Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungThe Model Got Better. Your Judgment Got Worse.(22.09.2026 um 03:02 Uhr)
Sichere ProgrammierungAIFeed - signed content permissions for AI web crawlers(22.09.2026 um 03:10 Uhr)
Sichere ProgrammierungThanks, glad you liked it!(22.09.2026 um 03:15 Uhr)
Sichere ProgrammierungA request for /.env shouldn't render your React app(22.09.2026 um 03:17 Uhr)
Sichere ProgrammierungAI-Agent Marketplaces Need Verifiable Delivery, Not More Listings(22.09.2026 um 03:20 Uhr)
AI & KI NachrichtenBeyond Bigger Models: Toward a Modular Cognitive Architecture(22.09.2026 um 03:21 Uhr)
Sichere ProgrammierungMasa Depan Manajemen Data: Mengenal Konsep Data Mesh yang Revolusioner(22.09.2026 um 03:22 Uhr)
Sichere ProgrammierungHow to Search Your Claude Code Conversation History(22.09.2026 um 03:22 Uhr)
Sichere ProgrammierungThe Model Got Better. Your Judgment Got Worse.(22.09.2026 um 03:02 Uhr)
Sichere ProgrammierungAIFeed - signed content permissions for AI web crawlers(22.09.2026 um 03:10 Uhr)
Sichere ProgrammierungThanks, glad you liked it!(22.09.2026 um 03:15 Uhr)
Sichere ProgrammierungA request for /.env shouldn't render your React app(22.09.2026 um 03:17 Uhr)
Sichere ProgrammierungAI-Agent Marketplaces Need Verifiable Delivery, Not More Listings(22.09.2026 um 03:20 Uhr)
AI & KI NachrichtenBeyond Bigger Models: Toward a Modular Cognitive Architecture(22.09.2026 um 03:21 Uhr)
Sichere ProgrammierungMasa Depan Manajemen Data: Mengenal Konsep Data Mesh yang Revolusioner(22.09.2026 um 03:22 Uhr)
Sichere ProgrammierungHow to Search Your Claude Code Conversation History(22.09.2026 um 03:22 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Title: I built a CLI that diagnoses your code before you ship

I built a CLI that diagnoses your code before you ship Every NestJS project I've worked on had the same problems: POST endpoints without auth guards Hardcoded API keys in source code .env not in .gitignore Zero tests No Swagger…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

I built a CLI that diagnoses your code before you ship

Every NestJS project I've worked on had the same problems:



POST endpoints without auth guards

Hardcoded API keys in source code

.env not in .gitignore

Zero tests

No Swagger documentation



I was tired of catching these manually in code reviews. So I built codediag.

What it does

bashnpx codediag scan .

One command. It auto-detects your stack and runs 5 analyzers:

codediag — Diagnostic Report



Project: my-nestjs-app

Stack: nestjs + typescript + prisma

Score: B+ (87/100)



API Health ███████████████░░░░░ 78

Security ██████████████████░░ 92

Dependencies ██████████████████░░ 91

Testing ████████████████░░░░ 82

Structure █████████████████░░░ 88

The 5 Analyzers




  1. API Health (NestJS)
    This is the differentiator. codediag uses ts-morph to do real AST analysis of your NestJS decorators — not regex pattern matching.
    It discovers every endpoint from @get(), @post(), @Put(), @Delete(), @Patch() decorators and checks:



Auth guards: Does this endpoint have @UseGuards()? Especially important for mutating endpoints.

DTO validation: Is the @body() parameter typed with a DTO class?

Swagger docs: Are @ApiOperation() and @ApiResponse() present?

Return types: Is there an explicit return type annotation?




  1. Security
    The stuff that ends up on HackerNews for the wrong reasons:



Hardcoded secrets (API keys, Stripe keys, AWS keys, GitHub tokens)

.env in .gitignore

Helmet middleware for HTTP security headers

CORS wildcard (origin: '*') detection

Rate limiting package installed

Password hashing library present




  1. Dependencies
    Your node_modules is a supply chain. codediag treats it like one:



npm audit vulnerabilities

Lock file existence

Deprecated packages

Engine specification

Essential scripts




  1. Testing



Test file existence and count

Framework detection (Jest, Vitest, Mocha, Ava)

Test-to-source file ratio

E2E test directory

Coverage threshold configuration




  1. Structure



README quality

Linter configuration (ESLint or Biome)

Formatter configuration (Prettier)

TypeScript strict mode

NestJS module organization

.env.example presence



Scoring

Each analyzer scores 0-100. The total is a weighted average:

AnalyzerWeightAPI Health25%Security30%Dependencies20%Testing15%Structure10%

Security gets the highest weight because shipping vulnerable code is the worst bug.

CI/CD

One line in your GitHub Actions:

yaml- run: npx codediag scan . --ci --threshold 80

Exits with code 1 if the score drops below your threshold.

What's next



Next.js analyzer

Express route analyzer

Web dashboard with trend tracking

AI-powered fix suggestions

VS Code extension



Try it

bashnpx codediag scan .

Zero config. MIT licensed. 33KB bundled.



GitHub: https://github.com/scuton-technology/codediag

npm: https://www.npmjs.com/package/codediag



I'd love to hear what checks you'd want added. Drop a comment or open an issue!

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Title: I built a CLI that diagnoses your code before you ship

Thematisch verwandte Begriffe: Title, built, that, diagnoses · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-49449 | Joplin is an open source note-taking and to-do application that organise…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick