DEV Community

Sabahattin Kalkan
Sabahattin Kalkan

Posted on

How I score the health of a Node.js API in one command

The problem

Code review catches logic bugs, but nobody reads every controller to check for a missing auth guard. Nobody traces every req.body to see whether it reaches a SQL string either.

One command

npx @sabahattink/codediag scan .
Enter fullscreen mode Exit fullscreen mode

What happens under the hood

  1. Discovery once. Files are indexed a single time, .gitignore-aware, with minified and oversized files skipped.
  2. AST, not regex. ts-morph parses each file once, and all analyzers share the result.
  3. Taint tracking. Request data is followed through up to three assignments into shell, SQL, and eval sinks.
  4. Explainable score. Every lost point maps to a rule ID in the score breakdown.

Using it in CI

- uses: sabahattink/codediag@v0
with:
threshold: 80
baseline: .codediag-baseline.json
Enter fullscreen mode Exit fullscreen mode




What's next

Path traversal, SSRF, and XSS rules are on the roadmap. Feedback on false positives is the most valuable contribution right now.

https://github.com/sabahattink/codediag

Top comments (0)