Uh oh!
There was an error while loading. Please reload this page.
chore(deps): update dependency jscpd to v5 - #123
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
Contributor
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
renovateBotforce-pushed
the
renovate/jscpd-5.x
branch
2 times, most recently
from
July 19, 2026 18:28
c65cf38 to
c73a4c6ComparerenovateBotforce-pushed
the
renovate/jscpd-5.x
branch
3 times, most recently
from
August 2, 2026 20:37
0c222b8 to
5cdfadcComparerenovateBotforce-pushed
the
renovate/jscpd-5.x
branch
5 times, most recently
from
August 18, 2026 16:49
84823dd to
b131b2dComparerenovateBotforce-pushed
the
renovate/jscpd-5.x
branch
3 times, most recently
from
September 1, 2026 15:52
7dd1cbe to
4b52cbbComparerenovateBotforce-pushed
the
renovate/jscpd-5.x
branch
from
September 3, 2026 12:01
4b52cbb to
54b48e3Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^4.0.5→^5.0.0Release Notes
kucherenko/jscpd (jscpd)
v5.1.2Compare Source
v5.1.1Compare Source
Bug Fixes
jscpdon npm installed the 5.0.16 engine instead of 5.1.0 — thejscpdwrapper package published itsoptionalDependenciespinned to the5.0.16platform binaries, sonpm i jscpd@5.1.0resolved a native binary one release behind andjscpd --versionreportedcpd 5.0.16. Everything 5.1.0 fixed was therefore absent forjscpdusers, including the Windows--baseline-from-reffix. Thecpdpackage was pinned correctly and is unaffected, as are the platform packages themselves — only the wrapper's pins were stale.The cause was in
scripts/sync-version.mjs: the wrapper's version and its platform pins were updated together behind a singleversion !== npmVersionguard, so once anything setversionbefore the script ran, the guard read "already up to date" and left the pins untouched. The two are now updated independently, and the script ends by verifying that every npm version and platform pin matches the release version, exiting non-zero if any disagree — the release workflow runs this script, so a repeat of this mismatch now fails the release instead of publishing. This is the same defect that produced the 5.0.13 republish; the earlier fix covered thecpdpackage but not thejscpdwrapper.Other
rust-version = "1.87"on crates.io, a floor the crate could not build on: theoxcparser crates require 1.96.0, andignore,globsetandaskamarequire 1.88. The value had been set when the Rust workspace was created and never revisited, and no CI job built at the declared MSRV, so the drift went unnoticed. CI now derives the toolchain fromrust-versionand checks against exactly that version.Published Packages
cpd-core@0.1.10on crates.iocpd-finder@0.1.13on crates.iocpd-reporter@0.1.11on crates.iocpd-tokenizer@0.1.12on crates.iojscpd@5.1.1on crates.iocpd@5.1.1on npmjscpd@5.1.1on npmjscpd-darwin-arm64@5.1.1on npmjscpd-darwin-x64@5.1.1on npmjscpd-linux-x64-gnu@5.1.1on npmjscpd-linux-arm64-gnu@5.1.1on npmjscpd-linux-x64-musl@5.1.1on npmjscpd-windows-x64-msvc@5.1.1on npmjscpd-windows-arm64-msvc@5.1.1on npmv5.1.0Compare Source
New Features
Windows on ARM support — npm installs now select a native
aarch64-pc-windows-msvcbinary from thejscpd-windows-arm64-msvcplatform package on Windows ARM64.Clone baseline (
--baseline,--update-baseline,--fail-on-new-clones) — gate CI on new duplication only. A committed baseline file (e.g..jscpd-baseline.json) records content-hash fingerprints of accepted clones (the same hash the SARIF reporter emits aspartialFingerprints["jscpdCloneHash/v1"], with a multiplicity count per fingerprint); clones absent from it are reported as new, and--fail-on-new-clones[=N]exits 1 when more than N (default 0) new clones are found — independently of--threshold, so legacy duplication is tolerated while regressions fail the build.--update-baselinerewrites the file from the current run (creating it if missing) and prints added/removed fingerprint counts so baseline growth stays visible in CI logs and PR review. The baseline file is versioned, sorted one fingerprint per line for reviewable diffs and trivial merges, and configurable via thebaseline/failOnNewClonesconfig keys. New-clone info flows through the reporters:[NEW]markers and a "(N new)" found-count inconsole/console-full, per-cloneisNewplus thenewClones/newDuplicatedLinesstatistics injson, levelerrorinsarif, andjscpd_new_clones/jscpd_new_duplicated_linesgauges inopenmetrics. (#944)Ephemeral baseline from a git ref (
--baseline-from-ref) — stateless variant of the clone baseline for PR gates without a committed file:cpd --baseline-from-ref origin/main --fail-on-new-clones .checks the base ref's tree out into a temporary detached git worktree (removed afterwards; shells out togitlike blame does), scans it with the same detection configuration, and compares the current run against that in-memory fingerprint set — clones absent from the base ref are new. Costs a second scan of the corpus, where the committed--baselinefile needs only one. When the ref is missing (shallow CI checkout) it fails with a clear hint togit fetch origin mainor usefetch-depth: 0. Config keybaselineFromRef; conflicts with--baseline/--update-baseline. (#944)OpenMetrics reporter (
--reporters openmetrics) — writesjscpd-metrics.txtin the OpenMetrics text exposition format, ready to be declared as a GitLab CIartifacts:reports:metricsartifact so merge requests show duplication metric changes against the target branch. Exposes gauges for files/lines/tokens analyzed, clones found, duplicated lines/tokens with percentages (project total plus aformat-labeled sample per format), and detection duration in seconds. (#422)CodeClimate / GitLab Code Quality reporter (
--reporters codeclimate, aliasgitlab) — writesgl-code-quality-report.json(the filename GitLab's docs use) in the CodeClimate issue format, restricted to the subset GitLab defines as its Code Quality report format, ready to be declared as anartifacts:reports:codequalityartifact so duplicates appear as code quality issues in merge requests — unlike the SARIF reporter, which GitLab ingests as security vulnerability findings. Each clone yields an issue per fragment (each describing the other location, plus the CodeClimateother_locationsfield), with a deterministic fingerprint derived from the clone's content hash so GitLab can tell new issues from pre-existing ones across pipeline runs. Severity isminor, escalating tomajorfor clones absent from a configured baseline or when the run exceeds--threshold. (#958)Config discovery in
.config/(dot-config convention) — auto-discovery now also checks.config/jscpd.json(and.config/.jscpd.json) per the dot-config convention, between the root.jscpd.jsonand thepackage.jsonjscpdkey. A root.jscpd.jsonstill wins, so existing setups are unaffected; paths inside the config resolve against the working directory, as with other auto-discovered sources. (#979)Bug Fixes
--formatvalues warn instead of silently matching nothing — a typo like--format cs(instead ofcsharp) used to scan 0 files and exit 0, indistinguishable from a clean codebase in CI. The CLI now prints a stderr warning naming the unsupported value and pointing to--list; custom formats declared via--formats-extsstay accepted. (#964)channel-rust-1.97.tomlmanifest, which broke with a fixed-output hash mismatch when Rust 1.97.1 was published. The toolchain is now pinned to the exact patch version (immutable manifest), so the hash can no longer drift. (#976)--baseline-from-refno longer reports every clone as new — the format-suffix stripper treated the drive colon in Windows verbatim paths (\\?\C:\..., the formcanonicalizereturns) as a:formatsuffix and truncated the base scan's source ids to\\?\C, so every snippet read behind the fingerprint computation failed silently and the ephemeral baseline never matched. A colon followed by a path separator is now recognized as structural. Clone fingerprints are also line-ending agnostic now (CR stripped before hashing), so committed baselines survive CRLF/LF differences between platforms.Other
glama.jsonmaintainer manifest and aDockerfilethat runs the stdio MCP server (jscpd --mcp), used by Glama to build and score the server listingDependencies
oxccrates to 0.147 in/rustthiserrorto 2.0.20,globsetto 0.4.20,ignoreto 0.4.33,logto 0.4.34 in/rustThank You ❤️
.config/subfolder (#979)--formatbehavior (#964)Published Packages
cpd-core@0.1.10on crates.iocpd-finder@0.1.12on crates.iocpd-reporter@0.1.10on crates.iocpd-tokenizer@0.1.11on crates.iojscpd@5.1.0on crates.iocpd@5.1.0on npmjscpd@5.1.0on npmjscpd-darwin-arm64@5.1.0on npmjscpd-darwin-x64@5.1.0on npmjscpd-linux-x64-gnu@5.1.0on npmjscpd-linux-arm64-gnu@5.1.0on npmjscpd-linux-x64-musl@5.1.0on npmjscpd-windows-x64-msvc@5.1.0on npmjscpd-windows-arm64-msvc@5.1.0on npmv5.0.16Compare Source
New Features
--mcp) —cpd --mcp /path/to/projectserves the Model Context Protocol on stdin/stdout; the project is scanned once at startup and kept in memory, socheck_duplicationsnippet checks answer in milliseconds. Tools:check_duplication,get_file_clones,get_statistics,check_current_directory. (#891)--summary) — opt-in refactoring-hotspot overview: top files and folders ranked by tokens, lines, size, or complexity, with each file's duplication share;--summary-topand--summary-bytune it. (#934)--skip-isolated) — skip duplication between monorepo folders owned by different teams (--skip-isolated "packages/a|packages/b"); clones inside one folder or against shared code are still reported. Config file:"skipIsolated": [["packages/a", "packages/b"]]. (#628, #942)Security
SECURITY.mdwith private vulnerability reporting, protectedmasterbranchBug Fixes
Thank You ❤️
skipIsolatedimplementation (#628), which this release ports to the Rust enginev5.0.15Compare Source
New Features
--sarif-error-tokens <N>flag (alsosarifErrorTokensin.jscpd.json): clones with at least N tokens are reported at levelerrorwhile smaller ones staywarning. When overall duplication exceeds--threshold, all SARIF results are emitted aserror. (#908)token_count, aclone_hash, and apartialFingerprintsentry (jscpdCloneHash/v1) for cross-run result identity in consumers like GitHub code scanning. (#909)jscpd/duplicate-coderule. (#914)Bug Fixes
tool.driver.versionand the HTML report version now match--version. (#915)Thank You ❤️
v5.0.14Compare Source
New Features
--cross-formats— detect clones across related formats via format equivalence groups sharing one comparison pool, e.g.--cross-formats "javascript,typescript"or thejs-tspreset. When a group mixes TypeScript with JavaScript, TS files are compared with erasable type syntax stripped. Also configurable ascrossFormatsin.jscpd.json/package.json. (#810)Bug Fixes
.mdfiles without code fences previously produced zero tokens and were silently skipped; prose is now tokenized, while embedded code fences keep their own sub-format pools. (#883)v5.0.12Compare Source
Dependencies
askama0.16.0,log0.4.33,env_logger0.11.11,rustc-hash2.1.3)v5.0.11Compare Source
New Features
Dependencies
cpd-corebumped to 0.1.6,cpd-tokenizerbumped to 0.1.7v5.0.10Compare Source
Bug Fixes
absolute: false. Fixes #827--skip-localto match jscpd v4 TypeScript semanticsRefactoring
cpd-reporter/src/shared.rsgitoxidetogit blame --porcelainv5.0.9Compare Source
New Features
jscpd-copy-paste-detectoraction for GitHub Actions Marketplace. Scan your repo for copy/paste in CI withuses: kucherenko/jscpd/.github/workflows/action.yml@v5Bug Fixes
cpdis installed as a nested dependency (e.g. in a project'snode_modulesvia a parent package). The runner now correctly locates the platform-specific binary relative to the installed package rather than assuming a top-level install. Fixes #816v5.0.8Compare Source
Bug Fixes
vm.max_map_count(default 131 072 on Linux). The walker previously held a liveMmapper discovered file; each rayon worker now opens and drops its mapping within the processing closure, capping concurrent mappings to the thread-pool size (typically 8–32). Fixes #813--patternnot matching relative paths when the scan root is absolute (e.g. CWD). Patterns likesrc/**/*.tsnow match correctly by comparing against both the relative path and the full absolute path, and bare patterns like*.tsgain a**/prefix to match at any depth. Fixes #811\nnow count the final line correctlyv5.0.7Compare Source
Bug Fixes
test/bundlerwith 320K+ nested for-loops). OXC's recursive-descent parser allocates one stack frame per AST nesting level; pathological inputs now exceed the default 8 MiB thread stack. Fixed by building a local rayonThreadPoolwith 64 MiB stacks instead of using the global pool (which silently fails on re-init)--max-sizeto1mb— files exceeding the limit are skipped at walk time, consistent with jscpd v4'smaxSizebehavior. This prevents OXC from ever seeing megabyte-scale generated files that would overflow the stack--workers Nnow correctly takes effect on everyrun()call (previouslybuild_global()silently no-op'd after the first invocation)v5.0.6Compare Source
New Features
.jscpd.jsonfieldspath,pattern,ignore, andignorePatternare now read and applied, matching jscpd v4 behaviorignoreandignorePatternare now distinct:ignorematches file-level globs,ignorePatternmatches code-level regex patterns (previously conflated).jscpd.jsonpath config support — reads scan directories from thepathfield, resolving relative paths against the config file's directoryjscpdnpm wrapper package — publishes the same Rust binary under thejscpdname on npm with v5.x versioning--exit-codenow matches v4 behavior: accepts optional integer value (--exit-codeexits 1,--exit-code 2exits 2);--thresholdand--exit-codeare now independentmemmap2) eliminates heap copies of file contents; SIMD-accelerated line counting (viamemchr); parallel detection pipeline usesflat_mapto avoid intermediate allocations; JS tokenizer no longer clones source strings before parsing (thanks to @auterium, #808)Bug Fixes
--exit-codeto match jscpd v4's--exitCodebehavior (was boolean, now optional integer)v5.0.5Compare Source
v5.0.4Compare Source
New Features
--absolute,--ignore-case,--formats-exts,--formats-namesflags; fixed--threshold, improved--max-sizeBug Fixes
jscpd-report.htmlat theoutput_dirrootas_nanos()instead ofsubsec_nanos())Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.