v1.0.0: full rewrite as @scanii/core - #1

Merged
rferreira merged 2 commits into
mainfrom
feat/v1.0.0-rewrite
Apr 28, 2026
Merged

v1.0.0: full rewrite as @scanii/core#1
rferreira merged 2 commits into
mainfrom
feat/v1.0.0-rewrite

Conversation

@rferreira

Copy link
Copy Markdown
Contributor

Summary

Full rewrite of the scanii-js skeleton (unpublishable monorepo with empty stubs) as a clean, single-package zero-dependency TypeScript SDK. Publishes as @scanii/core on npm at 1.0.0, replacing the placeholder 0.0.1 stub.

  • API surface mirrors scanii-java v8.0.0 translated to async/Promise TS — process, processAsync, fetch, retrieve, ping, createAuthToken, retrieveAuthToken, deleteAuthToken.
  • Errors:ScaniiError base, ScaniiAuthError (401/403), ScaniiRateLimitError (429, with retryAfter parsed from Retry-After).
  • Zero runtime deps. Native fetch + FormData + Blob + URLSearchParams. No axios, no node-fetch, no form-data, no undici.
  • Dual build: ESM + CJS + shipped .d.ts via tsup. Built artifacts: dist/index.cjs, dist/index.mjs, dist/index.d.ts, dist/index.d.mts.
  • Targets: Node 22+ and modern browsers (ES2022 + DOM).
  • API v2.2 throughout (skeleton was on v2.1).
  • Tests: Jest. Unit suite mocks global.fetch directly (no nock/undici). Integration suite hits scanii-cli at localhost:4000; uses the UUID 38DCC0C9-… inline fixture per workspace CLAUDE.md §5 (not EICAR — that gets quarantined on Windows / macOS runners).
  • CI:pr.yml on Node 22 + 24 across ubuntu / macos / windows, scanii-cli started via scanii/setup-cli-action@v1. release.yml triggered by release: published, publishes via OIDC trusted publishing on the npm GitHub environment, with --provenance.

Naming reminder

Package name on npm is @scanii/core — scoped, NOT unscoped scanii. The unscoped scanii name remains a deprecated 0.0.1 placeholder for squat-protection only and is not touched by this change. README has a one-line note pointing consumers from scanii to @scanii/core.

@scanii/react and @scanii/web are deferred — not touched here.

Out of scope (per packet)

  • Browser polyfills (Node 22+ and ES2022 browsers have everything natively).
  • React hooks / web components / monorepo / workspaces.
  • Retry logic, backoff, batch helpers, concurrency primitives — Principle 3.
  • Tag-pushing or release creation — Rafael's responsibility.

Test plan

  • npm ci clean install
  • npm run typecheck passes (strict TS, verbatimModuleSyntax, noUncheckedIndexedAccess)
  • npm run lint passes (eslint flat config, typescript-eslint recommended)
  • npm test — 32 tests pass (unit suite green; integration suite green against locally running scanii-cli, with documented self-skips for older cli builds missing the UUID signature / token-auth / callback delivery)
  • npm run build — emits dist/index.cjs (13 KB), dist/index.mjs (12 KB), index.d.ts (9 KB)
  • Smoke test: require('./dist/index.cjs') and dynamic-import('./dist/index.mjs') both resolve ScaniiClient, VERSION === "1.0.0"
  • Smoke test: end-to-end process() against a running scanii-cli — clean file returns findings: [], contentLength accurate
  • Reviewer: confirm GitHub npm environment is wired so the OIDC publish step can resolve at v1.0.0 tag time
  • Reviewer: spot-check that @scanii/core@0.0.1 placeholder will be cleanly superseded by v1.0.0 publish

🤖 Generated with Claude Code

Replaces the unpublishable scanii-js monorepo skeleton with a clean,
single-package zero-dependency TypeScript SDK published as @scanii/core
on npm.
API mirrors scanii-java v8.0.0 translated to async/Promise-returning TS:
process / processAsync / fetch / retrieve / ping / createAuthToken /
retrieveAuthToken / deleteAuthToken. Error hierarchy: ScaniiError,
ScaniiAuthError, ScaniiRateLimitError (with retryAfter).
Native fetch + FormData + Blob — no polyfills, no runtime deps. ESM +
CJS dual build via tsup with shipped .d.ts. Targets Node 22+ and modern
browsers.
Tests: jest unit suite mocking global.fetch + integration suite against
scanii-cli (started via scanii/setup-cli-action@v1 in CI). Malware
fixture is the UUID 38DCC0C9-... per workspace CLAUDE.md §5, generated
inline (not committed).
CI: pr.yml on Node 22+24 across ubuntu/macos/windows. release.yml
publishes to npm via OIDC trusted publishing on release: published —
does not create the GitHub Release.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Comment threadCHANGELOG.md Outdated

## 1.0.0 — Initial release

First public release of the Scanii Node SDK as `@scanii/core`. Replaces the unpublished `scanii-js` skeleton; supersedes the `@scanii/core@0.0.1` placeholder published to claim the name on npm.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove mention of scanii-js

Comment threadCHANGELOG.md Outdated

First public release of the Scanii Node SDK as `@scanii/core`. Replaces the unpublished `scanii-js` skeleton; supersedes the `@scanii/core@0.0.1` placeholder published to claim the name on npm.

**Reference frozen at `scanii-java` v8.0.0.** Method names, response shape, and error hierarchy mirror the Java reference, translated to idiomatic TypeScript.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove reference to the Java SDK

Comment threadCHANGELOG.md Outdated
- **scanii-cli** integration tests cover the cross-OS matrix (Linux / macOS / Windows on Node 22 + 24) without burning real Scanii credits.
- **OIDC trusted publishing** with provenance attestation.

### Migration

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove migration for first release

Per PR review: scanii-js and the @scanii/core@0.0.1 placeholder are
internal context, not consumer-facing release notes. Java reference is
implementation detail. No migration path applies for a first release.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@rferreira
rferreira merged commit f7443ba into mainApr 28, 2026
6 checks passed
@rferreira
rferreira deleted the feat/v1.0.0-rewrite branch April 28, 2026 10:45
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rferreira
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

v1.0.0: full rewrite as @scanii/core - #1

Merged
rferreira merged 2 commits into
mainfrom
feat/v1.0.0-rewrite
Apr 28, 2026
Merged

v1.0.0: full rewrite as @scanii/core#1
rferreira merged 2 commits into
mainfrom
feat/v1.0.0-rewrite

Conversation

@rferreira

Copy link
Copy Markdown
Contributor

Summary

Full rewrite of the scanii-js skeleton (unpublishable monorepo with empty stubs) as a clean, single-package zero-dependency TypeScript SDK. Publishes as @scanii/core on npm at 1.0.0, replacing the placeholder 0.0.1 stub.

  • API surface mirrors scanii-java v8.0.0 translated to async/Promise TS — process, processAsync, fetch, retrieve, ping, createAuthToken, retrieveAuthToken, deleteAuthToken.
  • Errors:ScaniiError base, ScaniiAuthError (401/403), ScaniiRateLimitError (429, with retryAfter parsed from Retry-After).
  • Zero runtime deps. Native fetch + FormData + Blob + URLSearchParams. No axios, no node-fetch, no form-data, no undici.
  • Dual build: ESM + CJS + shipped .d.ts via tsup. Built artifacts: dist/index.cjs, dist/index.mjs, dist/index.d.ts, dist/index.d.mts.
  • Targets: Node 22+ and modern browsers (ES2022 + DOM).
  • API v2.2 throughout (skeleton was on v2.1).
  • Tests: Jest. Unit suite mocks global.fetch directly (no nock/undici). Integration suite hits scanii-cli at localhost:4000; uses the UUID 38DCC0C9-… inline fixture per workspace CLAUDE.md §5 (not EICAR — that gets quarantined on Windows / macOS runners).
  • CI:pr.yml on Node 22 + 24 across ubuntu / macos / windows, scanii-cli started via scanii/setup-cli-action@v1. release.yml triggered by release: published, publishes via OIDC trusted publishing on the npm GitHub environment, with --provenance.

Naming reminder

Package name on npm is @scanii/core — scoped, NOT unscoped scanii. The unscoped scanii name remains a deprecated 0.0.1 placeholder for squat-protection only and is not touched by this change. README has a one-line note pointing consumers from scanii to @scanii/core.

@scanii/react and @scanii/web are deferred — not touched here.

Out of scope (per packet)

  • Browser polyfills (Node 22+ and ES2022 browsers have everything natively).
  • React hooks / web components / monorepo / workspaces.
  • Retry logic, backoff, batch helpers, concurrency primitives — Principle 3.
  • Tag-pushing or release creation — Rafael's responsibility.

Test plan

  • npm ci clean install
  • npm run typecheck passes (strict TS, verbatimModuleSyntax, noUncheckedIndexedAccess)
  • npm run lint passes (eslint flat config, typescript-eslint recommended)
  • npm test — 32 tests pass (unit suite green; integration suite green against locally running scanii-cli, with documented self-skips for older cli builds missing the UUID signature / token-auth / callback delivery)
  • npm run build — emits dist/index.cjs (13 KB), dist/index.mjs (12 KB), index.d.ts (9 KB)
  • Smoke test: require('./dist/index.cjs') and dynamic-import('./dist/index.mjs') both resolve ScaniiClient, VERSION === "1.0.0"
  • Smoke test: end-to-end process() against a running scanii-cli — clean file returns findings: [], contentLength accurate
  • Reviewer: confirm GitHub npm environment is wired so the OIDC publish step can resolve at v1.0.0 tag time
  • Reviewer: spot-check that @scanii/core@0.0.1 placeholder will be cleanly superseded by v1.0.0 publish

🤖 Generated with Claude Code

Replaces the unpublishable scanii-js monorepo skeleton with a clean,
single-package zero-dependency TypeScript SDK published as @scanii/core
on npm.
API mirrors scanii-java v8.0.0 translated to async/Promise-returning TS:
process / processAsync / fetch / retrieve / ping / createAuthToken /
retrieveAuthToken / deleteAuthToken. Error hierarchy: ScaniiError,
ScaniiAuthError, ScaniiRateLimitError (with retryAfter).
Native fetch + FormData + Blob — no polyfills, no runtime deps. ESM +
CJS dual build via tsup with shipped .d.ts. Targets Node 22+ and modern
browsers.
Tests: jest unit suite mocking global.fetch + integration suite against
scanii-cli (started via scanii/setup-cli-action@v1 in CI). Malware
fixture is the UUID 38DCC0C9-... per workspace CLAUDE.md §5, generated
inline (not committed).
CI: pr.yml on Node 22+24 across ubuntu/macos/windows. release.yml
publishes to npm via OIDC trusted publishing on release: published —
does not create the GitHub Release.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Comment threadCHANGELOG.md Outdated

## 1.0.0 — Initial release

First public release of the Scanii Node SDK as `@scanii/core`. Replaces the unpublished `scanii-js` skeleton; supersedes the `@scanii/core@0.0.1` placeholder published to claim the name on npm.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove mention of scanii-js

Comment threadCHANGELOG.md Outdated

First public release of the Scanii Node SDK as `@scanii/core`. Replaces the unpublished `scanii-js` skeleton; supersedes the `@scanii/core@0.0.1` placeholder published to claim the name on npm.

**Reference frozen at `scanii-java` v8.0.0.** Method names, response shape, and error hierarchy mirror the Java reference, translated to idiomatic TypeScript.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove reference to the Java SDK

Comment threadCHANGELOG.md Outdated
- **scanii-cli** integration tests cover the cross-OS matrix (Linux / macOS / Windows on Node 22 + 24) without burning real Scanii credits.
- **OIDC trusted publishing** with provenance attestation.

### Migration

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove migration for first release

Per PR review: scanii-js and the @scanii/core@0.0.1 placeholder are
internal context, not consumer-facing release notes. Java reference is
implementation detail. No migration path applies for a first release.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@rferreira
rferreira merged commit f7443ba into mainApr 28, 2026
6 checks passed
@rferreira
rferreira deleted the feat/v1.0.0-rewrite branch April 28, 2026 10:45
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rferreira
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

v1.0.0: full rewrite as @scanii/core - #1

Merged
rferreira merged 2 commits into
mainfrom
feat/v1.0.0-rewrite
Apr 28, 2026
Merged

v1.0.0: full rewrite as @scanii/core#1
rferreira merged 2 commits into
mainfrom
feat/v1.0.0-rewrite

Conversation

@rferreira

Copy link
Copy Markdown
Contributor

Summary

Full rewrite of the scanii-js skeleton (unpublishable monorepo with empty stubs) as a clean, single-package zero-dependency TypeScript SDK. Publishes as @scanii/core on npm at 1.0.0, replacing the placeholder 0.0.1 stub.

  • API surface mirrors scanii-java v8.0.0 translated to async/Promise TS — process, processAsync, fetch, retrieve, ping, createAuthToken, retrieveAuthToken, deleteAuthToken.
  • Errors:ScaniiError base, ScaniiAuthError (401/403), ScaniiRateLimitError (429, with retryAfter parsed from Retry-After).
  • Zero runtime deps. Native fetch + FormData + Blob + URLSearchParams. No axios, no node-fetch, no form-data, no undici.
  • Dual build: ESM + CJS + shipped .d.ts via tsup. Built artifacts: dist/index.cjs, dist/index.mjs, dist/index.d.ts, dist/index.d.mts.
  • Targets: Node 22+ and modern browsers (ES2022 + DOM).
  • API v2.2 throughout (skeleton was on v2.1).
  • Tests: Jest. Unit suite mocks global.fetch directly (no nock/undici). Integration suite hits scanii-cli at localhost:4000; uses the UUID 38DCC0C9-… inline fixture per workspace CLAUDE.md §5 (not EICAR — that gets quarantined on Windows / macOS runners).
  • CI:pr.yml on Node 22 + 24 across ubuntu / macos / windows, scanii-cli started via scanii/setup-cli-action@v1. release.yml triggered by release: published, publishes via OIDC trusted publishing on the npm GitHub environment, with --provenance.

Naming reminder

Package name on npm is @scanii/core — scoped, NOT unscoped scanii. The unscoped scanii name remains a deprecated 0.0.1 placeholder for squat-protection only and is not touched by this change. README has a one-line note pointing consumers from scanii to @scanii/core.

@scanii/react and @scanii/web are deferred — not touched here.

Out of scope (per packet)

  • Browser polyfills (Node 22+ and ES2022 browsers have everything natively).
  • React hooks / web components / monorepo / workspaces.
  • Retry logic, backoff, batch helpers, concurrency primitives — Principle 3.
  • Tag-pushing or release creation — Rafael's responsibility.

Test plan

  • npm ci clean install
  • npm run typecheck passes (strict TS, verbatimModuleSyntax, noUncheckedIndexedAccess)
  • npm run lint passes (eslint flat config, typescript-eslint recommended)
  • npm test — 32 tests pass (unit suite green; integration suite green against locally running scanii-cli, with documented self-skips for older cli builds missing the UUID signature / token-auth / callback delivery)
  • npm run build — emits dist/index.cjs (13 KB), dist/index.mjs (12 KB), index.d.ts (9 KB)
  • Smoke test: require('./dist/index.cjs') and dynamic-import('./dist/index.mjs') both resolve ScaniiClient, VERSION === "1.0.0"
  • Smoke test: end-to-end process() against a running scanii-cli — clean file returns findings: [], contentLength accurate
  • Reviewer: confirm GitHub npm environment is wired so the OIDC publish step can resolve at v1.0.0 tag time
  • Reviewer: spot-check that @scanii/core@0.0.1 placeholder will be cleanly superseded by v1.0.0 publish

🤖 Generated with Claude Code

Replaces the unpublishable scanii-js monorepo skeleton with a clean,
single-package zero-dependency TypeScript SDK published as @scanii/core
on npm.
API mirrors scanii-java v8.0.0 translated to async/Promise-returning TS:
process / processAsync / fetch / retrieve / ping / createAuthToken /
retrieveAuthToken / deleteAuthToken. Error hierarchy: ScaniiError,
ScaniiAuthError, ScaniiRateLimitError (with retryAfter).
Native fetch + FormData + Blob — no polyfills, no runtime deps. ESM +
CJS dual build via tsup with shipped .d.ts. Targets Node 22+ and modern
browsers.
Tests: jest unit suite mocking global.fetch + integration suite against
scanii-cli (started via scanii/setup-cli-action@v1 in CI). Malware
fixture is the UUID 38DCC0C9-... per workspace CLAUDE.md §5, generated
inline (not committed).
CI: pr.yml on Node 22+24 across ubuntu/macos/windows. release.yml
publishes to npm via OIDC trusted publishing on release: published —
does not create the GitHub Release.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Comment threadCHANGELOG.md Outdated

## 1.0.0 — Initial release

First public release of the Scanii Node SDK as `@scanii/core`. Replaces the unpublished `scanii-js` skeleton; supersedes the `@scanii/core@0.0.1` placeholder published to claim the name on npm.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove mention of scanii-js

Comment threadCHANGELOG.md Outdated

First public release of the Scanii Node SDK as `@scanii/core`. Replaces the unpublished `scanii-js` skeleton; supersedes the `@scanii/core@0.0.1` placeholder published to claim the name on npm.

**Reference frozen at `scanii-java` v8.0.0.** Method names, response shape, and error hierarchy mirror the Java reference, translated to idiomatic TypeScript.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove reference to the Java SDK

Comment threadCHANGELOG.md Outdated
- **scanii-cli** integration tests cover the cross-OS matrix (Linux / macOS / Windows on Node 22 + 24) without burning real Scanii credits.
- **OIDC trusted publishing** with provenance attestation.

### Migration

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove migration for first release

Per PR review: scanii-js and the @scanii/core@0.0.1 placeholder are
internal context, not consumer-facing release notes. Java reference is
implementation detail. No migration path applies for a first release.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@rferreira
rferreira merged commit f7443ba into mainApr 28, 2026
6 checks passed
@rferreira
rferreira deleted the feat/v1.0.0-rewrite branch April 28, 2026 10:45
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rferreira
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

v1.0.0: full rewrite as @scanii/core - #1

Merged
rferreira merged 2 commits into
mainfrom
feat/v1.0.0-rewrite
Apr 28, 2026
Merged

v1.0.0: full rewrite as @scanii/core#1
rferreira merged 2 commits into
mainfrom
feat/v1.0.0-rewrite

Conversation

@rferreira

Copy link
Copy Markdown
Contributor

Summary

Full rewrite of the scanii-js skeleton (unpublishable monorepo with empty stubs) as a clean, single-package zero-dependency TypeScript SDK. Publishes as @scanii/core on npm at 1.0.0, replacing the placeholder 0.0.1 stub.

  • API surface mirrors scanii-java v8.0.0 translated to async/Promise TS — process, processAsync, fetch, retrieve, ping, createAuthToken, retrieveAuthToken, deleteAuthToken.
  • Errors:ScaniiError base, ScaniiAuthError (401/403), ScaniiRateLimitError (429, with retryAfter parsed from Retry-After).
  • Zero runtime deps. Native fetch + FormData + Blob + URLSearchParams. No axios, no node-fetch, no form-data, no undici.
  • Dual build: ESM + CJS + shipped .d.ts via tsup. Built artifacts: dist/index.cjs, dist/index.mjs, dist/index.d.ts, dist/index.d.mts.
  • Targets: Node 22+ and modern browsers (ES2022 + DOM).
  • API v2.2 throughout (skeleton was on v2.1).
  • Tests: Jest. Unit suite mocks global.fetch directly (no nock/undici). Integration suite hits scanii-cli at localhost:4000; uses the UUID 38DCC0C9-… inline fixture per workspace CLAUDE.md §5 (not EICAR — that gets quarantined on Windows / macOS runners).
  • CI:pr.yml on Node 22 + 24 across ubuntu / macos / windows, scanii-cli started via scanii/setup-cli-action@v1. release.yml triggered by release: published, publishes via OIDC trusted publishing on the npm GitHub environment, with --provenance.

Naming reminder

Package name on npm is @scanii/core — scoped, NOT unscoped scanii. The unscoped scanii name remains a deprecated 0.0.1 placeholder for squat-protection only and is not touched by this change. README has a one-line note pointing consumers from scanii to @scanii/core.

@scanii/react and @scanii/web are deferred — not touched here.

Out of scope (per packet)

  • Browser polyfills (Node 22+ and ES2022 browsers have everything natively).
  • React hooks / web components / monorepo / workspaces.
  • Retry logic, backoff, batch helpers, concurrency primitives — Principle 3.
  • Tag-pushing or release creation — Rafael's responsibility.

Test plan

  • npm ci clean install
  • npm run typecheck passes (strict TS, verbatimModuleSyntax, noUncheckedIndexedAccess)
  • npm run lint passes (eslint flat config, typescript-eslint recommended)
  • npm test — 32 tests pass (unit suite green; integration suite green against locally running scanii-cli, with documented self-skips for older cli builds missing the UUID signature / token-auth / callback delivery)
  • npm run build — emits dist/index.cjs (13 KB), dist/index.mjs (12 KB), index.d.ts (9 KB)
  • Smoke test: require('./dist/index.cjs') and dynamic-import('./dist/index.mjs') both resolve ScaniiClient, VERSION === "1.0.0"
  • Smoke test: end-to-end process() against a running scanii-cli — clean file returns findings: [], contentLength accurate
  • Reviewer: confirm GitHub npm environment is wired so the OIDC publish step can resolve at v1.0.0 tag time
  • Reviewer: spot-check that @scanii/core@0.0.1 placeholder will be cleanly superseded by v1.0.0 publish

🤖 Generated with Claude Code

Replaces the unpublishable scanii-js monorepo skeleton with a clean,
single-package zero-dependency TypeScript SDK published as @scanii/core
on npm.
API mirrors scanii-java v8.0.0 translated to async/Promise-returning TS:
process / processAsync / fetch / retrieve / ping / createAuthToken /
retrieveAuthToken / deleteAuthToken. Error hierarchy: ScaniiError,
ScaniiAuthError, ScaniiRateLimitError (with retryAfter).
Native fetch + FormData + Blob — no polyfills, no runtime deps. ESM +
CJS dual build via tsup with shipped .d.ts. Targets Node 22+ and modern
browsers.
Tests: jest unit suite mocking global.fetch + integration suite against
scanii-cli (started via scanii/setup-cli-action@v1 in CI). Malware
fixture is the UUID 38DCC0C9-... per workspace CLAUDE.md §5, generated
inline (not committed).
CI: pr.yml on Node 22+24 across ubuntu/macos/windows. release.yml
publishes to npm via OIDC trusted publishing on release: published —
does not create the GitHub Release.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Comment threadCHANGELOG.md Outdated

## 1.0.0 — Initial release

First public release of the Scanii Node SDK as `@scanii/core`. Replaces the unpublished `scanii-js` skeleton; supersedes the `@scanii/core@0.0.1` placeholder published to claim the name on npm.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove mention of scanii-js

Comment threadCHANGELOG.md Outdated

First public release of the Scanii Node SDK as `@scanii/core`. Replaces the unpublished `scanii-js` skeleton; supersedes the `@scanii/core@0.0.1` placeholder published to claim the name on npm.

**Reference frozen at `scanii-java` v8.0.0.** Method names, response shape, and error hierarchy mirror the Java reference, translated to idiomatic TypeScript.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove reference to the Java SDK

Comment threadCHANGELOG.md Outdated
- **scanii-cli** integration tests cover the cross-OS matrix (Linux / macOS / Windows on Node 22 + 24) without burning real Scanii credits.
- **OIDC trusted publishing** with provenance attestation.

### Migration

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove migration for first release

Per PR review: scanii-js and the @scanii/core@0.0.1 placeholder are
internal context, not consumer-facing release notes. Java reference is
implementation detail. No migration path applies for a first release.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@rferreira
rferreira merged commit f7443ba into mainApr 28, 2026
6 checks passed
@rferreira
rferreira deleted the feat/v1.0.0-rewrite branch April 28, 2026 10:45
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rferreira
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

v1.0.0: full rewrite as @scanii/core - #1

Merged
rferreira merged 2 commits into
mainfrom
feat/v1.0.0-rewrite
Apr 28, 2026
Merged

v1.0.0: full rewrite as @scanii/core#1
rferreira merged 2 commits into
mainfrom
feat/v1.0.0-rewrite

Conversation

@rferreira

Copy link
Copy Markdown
Contributor

Summary

Full rewrite of the scanii-js skeleton (unpublishable monorepo with empty stubs) as a clean, single-package zero-dependency TypeScript SDK. Publishes as @scanii/core on npm at 1.0.0, replacing the placeholder 0.0.1 stub.

  • API surface mirrors scanii-java v8.0.0 translated to async/Promise TS — process, processAsync, fetch, retrieve, ping, createAuthToken, retrieveAuthToken, deleteAuthToken.
  • Errors:ScaniiError base, ScaniiAuthError (401/403), ScaniiRateLimitError (429, with retryAfter parsed from Retry-After).
  • Zero runtime deps. Native fetch + FormData + Blob + URLSearchParams. No axios, no node-fetch, no form-data, no undici.
  • Dual build: ESM + CJS + shipped .d.ts via tsup. Built artifacts: dist/index.cjs, dist/index.mjs, dist/index.d.ts, dist/index.d.mts.
  • Targets: Node 22+ and modern browsers (ES2022 + DOM).
  • API v2.2 throughout (skeleton was on v2.1).
  • Tests: Jest. Unit suite mocks global.fetch directly (no nock/undici). Integration suite hits scanii-cli at localhost:4000; uses the UUID 38DCC0C9-… inline fixture per workspace CLAUDE.md §5 (not EICAR — that gets quarantined on Windows / macOS runners).
  • CI:pr.yml on Node 22 + 24 across ubuntu / macos / windows, scanii-cli started via scanii/setup-cli-action@v1. release.yml triggered by release: published, publishes via OIDC trusted publishing on the npm GitHub environment, with --provenance.

Naming reminder

Package name on npm is @scanii/core — scoped, NOT unscoped scanii. The unscoped scanii name remains a deprecated 0.0.1 placeholder for squat-protection only and is not touched by this change. README has a one-line note pointing consumers from scanii to @scanii/core.

@scanii/react and @scanii/web are deferred — not touched here.

Out of scope (per packet)

  • Browser polyfills (Node 22+ and ES2022 browsers have everything natively).
  • React hooks / web components / monorepo / workspaces.
  • Retry logic, backoff, batch helpers, concurrency primitives — Principle 3.
  • Tag-pushing or release creation — Rafael's responsibility.

Test plan

  • npm ci clean install
  • npm run typecheck passes (strict TS, verbatimModuleSyntax, noUncheckedIndexedAccess)
  • npm run lint passes (eslint flat config, typescript-eslint recommended)
  • npm test — 32 tests pass (unit suite green; integration suite green against locally running scanii-cli, with documented self-skips for older cli builds missing the UUID signature / token-auth / callback delivery)
  • npm run build — emits dist/index.cjs (13 KB), dist/index.mjs (12 KB), index.d.ts (9 KB)
  • Smoke test: require('./dist/index.cjs') and dynamic-import('./dist/index.mjs') both resolve ScaniiClient, VERSION === "1.0.0"
  • Smoke test: end-to-end process() against a running scanii-cli — clean file returns findings: [], contentLength accurate
  • Reviewer: confirm GitHub npm environment is wired so the OIDC publish step can resolve at v1.0.0 tag time
  • Reviewer: spot-check that @scanii/core@0.0.1 placeholder will be cleanly superseded by v1.0.0 publish

🤖 Generated with Claude Code

Replaces the unpublishable scanii-js monorepo skeleton with a clean,
single-package zero-dependency TypeScript SDK published as @scanii/core
on npm.
API mirrors scanii-java v8.0.0 translated to async/Promise-returning TS:
process / processAsync / fetch / retrieve / ping / createAuthToken /
retrieveAuthToken / deleteAuthToken. Error hierarchy: ScaniiError,
ScaniiAuthError, ScaniiRateLimitError (with retryAfter).
Native fetch + FormData + Blob — no polyfills, no runtime deps. ESM +
CJS dual build via tsup with shipped .d.ts. Targets Node 22+ and modern
browsers.
Tests: jest unit suite mocking global.fetch + integration suite against
scanii-cli (started via scanii/setup-cli-action@v1 in CI). Malware
fixture is the UUID 38DCC0C9-... per workspace CLAUDE.md §5, generated
inline (not committed).
CI: pr.yml on Node 22+24 across ubuntu/macos/windows. release.yml
publishes to npm via OIDC trusted publishing on release: published —
does not create the GitHub Release.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Comment threadCHANGELOG.md Outdated

## 1.0.0 — Initial release

First public release of the Scanii Node SDK as `@scanii/core`. Replaces the unpublished `scanii-js` skeleton; supersedes the `@scanii/core@0.0.1` placeholder published to claim the name on npm.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove mention of scanii-js

Comment threadCHANGELOG.md Outdated

First public release of the Scanii Node SDK as `@scanii/core`. Replaces the unpublished `scanii-js` skeleton; supersedes the `@scanii/core@0.0.1` placeholder published to claim the name on npm.

**Reference frozen at `scanii-java` v8.0.0.** Method names, response shape, and error hierarchy mirror the Java reference, translated to idiomatic TypeScript.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove reference to the Java SDK

Comment threadCHANGELOG.md Outdated
- **scanii-cli** integration tests cover the cross-OS matrix (Linux / macOS / Windows on Node 22 + 24) without burning real Scanii credits.
- **OIDC trusted publishing** with provenance attestation.

### Migration

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove migration for first release

Per PR review: scanii-js and the @scanii/core@0.0.1 placeholder are
internal context, not consumer-facing release notes. Java reference is
implementation detail. No migration path applies for a first release.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@rferreira
rferreira merged commit f7443ba into mainApr 28, 2026
6 checks passed
@rferreira
rferreira deleted the feat/v1.0.0-rewrite branch April 28, 2026 10:45
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rferreira
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

v1.0.0: full rewrite as @scanii/core - #1

Merged
rferreira merged 2 commits into
mainfrom
feat/v1.0.0-rewrite
Apr 28, 2026
Merged

v1.0.0: full rewrite as @scanii/core#1
rferreira merged 2 commits into
mainfrom
feat/v1.0.0-rewrite

Conversation

@rferreira

Copy link
Copy Markdown
Contributor

Summary

Full rewrite of the scanii-js skeleton (unpublishable monorepo with empty stubs) as a clean, single-package zero-dependency TypeScript SDK. Publishes as @scanii/core on npm at 1.0.0, replacing the placeholder 0.0.1 stub.

  • API surface mirrors scanii-java v8.0.0 translated to async/Promise TS — process, processAsync, fetch, retrieve, ping, createAuthToken, retrieveAuthToken, deleteAuthToken.
  • Errors:ScaniiError base, ScaniiAuthError (401/403), ScaniiRateLimitError (429, with retryAfter parsed from Retry-After).
  • Zero runtime deps. Native fetch + FormData + Blob + URLSearchParams. No axios, no node-fetch, no form-data, no undici.
  • Dual build: ESM + CJS + shipped .d.ts via tsup. Built artifacts: dist/index.cjs, dist/index.mjs, dist/index.d.ts, dist/index.d.mts.
  • Targets: Node 22+ and modern browsers (ES2022 + DOM).
  • API v2.2 throughout (skeleton was on v2.1).
  • Tests: Jest. Unit suite mocks global.fetch directly (no nock/undici). Integration suite hits scanii-cli at localhost:4000; uses the UUID 38DCC0C9-… inline fixture per workspace CLAUDE.md §5 (not EICAR — that gets quarantined on Windows / macOS runners).
  • CI:pr.yml on Node 22 + 24 across ubuntu / macos / windows, scanii-cli started via scanii/setup-cli-action@v1. release.yml triggered by release: published, publishes via OIDC trusted publishing on the npm GitHub environment, with --provenance.

Naming reminder

Package name on npm is @scanii/core — scoped, NOT unscoped scanii. The unscoped scanii name remains a deprecated 0.0.1 placeholder for squat-protection only and is not touched by this change. README has a one-line note pointing consumers from scanii to @scanii/core.

@scanii/react and @scanii/web are deferred — not touched here.

Out of scope (per packet)

  • Browser polyfills (Node 22+ and ES2022 browsers have everything natively).
  • React hooks / web components / monorepo / workspaces.
  • Retry logic, backoff, batch helpers, concurrency primitives — Principle 3.
  • Tag-pushing or release creation — Rafael's responsibility.

Test plan

  • npm ci clean install
  • npm run typecheck passes (strict TS, verbatimModuleSyntax, noUncheckedIndexedAccess)
  • npm run lint passes (eslint flat config, typescript-eslint recommended)
  • npm test — 32 tests pass (unit suite green; integration suite green against locally running scanii-cli, with documented self-skips for older cli builds missing the UUID signature / token-auth / callback delivery)
  • npm run build — emits dist/index.cjs (13 KB), dist/index.mjs (12 KB), index.d.ts (9 KB)
  • Smoke test: require('./dist/index.cjs') and dynamic-import('./dist/index.mjs') both resolve ScaniiClient, VERSION === "1.0.0"
  • Smoke test: end-to-end process() against a running scanii-cli — clean file returns findings: [], contentLength accurate
  • Reviewer: confirm GitHub npm environment is wired so the OIDC publish step can resolve at v1.0.0 tag time
  • Reviewer: spot-check that @scanii/core@0.0.1 placeholder will be cleanly superseded by v1.0.0 publish

🤖 Generated with Claude Code

Replaces the unpublishable scanii-js monorepo skeleton with a clean,
single-package zero-dependency TypeScript SDK published as @scanii/core
on npm.
API mirrors scanii-java v8.0.0 translated to async/Promise-returning TS:
process / processAsync / fetch / retrieve / ping / createAuthToken /
retrieveAuthToken / deleteAuthToken. Error hierarchy: ScaniiError,
ScaniiAuthError, ScaniiRateLimitError (with retryAfter).
Native fetch + FormData + Blob — no polyfills, no runtime deps. ESM +
CJS dual build via tsup with shipped .d.ts. Targets Node 22+ and modern
browsers.
Tests: jest unit suite mocking global.fetch + integration suite against
scanii-cli (started via scanii/setup-cli-action@v1 in CI). Malware
fixture is the UUID 38DCC0C9-... per workspace CLAUDE.md §5, generated
inline (not committed).
CI: pr.yml on Node 22+24 across ubuntu/macos/windows. release.yml
publishes to npm via OIDC trusted publishing on release: published —
does not create the GitHub Release.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Comment threadCHANGELOG.md Outdated

## 1.0.0 — Initial release

First public release of the Scanii Node SDK as `@scanii/core`. Replaces the unpublished `scanii-js` skeleton; supersedes the `@scanii/core@0.0.1` placeholder published to claim the name on npm.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove mention of scanii-js

Comment threadCHANGELOG.md Outdated

First public release of the Scanii Node SDK as `@scanii/core`. Replaces the unpublished `scanii-js` skeleton; supersedes the `@scanii/core@0.0.1` placeholder published to claim the name on npm.

**Reference frozen at `scanii-java` v8.0.0.** Method names, response shape, and error hierarchy mirror the Java reference, translated to idiomatic TypeScript.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove reference to the Java SDK

Comment threadCHANGELOG.md Outdated
- **scanii-cli** integration tests cover the cross-OS matrix (Linux / macOS / Windows on Node 22 + 24) without burning real Scanii credits.
- **OIDC trusted publishing** with provenance attestation.

### Migration

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove migration for first release

Per PR review: scanii-js and the @scanii/core@0.0.1 placeholder are
internal context, not consumer-facing release notes. Java reference is
implementation detail. No migration path applies for a first release.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@rferreira
rferreira merged commit f7443ba into mainApr 28, 2026
6 checks passed
@rferreira
rferreira deleted the feat/v1.0.0-rewrite branch April 28, 2026 10:45
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rferreira
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

v1.0.0: full rewrite as @scanii/core - #1

Merged
rferreira merged 2 commits into
mainfrom
feat/v1.0.0-rewrite
Apr 28, 2026
Merged

v1.0.0: full rewrite as @scanii/core#1
rferreira merged 2 commits into
mainfrom
feat/v1.0.0-rewrite

Conversation

@rferreira

Copy link
Copy Markdown
Contributor

Summary

Full rewrite of the scanii-js skeleton (unpublishable monorepo with empty stubs) as a clean, single-package zero-dependency TypeScript SDK. Publishes as @scanii/core on npm at 1.0.0, replacing the placeholder 0.0.1 stub.

  • API surface mirrors scanii-java v8.0.0 translated to async/Promise TS — process, processAsync, fetch, retrieve, ping, createAuthToken, retrieveAuthToken, deleteAuthToken.
  • Errors:ScaniiError base, ScaniiAuthError (401/403), ScaniiRateLimitError (429, with retryAfter parsed from Retry-After).
  • Zero runtime deps. Native fetch + FormData + Blob + URLSearchParams. No axios, no node-fetch, no form-data, no undici.
  • Dual build: ESM + CJS + shipped .d.ts via tsup. Built artifacts: dist/index.cjs, dist/index.mjs, dist/index.d.ts, dist/index.d.mts.
  • Targets: Node 22+ and modern browsers (ES2022 + DOM).
  • API v2.2 throughout (skeleton was on v2.1).
  • Tests: Jest. Unit suite mocks global.fetch directly (no nock/undici). Integration suite hits scanii-cli at localhost:4000; uses the UUID 38DCC0C9-… inline fixture per workspace CLAUDE.md §5 (not EICAR — that gets quarantined on Windows / macOS runners).
  • CI:pr.yml on Node 22 + 24 across ubuntu / macos / windows, scanii-cli started via scanii/setup-cli-action@v1. release.yml triggered by release: published, publishes via OIDC trusted publishing on the npm GitHub environment, with --provenance.

Naming reminder

Package name on npm is @scanii/core — scoped, NOT unscoped scanii. The unscoped scanii name remains a deprecated 0.0.1 placeholder for squat-protection only and is not touched by this change. README has a one-line note pointing consumers from scanii to @scanii/core.

@scanii/react and @scanii/web are deferred — not touched here.

Out of scope (per packet)

  • Browser polyfills (Node 22+ and ES2022 browsers have everything natively).
  • React hooks / web components / monorepo / workspaces.
  • Retry logic, backoff, batch helpers, concurrency primitives — Principle 3.
  • Tag-pushing or release creation — Rafael's responsibility.

Test plan

  • npm ci clean install
  • npm run typecheck passes (strict TS, verbatimModuleSyntax, noUncheckedIndexedAccess)
  • npm run lint passes (eslint flat config, typescript-eslint recommended)
  • npm test — 32 tests pass (unit suite green; integration suite green against locally running scanii-cli, with documented self-skips for older cli builds missing the UUID signature / token-auth / callback delivery)
  • npm run build — emits dist/index.cjs (13 KB), dist/index.mjs (12 KB), index.d.ts (9 KB)
  • Smoke test: require('./dist/index.cjs') and dynamic-import('./dist/index.mjs') both resolve ScaniiClient, VERSION === "1.0.0"
  • Smoke test: end-to-end process() against a running scanii-cli — clean file returns findings: [], contentLength accurate
  • Reviewer: confirm GitHub npm environment is wired so the OIDC publish step can resolve at v1.0.0 tag time
  • Reviewer: spot-check that @scanii/core@0.0.1 placeholder will be cleanly superseded by v1.0.0 publish

🤖 Generated with Claude Code

Replaces the unpublishable scanii-js monorepo skeleton with a clean,
single-package zero-dependency TypeScript SDK published as @scanii/core
on npm.
API mirrors scanii-java v8.0.0 translated to async/Promise-returning TS:
process / processAsync / fetch / retrieve / ping / createAuthToken /
retrieveAuthToken / deleteAuthToken. Error hierarchy: ScaniiError,
ScaniiAuthError, ScaniiRateLimitError (with retryAfter).
Native fetch + FormData + Blob — no polyfills, no runtime deps. ESM +
CJS dual build via tsup with shipped .d.ts. Targets Node 22+ and modern
browsers.
Tests: jest unit suite mocking global.fetch + integration suite against
scanii-cli (started via scanii/setup-cli-action@v1 in CI). Malware
fixture is the UUID 38DCC0C9-... per workspace CLAUDE.md §5, generated
inline (not committed).
CI: pr.yml on Node 22+24 across ubuntu/macos/windows. release.yml
publishes to npm via OIDC trusted publishing on release: published —
does not create the GitHub Release.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Comment threadCHANGELOG.md Outdated

## 1.0.0 — Initial release

First public release of the Scanii Node SDK as `@scanii/core`. Replaces the unpublished `scanii-js` skeleton; supersedes the `@scanii/core@0.0.1` placeholder published to claim the name on npm.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove mention of scanii-js

Comment threadCHANGELOG.md Outdated

First public release of the Scanii Node SDK as `@scanii/core`. Replaces the unpublished `scanii-js` skeleton; supersedes the `@scanii/core@0.0.1` placeholder published to claim the name on npm.

**Reference frozen at `scanii-java` v8.0.0.** Method names, response shape, and error hierarchy mirror the Java reference, translated to idiomatic TypeScript.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove reference to the Java SDK

Comment threadCHANGELOG.md Outdated
- **scanii-cli** integration tests cover the cross-OS matrix (Linux / macOS / Windows on Node 22 + 24) without burning real Scanii credits.
- **OIDC trusted publishing** with provenance attestation.

### Migration

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove migration for first release

Per PR review: scanii-js and the @scanii/core@0.0.1 placeholder are
internal context, not consumer-facing release notes. Java reference is
implementation detail. No migration path applies for a first release.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@rferreira
rferreira merged commit f7443ba into mainApr 28, 2026
6 checks passed
@rferreira
rferreira deleted the feat/v1.0.0-rewrite branch April 28, 2026 10:45
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rferreira
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

v1.0.0: full rewrite as @scanii/core - #1

Merged
rferreira merged 2 commits into
mainfrom
feat/v1.0.0-rewrite
Apr 28, 2026
Merged

v1.0.0: full rewrite as @scanii/core#1
rferreira merged 2 commits into
mainfrom
feat/v1.0.0-rewrite

Conversation

@rferreira

Copy link
Copy Markdown
Contributor

Summary

Full rewrite of the scanii-js skeleton (unpublishable monorepo with empty stubs) as a clean, single-package zero-dependency TypeScript SDK. Publishes as @scanii/core on npm at 1.0.0, replacing the placeholder 0.0.1 stub.

  • API surface mirrors scanii-java v8.0.0 translated to async/Promise TS — process, processAsync, fetch, retrieve, ping, createAuthToken, retrieveAuthToken, deleteAuthToken.
  • Errors:ScaniiError base, ScaniiAuthError (401/403), ScaniiRateLimitError (429, with retryAfter parsed from Retry-After).
  • Zero runtime deps. Native fetch + FormData + Blob + URLSearchParams. No axios, no node-fetch, no form-data, no undici.
  • Dual build: ESM + CJS + shipped .d.ts via tsup. Built artifacts: dist/index.cjs, dist/index.mjs, dist/index.d.ts, dist/index.d.mts.
  • Targets: Node 22+ and modern browsers (ES2022 + DOM).
  • API v2.2 throughout (skeleton was on v2.1).
  • Tests: Jest. Unit suite mocks global.fetch directly (no nock/undici). Integration suite hits scanii-cli at localhost:4000; uses the UUID 38DCC0C9-… inline fixture per workspace CLAUDE.md §5 (not EICAR — that gets quarantined on Windows / macOS runners).
  • CI:pr.yml on Node 22 + 24 across ubuntu / macos / windows, scanii-cli started via scanii/setup-cli-action@v1. release.yml triggered by release: published, publishes via OIDC trusted publishing on the npm GitHub environment, with --provenance.

Naming reminder

Package name on npm is @scanii/core — scoped, NOT unscoped scanii. The unscoped scanii name remains a deprecated 0.0.1 placeholder for squat-protection only and is not touched by this change. README has a one-line note pointing consumers from scanii to @scanii/core.

@scanii/react and @scanii/web are deferred — not touched here.

Out of scope (per packet)

  • Browser polyfills (Node 22+ and ES2022 browsers have everything natively).
  • React hooks / web components / monorepo / workspaces.
  • Retry logic, backoff, batch helpers, concurrency primitives — Principle 3.
  • Tag-pushing or release creation — Rafael's responsibility.

Test plan

  • npm ci clean install
  • npm run typecheck passes (strict TS, verbatimModuleSyntax, noUncheckedIndexedAccess)
  • npm run lint passes (eslint flat config, typescript-eslint recommended)
  • npm test — 32 tests pass (unit suite green; integration suite green against locally running scanii-cli, with documented self-skips for older cli builds missing the UUID signature / token-auth / callback delivery)
  • npm run build — emits dist/index.cjs (13 KB), dist/index.mjs (12 KB), index.d.ts (9 KB)
  • Smoke test: require('./dist/index.cjs') and dynamic-import('./dist/index.mjs') both resolve ScaniiClient, VERSION === "1.0.0"
  • Smoke test: end-to-end process() against a running scanii-cli — clean file returns findings: [], contentLength accurate
  • Reviewer: confirm GitHub npm environment is wired so the OIDC publish step can resolve at v1.0.0 tag time
  • Reviewer: spot-check that @scanii/core@0.0.1 placeholder will be cleanly superseded by v1.0.0 publish

🤖 Generated with Claude Code

Replaces the unpublishable scanii-js monorepo skeleton with a clean,
single-package zero-dependency TypeScript SDK published as @scanii/core
on npm.
API mirrors scanii-java v8.0.0 translated to async/Promise-returning TS:
process / processAsync / fetch / retrieve / ping / createAuthToken /
retrieveAuthToken / deleteAuthToken. Error hierarchy: ScaniiError,
ScaniiAuthError, ScaniiRateLimitError (with retryAfter).
Native fetch + FormData + Blob — no polyfills, no runtime deps. ESM +
CJS dual build via tsup with shipped .d.ts. Targets Node 22+ and modern
browsers.
Tests: jest unit suite mocking global.fetch + integration suite against
scanii-cli (started via scanii/setup-cli-action@v1 in CI). Malware
fixture is the UUID 38DCC0C9-... per workspace CLAUDE.md §5, generated
inline (not committed).
CI: pr.yml on Node 22+24 across ubuntu/macos/windows. release.yml
publishes to npm via OIDC trusted publishing on release: published —
does not create the GitHub Release.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Comment threadCHANGELOG.md Outdated

## 1.0.0 — Initial release

First public release of the Scanii Node SDK as `@scanii/core`. Replaces the unpublished `scanii-js` skeleton; supersedes the `@scanii/core@0.0.1` placeholder published to claim the name on npm.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove mention of scanii-js

Comment threadCHANGELOG.md Outdated

First public release of the Scanii Node SDK as `@scanii/core`. Replaces the unpublished `scanii-js` skeleton; supersedes the `@scanii/core@0.0.1` placeholder published to claim the name on npm.

**Reference frozen at `scanii-java` v8.0.0.** Method names, response shape, and error hierarchy mirror the Java reference, translated to idiomatic TypeScript.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove reference to the Java SDK

Comment threadCHANGELOG.md Outdated
- **scanii-cli** integration tests cover the cross-OS matrix (Linux / macOS / Windows on Node 22 + 24) without burning real Scanii credits.
- **OIDC trusted publishing** with provenance attestation.

### Migration

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove migration for first release

Per PR review: scanii-js and the @scanii/core@0.0.1 placeholder are
internal context, not consumer-facing release notes. Java reference is
implementation detail. No migration path applies for a first release.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@rferreira
rferreira merged commit f7443ba into mainApr 28, 2026
6 checks passed
@rferreira
rferreira deleted the feat/v1.0.0-rewrite branch April 28, 2026 10:45
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rferreira