Repository navigation
✨ [feat] improve CLI and language discovery - #10
Conversation
✨ [feat] Classify all 75 layouts across 45 language facets, add three live-validated badge combinations, and expose language metadata through the generated catalog and package API. ✨ [feat] Add URL-persisted language filtering, responsive gallery controls, language metadata on cards, and trusted-literal normalization for persisted view and sort preferences. 🧪 [test] Cover language filtering, generated catalog metadata, pagination, and untrusted gallery preference fallbacks. 📝 [docs] Document canonical language annotations and live SVG-title validation rules for future layout contributions.
✨ [feat] Add structured command help, language-aware discovery, Git context detection, validated command options, output files, clipboard support, JSON modes, aliases, and actionable error suggestions. ✨ [feat] Render responsive ANSI badge previews with NO_COLOR support, optional bounded live Badgen SVG-title lookups, and clean Markdown summaries piped to Glow. 🧪 [test] Cover terminal width behavior, preview parsing and warnings, CLI discovery, rendering, and option validation. 📝 [docs] Replace the CLI guide and refresh README examples for the expanded terminal workflow.
🐛 [fix] Replace the multi-pass SVG title decoder with a single-pass XML entity parser that preserves nested encodings and rejects invalid XML code points. 🧪 [test] Cover named, decimal, hexadecimal, nested, and out-of-range entity behavior reported by CodeQL.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 834890e694
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const match = | ||
| /github\.com[\/:](?<owner>[^\s\/:]+)\/(?<repo>[^\s\/]+?)(?:\.git)?$/iv.exec( | ||
| remote.trim() |
There was a problem hiding this comment.
Anchor GitHub detection to the actual remote host
When a non-GitHub remote merely contains github.com/ in its hostname or path—for example, https://gitlab.com/github.com/foo/bar.git—this unanchored regex reports foo/bar as a GitHub repository. The new automatic context then silently renders badges and README blocks for github.com/foo/bar instead of requiring explicit coordinates as documented; parse the URL/SSH host and require it to equal github.com.
Useful? React with 👍 / 👎.
| [](https://coveralls.io/github/OWNER/REPO?branch=BRANCH) | ||
| [](https://deepscan.io/dashboard/#view=project&tid=DEEPSCAN_TEAM&pid=DEEPSCAN_PROJECT&bid=DEEPSCAN_BRANCH) | ||
| [](https://github.com/xojs/xo) | ||
| [](https://www.sonarsource.com/solutions/security/) |
There was a problem hiding this comment.
Point the Tidelift badge at its package report
When users copy or render this canonical conditional layout, clicking the Tidelift subscription badge opens a generic SonarSource security page that is unrelated to both Tidelift and PACKAGE. Replace the destination with the corresponding Tidelift package/subscription page so the badge leads to the report it describes.
AGENTS.md reference: AGENTS.md:L3-L3
Useful? React with 👍 / 👎.
| /** @param {BadgeCatalogEntry} entry @param {string} placeholder */ | ||
| function exampleValue(entry, placeholder) { | ||
| const haystack = `${entry.category} ${entry.title}`; | ||
| const haystack = `${entry.category} ${entry.languages.join(" ")} ${entry.title}`; |
There was a problem hiding this comment.
Add preview values for the new service placeholders
When the gallery initially renders the new Mastodon layout or the DeepScan row in Conditional badges, generalExamples has no values for MASTODON_USER, MASTODON_SERVER, or any DEEPSCAN_* placeholder, so exampleValue falls back to the literal uppercase names and the supposedly personalized preview requests invalid service coordinates. Add working non-secret examples for these newly canonical placeholders, as is already done for the other service-specific fields.
AGENTS.md reference: AGENTS.md:L3-L3
Useful? React with 👍 / 👎.
| const suspiciousTitlePattern = | ||
| /(?:^|\b)(?:429|500|discontinued|error|timeout|undefined|unknown)(?:\b|$)/iv; |
There was a problem hiding this comment.
Restrict numeric error detection to actual error titles
When a valid live metric happens to equal 429 or 500—for example, a repository with exactly 500 stars or a package with 1,500 downloads—the word-boundary pattern matches that ordinary count and marks the badge as an error. Detect these numbers only in an HTTP/error context rather than anywhere in the SVG title so legitimate milestone values are not rendered as red warnings.
Useful? React with 👍 / 👎.
🚜 [refactor] Extract parsed-option recording from the argument loop and centralize singular layout-count formatting to remove the two Sonar maintainability findings without changing CLI behavior.
🧪 [test] Exercise automatic color policy, all semantic ANSI roles, badge contrast, malformed tables, constrained widths, safe URL metadata, network and HTTP failures, missing SVG titles, and single-pass XML entities. 🦺 [test] Restore the existing coverage gate without lowering thresholds: 97.82% statements, 91.41% branches, 100% functions, and 99.19% lines.
|
Codecov Report❌ Patch coverage is
@@ Coverage Diff @@
## main #10 +/- ##
==========================================
- Coverage 93.44% 92.56% -0.88%
==========================================
Files 4 6 +2
Lines 122 269 +147
Branches 30 79 +49
==========================================
+ Hits 114 249 +135
Misses 2 2
- Partials 6 18 +12
Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1dad51b8e4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const maximumWidth = Math.max( | ||
| headers.length * 8, | ||
| options.maxWidth ?? | ||
| (process.stdout.columns > 0 ? process.stdout.columns : 100) | ||
| ); |
There was a problem hiding this comment.
When stdout is narrower than headers.length * 8—for example, badge-layouts list in a 30-column terminal—this lower bound ignores the detected terminal width, and the per-column minimums can make the five-column list at least 46 characters wide. The terminal then wraps or misaligns the table instead of contracting to the available width; permit narrower columns or switch to a compact layout when the requested width is below the table minimum.
Useful? React with 👍 / 👎.
| if (parsed.booleans.has("json")) { | ||
| ensureNoOutputFile(parsed); |
There was a problem hiding this comment.
Validate output combinations before copying
When a supported clipboard utility is installed and the user combines --copy --json --output, the command updates the clipboard and prints a success message before ensureNoOutputFile rejects the invocation and returns a failure status. The same ordering exists in the render path, so both commands can perform an externally visible side effect despite reporting failure; reject the incompatible output combination before invoking the clipboard tool.
Useful? React with 👍 / 👎.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1dad51b8e4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| return { ...badge, error: "SVG title unavailable" }; | ||
| } | ||
| const decodedTitle = decodeXml(title.trim()); | ||
| return suspiciousTitlePattern.test(decodedTitle) |
There was a problem hiding this comment.
Strip terminal controls from live badge titles
When --live receives an SVG title containing terminal control characters—whether reflected from upstream badge metadata or returned by a compromised service—decodedTitle is passed unchanged to the ANSI renderer and Glow, allowing escape sequences such as OSC links or cursor-control codes to affect the user's terminal. Remove C0/C1 and escape characters from fetched titles before storing or displaying them.
Useful? React with 👍 / 👎.
| if (!response.ok) return { ...badge, error: `HTTP ${response.status}` }; | ||
| const title = /<title>(?<title>[\s\S]*?)<\/title>/v.exec( | ||
| await response.text() |
There was a problem hiding this comment.
Reject non-SVG live-preview responses
When Badgen or an intermediary returns a successful HTML error page containing a <title> element, this code accepts that page title as the badge's live value because it checks only the HTTP status before applying a generic title regex. Validate the response content type or SVG root before extracting the title so --live reports these responses as failures instead of displaying unrelated HTML page titles as badge data.
Useful? React with 👍 / 👎.



Summary
NO_COLORsupport, Git context detection, output/copy modes, and JSON output.sonarcloud.propertiesscopeFindings resolved during PR verification
js/double-escapingby replacing the multi-pass SVG title decoder with a single-pass XML entity parserValidation
npm run release:verifyHosted verification
Final candidate
1dad51b8e4f6dccdab5e9977b4bd0dd1ba3d31a8has no blocking checks. SonarQube Cloud reports anOKgate with zero open PR issues and zero hotspots. CodeQL alert 11 is fixed. Validate, CodeQL, Codecov project/patch/components, dependency review, Gitleaks, TruffleHog, Socket, and StepSecurity all pass.Coverage remains owned by Codecov; SonarQube Cloud intentionally uses Automatic Analysis without coverage imports.