Skip to content

Releases: codacy/codacy-cloud-cli

v1.11.0

Choose a tag to compare

@github-actions github-actions released this 11 Sep 09:52
Immutable release. Only release title and notes can be modified.
218c108

Minor Changes

  • #48 e58f17a Thanks @alerizzo! - Show the repository's coverage status, not just its percentage.

    Codacy now reports whether a repository's coverage is up to date, still waiting
    on a report, has stopped receiving them, or was never set up — and the CLI can
    tell those apart:

    • codacy repos marks a repository whose latest commit has no report yet with a
      dim after its last known value, and shows a dim instead of a number
      for one that has stopped receiving reports. A legend under the table explains
      only the states actually present in the listing.
    • codacy repo's Metrics section spells the same states out, with the date and
      commit of the last report, and notes when a stopped repository's coverage gate
      is no longer being enforced. A repository that never had coverage now reads
      Not set up rather than a bare N/A.
    • codacy repo's Analysis row reads coverage state from the API's own status
      field instead of inferring it from a separate request. This fixes repositories
      that were reported as healthy while showing a stale percentage, drops one
      request per run, and makes the coverage state available under a repository
      token for the first time.

    --output json gains coverage.status, coverage.lastCommitWithCoverage,
    coverage.statusUpdatedAt and coverage.valueUpdatedAt on both commands. Under
    a repository token, codacy repo's unavailable array is now ["pullRequests"]
    only.

  • #45 e21f321 Thanks @alerizzo! - New -k, --matches-stack [value] filter on codacy patterns, which narrows a tool's code patterns to those that do (or don't) match the repository's detected stack.

    It's a tri-state flag, the same shape as issues --false-positives:

    codacy patterns eslint9 --matches-stack          # only patterns matching the repo stack
    codacy patterns eslint9 --matches-stack true     # same
    codacy patterns eslint9 --matches-stack false    # only patterns that don't match
    codacy patterns eslint9                          # unfiltered

    The filter applies in bulk mode too, so --enable-all / --disable-all can be scoped to the stack:

    codacy patterns eslint9 --disable-all --matches-stack false

    The summary printed after a bulk update still reports counts for the whole tool, not just the updated subset.

    Only true and false are accepted as values. Because Commander's optional-value syntax consumes the next token, a lax parser would let codacy patterns gh org repo --matches-stack eslint silently swallow the tool name and then fail with a confusing positional-count error; the flag now rejects non-boolean values with a message that says what to do instead.

v1.10.0

Choose a tag to compare

@github-actions github-actions released this 09 Sep 13:37
Immutable release. Only release title and notes can be modified.
1e0f160

Minor Changes

  • #43 3b215b3 Thanks @alerizzo! - Add HTTP/HTTPS proxy and TLS support, so the CLI works behind a corporate proxy (#40).

    Every command now honors the standard environment variables:

    • HTTPS_PROXY / HTTP_PROXY (and lowercase) — proxy URL per scheme; a bare host:port is accepted
    • NO_PROXY / no_proxy — hosts that bypass the proxy (*, .suffix), matched per request
    • SSL_CERT_FILE / NODE_EXTRA_CA_CERTS — PEM CA bundle for a TLS-intercepting proxy
    • CODACY_CLI_INSECURE — disable TLS verification as a last resort (warns on stderr)

    These are the same variable names the Codacy Analysis CLI and the Codacy VS Code extension use, so one environment configures all of them. The implementation is the shared configureProxy() from @codacy/tooling rather than a local reimplementation, which is what keeps the behavior identical across the tools. Misconfiguration fails immediately rather than silently doing something else: an unreadable or non-PEM CA bundle reports the path instead of quietly falling back to the default trust store, and a malformed proxy URL reports which variable was wrong and why (with any proxy password redacted) instead of a bare Invalid URL.

    Nothing changes when no proxy variable is set — the proxy dependency is loaded lazily, so an unproxied run has no measurable overhead.

    Thanks to @rattalur for reporting the gap and for the initial implementation in #39.

v1.9.0

Choose a tag to compare

@github-actions github-actions released this 11 Aug 12:26
Immutable release. Only release title and notes can be modified.
6584be5

Minor Changes

  • #37 402edd8 Thanks @alerizzo! - Add repository (project) token support

    You can now authenticate with a repository token — scoped to a single repository — instead of a personal account API token that reaches every organization and repository you can see. This is the right credential for CI and for the auto-configuration agent: if it leaks, the blast radius is one repository.

    codacy tools --repository-token <your-repository-token>
    # or, for a whole CI job:
    export CODACY_PROJECT_TOKEN=<your-repository-token>

    Get one from Codacy > Repository > Settings > Integrations > Project API token. The new --repository-token <token> flag is accepted by every command, and CODACY_PROJECT_TOKEN is picked up automatically.

    Token precedence (identical to the Codacy Analysis CLI): --repository-token > CODACY_PROJECT_TOKEN > CODACY_API_TOKEN > stored codacy login. An explicit --repository-token wins outright, so a deliberately scoped run is never silently widened. Note that CODACY_PROJECT_TOKEN outranks CODACY_API_TOKEN — unset it if you want your account token used.

    Not every command accepts a repository token, because Codacy only honours them on a limited set of repository-scoped operations:

    • Fully supported: tools, tool, patterns, pattern, issues (including --overview), tools --import, repository --reanalyze / --reanalyze-and-wait.
    • Partially supported: repository works but omits the pull request and coverage sections. In --output json, pullRequests stays an empty array and a new unavailable: ["pullRequests"] field marks what couldn't be fetched. Output under an account token is unchanged.
    • Account token required: info, repositories, ls, directories, pull-request, pull-requests, issue, findings, finding, issues --ignore/--ignored, tools --import --force, and repository's --add/--remove/--follow/--unfollow/--link-standard/--unlink-standard.

    Unsupported combinations now fail immediately with a message naming the operation, why a repository token can't perform it, and which token is in use — instead of sending a request that comes back as a bare Unauthorized.

    codacy login continues to store account tokens only; repository tokens are passed per command or via the environment.

    Also fixed: codacy repository no longer loses the entire dashboard when the pull request lookup fails, and codacy login no longer reports a repository token as "invalid" when it is rejected for being the wrong kind of token.

v1.8.0

Choose a tag to compare

@github-actions github-actions released this 03 Aug 10:40
Immutable release. Only release title and notes can be modified.
c9cd8d3

Minor Changes

  • #35 72a4d3b Thanks @pedrobpereira! - New pull-requests (prs) command: lists pull requests for a repository, with the same analysis-gated columns as repository's "Open Pull Requests" table. -q, --search and -B, --base filter by free text (title/author handle) and target branch, mapping to the API's textQuery/targetBranch params; -S, --state filters by open (default) or closed.

Patch Changes

  • #35 72a4d3b Thanks @pedrobpereira! - Fix findings's pagination warning silently not firing when the API response omits pagination.total: the guard now also checks for a remaining cursor, so a trailing page of results is no longer hidden from the --limit hint.

  • #35 72a4d3b Thanks @pedrobpereira! - formatStandards() (used by repository's Open Pull Requests table, pull-request's Up to Standards row, and pull-requests' ✓ column) now shows a dim while a pull request is still being analysed, instead of falling through to a hard ✗ on gate data that isn't final yet.

  • #35 72a4d3b Thanks @pedrobpereira! - Fix PR complexity showing as no data, and polish the pull-requests table. Complexity is now read from the API's nested quality object, which is where the pull-request endpoints actually return it — pull-requests, pull-request and repository all previously rendered it as empty. The pull-requests table now leads with the up-to-standards column, orders metrics the same way repositories does (issues, complexity, duplication, coverage), hides the Coverage column when no listed PR has coverage data, shows - instead of N/A for metrics with no value, and no longer signs a zero issue count (0 instead of -0). --output json now includes the quality and coverage resultReasons, so consumers can see which gates passed or failed.

v1.7.0

Choose a tag to compare

@github-actions github-actions released this 29 Jul 12:41
Immutable release. Only release title and notes can be modified.
1d0e9da

Minor Changes

  • #34 c26ff79 Thanks @pedrobpereira! - issue, issues, pull-request --issue, finding, and findings now show vulnerable/affected functions for SCA issues and findings with a linked OSV advisory (CommitIssue.advisoryInformation / SrmItem.advisoryInformation). Card views show a compact one-line summary; detail views show the full list with advisory ID and published date. Included in --output json for all five commands.

Patch Changes

  • #30 12c1a33 Thanks @alerizzo! - Neutralize terminal control characters in human-readable output (CWE-150).
    Repository-derived values shown by the CLI — PR and finding titles, author
    names, branches, file paths, diff and file content, issue messages, and package
    names — are now stripped of ANSI/OSC escape and other control bytes before being
    printed, so a crafted pull request can no longer repaint or hide findings, spoof
    gate status, or trigger terminal side effects (e.g. clipboard writes) when you
    run the CLI against it. Offending bytes are shown in visible caret notation
    (e.g. ^[) instead of being interpreted. --output json is unaffected — it
    still returns the original values, escaped by JSON encoding.

  • #34 c26ff79 Thanks @pedrobpereira! - Sanitize vulnerable/affected function names and the advisory ID (CommitIssue.advisoryInformation / SrmItem.advisoryInformation) before printing them in issue, issues, pull-request --issue, finding, and findings. These values come from the linked OSV advisory, so — like other repository-derived output — they are now passed through sanitizeText() to strip ANSI/OSC control bytes (CWE-150) instead of being printed raw.

v1.6.0

Choose a tag to compare

@github-actions github-actions released this 20 Jul 16:45
Immutable release. Only release title and notes can be modified.
d54aecc

Minor Changes

  • #28 440a57f Thanks @claudiacodacy! - codacy issues --ignore now asks for confirmation before bulk-ignoring. It
    prints how many issues match the current filters and only proceeds when you
    answer y, guarding against a mistyped or too-broad filter ignoring far more
    issues than intended. Pass --skip-confirmation (-y) to bypass the prompt in
    CI or scripts; in a non-interactive shell without that flag the command aborts
    without ignoring anything.

  • #28 440a57f Thanks @claudiacodacy! - Add codacy issues --ignored (-i) to list issues that were marked as ignored
    on Codacy. Without the flag, codacy issues behaves exactly as before; pass
    --ignored to see the ignored ones instead. The
    ignored listing accepts all the same filters as the normal search (--branch,
    --severities, --categories, --tools, --patterns, --languages, --tags,
    --authors, --limit, and --false-positives), and each ignored issue shows
    who ignored it, when, the reason, and any comment. It cannot be combined with
    --overview or --ignore. --output json emits an ignoredIssues array.
    Unignoring individual issues stays with codacy issue <id> --unignore.

v1.5.0

Choose a tag to compare

@github-actions github-actions released this 10 Jul 13:14
Immutable release. Only release title and notes can be modified.
97942fc

Minor Changes

  • #26 bf903e4 Thanks @alerizzo! - Add ls and directories commands to browse a repository's tree with quality
    metrics. ls lists the directories and files at a path — showing Grade, Issues,
    Complexity, Duplication, and Coverage per row — and directories (alias dirs)
    lists folders only, with --plus-children to also show one level of
    sub-directories as a └─ tree. Both auto-detect the provider/organization/repository
    from the git remote and the path from your current directory (relative to the
    repo root); override with positional args, --path, and --branch. Sort with
    --sort <field> (name, issues, grade, duplication, complexity,
    coverage) and --direction asc|desc. codacy ls --search <term> finds files
    at any depth under the path. Folders and files are marked with and · (no
    emojis). Both commands fetch every page of results, so nothing is truncated.

  • #24 bf527ad Thanks @alerizzo! - Add an npm-style "update available" notice. When a newer version is published, the
    CLI prints a one-time upgrade hint to stderr — it never auto-updates. The notice
    only shows with the default --output table in an interactive terminal; it is
    suppressed for --output json, when piped, in CI, and under npx/npm scripts, so
    machine-readable stdout stays byte-clean. The version lookup runs in a non-blocking
    background process (at most once a day) and never affects timing or exit codes. Opt
    out via CODACY_DISABLE_UPDATE_CHECK, NO_UPDATE_NOTIFIER, or --no-update-notifier.
    A package.json overrides entry pins update-notifier's transitive got/package-json
    to patched, still-CommonJS versions to avoid CVE-2022-33987.

Patch Changes

  • #27 c5c9af5 Thanks @alerizzo! - Stop issues --overview from suggesting noise reduction on repositories that aren't
    actually noisy. The "Suggested actions to reduce noise" section now requires two absolute
    floors before anything is suggested: the repository must have at least 200 issues in total,
    and an individual pattern must produce at least 100 issues on its own. The per-pattern floor
    matters because a repository with a long tail of tiny patterns pulls the median issues-per-
    pattern very low, which previously made a pattern with only a handful of issues look
    disproportionate — now a rule has to genuinely flood the repo before it's flagged. On top of
    those floors, a pattern must still show a relative signal: the "dominant share" rule (≥10% of
    all issues) only applies when there are at least 11 distinct patterns (an even split of N
    patterns only drops below 10% once N is above 10, so 8-10 balanced patterns would otherwise
    all be flagged), and the "disproportionate count" rule now compares each
    pattern against the median issues-per-pattern instead of the mean, so a single huge
    pattern can no longer inflate the baseline and hide smaller-but-still-disproportionate ones.

v1.4.0

Choose a tag to compare

@github-actions github-actions released this 25 Jun 19:49
Immutable release. Only release title and notes can be modified.
4fcf85d

Minor Changes

  • #20 cbf62d5 Thanks @alerizzo! - codacy findings and codacy finding now show the vulnerable dependency's import chain for SCA findings that carry the new dependencyChains field. Each finding is labelled Direct (Update <pkg> to <fixedVersion>) or Transitive (<pkg> → … → <pkg> (Fixed in <fixedVersion>)), and chains with 4+ packages collapse their middle to <first> → ... N more ... → <last>. The list shows the first chain plus ... and X more; the detail lists every chain aligned under a single label. dependencyChains is also included in --output json.

v1.3.1

Choose a tag to compare

@github-actions github-actions released this 19 Jun 12:52
Immutable release. Only release title and notes can be modified.
f11cf1a

Patch Changes

  • #18 7b09b5b Thanks @manufacturist! - Fix --version flag reporting hardcoded 1.0.0 instead of the actual package version. The CLI now reads the version dynamically from package.json at runtime via require, so the reported version stays in sync with every release automatically.

v1.3.0

Choose a tag to compare

@github-actions github-actions released this 18 Jun 13:27
Immutable release. Only release title and notes can be modified.
32a2203

Minor Changes

  • #16 8f86866 Thanks @manufacturist! - codacy repo --output json now includes a fileCount field on the repository object, plucked from coverage.numberTotalFiles on the existing getRepositoryWithAnalysis response. The field is present even on repos without coverage data, so no extra API call is needed. Lets consumers (e.g. the configure-codacy-cloud skill) read repo size without a separate roundtrip.