Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
[ Use it online • Features • Pricing • About us • GitHub • Blog • Twitter ]
Codacy is a hosted automated code review service.
Codacy automatically applies some patterns to your project and grades it so you can take a first glance of its health. We'll also provide you with all the detailed information required to improve it, effectively helping you tackle your technical debt.
Run
[sudo] npm install -g codacy-cli
Go to your account and click generate. Then you can load your token with one of the following methods:
Default configuration file .codacy
Custom configuration file with -c
or --config
Introduce it interactively in the CLI when requested
{
"apiToken":"**************"
}
Usage:
codacy [options]
Options:
-h, --help output usage information
-V, --version output the version number
-c, --config [file] load the specified configuration file
-o, --output [format] select the output format:
* raw (default)
* json
* table
-l, --projects list projects
-p, --project [projectId | <projectOwner,projectName>] view project issues
-C, --commit [sha] view commit overview (dependsOn: --project)
-D, --delta view commit delta (dependsOn: --commit)
-a, --analyse [file] analyse the specified file or directory
For support, email team@codacy.com
To report a bug you can create a GitHub Issue and describe your problem or suggestion.
Before reporting a bug check if there are no open or closed tickets that cover your issue.
Codacy Command Line Interface(CLI) is distributed under the MIT License.
We really appreciate all kind of feedback. Thanks for using Codacy!
FAQs
Command Line Interface(CLI) tool for Codacy
The npm package codacy-cli receives a total of 1 weekly downloads. As such, codacy-cli popularity was classified as not popular.
We found that codacy-cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.