{"_id":"@adhix11/shipguard","_rev":"3-e00b836ad639de90217c8384e30fc090","name":"@adhix11/shipguard","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"@adhix11/shipguard","version":"0.1.0","keywords":["preflight","scanner","secrets","security","lint","cli","devtools","shipguard","env","debug","test-safety","code-review","ai-code","release","pre-commit"],"author":{"name":"adhix11"},"license":"MIT","_id":"@adhix11/shipguard@0.1.0","maintainers":[{"name":"adhix11","email":"adhix11@gmail.com"}],"homepage":"https://github.com/adhix11/shipguard#readme","bugs":{"url":"https://github.com/adhix11/shipguard/issues"},"bin":{"shipguard":"dist/index.js"},"dist":{"shasum":"720b5be37251a1a14c3b8fb60bb2a10ef4597c2d","tarball":"https://registry.npmjs.org/@adhix11/shipguard/-/shipguard-0.1.0.tgz","fileCount":5,"integrity":"sha512-atEyaS5keIeVpVvAEBsqB92AMwFXmDTp/eL4R1vnEXDiuaKsKcpN6em2xltKnjoRc/3CYqYzOk0TrzlbKt6uiQ==","signatures":[{"sig":"MEYCIQD254smq0P64X0d3P2tXN6t4zfk3QMWTuRtRov2VrF1aAIhAPMTeWpnyWg4mS9ijBD0tx4ILsfCd42R7QU/kFrNOxpx","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":66494},"main":"./dist/index.js","type":"module","engines":{"node":">=16.0.0"},"scripts":{"dev":"tsup --watch","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"adhix11","email":"adhix11@gmail.com"},"repository":{"url":"git+https://github.com/adhix11/shipguard.git","type":"git"},"_npmVersion":"11.6.2","description":"A zero-config preflight scanner for JavaScript and TypeScript projects. Detect secrets, missing env docs, debug code, risky test flags, and basic package readiness before you ship.","directories":{},"_nodeVersion":"22.19.0","dependencies":{"fast-glob":"^3.3.3","picocolors":"^1.1.1"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.4.0","typescript":"^5.8.0","@types/node":"^22.15.0"},"_npmOperationalInternal":{"tmp":"tmp/shipguard_0.1.0_1782406112074_0.5625697011839697","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@adhix11/shipguard","version":"0.1.1","keywords":["preflight","scanner","secrets","security","lint","cli","devtools","shipguard","env","debug","test-safety","code-review","ai-code","release","pre-commit"],"author":{"name":"adhix11"},"license":"MIT","_id":"@adhix11/shipguard@0.1.1","maintainers":[{"name":"adhix11","email":"adhix11@gmail.com"}],"homepage":"https://github.com/adhix11/shipguard#readme","bugs":{"url":"https://github.com/adhix11/shipguard/issues"},"bin":{"shipguard":"dist/index.js"},"dist":{"shasum":"c09ab9d3d1dc2562411d0207713d2a5f862e3837","tarball":"https://registry.npmjs.org/@adhix11/shipguard/-/shipguard-0.1.1.tgz","fileCount":5,"integrity":"sha512-ExpIAL/FOgo8kaTxpoj1XOGgedLGZtnKuOi9+EufZM68mGha7J2QobRw3ii4ZUSA/rmuagf4koFbecRzUNA92w==","signatures":[{"sig":"MEYCIQCOqplIkMX9Cz4w+U21VgGQbUCWCK2D1AYzS4xUrqrW9gIhAJLEXEJSSKmp6XlYA+Qg477CzltuEfnE39tzhQQhzdvs","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":66500},"main":"./dist/index.js","type":"module","engines":{"node":">=16.0.0"},"scripts":{"dev":"tsup --watch","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"adhix11","email":"adhix11@gmail.com"},"repository":{"url":"git+https://github.com/adhix11/shipguard.git","type":"git"},"_npmVersion":"11.6.2","description":"A zero-config preflight scanner for JavaScript and TypeScript projects. Detect secrets, missing env docs, debug code, risky test flags, and basic package readiness before you ship.","directories":{},"_nodeVersion":"22.19.0","dependencies":{"fast-glob":"^3.3.3","picocolors":"^1.1.1"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.4.0","typescript":"^5.8.0","@types/node":"^22.15.0"},"_npmOperationalInternal":{"tmp":"tmp/shipguard_0.1.1_1782406458265_0.6137222822667783","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@adhix11/shipguard","version":"0.1.2","description":"A zero-config preflight scanner for JavaScript and TypeScript projects. Detect secrets, missing env docs, debug code, risky test flags, and basic package readiness before you ship.","author":{"name":"adhix11"},"license":"MIT","type":"module","bin":{"shipguard":"dist/index.js"},"main":"./dist/index.js","scripts":{"build":"tsup","dev":"tsup --watch","prepublishOnly":"npm run build"},"keywords":["preflight","scanner","secrets","security","lint","cli","devtools","shipguard","env","debug","test-safety","code-review","ai-code","release","pre-commit"],"repository":{"type":"git","url":"git+https://github.com/adhix11/shipguard.git"},"bugs":{"url":"https://github.com/adhix11/shipguard/issues"},"homepage":"https://github.com/adhix11/shipguard#readme","engines":{"node":">=16.0.0"},"dependencies":{"fast-glob":"^3.3.3","picocolors":"^1.1.1"},"devDependencies":{"@types/node":"^22.15.0","tsup":"^8.4.0","typescript":"^5.8.0"},"_id":"@adhix11/shipguard@0.1.2","_nodeVersion":"22.19.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-pQ6e549g8IP48R7zK+wdrWWrJNWZGCMmF1/UWReqsZuKUGLcYHqwSskydjTseZ9N0GidpgKh9xNGDWZTJteupA==","shasum":"8d2829df292fdcdae7548c0ff5a8dd3e4d6c4e7a","tarball":"https://registry.npmjs.org/@adhix11/shipguard/-/shipguard-0.1.2.tgz","fileCount":5,"unpackedSize":66499,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQD4S0a4CFcQjv5Iu+Ey719yr/Rxa94cY/T0TcOsAW4IeQIhAIrF1x9dBfL3ii23LM1MumbYj/P2W9L3FLBuGra51L+Q"}]},"_npmUser":{"name":"adhix11","email":"adhix11@gmail.com"},"directories":{},"maintainers":[{"name":"adhix11","email":"adhix11@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/shipguard_0.1.2_1782406668587_0.8603440435489802"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-25T16:48:31.935Z","modified":"2026-06-25T16:57:48.827Z","0.1.0":"2026-06-25T16:48:32.291Z","0.1.1":"2026-06-25T16:54:18.452Z","0.1.2":"2026-06-25T16:57:48.739Z"},"bugs":{"url":"https://github.com/adhix11/shipguard/issues"},"author":{"name":"adhix11"},"license":"MIT","homepage":"https://github.com/adhix11/shipguard#readme","keywords":["preflight","scanner","secrets","security","lint","cli","devtools","shipguard","env","debug","test-safety","code-review","ai-code","release","pre-commit"],"repository":{"type":"git","url":"git+https://github.com/adhix11/shipguard.git"},"description":"A zero-config preflight scanner for JavaScript and TypeScript projects. Detect secrets, missing env docs, debug code, risky test flags, and basic package readiness before you ship.","maintainers":[{"name":"adhix11","email":"adhix11@gmail.com"}],"readme":"# 🚢 ShipGuard\n\n**Catch costly production mistakes before you ship.**\n\nA zero-config preflight scanner for JavaScript and TypeScript projects. Detect secrets, missing env docs, debug code, risky test flags, and basic package readiness before you ship.\n\n[![npm version](https://img.shields.io/npm/v/@adhix11/shipguard.svg)](https://www.npmjs.com/package/@adhix11/shipguard)\n[![license](https://img.shields.io/npm/l/@adhix11/shipguard.svg)](https://github.com/adhix11/shipguard/blob/main/LICENSE)\n\n---\n\n## Why?\n\nDevelopers often forget small but critical things before pushing code:\n\n| Pain | Example |\n|------|---------|\n| **Secret leakage** | AWS key, JWT secret, DB password inside code |\n| **Missing env docs** | Code uses `process.env.DB_URL`, but `.env.example` doesn't mention it |\n| **Debug code** | `console.log`, `debugger`, temporary test code left in |\n| **Test mistakes** | `describe.only`, `it.only`, skipped tests |\n| **Risky package scripts** | Suspicious `postinstall`, `preinstall`, shell commands |\n| **Poor release readiness** | No README, no LICENSE, missing package.json fields |\n\nWith AI-generated code accelerating development, the bottleneck has shifted from **writing code** to **reviewing and validating it**. ShipGuard helps you catch the things that slip through.\n\n---\n\n## Quick Start\n\nRun with zero setup:\n\n```bash\nnpx @adhix11/shipguard\n```\n\nOr install globally:\n\n```bash\nnpm install -g @adhix11/shipguard\nshipguard\n```\n\n---\n\n## What It Scans\n\n### 🔐 Secrets Risk\n- AWS Access Keys & Secret Keys\n- Private key blocks (`-----BEGIN PRIVATE KEY-----`)\n- MongoDB connection URIs (`mongodb+srv://...`)\n- Hardcoded passwords (`password = \"...\"`)\n- JWT secrets\n- API keys & tokens (GitHub, OpenAI, Stripe, Slack)\n\n### 📋 Missing Env Documentation\n- Finds all `process.env.XYZ` and `import.meta.env.XYZ` in your code\n- Cross-references with `.env.example`\n- Reports any environment variables missing from documentation\n\n### 🐛 Debug Code\n- `console.log`, `console.debug`, `console.warn`\n- `debugger` statements\n- `TODO`, `FIXME`, `HACK`, `XXX` comments\n- `alert()` calls\n\n### 🧪 Test Risk\n- `describe.only()`, `it.only()`, `test.only()` — focused tests\n- `describe.skip()`, `it.skip()`, `test.skip()` — skipped tests\n- `fdescribe`, `fit`, `xit`, `xdescribe` — Jasmine equivalents\n\n### 📦 Package Health\n- README.md exists\n- LICENSE exists\n- `package.json` has `name`, `version`, `description`\n- Entry point (`main`, `bin`, `module`, or `exports`) is defined\n- Risky lifecycle scripts (`postinstall`, `preinstall`) with suspicious commands\n\n---\n\n## Example Output\n\n```\n🚢 ShipGuard Report\n──────────────────────────────────────────────────\n\n❌ Secrets Risk\n  src/config/db.ts\n  ✗ Possible MongoDB URI found (line 8)\n\n⚠️ Missing Env Documentation\n  .env.example\n  ● .env.example is missing 3 variables:\n  ● Missing: DB_URL\n  ● Missing: JWT_SECRET\n  ● Missing: AWS_REGION\n\n⚠️ Debug Code Found\n  src/app.ts\n  ● console.log found (line 42)\n\n❌ Test Risk\n  src/__tests__/user.test.ts\n  ✗ it.only found — other tests will be skipped (line 18)\n\n──────────────────────────────────────────────────\nSummary:\n  2 critical issues\n  4 warnings\n\n✗ Run failed. Fix critical issues before shipping.\n```\n\n---\n\n## CLI Options\n\n| Option | Description |\n|--------|-------------|\n| `--strict` | Treat warnings as errors (exit code 1 for any issue) |\n| `--json` | Output results as JSON for CI/CD integration |\n| `--ignore <dirs>` | Comma-separated directories to ignore |\n| `--help`, `-h` | Show help message |\n| `--version`, `-v` | Show version number |\n\n### Examples\n\n```bash\n# Basic scan\nnpx @adhix11/shipguard\n\n# Strict mode — fail on any warning\nnpx @adhix11/shipguard --strict\n\n# JSON output for CI pipelines\nnpx @adhix11/shipguard --json\n\n# Ignore specific directories\nnpx @adhix11/shipguard --ignore \"dist,build,coverage\"\n```\n\n---\n\n## Default Ignores\n\nShipGuard automatically skips these directories:\n\n`node_modules`, `dist`, `build`, `.git`, `.next`, `.nuxt`, `coverage`, `.cache`, `.turbo`, `.output`, `out`\n\nAnd these files: `*.min.js`, `*.min.css`, `*.map`, `package-lock.json`, `yarn.lock`, `pnpm-lock.yaml`\n\n---\n\n## CI/CD Integration\n\n### GitHub Actions\n\n```yaml\n- name: ShipGuard Preflight Check\n  run: npx @adhix11/shipguard --strict\n```\n\n### Pre-commit Hook (with Husky)\n\n```bash\nnpx husky add .husky/pre-commit \"npx @adhix11/shipguard\"\n```\n\n---\n\n## Exit Codes\n\n| Code | Meaning |\n|------|---------|\n| `0` | All clear (or warnings only without `--strict`) |\n| `1` | Critical issues found (or warnings in `--strict` mode) |\n| `2` | ShipGuard internal error |\n\n---\n\n## License\n\nMIT © [adhix11](https://github.com/adhix11)\n","readmeFilename":"README.md"}