Releases: deniscuciuc/compose-analyzer
Releases · deniscuciuc/compose-analyzer
Release list
v1.1.0
Added
- A programmatic API.
ComposeAnalyzeris exported from the package root, alongside the
analyzers, collectors, reporters and every report type. Importing the package now has no
side effects — previouslyrequire("@deniscuciuc/compose-analyzer")parsedprocess.argv
and ran an analysis, because the CLI was the package entry point andmain/types
pointed at it. The CLI moved tosrc/cli/main.tsand is still reached through the
compose-analyzerbinary. - Nine tests covering the API, issue ordering, the missing-file path, and HTML escaping of
hostile service names and issue titles. SECURITY.md,CODE_OF_CONDUCT.mdandCODEOWNERS.- A README banner.
Changed
- The minimum supported Node.js version is now 22. Node 20 reached end of life on
30 April 2026. - TypeScript 7 with
nodenextmodule resolution, and@types/nodenamed explicitly in
tsconfig.json— TypeScript 7 no longer reliably auto-includes it. - Stricter TypeScript (
noUncheckedIndexedAccessand friends) and Biome rules; unused
variables and imports are errors rather than warnings, and the lint scope now covers
test/andscripts/. - Updated
dockerodeto 5,js-yamlto 5,@inquirer/promptsand@biomejs/biome, and
the GitHub Actions to their current majors. Verified against a live Docker daemon, not
just a green type-check. - Dropped
ts-node, which is incompatible with TypeScript 7. The dev scripts and the CLI
test now run the built output — the same code path that ships. - Removed
@types/js-yaml: js-yaml 5 bundles its own types, and keeping the v4 types
alongside would have shadowed them with the previous API. - CI runs on every branch rather than only
mainanddevelop, cancels superseded runs,
and adds Node 24. Publishing emits npm provenance and verifies the tag matches
package.json.
Fixed
parseOptionscalledprocess.exit(0)for--help, which made the parser untestable and
left unreachable code after it. It sets ahelpflag and the caller decides.- The entry point set
process.exitCodeinstead of callingprocess.exit, which could
truncate buffered stdout when piping--jsonto a file. - Exposed
./package.jsonthrough theexportsmap, so tooling that reads a dependency's
manifest does not fail withERR_PACKAGE_PATH_NOT_EXPORTED.
v1.0.0
Added
- Docker Compose analyzer CLI with full, health, image, security, reliability, resource, and network commands
- YAML parsing for Compose v2, v3, and versionless files
- Image analysis for unpinned images and
:latesttags - Security analysis for secrets in environment variables, privileged containers, and exposed database ports
- Reliability analysis for healthchecks,
depends_onconditions, and restart policies - Resource analysis for missing CPU and memory limits
- Network analysis for default-network usage and random host port publishing
- Health score (0–100), Markdown/JSON/HTML reports, and report diffing
- Optional Docker daemon runtime enrichment with
--with-docker - Interactive CLI flows for analysis, reports, and settings
- Node built-in tests, GitHub Actions CI workflow, publish workflow, and OSS project metadata