batmanuel
v0.0.26
Published
Batmanuel - A code quality analysis tool
Readme
Batmanuel
Batmanuel is a CLI for analyzing code quality and safely remediating npm dependency vulnerabilities. It analyzes a local project directory.
Install
npm install --save-dev batmanuelFor development in this repository:
npm install
npm run buildCommands
batmanuel analyze [path] [--verbose]
batmanuel dependencies-fix [path] [--verbose]
batmanuel --helppath defaults to the current directory. --verbose (or -v) displays internal execution logs.
Analyze a project
batmanuel analyze .The command prints an AnalysisReport JSON document containing the score, quality-gate result, metrics, and issues found by the duplication, security, and dependency scanners.
Remediate npm vulnerabilities
batmanuel dependencies-fix . --verboseThis command supports npm projects with a package-lock.json. It uses OSV and npm audit --json metadata, applies compatible direct-dependency or parent-dependency updates, and uses npm overrides for transitive fixes. When an npm advisory supplies a safe upper bound, Batmanuel can add the required transitive override even across a major version; direct dependency major-version updates still require manual review.
Before writing changes, Batmanuel backs up package.json and package-lock.json. It restores both files if npm install or vulnerability revalidation fails.
CI usage
Run Batmanuel directly in the checked-out repository:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 22
- run: npm ci
- run: npx batmanuel analyze . > batmanuel-report.json
- run: jq -e '.passed == true' batmanuel-report.jsonDevelopment
npm run build
npm test -- --runInBand --watchman=false