@jokalala/analyzer-engine
v0.1.10
Published
Standalone Jokalala SAST HTTP engine for the CLI (loopback) with Stage-2 LLM providers (OpenRouter, DeepSeek, Anthropic/Claude, OpenAI, Ollama)
Readme
@jokalala/analyzer-engine
Loopback HTTP SAST engine for jokalala-cli.
npx @jokalala/analyzer-engine
# → http://127.0.0.1:3847/healthWhen run inside the Jokalala monorepo (or with JOKALALA_REPO_ROOT), loads EnhancedStaticCodeAnalyzer from source. Published npm packages include a vendor bundle with Stage-2 providers: OpenRouter, DeepSeek, Anthropic/Claude, OpenAI, Ollama.
Stage-2 OpenRouter (npm / local engine)
Preferred by default when OPENROUTER_API_KEY is set — one key routes to many
backing models (including free-tier ones), so Stage-2 isn't hostage to a
single vendor's quota/auth state.
export OPENROUTER_API_KEY=sk-or-...
export OPENROUTER_MODEL=deepseek/deepseek-chat # optional, defaults to a free model
npx @jokalala/[email protected]
# → http://127.0.0.1:3847/healthStage-2 Anthropic (npm / local engine)
export ANTHROPIC_API_KEY=sk-ant-...
export CODE_ANALYZER_STAGE2_PROVIDER=anthropic # required if OPENROUTER_API_KEY/DEEPSEEK_API_KEY is also set
npx @jokalala/[email protected]
# → http://127.0.0.1:3847/healthThen scan without a cloud key so the CLI uses the local engine:
unset JOKALALA_API_KEY
jokalala scan . --pro --precision highThe Rust CLI auto-spawns this package when no API key is set and no healthy local service is running (JOKALALA_AUTO_ENGINE=0 to disable).
