Skip to content

build(deps-dev): bump jscpd from 5.3.0 to 5.4.0 - #142

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/jscpd-5.3.3
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/jscpd-5.3.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Bumps jscpd from 5.3.0 to 5.4.0.

Release notes

Sourced from jscpd's releases.

Release v5.4.0

New Features

  • A language server: jscpd --lsp. An editor starts jscpd for a workspace, and the files you edit get what jscpd finds as diagnostics that follow the text in the editor, saved or not. After 300 ms without typing, the server tokenizes the file again from the buffer and searches its detection pool again from the tokens it keeps for the rest of the project.

    • The server runs five analyses: clones (exact, renamed and near-miss copies), similar functions (--similarity), semantic clones (--semantic), dead code (--dead-code) and complexity, with a limit of 15 per function and the complex-file bar of the health score per file. Only clones are on unless you turn the others on, with --lsp-analyses, with the lsp section of .jscpd.json, or from the editor's settings, and each place wins over the one before it.
    • The code of each diagnostic is the id of its rule, the one the SARIF reporters write for clones and dead code. A clone is a warning, as in SARIF, and lsp.clones.warningTokens lowers the smaller ones to information. Dead code is a hint that editors fade.
    • Each .jscpd.json in the workspace makes its folder a project of its own, and clones are found within a project. A workspace with no config is one project across all its folders.
    • A clone comes with "Go to the other copy" and "Ignore this clone", which wraps the fragment in jscpd:ignore-start and jscpd:ignore-end comments. Dead code and semantic clones run in the background after a save, and the progress of each run ends with what it found, such as 94 files, 13 clones.
    • Editor clients can ask for the whole project's clones, semantic pairs, dead code, complexity and statistics with custom requests.
    • docs/editors.md has the setup for Neovim, Helix, Sublime Text, Emacs and JetBrains IDEs, and fixtures/lsp-demo is a project that shows each analysis. (#1120, #1121, #1122)
  • Comparing two codebases, experimental: --compare. jscpd --compare source target pairs the functions of two folders with the --semantic model and reports which functions of each side have a counterpart in the other. During a port to another language or platform, that is what is still to port; for two implementations of one app, it is what only one of them has.

    • A function pairs with its counterpart when the model finds them each other's closest match. A short function the model cannot place pairs by name when the names match once case and underscores are ignored and the code is similar enough. Every pair has its similarity and a level, high, medium or low, and the report lists the pairs under other names on their own.
    • Tests and code are measured apart, and a test pairs only with a test. jscpd tells a test by the conventions of its language, such as *_test.go, test_*.py, *.test.ts or Rust's #[cfg(test)], and JavaScript test cases take part under their titles.
    • The console, JSON and Markdown reporters print the totals per side and per file, the functions with no counterpart and the pairs. -r html writes a migration map: both sides as dependency graphs with the pairs bridging them, a table of the same pairs, and the functions ready to port, whose callees all have a counterpart already. The JSON report lists those as readyToPort.
    • On the Java and Python versions of nayuki/QR-Code-generator, it paired 30 of 41 Java functions with no wrong pair. fixtures/compare-demo is a runnable example. (#1115, #1118, #1119)
  • Agent skills for ports. compare-codebases explains how --compare pairs functions and how to check a comparison. code-migration ports a codebase tests first, binds tests to code by coverage, and takes the next function to port from --compare. Install them with npx skills add kucherenko/jscpd --skill <name>. (#1115, #1117)

Changes

  • Pairs from --similarity have a SARIF rule of their own, jscpd/similar-function. The similar kind comes from two mechanisms that find different things, and SARIF filed both under jscpd/similar-code. That rule now keeps the copies merged across a gap (--max-gap-lines), and Code Climate's check_name follows. GitHub code scanning matches alerts by rule, so the first upload of --similarity results after the update closes the old alerts and opens the same findings under the new rule. (#1121)

Other

  • A failed cargo publish now fails the release job instead of passing it. (#1116)

Published Packages

  • basta@0.3.0 on crates.io
  • cpd-core@0.1.20 on crates.io
  • cpd-finder@0.1.20 on crates.io
  • cpd-reporter@0.1.21 on crates.io
  • cpd-semantic@0.1.1 on crates.io
  • cpd-tokenizer@0.1.19 on crates.io
  • jscpd@5.4.0 on crates.io
  • cpd@5.4.0 on npm
  • jscpd@5.4.0 on npm
  • jscpd-darwin-arm64@5.4.0 on npm
  • jscpd-darwin-x64@5.4.0 on npm
  • jscpd-linux-x64-gnu@5.4.0 on npm
  • jscpd-linux-arm64-gnu@5.4.0 on npm
  • jscpd-linux-x64-musl@5.4.0 on npm
  • jscpd-linux-arm64-musl@5.4.0 on npm
  • jscpd-windows-x64-msvc@5.4.0 on npm
  • jscpd-windows-arm64-msvc@5.4.0 on npm
  • jscpd==5.4.0 on PyPI

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 3, 2026
@greptile-apps

greptile-apps Bot commented Oct 3, 2026

Copy link
Copy Markdown

PR author is in the excluded authors list.

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: f124e2d8-7f6d-45f9-b903-2d843b761e6c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dependabot dependabot Bot changed the title build(deps-dev): bump jscpd from 5.3.0 to 5.3.3 build(deps-dev): bump jscpd from 5.3.0 to 5.4.0 Oct 4, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/jscpd-5.3.3 branch from 5de1531 to 95daa86 Compare October 4, 2026 08:28
@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Superseded by #146, which carries this update together with the PM CLI 2026.10.4 certification.

Bumps [jscpd](https://github.com/kucherenko/jscpd/tree/HEAD/rust/jscpd) from 5.3.0 to 5.4.0.
- [Release notes](https://github.com/kucherenko/jscpd/releases)
- [Commits](https://github.com/kucherenko/jscpd/commits/v5.4.0/rust/jscpd)

---
updated-dependencies:
- dependency-name: jscpd
  dependency-version: 5.3.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/jscpd-5.3.3 branch from 95daa86 to 4fe1f97 Compare October 4, 2026 10:05
unbraind added a commit that referenced this pull request Oct 4, 2026
…ency updates

Pin @unbrained/pm-cli to 2026.10.4 with pm-ops 2026.10.4 and
pm-changelog 2026.9.25, take over the pending Dependabot dependency
updates (eslint 10.12.0, jscpd 5.4.0, @types/node 26.6.4) and the
codeql-action pinned SHA group, and recopy the canonical pm-ops
merge-driver launcher byte-for-byte. README gate host pin follows the
dev dependency. pm-github is registered as a managed extension for
read-only preview only.

Supersedes #137 #142 #143 #144 #145 #140.
unbraind added a commit that referenced this pull request Oct 4, 2026
… updates (#146)

* Certify pm-csv on PM CLI/SDK 2026.10.4 and consolidate pending dependency updates

Pin @unbrained/pm-cli to 2026.10.4 with pm-ops 2026.10.4 and
pm-changelog 2026.9.25, take over the pending Dependabot dependency
updates (eslint 10.12.0, jscpd 5.4.0, @types/node 26.6.4) and the
codeql-action pinned SHA group, and recopy the canonical pm-ops
merge-driver launcher byte-for-byte. README gate host pin follows the
dev dependency. pm-github is registered as a managed extension for
read-only preview only.

Supersedes #137 #142 #143 #144 #145 #140.

* docs(pm): upgrade pm-github extension evidence to 2026.10.4

pm-github 2026.10.4 was published during the certification window;
re-ran the read-only previews against the repo with the upgraded
extension and recorded the result on pm-csv-hzn7.

* test: cover broken merge-driver installs and finish exact certification pins

* test: run new merge-driver regressions without platform skips

* test: make merge-driver fixtures portable and isolate lookup paths

---------

Co-authored-by: SteveBot <1153461+unbraind@users.noreply.github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Looks like jscpd is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 4, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/jscpd-5.3.3 branch October 4, 2026 12:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant