saz-enforce
v2.3.2
Published
Enterprise React/Next.js code enforcement — ESLint, Tailwind, TypeScript configs + security scan, auto-fix, scoring, CI/CD, hooks by Muhammad Salman
Maintainers
Readme
saz-enforce
Enterprise code enforcement for React & Next.js — by Muhammad Salman
120 rules | auto-fix | scoring (A+ to F) | perf audit | security scan | HTML dashboard | feature tracker | CI/CD | zero runtime deps
New Project
npm install -D saz-enforce
npx saz initAsks 8 questions (team, framework, language, typography, animations, Kafka, i18n, theme) and generates:
- Complete project scaffold (React/Vite or Next.js, JS or TS)
- Redux store, Axios service layer, useForm hook, design tokens
- ESLint, Tailwind, TypeScript, PostCSS configs (auto-detect versions)
- Standards docs, CLAUDE.md for AI tools, package.json scripts
Existing Project
npm install -D saz-enforce
npx saz status # see what's set up vs missing
npx saz check --report # find all violations
npx saz fix # auto-fix what's fixable
npx saz baseline # freeze current violations
npx saz check --baseline --report # CI only fails on NEW violationsnpx saz status output:
Foundation
✓ package.json
✓ React node_modules/react/package.json
✓ Next.js node_modules/next/package.json
✗ saz-enforce → npm install -D saz-enforce
Core Files
✓ Axios instance src/services/axiosInstance.ts
✓ Redux store src/store/index.ts
✗ useForm → npx saz init
Optional
⬚ Kafka queue (not installed)
⬚ i18n (not installed)
Code Quality (47 violations)
████████████████ src/components/ 32
██████ src/store/ 8
Health: █████████████████████████░░░░░ 83%✓= found (with file path)✗= required but missing (must fix)○= recommended (should fix)⬚= optional (your choice)
Commands
# Scan & Fix
npx saz check # interactive audit (file by file)
npx saz check --report # CI mode (exit 1 on violations)
npx saz check --fix-all # auto-fix all fixable violations
npx saz check --baseline # only new violations above baseline
npx saz check --changed # only git-changed files
npx saz fix # auto-fix + ESLint --fix + Prettier
npx saz watch # real-time scan on save
# Analyze
npx saz score # grade A+ to F across 12 categories
npx saz perf # rendering performance audit (layout, paint, CWV)
npx saz security # security vulnerability scan
npx saz status # project health report with file paths
npx saz dashboard # interactive HTML report (opens browser)
npx saz rules # list all 120 active rules
# Automate
npx saz hooks # install pre-commit hooks
npx saz ci --github # generate GitHub Actions workflow
npx saz baseline # freeze violations for incremental CI
# Setup
npx saz init # scaffold project
npx saz arch --fix # auto-create missing directories
npx saz claude # generate CLAUDE.md for AI tools
npx saz doctor # detect version drift
npx saz eject <target> # make config standalone
npx saz migrate # interactive migration with backupMost commands support --json and --dir <path>.
Configs
// ESLint (auto-detects v8 legacy / v9 flat config)
module.exports = require("saz-enforce/configs/eslint"); // JS
module.exports = require("saz-enforce/configs/eslint-ts"); // TS
// Tailwind (auto-detects v3/v4)
module.exports = { presets: [require("saz-enforce/configs/tailwind")] };
// TypeScript + Prettier
{ "extends": "saz-enforce/configs/tsconfig.json" }
module.exports = require("saz-enforce/configs/prettier");120 Rules
| Category | Count | Examples |
|------------------|-------|--------------------------------------------------|
| Code Quality | 21 | No var, strict equality, no magic numbers |
| Performance | 17 | Layout thrashing, passive scroll, image CLS/LCP |
| Security | 16 | No eval, no localStorage tokens |
| Accessibility | 13 | alt text, onKeyDown + onClick, 44px touch targets |
| Type Safety | 12 | No any, no assertions, prefer ?? |
| React Patterns | 12 | No index keys, no inline handlers |
| HTML5 Semantics | 12 | <dialog>, <nav>, <header>, <time> |
| CSS / Tailwind | 6 | Design tokens only, no raw colors |
| Design Lint | 6 | Deprecated tokens, focus-visible |
| Data Fetching | 5 | Axios instance, abort signals |
Plus Project Structure and Config Setup in scoring (12 categories total).
Optional Features
Configured during npx saz init:
- Design Patterns — 14-token typography, HSL colors, landing page templates
- Animations — 11 CSS keyframes, RevealSection, StaggerGrid, TiltCard
- Kafka Queue — createQueueThunk, GlobalMessageBar, dev simulator
- i18n — i18next + RTL, English + Arabic, LanguageSwitcher
- Theme System — Light/Dark + 5 static themes, ThemeProvider
- BMAD Agents — 7 AI agents + MCP config for Claude Code/Cursor/Windsurf
Custom Rules
// saz.rules.js — add project-specific rules
module.exports = [
{ id: "no-moment", description: "Use date-fns", severity: "error",
test: (line) => /\bmoment\s*\(/.test(line) },
];// saz.config.json — override severity
{ "rules": { "no-console": "off", "no-any": "warning" } }// Inline suppression
const x = eval(code); // saz-ignore sec-eval-usageRequirements
- Node.js
>=16.0.0— zero runtime dependencies - ESLint
>=8.0.0| Tailwind>=3.0.0| TypeScript>=4.9.0(all optional) - Skip postinstall:
SAZ_SKIP_POSTINSTALL=1 npm install saz-enforce
