The problem
Code review catches logic bugs, but nobody reads every controller to check for a missing auth guard. Nobody traces every req.body to see whether it reaches a SQL string either.
One command
npx @sabahattink/codediag scan .
What happens under the hood
- Discovery once. Files are indexed a single time, .gitignore-aware, with minified and oversized files skipped.
- AST, not regex. ts-morph parses each file once, and all analyzers share the result.
- Taint tracking. Request data is followed through up to three assignments into shell, SQL, and eval sinks.
- Explainable score. Every lost point maps to a rule ID in the score breakdown.
Using it in CI
- uses: sabahattink/codediag@v0
with:
threshold: 80
baseline: .codediag-baseline.json
What's next
Path traversal, SSRF, and XSS rules are on the roadmap. Feedback on false positives is the most valuable contribution right now.

Top comments (0)