-
#37
402edd8Thanks @alerizzo! - Add repository (project) token supportYou can now authenticate with a repository token — scoped to a single repository — instead of a personal account API token that reaches every organization and repository you can see. This is the right credential for CI and for the auto-configuration agent: if it leaks, the blast radius is one repository.
codacy tools --repository-token <your-repository-token> # or, for a whole CI job: export CODACY_PROJECT_TOKEN=<your-repository-token>
Get one from Codacy > Repository > Settings > Integrations > Project API token. The new
--repository-token <token>flag is accepted by every command, andCODACY_PROJECT_TOKENis picked up automatically.Token precedence (identical to the Codacy Analysis CLI):
--repository-token>CODACY_PROJECT_TOKEN>CODACY_API_TOKEN> storedcodacy login. An explicit--repository-tokenwins outright, so a deliberately scoped run is never silently widened. Note thatCODACY_PROJECT_TOKENoutranksCODACY_API_TOKEN— unset it if you want your account token used.Not every command accepts a repository token, because Codacy only honours them on a limited set of repository-scoped operations:
- Fully supported:
tools,tool,patterns,pattern,issues(including--overview),tools --import,repository --reanalyze/--reanalyze-and-wait. - Partially supported:
repositoryworks but omits the pull request and coverage sections. In--output json,pullRequestsstays an empty array and a newunavailable: ["pullRequests"]field marks what couldn't be fetched. Output under an account token is unchanged. - Account token required:
info,repositories,ls,directories,pull-request,pull-requests,issue,findings,finding,issues --ignore/--ignored,tools --import --force, andrepository's--add/--remove/--follow/--unfollow/--link-standard/--unlink-standard.
Unsupported combinations now fail immediately with a message naming the operation, why a repository token can't perform it, and which token is in use — instead of sending a request that comes back as a bare
Unauthorized.codacy logincontinues to store account tokens only; repository tokens are passed per command or via the environment.Also fixed:
codacy repositoryno longer loses the entire dashboard when the pull request lookup fails, andcodacy loginno longer reports a repository token as "invalid" when it is rejected for being the wrong kind of token. - Fully supported:
- #35
72a4d3bThanks @pedrobpereira! - Newpull-requests(prs) command: lists pull requests for a repository, with the same analysis-gated columns asrepository's "Open Pull Requests" table.-q, --searchand-B, --basefilter by free text (title/author handle) and target branch, mapping to the API'stextQuery/targetBranchparams;-S, --statefilters by open (default) or closed.
-
#35
72a4d3bThanks @pedrobpereira! - Fixfindings's pagination warning silently not firing when the API response omitspagination.total: the guard now also checks for a remainingcursor, so a trailing page of results is no longer hidden from the--limithint. -
#35
72a4d3bThanks @pedrobpereira! -formatStandards()(used byrepository's Open Pull Requests table,pull-request's Up to Standards row, andpull-requests' ✓ column) now shows a dim⋯while a pull request is still being analysed, instead of falling through to a hard ✗ on gate data that isn't final yet. -
#35
72a4d3bThanks @pedrobpereira! - Fix PR complexity showing as no data, and polish thepull-requeststable. Complexity is now read from the API's nestedqualityobject, which is where the pull-request endpoints actually return it —pull-requests,pull-requestandrepositoryall previously rendered it as empty. Thepull-requeststable now leads with the up-to-standards column, orders metrics the same wayrepositoriesdoes (issues, complexity, duplication, coverage), hides the Coverage column when no listed PR has coverage data, shows-instead ofN/Afor metrics with no value, and no longer signs a zero issue count (0instead of-0).--output jsonnow includes the quality and coverageresultReasons, so consumers can see which gates passed or failed.
- #34
c26ff79Thanks @pedrobpereira! -issue,issues,pull-request --issue,finding, andfindingsnow show vulnerable/affected functions for SCA issues and findings with a linked OSV advisory (CommitIssue.advisoryInformation/SrmItem.advisoryInformation). Card views show a compact one-line summary; detail views show the full list with advisory ID and published date. Included in--output jsonfor all five commands.
-
#30
12c1a33Thanks @alerizzo! - Neutralize terminal control characters in human-readable output (CWE-150). Repository-derived values shown by the CLI — PR and finding titles, author names, branches, file paths, diff and file content, issue messages, and package names — are now stripped of ANSI/OSC escape and other control bytes before being printed, so a crafted pull request can no longer repaint or hide findings, spoof gate status, or trigger terminal side effects (e.g. clipboard writes) when you run the CLI against it. Offending bytes are shown in visible caret notation (e.g.^[) instead of being interpreted.--output jsonis unaffected — it still returns the original values, escaped by JSON encoding. -
#34
c26ff79Thanks @pedrobpereira! - Sanitize vulnerable/affected function names and the advisory ID (CommitIssue.advisoryInformation/SrmItem.advisoryInformation) before printing them inissue,issues,pull-request --issue,finding, andfindings. These values come from the linked OSV advisory, so — like other repository-derived output — they are now passed throughsanitizeText()to strip ANSI/OSC control bytes (CWE-150) instead of being printed raw.
-
#28
440a57fThanks @claudiacodacy! -codacy issues --ignorenow asks for confirmation before bulk-ignoring. It prints how many issues match the current filters and only proceeds when you answery, guarding against a mistyped or too-broad filter ignoring far more issues than intended. Pass--skip-confirmation(-y) to bypass the prompt in CI or scripts; in a non-interactive shell without that flag the command aborts without ignoring anything. -
#28
440a57fThanks @claudiacodacy! - Addcodacy issues --ignored(-i) to list issues that were marked as ignored on Codacy. Without the flag,codacy issuesbehaves exactly as before; pass--ignoredto see the ignored ones instead. The ignored listing accepts all the same filters as the normal search (--branch,--severities,--categories,--tools,--patterns,--languages,--tags,--authors,--limit, and--false-positives), and each ignored issue shows who ignored it, when, the reason, and any comment. It cannot be combined with--overviewor--ignore.--output jsonemits anignoredIssuesarray. Unignoring individual issues stays withcodacy issue <id> --unignore.
-
#26
bf903e4Thanks @alerizzo! - Addlsanddirectoriescommands to browse a repository's tree with quality metrics.lslists the directories and files at a path — showing Grade, Issues, Complexity, Duplication, and Coverage per row — anddirectories(aliasdirs) lists folders only, with--plus-childrento also show one level of sub-directories as a└─tree. Both auto-detect the provider/organization/repository from the git remote and the path from your current directory (relative to the repo root); override with positional args,--path, and--branch. Sort with--sort <field>(name,issues,grade,duplication,complexity,coverage) and--direction asc|desc.codacy ls --search <term>finds files at any depth under the path. Folders and files are marked with▸and·(no emojis). Both commands fetch every page of results, so nothing is truncated. -
#24
bf527adThanks @alerizzo! - Add an npm-style "update available" notice. When a newer version is published, the CLI prints a one-time upgrade hint to stderr — it never auto-updates. The notice only shows with the default--output tablein an interactive terminal; it is suppressed for--output json, when piped, in CI, and undernpx/npm scripts, so machine-readable stdout stays byte-clean. The version lookup runs in a non-blocking background process (at most once a day) and never affects timing or exit codes. Opt out viaCODACY_DISABLE_UPDATE_CHECK,NO_UPDATE_NOTIFIER, or--no-update-notifier. A package.jsonoverridesentry pinsupdate-notifier's transitivegot/package-jsonto patched, still-CommonJS versions to avoid CVE-2022-33987.
- #27
c5c9af5Thanks @alerizzo! - Stopissues --overviewfrom suggesting noise reduction on repositories that aren't actually noisy. The "Suggested actions to reduce noise" section now requires two absolute floors before anything is suggested: the repository must have at least 200 issues in total, and an individual pattern must produce at least 100 issues on its own. The per-pattern floor matters because a repository with a long tail of tiny patterns pulls the median issues-per- pattern very low, which previously made a pattern with only a handful of issues look disproportionate — now a rule has to genuinely flood the repo before it's flagged. On top of those floors, a pattern must still show a relative signal: the "dominant share" rule (≥10% of all issues) only applies when there are at least 11 distinct patterns (an even split of N patterns only drops below 10% once N is above 10, so 8-10 balanced patterns would otherwise all be flagged), and the "disproportionate count" rule now compares each pattern against the median issues-per-pattern instead of the mean, so a single huge pattern can no longer inflate the baseline and hide smaller-but-still-disproportionate ones.
- #20
cbf62d5Thanks @alerizzo! -codacy findingsandcodacy findingnow show the vulnerable dependency's import chain for SCA findings that carry the newdependencyChainsfield. Each finding is labelled Direct (Update <pkg> to <fixedVersion>) or Transitive (<pkg> → … → <pkg> (Fixed in <fixedVersion>)), and chains with 4+ packages collapse their middle to<first> → ... N more ... → <last>. The list shows the first chain plus... and X more; the detail lists every chain aligned under a single label.dependencyChainsis also included in--output json.
- #18
7b09b5bThanks @manufacturist! - Fix--versionflag reporting hardcoded1.0.0instead of the actual package version. The CLI now reads the version dynamically frompackage.jsonat runtime viarequire, so the reported version stays in sync with every release automatically.
- #16
8f86866Thanks @manufacturist! -codacy repo --output jsonnow includes afileCountfield on the repository object, plucked fromcoverage.numberTotalFileson the existinggetRepositoryWithAnalysisresponse. The field is present even on repos without coverage data, so no extra API call is needed. Lets consumers (e.g. theconfigure-codacy-cloudskill) read repo size without a separate roundtrip.
- #14
ca896dfThanks @pedrobpereira! - Adds possibility of using the cli againsta other environments
-
#11
12ad8a3Thanks @alerizzo! - Auto-detect provider, organization, and repository from the git remote origin URL. All repository-scoped commands now work without explicitly passing<provider> <organization> <repository>— just run them inside a git repo with anoriginremote pointing at GitHub, GitLab, or Bitbucket. -
#13
f039b39Thanks @alerizzo! - Improveissues --overview. The False Positives table now uses human-friendly labels ("Not a False Positive" / "Potential False Positive") instead of the rawbelowThreshold/equalOrAboveThresholdAPI bucket names. The overview also adds a "Suggested actions to reduce noise" section that flags noisy patterns — those accounting for at least 10% of all issues, or at least 3× the average issues-per-pattern — and prints a ready-to-runcodacy pattern <tool> <patternId> --disablecommand for each (the owning tool is resolved automatically; suggestions whose tool can't be resolved are omitted).--output jsonoutput is unchanged. -
#13
f039b39Thanks @alerizzo! - Make the pattern commands aware of local configuration files and coding standards.pattern <tool> <patternId>with no action flag now shows the pattern's information (same card as thepatternscommand, with--output jsonsupport). Since there's no single-pattern endpoint, it searches by ID and keeps the exact match.- When a tool is driven by a local configuration file,
patterns(list) andpattern(info) print<tool> is using a local configuration file.and skip fetching patterns;patterns --enable-all/--disable-allandpattern --enable/--disable/--parameterrefuse withTool uses a local configuration file, can't be updated. pattern --enable/--disable/--parameteralso refuses patterns enforced by a coding standard withPattern enforced by <standard> coding standard, can't be modified.issues --overviewnoise suggestions now adapt per pattern: a runnablecodacy pattern … --disablecommand when possible, otherwise a manual step —Update your local <tool> configuration file to disable the patternorUpdate <coding standard> to disable the pattern.
-
#13
f039b39Thanks @alerizzo! - Add a--reanalyze-and-wait(-w) variant to therepositoryandpull-requestcommands. Unlike--reanalyze(which triggers analysis and exits), this blocking variant captures a baseline of the current issues, triggers the reanalysis, polls until it finishes (every 10s, up to 20 minutes), and then prints how long the analysis took and what changed — issue deltas by pattern, severity, and category. Supports--output json.
- #9
a973363Thanks @alerizzo! - Fix tools import to preserve cloud-only tools (only disable tools the local CLI supports), handle config-file mode correctly (skip pattern reset when useLocalConfigurationFile is set), and surface structured API error details on import failures.
-
#6
0280af1Thanks @alerizzo! - ### Changes since v1.0.5-
--toolsfilter for issues command (#4): Added--toolsoption to filter issues by the tool/pattern that detected them. Includes new formatting utilities for tool name display. -
Filter and bulk-ignore for false positives (#5): Added
--categoryand--severityfilters to the issues command. Introduced bulk-ignore functionality to ignore multiple issues matching filter criteria, streamlining false-positive triage workflows. -
Pin GitHub Actions to SHA hashes (#2): Pinned all GitHub Actions workflow dependencies to commit SHAs for improved supply-chain security.
-
Adopt changesets for automated versioning and publishing (#6): Replaced the manual publish workflow with a changesets-based release pipeline. PRs now require a changeset file, and merging to main triggers automated version bumps and npm publishing with provenance.
-