
Security News
Risky Biz Podcast: Making Reachability Analysis Work in Real-World Codebases
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
nganalyzer
is a tool for linting Angular apps.
npm install --save-dev nganalyzer
yarn add --dev nganalyzer
nganalyzer --help
: display help infonganalyzer --version
: display the installed versionnganalyzer [--project ./tsconfig.json]
: lint a project and report failuresAdd an nganalyzer.json
file at the root of your project to configure which rules to run.
{
"rules": {
"no-unused-component": true,
"no-unused-component-binding": true
}
}
no-usused-component
: reports when a component is not usedno-unused-component-bindings
: reports when a component input or output is not usedThese rules could be implemented as tslint
rules. In fact, I originally did implement them as
tslint
rules. However, since these rules require the entire application structure to be read,
applying these rules via tslint
does not work as well. The tslint-language-service
, for
example, seemed to slow down the editor when applying the rules. Also, you don't get much benefit
from continuously applying these kinds of rules in the editor. Therefore, I thought it would be
best to ship these rules in a separate tool that can be run once when building a project.
FAQs
`nganalyzer` is a tool for linting Angular apps.
The npm package nganalyzer receives a total of 2 weekly downloads. As such, nganalyzer popularity was classified as not popular.
We found that nganalyzer demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.
Security News
CISA’s 2025 draft SBOM guidance adds new fields like hashes, licenses, and tool metadata to make software inventories more actionable.