sending a request that comes back as a bare
Unauthorized.codacy logincontinues to store account tokens only; repository tokens are passed per command or via the environment.Also fixed:
codacy repositoryno longer loses the entire dashboard when the pull request lookup fails, andcodacy loginno longer reports a repository token as "invalid" when it is rejected for being the wrong kind of token. - Fully supported:
v1.8.0
Minor Changes
- #35
72a4d3bThanks @pedrobpereira! - Newpull-requests(prs) command: lists pull requests for a repository, with the same analysis-gated columns asrepository's "Open Pull Requests" table.-q, --searchand-B, --basefilter by free text (title/author handle) and target branch, mapping to the API'stextQuery/targetBranchparams;-S, --statefilters by open (default) or closed.
Patch Changes
-
#35
72a4d3bThanks @pedrobpereira! - Fixfindings's pagination warning silently not firing when the API response omitspagination.total: the guard now also checks for a remainingcursor, so a trailing page of results is no longer hidden from the--limithint. -
#35
72a4d3bThanks @pedrobpereira! -formatStandards()(used byrepository's Open Pull Requests table,pull-request's Up to Standards row, andpull-requests' ✓ column) now shows a dim⋯while a pull request is still being analysed, instead of falling through to a hard ✗ on gate data that isn't final yet. -
#35
72a4d3bThanks @pedrobpereira! - Fix PR complexity showing as no data, and polish thepull-requeststable. Complexity is now read from the API's nestedqualityobject, which is where the pull-request endpoints actually return it —pull-requests,pull-requestandrepositoryall previously rendered it as empty. Thepull-requeststable now leads with the up-to-standards column, orders metrics the same wayrepositoriesdoes (issues, complexity, duplication, coverage), hides the Coverage column when no listed PR has coverage data, shows-instead ofN/Afor metrics with no value, and no longer signs a zero issue count (0instead of-0).--output jsonnow includes the quality and coverageresultReasons, so consumers can see which gates passed or failed.
v1.7.0
Minor Changes
- #34
c26ff79Thanks @pedrobpereira! -issue,issues,pull-request --issue,finding, andfindingsnow show vulnerable/affected functions for SCA issues and findings with a linked OSV advisory (CommitIssue.advisoryInformation/SrmItem.advisoryInformation). Card views show a compact one-line summary; detail views show the full list with advisory ID and published date. Included in--output jsonfor all five commands.
Patch Changes
-
#30
12c1a33Thanks @alerizzo! - Neutralize terminal control characters in human-readable output (CWE-150).
Repository-derived values shown by the CLI — PR and finding titles, author
names, branches, file paths, diff and file content, issue messages, and package
names — are now stripped of ANSI/OSC escape and other control bytes before being
printed, so a crafted pull request can no longer repaint or hide findings, spoof
gate status, or trigger terminal side effects (e.g. clipboard writes) when you
run the CLI against it. Offending bytes are shown in visible caret notation
(e.g.^[) instead of being interpreted.--output jsonis unaffected — it
still returns the original values, escaped by JSON encoding. -
#34
c26ff79Thanks @pedrobpereira! - Sanitize vulnerable/affected function names and the advisory ID (CommitIssue.advisoryInformation/SrmItem.advisoryInformation) before printing them inissue,issues,pull-request --issue,finding, andfindings. These values come from the linked OSV advisory, so — like other repository-derived output — they are now passed throughsanitizeText()to strip ANSI/OSC control bytes (CWE-150) instead of being printed raw.
v1.6.0
Minor Changes
-
#28
440a57fThanks @claudiacodacy! -codacy issues --ignorenow asks for confirmation before bulk-ignoring. It
prints how many issues match the current filters and only proceeds when you
answery, guarding against a mistyped or too-broad filter ignoring far more
issues than intended. Pass--skip-confirmation(-y) to bypass the prompt in
CI or scripts; in a non-interactive shell without that flag the command aborts
without ignoring anything. -
#28
440a57fThanks @claudiacodacy! - Addcodacy issues --ignored(-i) to list issues that were marked as ignored
on Codacy. Without the flag,codacy issuesbehaves exactly as before; pass
--ignoredto see the ignored ones instead. The
ignored listing accepts all the same filters as the normal search (--branch,
--severities,--categories,--tools,--patterns,--languages,--tags,
--authors,--limit, and--false-positives), and each ignored issue shows
who ignored it, when, the reason, and any comment. It cannot be combined with
--overviewor--ignore.--output jsonemits anignoredIssuesarray.
Unignoring individual issues stays withcodacy issue <id> --unignore.
v1.5.0
Minor Changes
-
#26
bf903e4Thanks @alerizzo! - Addlsanddirectoriescommands to browse a repository's tree with quality
metrics.lslists the directories and files at a path — showing Grade, Issues,
Complexity, Duplication, and Coverage per row — anddirectories(aliasdirs)
lists folders only, with--plus-childrento also show one level of
sub-directories as a└─tree. Both auto-detect the provider/organization/repository
from the git remote and the path from your current directory (relative to the
repo root); override with positional args,--path, and--branch. Sort with
--sort <field>(name,issues,grade,duplication,complexity,
coverage) and--direction asc|desc.codacy ls --search <term>finds files
at any depth under the path. Folders and files are marked with▸and·(no
emojis). Both commands fetch every page of results, so nothing is truncated. -
#24
bf527adThanks @alerizzo! - Add an npm-style "update available" notice. When a newer version is published, the
CLI prints a one-time upgrade hint to stderr — it never auto-updates. The notice
only shows with the default--output tablein an interactive terminal; it is
suppressed for--output json, when piped, in CI, and undernpx/npm scripts, so
machine-readable stdout stays byte-clean. The version lookup runs in a non-blocking
background process (at most once a day) and never affects timing or exit codes. Opt
out viaCODACY_DISABLE_UPDATE_CHECK,NO_UPDATE_NOTIFIER, or--no-update-notifier.
A package.jsonoverridesentry pinsupdate-notifier's transitivegot/package-json
to patched, still-CommonJS versions to avoid CVE-2022-33987.
Patch Changes
- #27
c5c9af5Thanks @alerizzo! - Stopissues --overviewfrom suggesting noise reduction on repositories that aren't
actually noisy. The "Suggested actions to reduce noise" section now requires two absolute
floors before anything is suggested: the repository must have at least 200 issues in total,
and an individual pattern must produce at least 100 issues on its own. The per-pattern floor
matters because a repository with a long tail of tiny patterns pulls the median issues-per-
pattern very low, which previously made a pattern with only a handful of issues look
disproportionate — now a rule has to genuinely flood the repo before it's flagged. On top of
those floors, a pattern must still show a relative signal: the "dominant share" rule (≥10% of
all issues) only applies when there are at least 11 distinct patterns (an even split of N
patterns only drops below 10% once N is above 10, so 8-10 balanced patterns would otherwise
all be flagged), and the "disproportionate count" rule now compares each
pattern against the median issues-per-pattern instead of the mean, so a single huge
pattern can no longer inflate the baseline and hide smaller-but-still-disproportionate ones.
v1.4.0
Minor Changes
- #20
cbf62d5Thanks @alerizzo! -codacy findingsandcodacy findingnow show the vulnerable dependency's import chain for SCA findings that carry the newdependencyChainsfield. Each finding is labelled Direct (Update <pkg> to <fixedVersion>) or Transitive (<pkg> → … → <pkg> (Fixed in <fixedVersion>)), and chains with 4+ packages collapse their middle to<first> → ... N more ... → <last>. The list shows the first chain plus... and X more; the detail lists every chain aligned under a single label.dependencyChainsis also included in--output json.
v1.3.1
Patch Changes
- #18
7b09b5bThanks @manufacturist! - Fix--versionflag reporting hardcoded1.0.0instead of the actual package version. The CLI now reads the version dynamically frompackage.jsonat runtime viarequire, so the reported version stays in sync with every release automatically.
v1.3.0
Minor Changes
- #16
8f86866Thanks @manufacturist! -codacy repo --output jsonnow includes afileCountfield on the repository object, plucked fromcoverage.numberTotalFileson the existinggetRepositoryWithAnalysisresponse. The field is present even on repos without coverage data, so no extra API call is needed. Lets consumers (e.g. theconfigure-codacy-cloudskill) read repo size without a separate roundtrip.