
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
A command-line utility for analyzing JavaScript code, detecting unused variables and functions, and modifying code by listing, commenting, or deleting unused items based on the specified action.
A command-line utility for analyzing JavaScript code, detecting unused variables and functions, and modifying code by listing, commenting, or deleting unused items based on the specified action.
Install the library globally or locally using npm:
# Globally
npm install -g code-sweep
# Locally (for project usage)
npm install code-sweep --save-dev
After installation, use the CLI tool by specifying a directory and action.
code-sweep -d <directory_path> -a <action>
-d, --directory <path> (required): Specifies the directory to analyze.
-a, --action <action> (required): Specifies the action to perform. Options:
list: List unused code without making changes.
comment: Add comments to unused code with // TODO: Unused Variable or // TODO: Unused Function.
delete: Remove unused code from the codebase.
List Unused Code
code-sweep -d src -a list
Lists all unused variables and functions in the src directory.
Comment Unused Code
# Adds comments to unused variables and functions in the src directory.
code-sweep -d src -a comment
Delete Unused Code
# Deletes unused variables and functions from files in the src directory.
code-sweep -d src -a delete
This library can also be used programmatically:
const { readDirectory, parseFileToAST, findUnused, commentCode, deleteCode } = require('code-sweep');
// Example: Read files in a directory and find unused code
const files = readDirectory('./src');
files.forEach((file) => {
const ast = parseFileToAST(file);
const unusedItems = findUnused(ast);
console.log('Unused items:', unusedItems);
});
This project is licensed under the MIT License.
For issues, questions, or contributions, please reach out to edekobifrank@gmail.com
FAQs
A command-line utility for analyzing JavaScript code, detecting unused variables and functions, and modifying code by listing, commenting, or deleting unused items based on the specified action.
We found that code-sweep demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.