@stackblender/flag-marshal
v0.1.2
Published
Find feature-flag debt across JavaScript, TypeScript, Java, and Kotlin repositories.
Maintainers
Readme
Flag Marshal
Find feature-flag debt without uploading your source code.
Flag Marshal inventories feature flags in a local repository, reports stale or undocumented flags with supporting evidence, and identifies key expressions it cannot safely resolve instead of guessing.
Quick start
Requires Node.js 20 or newer.
npx @stackblender/flag-marshal scan .Or install the commands globally:
npm install --global @stackblender/flag-marshal
flag-marshal scan .marshal is available as a shorter alias. A scan reports findings but always
exits successfully, so trying it will not break a build.
What it detects
| Surface | Current support |
| --- | --- |
| Languages | JavaScript, TypeScript, Java, Kotlin |
| Providers | LaunchDarkly, OpenFeature, Unleash, Togglz |
| Framework configuration | Spring @ConditionalOnProperty, application*.properties, application*.yml |
| Other configuration | .env* feature switches |
| Custom helpers | Method names configured in .flagmarshal.yml |
Provider calls must have both a matching import and a receiver bound to that
provider. This avoids treating unrelated methods such as isEnabled() or
variation() as feature flags.
Literal keys, same-file immutable constants, simple constant concatenation,
Togglz enum constants, and NamedFeature("key") are supported. Computed keys are
reported as unresolved and never assigned a guessed value.
Useful output
Human-readable output is the default:
flag-marshal scan ./my-repositoryUse JSON for scripts and agents, or Markdown for sharing a report:
flag-marshal scan . --json --no-git
flag-marshal scan . --format=markdown--no-git skips repository history and makes output deterministic. Run
flag-marshal --help for the complete command reference.
Custom flag helpers
For a homegrown helper such as Features.enabled("checkout-v2"), add a
.flagmarshal.yml file at the repository root:
customPatterns:
methods:
- enabledPrivacy and limitations
Analysis runs on your machine. Flag Marshal has no hosted backend, account, telemetry, or source upload, and the analysis core is tested to reject network dependencies.
This is static analysis, not runtime proof that a flag can be removed. Findings include confidence and evidence, and unsupported languages or unresolved keys are reported as coverage limitations. Review the evidence before changing production code.
Support
Documentation, release status, and issue forms are in the Flag Marshal support repository. Report a bug or detection problem, or report a security concern privately. Flag keys can reveal unreleased features, so replace them with placeholders before posting.
License
Flag Marshal is source-available software distributed under proprietary terms. See LICENSE. Runtime dependency notices are in THIRD_PARTY_NOTICES.md.
