Skip to content

Releases: thefgxdev/faultline

v0.1.1 · AGPL-3.0, four fixes, 38 edge tests

Choose a tag to compare

@thefgxdev thefgxdev released this 25 Sep 19:50

faultline 0.1.1

License change. From this version faultline is licensed under AGPL-3.0-or-later (v0.1.0 was MIT; copies of v0.1.0 keep MIT for that version only). Using faultline on your code stays free for everyone, commercial or not. Modified copies that are distributed or offered as a service must publish their source under the same license and keep the author's notice. Commercial licensing for closed modifications: contato@fgxdev.com. See AUTHORSHIP.md.

Fixes (found by two extra rounds of testing: 38 new edge-case tests plus scans of real-world code)

  • --ignore / .faultlineignore: glob patterns containing ? produced a broken expression. Globs are now tokenised once and cached.
  • no-lockfile: yarn.lock and bun.lock were never seen by the scanner, so Yarn and Bun projects were wrongly flagged.
  • swallowed-error: a catch that logs the caught error (console.log(e.message)) is no longer flagged; a log that drops the error still is.
  • sql-string-concat: no longer fires on an English string such as a commit message Update ${file} or on Buffer.from(...); a real SQL clause must be present.

Added

  • AUTHORSHIP.md: authorship and licensing statement in plain language.
  • test/edge.mjs: 38 edge-case tests (CLI flags, exit codes, suppressions, CRLF/BOM, unicode paths, JSON/Markdown output, every rule's silent cases). CI now runs both suites and a self-scan of the whole repository on Node 18, 20 and 22.
  • CONTRIBUTING.md: contributors keep their copyright and grant the maintainer the right to distribute contributions under the AGPL and under a commercial license.

Zero dependencies. npx github:thefgxdev/faultline . --fail-on high

faultline v0.1.0

Choose a tag to compare

@thefgxdev thefgxdev released this 25 Sep 19:28

First public release. Created by Felipe Guedes (fgxdev.com), Toledo, Paraná, Brazil.

  • 22 rules across secrets, boundaries, errors, idempotency, injection, auth, tenancy, data, web and infra
  • Zero dependencies, Node 18+
  • CLI with severity exit codes, Markdown report, JSON output, .faultlineignore and inline suppressions
  • Composite GitHub Action
  • Test suite with bad and good fixtures; CI on Node 18, 20 and 22

Authorship: every source file carries the copyright notice; see NOTICE and CITATION.cff. MIT License.