chore(deps): update dependency jscpd to v4.3.0 - #229

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jscpd-4.x-lockfile
Open

chore(deps): update dependency jscpd to v4.3.0#229
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jscpd-4.x-lockfile

Conversation

@renovate

@renovaterenovateBot commented May 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
jscpd (source)4.0.94.3.0ageconfidence

Release Notes

kucherenko/jscpd (jscpd)

v4.3.0

Compare Source

New Features
  • Color auto-detection — ANSI colors are disabled automatically when stdout is not a TTY (piped or redirected output), with new --colors / --no-colors flags and a colors config key to override. Precedence: explicit flag/config → FORCE_COLORNO_COLOR → TTY detection. The statistics table is covered too. (#​893, #​899)
  • jscpd-server: MCP protocol revision 2026-07-28 — migrated to the official MCP SDK v2 with the stateless 2026-07-28 revision and a legacy fallback for 2025-era clients, DNS-rebinding protection (Origin/Host allowlists with --allowed-origin/--allowed-host) on both /mcp and the REST API, a loopback default bind (127.0.0.1), and a hardened start/stop lifecycle. (#​902)
Bug Fixes
  • consoleFull no longer prints clones twice — the progress announcer is skipped for reporters that print every clone themselves (ai, consoleFull); jscpd-server shares the same wiring. (#​900)
  • Inclusive source line counts — fixes off-by-one line counts in statistics and reports. (#​881)
  • jscpd-server log colors — server output now respects NO_COLOR/FORCE_COLOR and TTY detection like the CLI.
Security
  • Resolved all 27 open Dependabot alerts on transitive dependencies (fast-uri, hono, js-yaml, brace-expansion, nanoid, postcss, ip-address, body-parser and others) by restoring the pnpm override mechanism — overrides now live in pnpm-workspace.yaml, where pnpm 10 actually reads them. CI installs use --frozen-lockfile so lockfile drift fails loudly.
Thank You ❤️

This release was shaped by community contributions — huge thanks to:


v4.2.5

Compare Source

Bug Fixes
  • JSON reporter duplicate token countstokens was always reported as 0 in JSON output; now computed from token positions (end.position - start.position) (#​801).
  • Gitignore parent-directory walk.gitignore files in parent directories up to the repo root are now read and combined with scan-directory .gitignore files. Also reads .git/info/exclude and the global core.excludesFile for full parity with Git's ignore resolution (#​741).
  • Commander v15 migration — CLI option parsing migrated from direct property access (cli.minTokens, etc.) to the cli.opts() API required by Commander v8+. The --no-gitignore / --gitignore flag handling was rewritten to use Commander's native negation support instead of rawArgs inspection.
  • Vitest 4.1.0 — bumped from 3.2.4 to address CVE-2026-47429.
  • Commander v15 — bumped from v5 to v15, enabling modern Node.js compatibility.
  • Pug 3.0.4, node-sarif-builder 4.1.0, nodemon 3.1.14 — dependency bumps for security and compatibility.

v4.2.4

Compare Source

v4.2.3

Compare Source

v4.2.2

Compare Source

v4.2.1

Compare Source

v4.2.0

Compare Source

Breaking Changes
  • Vue SFC tokenization.vue files are no longer tokenized as markup. Each block is now dispatched to its own sub-format: <script>javascript, <script lang="ts">typescript, <template>markup, <style>css, <style lang="scss">scss, <style lang="less">less. Clone reports for .vue files now appear under these resolved sub-format names. Any tooling or configuration that relied on .vue clones being reported under markup must be updated.
  • --formatsExts users — custom mappings that pointed .vue to markup (e.g. "formatsExts": { "markup": ["vue"] }) will no longer take effect because .vue is handled by the dedicated vue format processor. Remove or update such mappings.
New Features
  • Custom tokenizer backend — replaced the prismjs npm package with a self-contained reprism-based grammar engine. ~11.5% faster tokenization on real projects (avg 1126 ms → 997 ms on a 548-file, 223-format scan).
  • Cross-format detection — Vue SFC (.vue), Svelte (.svelte), Astro (.astro), and Markdown files are now tokenized per-block/per-section. A <script> block in a .vue file can match a .ts file; a fenced code block in Markdown can match a .py file.
  • 223 supported formats — Apex, CFML/ColdFusion, GDScript, Svelte, Astro, and 70+ additional languages added (up from 152). See FORMATS.md.
  • Shebang detection — extensionless executable scripts (e.g. /usr/bin/env python3) are auto-detected by their #! shebang line and tokenized in the correct language.
  • --store-path — configure a custom directory for the LevelDB cache, eliminating collisions when multiple jscpd processes run in parallel on the same machine.
  • --skipComments — shorthand flag for --mode weak, which strips comments before detection.
  • --formats-names — map specific filenames (e.g. Makefile, Dockerfile) to a detection format.
Bug Fixes
  • Entire-file duplicates silently dropped (@jscpd/core#​728) — RabinKarp flushed the pending clone on a store hit at end-of-file instead of on a miss. Files that are complete copies of each other were undetected. Fixed.
  • ReDoS hang on Lisp/Elisp files (@jscpd/tokenizer#​737) — the Lisp string regex /"(?:[^"\\]*|\\.)*"/ could catastrophically backtrack (O(2ⁿ)) on unterminated strings. Replaced with a linear /"(?:[^"\\]|\\[\s\S])*"/ pattern.
  • Process crash on malformed package.json (#​739) — readJSONSync threw an unhandled SyntaxError when package.json contained invalid JSON, killing the process. Now emits a warning and continues with an empty config.
  • Vue SFC cross-file detection broken — the detector used the file-level format (vue) as the store namespace for all SFC blocks, preventing a <script> block in one .vue file from ever matching a <script> block in another. The namespace now reflects each block's resolved sub-format.
  • Vue SFC incorrect column numbers — tokens on the first line of a block carried block-relative column 1 instead of file-absolute column numbers. Fixed in @jscpd/tokenizer.
  • 50 dependency security vulnerabilities remediated across the monorepo (Dependabot batches).
Known Limitations
  • Malformed SFC blocks (e.g. unclosed tags, invalid attributes) are silently skipped and do not contribute tokens.

v4.1.1

Compare Source

v4.1.0

Compare Source

New Features
  • AI Reporter — new ai reporter that produces compact, token-efficient clone output specifically designed for feeding results into language models and AI tooling. Use --reporters ai to activate it.
  • MCP Server enhancements — the Model Context Protocol server now exposes a jscpd://statistics resource and supports a recheck endpoint so AI agents can trigger a rescan without restarting the process.
  • Apex & CFML language support — jscpd can now detect duplicate code in Salesforce Apex and ColdFusion Markup Language (CFML) files (closes #​83, #​619).
  • GDScript support — detect copy-paste duplication in Godot Engine GDScript files.
  • HTML reporter footer — the HTML report now displays a branded footer with the jscpd version and a sponsor link.
  • --noTips flag — suppress the usage-tip messages that appear after a detection run.
  • CI: Node.js 22.x / 24.x — continuous integration updated to test against the latest Node.js LTS and current releases.
Performance
  • Tokenizer — grammars are now loaded lazily, hot paths are O(n), and the spark-md5 dependency has been removed in favour of a lighter built-in implementation. Startup time and memory usage are noticeably reduced on large codebases.
  • Replaced the vendored reprism syntax library with the official prismjs npm package, shrinking the installed footprint.
Bug Fixes
  • Restored the correct start.line expectation for weak-mode clone detection.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@w3nl

w3nl commented May 10, 2026

Copy link
Copy Markdown
Contributor

Snyk checks have passed. No issues have been found so far.

StatusScan Engine Critical High Medium LowTotal (0)
Open Source Security0000 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@codacy-production

codacy-productionBot commented May 10, 2026

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics0 complexity · 0 duplication

MetricResults
Complexity0
Duplication0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0886e4a to 612af4cCompareMay 12, 2026 08:40
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.1.0chore(deps): update dependency jscpd to v4.1.1May 12, 2026
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.1.1chore(deps): update dependency jscpd to v4.2.0May 14, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch 2 times, most recently from 12e0d4f to 0b3832dCompareMay 15, 2026 17:43
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.0chore(deps): update dependency jscpd to v4.2.1May 15, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0b3832d to 90f5afbCompareMay 15, 2026 21:00
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.1chore(deps): update dependency jscpd to v4.2.2May 15, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 90f5afb to 398abebCompareMay 17, 2026 12:56
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.2chore(deps): update dependency jscpd to v4.2.3May 17, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 398abeb to e743d77CompareMay 25, 2026 18:45
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.3chore(deps): update dependency jscpd to v4.2.4May 25, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from e743d77 to ece9b15CompareJune 7, 2026 17:50
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.4chore(deps): update dependency jscpd to v4.2.5Jun 7, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from ece9b15 to 0c388fbCompareAugust 11, 2026 22:33
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0c388fb to 92c33f1CompareAugust 13, 2026 17:56
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.5chore(deps): update dependency jscpd to v4.3.0Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@w3nl
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore(deps): update dependency jscpd to v4.3.0 - #229

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jscpd-4.x-lockfile
Open

chore(deps): update dependency jscpd to v4.3.0#229
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jscpd-4.x-lockfile

Conversation

@renovate

@renovaterenovateBot commented May 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
jscpd (source)4.0.94.3.0ageconfidence

Release Notes

kucherenko/jscpd (jscpd)

v4.3.0

Compare Source

New Features
  • Color auto-detection — ANSI colors are disabled automatically when stdout is not a TTY (piped or redirected output), with new --colors / --no-colors flags and a colors config key to override. Precedence: explicit flag/config → FORCE_COLORNO_COLOR → TTY detection. The statistics table is covered too. (#​893, #​899)
  • jscpd-server: MCP protocol revision 2026-07-28 — migrated to the official MCP SDK v2 with the stateless 2026-07-28 revision and a legacy fallback for 2025-era clients, DNS-rebinding protection (Origin/Host allowlists with --allowed-origin/--allowed-host) on both /mcp and the REST API, a loopback default bind (127.0.0.1), and a hardened start/stop lifecycle. (#​902)
Bug Fixes
  • consoleFull no longer prints clones twice — the progress announcer is skipped for reporters that print every clone themselves (ai, consoleFull); jscpd-server shares the same wiring. (#​900)
  • Inclusive source line counts — fixes off-by-one line counts in statistics and reports. (#​881)
  • jscpd-server log colors — server output now respects NO_COLOR/FORCE_COLOR and TTY detection like the CLI.
Security
  • Resolved all 27 open Dependabot alerts on transitive dependencies (fast-uri, hono, js-yaml, brace-expansion, nanoid, postcss, ip-address, body-parser and others) by restoring the pnpm override mechanism — overrides now live in pnpm-workspace.yaml, where pnpm 10 actually reads them. CI installs use --frozen-lockfile so lockfile drift fails loudly.
Thank You ❤️

This release was shaped by community contributions — huge thanks to:


v4.2.5

Compare Source

Bug Fixes
  • JSON reporter duplicate token countstokens was always reported as 0 in JSON output; now computed from token positions (end.position - start.position) (#​801).
  • Gitignore parent-directory walk.gitignore files in parent directories up to the repo root are now read and combined with scan-directory .gitignore files. Also reads .git/info/exclude and the global core.excludesFile for full parity with Git's ignore resolution (#​741).
  • Commander v15 migration — CLI option parsing migrated from direct property access (cli.minTokens, etc.) to the cli.opts() API required by Commander v8+. The --no-gitignore / --gitignore flag handling was rewritten to use Commander's native negation support instead of rawArgs inspection.
  • Vitest 4.1.0 — bumped from 3.2.4 to address CVE-2026-47429.
  • Commander v15 — bumped from v5 to v15, enabling modern Node.js compatibility.
  • Pug 3.0.4, node-sarif-builder 4.1.0, nodemon 3.1.14 — dependency bumps for security and compatibility.

v4.2.4

Compare Source

v4.2.3

Compare Source

v4.2.2

Compare Source

v4.2.1

Compare Source

v4.2.0

Compare Source

Breaking Changes
  • Vue SFC tokenization.vue files are no longer tokenized as markup. Each block is now dispatched to its own sub-format: <script>javascript, <script lang="ts">typescript, <template>markup, <style>css, <style lang="scss">scss, <style lang="less">less. Clone reports for .vue files now appear under these resolved sub-format names. Any tooling or configuration that relied on .vue clones being reported under markup must be updated.
  • --formatsExts users — custom mappings that pointed .vue to markup (e.g. "formatsExts": { "markup": ["vue"] }) will no longer take effect because .vue is handled by the dedicated vue format processor. Remove or update such mappings.
New Features
  • Custom tokenizer backend — replaced the prismjs npm package with a self-contained reprism-based grammar engine. ~11.5% faster tokenization on real projects (avg 1126 ms → 997 ms on a 548-file, 223-format scan).
  • Cross-format detection — Vue SFC (.vue), Svelte (.svelte), Astro (.astro), and Markdown files are now tokenized per-block/per-section. A <script> block in a .vue file can match a .ts file; a fenced code block in Markdown can match a .py file.
  • 223 supported formats — Apex, CFML/ColdFusion, GDScript, Svelte, Astro, and 70+ additional languages added (up from 152). See FORMATS.md.
  • Shebang detection — extensionless executable scripts (e.g. /usr/bin/env python3) are auto-detected by their #! shebang line and tokenized in the correct language.
  • --store-path — configure a custom directory for the LevelDB cache, eliminating collisions when multiple jscpd processes run in parallel on the same machine.
  • --skipComments — shorthand flag for --mode weak, which strips comments before detection.
  • --formats-names — map specific filenames (e.g. Makefile, Dockerfile) to a detection format.
Bug Fixes
  • Entire-file duplicates silently dropped (@jscpd/core#​728) — RabinKarp flushed the pending clone on a store hit at end-of-file instead of on a miss. Files that are complete copies of each other were undetected. Fixed.
  • ReDoS hang on Lisp/Elisp files (@jscpd/tokenizer#​737) — the Lisp string regex /"(?:[^"\\]*|\\.)*"/ could catastrophically backtrack (O(2ⁿ)) on unterminated strings. Replaced with a linear /"(?:[^"\\]|\\[\s\S])*"/ pattern.
  • Process crash on malformed package.json (#​739) — readJSONSync threw an unhandled SyntaxError when package.json contained invalid JSON, killing the process. Now emits a warning and continues with an empty config.
  • Vue SFC cross-file detection broken — the detector used the file-level format (vue) as the store namespace for all SFC blocks, preventing a <script> block in one .vue file from ever matching a <script> block in another. The namespace now reflects each block's resolved sub-format.
  • Vue SFC incorrect column numbers — tokens on the first line of a block carried block-relative column 1 instead of file-absolute column numbers. Fixed in @jscpd/tokenizer.
  • 50 dependency security vulnerabilities remediated across the monorepo (Dependabot batches).
Known Limitations
  • Malformed SFC blocks (e.g. unclosed tags, invalid attributes) are silently skipped and do not contribute tokens.

v4.1.1

Compare Source

v4.1.0

Compare Source

New Features
  • AI Reporter — new ai reporter that produces compact, token-efficient clone output specifically designed for feeding results into language models and AI tooling. Use --reporters ai to activate it.
  • MCP Server enhancements — the Model Context Protocol server now exposes a jscpd://statistics resource and supports a recheck endpoint so AI agents can trigger a rescan without restarting the process.
  • Apex & CFML language support — jscpd can now detect duplicate code in Salesforce Apex and ColdFusion Markup Language (CFML) files (closes #​83, #​619).
  • GDScript support — detect copy-paste duplication in Godot Engine GDScript files.
  • HTML reporter footer — the HTML report now displays a branded footer with the jscpd version and a sponsor link.
  • --noTips flag — suppress the usage-tip messages that appear after a detection run.
  • CI: Node.js 22.x / 24.x — continuous integration updated to test against the latest Node.js LTS and current releases.
Performance
  • Tokenizer — grammars are now loaded lazily, hot paths are O(n), and the spark-md5 dependency has been removed in favour of a lighter built-in implementation. Startup time and memory usage are noticeably reduced on large codebases.
  • Replaced the vendored reprism syntax library with the official prismjs npm package, shrinking the installed footprint.
Bug Fixes
  • Restored the correct start.line expectation for weak-mode clone detection.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@w3nl

w3nl commented May 10, 2026

Copy link
Copy Markdown
Contributor

Snyk checks have passed. No issues have been found so far.

StatusScan Engine Critical High Medium LowTotal (0)
Open Source Security0000 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@codacy-production

codacy-productionBot commented May 10, 2026

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics0 complexity · 0 duplication

MetricResults
Complexity0
Duplication0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0886e4a to 612af4cCompareMay 12, 2026 08:40
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.1.0chore(deps): update dependency jscpd to v4.1.1May 12, 2026
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.1.1chore(deps): update dependency jscpd to v4.2.0May 14, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch 2 times, most recently from 12e0d4f to 0b3832dCompareMay 15, 2026 17:43
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.0chore(deps): update dependency jscpd to v4.2.1May 15, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0b3832d to 90f5afbCompareMay 15, 2026 21:00
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.1chore(deps): update dependency jscpd to v4.2.2May 15, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 90f5afb to 398abebCompareMay 17, 2026 12:56
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.2chore(deps): update dependency jscpd to v4.2.3May 17, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 398abeb to e743d77CompareMay 25, 2026 18:45
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.3chore(deps): update dependency jscpd to v4.2.4May 25, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from e743d77 to ece9b15CompareJune 7, 2026 17:50
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.4chore(deps): update dependency jscpd to v4.2.5Jun 7, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from ece9b15 to 0c388fbCompareAugust 11, 2026 22:33
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0c388fb to 92c33f1CompareAugust 13, 2026 17:56
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.5chore(deps): update dependency jscpd to v4.3.0Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@w3nl
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): update dependency jscpd to v4.3.0 - #229

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jscpd-4.x-lockfile
Open

chore(deps): update dependency jscpd to v4.3.0#229
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jscpd-4.x-lockfile

Conversation

@renovate

@renovaterenovateBot commented May 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
jscpd (source)4.0.94.3.0ageconfidence

Release Notes

kucherenko/jscpd (jscpd)

v4.3.0

Compare Source

New Features
  • Color auto-detection — ANSI colors are disabled automatically when stdout is not a TTY (piped or redirected output), with new --colors / --no-colors flags and a colors config key to override. Precedence: explicit flag/config → FORCE_COLORNO_COLOR → TTY detection. The statistics table is covered too. (#​893, #​899)
  • jscpd-server: MCP protocol revision 2026-07-28 — migrated to the official MCP SDK v2 with the stateless 2026-07-28 revision and a legacy fallback for 2025-era clients, DNS-rebinding protection (Origin/Host allowlists with --allowed-origin/--allowed-host) on both /mcp and the REST API, a loopback default bind (127.0.0.1), and a hardened start/stop lifecycle. (#​902)
Bug Fixes
  • consoleFull no longer prints clones twice — the progress announcer is skipped for reporters that print every clone themselves (ai, consoleFull); jscpd-server shares the same wiring. (#​900)
  • Inclusive source line counts — fixes off-by-one line counts in statistics and reports. (#​881)
  • jscpd-server log colors — server output now respects NO_COLOR/FORCE_COLOR and TTY detection like the CLI.
Security
  • Resolved all 27 open Dependabot alerts on transitive dependencies (fast-uri, hono, js-yaml, brace-expansion, nanoid, postcss, ip-address, body-parser and others) by restoring the pnpm override mechanism — overrides now live in pnpm-workspace.yaml, where pnpm 10 actually reads them. CI installs use --frozen-lockfile so lockfile drift fails loudly.
Thank You ❤️

This release was shaped by community contributions — huge thanks to:


v4.2.5

Compare Source

Bug Fixes
  • JSON reporter duplicate token countstokens was always reported as 0 in JSON output; now computed from token positions (end.position - start.position) (#​801).
  • Gitignore parent-directory walk.gitignore files in parent directories up to the repo root are now read and combined with scan-directory .gitignore files. Also reads .git/info/exclude and the global core.excludesFile for full parity with Git's ignore resolution (#​741).
  • Commander v15 migration — CLI option parsing migrated from direct property access (cli.minTokens, etc.) to the cli.opts() API required by Commander v8+. The --no-gitignore / --gitignore flag handling was rewritten to use Commander's native negation support instead of rawArgs inspection.
  • Vitest 4.1.0 — bumped from 3.2.4 to address CVE-2026-47429.
  • Commander v15 — bumped from v5 to v15, enabling modern Node.js compatibility.
  • Pug 3.0.4, node-sarif-builder 4.1.0, nodemon 3.1.14 — dependency bumps for security and compatibility.

v4.2.4

Compare Source

v4.2.3

Compare Source

v4.2.2

Compare Source

v4.2.1

Compare Source

v4.2.0

Compare Source

Breaking Changes
  • Vue SFC tokenization.vue files are no longer tokenized as markup. Each block is now dispatched to its own sub-format: <script>javascript, <script lang="ts">typescript, <template>markup, <style>css, <style lang="scss">scss, <style lang="less">less. Clone reports for .vue files now appear under these resolved sub-format names. Any tooling or configuration that relied on .vue clones being reported under markup must be updated.
  • --formatsExts users — custom mappings that pointed .vue to markup (e.g. "formatsExts": { "markup": ["vue"] }) will no longer take effect because .vue is handled by the dedicated vue format processor. Remove or update such mappings.
New Features
  • Custom tokenizer backend — replaced the prismjs npm package with a self-contained reprism-based grammar engine. ~11.5% faster tokenization on real projects (avg 1126 ms → 997 ms on a 548-file, 223-format scan).
  • Cross-format detection — Vue SFC (.vue), Svelte (.svelte), Astro (.astro), and Markdown files are now tokenized per-block/per-section. A <script> block in a .vue file can match a .ts file; a fenced code block in Markdown can match a .py file.
  • 223 supported formats — Apex, CFML/ColdFusion, GDScript, Svelte, Astro, and 70+ additional languages added (up from 152). See FORMATS.md.
  • Shebang detection — extensionless executable scripts (e.g. /usr/bin/env python3) are auto-detected by their #! shebang line and tokenized in the correct language.
  • --store-path — configure a custom directory for the LevelDB cache, eliminating collisions when multiple jscpd processes run in parallel on the same machine.
  • --skipComments — shorthand flag for --mode weak, which strips comments before detection.
  • --formats-names — map specific filenames (e.g. Makefile, Dockerfile) to a detection format.
Bug Fixes
  • Entire-file duplicates silently dropped (@jscpd/core#​728) — RabinKarp flushed the pending clone on a store hit at end-of-file instead of on a miss. Files that are complete copies of each other were undetected. Fixed.
  • ReDoS hang on Lisp/Elisp files (@jscpd/tokenizer#​737) — the Lisp string regex /"(?:[^"\\]*|\\.)*"/ could catastrophically backtrack (O(2ⁿ)) on unterminated strings. Replaced with a linear /"(?:[^"\\]|\\[\s\S])*"/ pattern.
  • Process crash on malformed package.json (#​739) — readJSONSync threw an unhandled SyntaxError when package.json contained invalid JSON, killing the process. Now emits a warning and continues with an empty config.
  • Vue SFC cross-file detection broken — the detector used the file-level format (vue) as the store namespace for all SFC blocks, preventing a <script> block in one .vue file from ever matching a <script> block in another. The namespace now reflects each block's resolved sub-format.
  • Vue SFC incorrect column numbers — tokens on the first line of a block carried block-relative column 1 instead of file-absolute column numbers. Fixed in @jscpd/tokenizer.
  • 50 dependency security vulnerabilities remediated across the monorepo (Dependabot batches).
Known Limitations
  • Malformed SFC blocks (e.g. unclosed tags, invalid attributes) are silently skipped and do not contribute tokens.

v4.1.1

Compare Source

v4.1.0

Compare Source

New Features
  • AI Reporter — new ai reporter that produces compact, token-efficient clone output specifically designed for feeding results into language models and AI tooling. Use --reporters ai to activate it.
  • MCP Server enhancements — the Model Context Protocol server now exposes a jscpd://statistics resource and supports a recheck endpoint so AI agents can trigger a rescan without restarting the process.
  • Apex & CFML language support — jscpd can now detect duplicate code in Salesforce Apex and ColdFusion Markup Language (CFML) files (closes #​83, #​619).
  • GDScript support — detect copy-paste duplication in Godot Engine GDScript files.
  • HTML reporter footer — the HTML report now displays a branded footer with the jscpd version and a sponsor link.
  • --noTips flag — suppress the usage-tip messages that appear after a detection run.
  • CI: Node.js 22.x / 24.x — continuous integration updated to test against the latest Node.js LTS and current releases.
Performance
  • Tokenizer — grammars are now loaded lazily, hot paths are O(n), and the spark-md5 dependency has been removed in favour of a lighter built-in implementation. Startup time and memory usage are noticeably reduced on large codebases.
  • Replaced the vendored reprism syntax library with the official prismjs npm package, shrinking the installed footprint.
Bug Fixes
  • Restored the correct start.line expectation for weak-mode clone detection.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@w3nl

w3nl commented May 10, 2026

Copy link
Copy Markdown
Contributor

Snyk checks have passed. No issues have been found so far.

StatusScan Engine Critical High Medium LowTotal (0)
Open Source Security0000 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@codacy-production

codacy-productionBot commented May 10, 2026

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics0 complexity · 0 duplication

MetricResults
Complexity0
Duplication0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0886e4a to 612af4cCompareMay 12, 2026 08:40
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.1.0chore(deps): update dependency jscpd to v4.1.1May 12, 2026
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.1.1chore(deps): update dependency jscpd to v4.2.0May 14, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch 2 times, most recently from 12e0d4f to 0b3832dCompareMay 15, 2026 17:43
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.0chore(deps): update dependency jscpd to v4.2.1May 15, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0b3832d to 90f5afbCompareMay 15, 2026 21:00
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.1chore(deps): update dependency jscpd to v4.2.2May 15, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 90f5afb to 398abebCompareMay 17, 2026 12:56
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.2chore(deps): update dependency jscpd to v4.2.3May 17, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 398abeb to e743d77CompareMay 25, 2026 18:45
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.3chore(deps): update dependency jscpd to v4.2.4May 25, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from e743d77 to ece9b15CompareJune 7, 2026 17:50
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.4chore(deps): update dependency jscpd to v4.2.5Jun 7, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from ece9b15 to 0c388fbCompareAugust 11, 2026 22:33
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0c388fb to 92c33f1CompareAugust 13, 2026 17:56
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.5chore(deps): update dependency jscpd to v4.3.0Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@w3nl
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): update dependency jscpd to v4.3.0 - #229

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jscpd-4.x-lockfile
Open

chore(deps): update dependency jscpd to v4.3.0#229
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jscpd-4.x-lockfile

Conversation

@renovate

@renovaterenovateBot commented May 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
jscpd (source)4.0.94.3.0ageconfidence

Release Notes

kucherenko/jscpd (jscpd)

v4.3.0

Compare Source

New Features
  • Color auto-detection — ANSI colors are disabled automatically when stdout is not a TTY (piped or redirected output), with new --colors / --no-colors flags and a colors config key to override. Precedence: explicit flag/config → FORCE_COLORNO_COLOR → TTY detection. The statistics table is covered too. (#​893, #​899)
  • jscpd-server: MCP protocol revision 2026-07-28 — migrated to the official MCP SDK v2 with the stateless 2026-07-28 revision and a legacy fallback for 2025-era clients, DNS-rebinding protection (Origin/Host allowlists with --allowed-origin/--allowed-host) on both /mcp and the REST API, a loopback default bind (127.0.0.1), and a hardened start/stop lifecycle. (#​902)
Bug Fixes
  • consoleFull no longer prints clones twice — the progress announcer is skipped for reporters that print every clone themselves (ai, consoleFull); jscpd-server shares the same wiring. (#​900)
  • Inclusive source line counts — fixes off-by-one line counts in statistics and reports. (#​881)
  • jscpd-server log colors — server output now respects NO_COLOR/FORCE_COLOR and TTY detection like the CLI.
Security
  • Resolved all 27 open Dependabot alerts on transitive dependencies (fast-uri, hono, js-yaml, brace-expansion, nanoid, postcss, ip-address, body-parser and others) by restoring the pnpm override mechanism — overrides now live in pnpm-workspace.yaml, where pnpm 10 actually reads them. CI installs use --frozen-lockfile so lockfile drift fails loudly.
Thank You ❤️

This release was shaped by community contributions — huge thanks to:


v4.2.5

Compare Source

Bug Fixes
  • JSON reporter duplicate token countstokens was always reported as 0 in JSON output; now computed from token positions (end.position - start.position) (#​801).
  • Gitignore parent-directory walk.gitignore files in parent directories up to the repo root are now read and combined with scan-directory .gitignore files. Also reads .git/info/exclude and the global core.excludesFile for full parity with Git's ignore resolution (#​741).
  • Commander v15 migration — CLI option parsing migrated from direct property access (cli.minTokens, etc.) to the cli.opts() API required by Commander v8+. The --no-gitignore / --gitignore flag handling was rewritten to use Commander's native negation support instead of rawArgs inspection.
  • Vitest 4.1.0 — bumped from 3.2.4 to address CVE-2026-47429.
  • Commander v15 — bumped from v5 to v15, enabling modern Node.js compatibility.
  • Pug 3.0.4, node-sarif-builder 4.1.0, nodemon 3.1.14 — dependency bumps for security and compatibility.

v4.2.4

Compare Source

v4.2.3

Compare Source

v4.2.2

Compare Source

v4.2.1

Compare Source

v4.2.0

Compare Source

Breaking Changes
  • Vue SFC tokenization.vue files are no longer tokenized as markup. Each block is now dispatched to its own sub-format: <script>javascript, <script lang="ts">typescript, <template>markup, <style>css, <style lang="scss">scss, <style lang="less">less. Clone reports for .vue files now appear under these resolved sub-format names. Any tooling or configuration that relied on .vue clones being reported under markup must be updated.
  • --formatsExts users — custom mappings that pointed .vue to markup (e.g. "formatsExts": { "markup": ["vue"] }) will no longer take effect because .vue is handled by the dedicated vue format processor. Remove or update such mappings.
New Features
  • Custom tokenizer backend — replaced the prismjs npm package with a self-contained reprism-based grammar engine. ~11.5% faster tokenization on real projects (avg 1126 ms → 997 ms on a 548-file, 223-format scan).
  • Cross-format detection — Vue SFC (.vue), Svelte (.svelte), Astro (.astro), and Markdown files are now tokenized per-block/per-section. A <script> block in a .vue file can match a .ts file; a fenced code block in Markdown can match a .py file.
  • 223 supported formats — Apex, CFML/ColdFusion, GDScript, Svelte, Astro, and 70+ additional languages added (up from 152). See FORMATS.md.
  • Shebang detection — extensionless executable scripts (e.g. /usr/bin/env python3) are auto-detected by their #! shebang line and tokenized in the correct language.
  • --store-path — configure a custom directory for the LevelDB cache, eliminating collisions when multiple jscpd processes run in parallel on the same machine.
  • --skipComments — shorthand flag for --mode weak, which strips comments before detection.
  • --formats-names — map specific filenames (e.g. Makefile, Dockerfile) to a detection format.
Bug Fixes
  • Entire-file duplicates silently dropped (@jscpd/core#​728) — RabinKarp flushed the pending clone on a store hit at end-of-file instead of on a miss. Files that are complete copies of each other were undetected. Fixed.
  • ReDoS hang on Lisp/Elisp files (@jscpd/tokenizer#​737) — the Lisp string regex /"(?:[^"\\]*|\\.)*"/ could catastrophically backtrack (O(2ⁿ)) on unterminated strings. Replaced with a linear /"(?:[^"\\]|\\[\s\S])*"/ pattern.
  • Process crash on malformed package.json (#​739) — readJSONSync threw an unhandled SyntaxError when package.json contained invalid JSON, killing the process. Now emits a warning and continues with an empty config.
  • Vue SFC cross-file detection broken — the detector used the file-level format (vue) as the store namespace for all SFC blocks, preventing a <script> block in one .vue file from ever matching a <script> block in another. The namespace now reflects each block's resolved sub-format.
  • Vue SFC incorrect column numbers — tokens on the first line of a block carried block-relative column 1 instead of file-absolute column numbers. Fixed in @jscpd/tokenizer.
  • 50 dependency security vulnerabilities remediated across the monorepo (Dependabot batches).
Known Limitations
  • Malformed SFC blocks (e.g. unclosed tags, invalid attributes) are silently skipped and do not contribute tokens.

v4.1.1

Compare Source

v4.1.0

Compare Source

New Features
  • AI Reporter — new ai reporter that produces compact, token-efficient clone output specifically designed for feeding results into language models and AI tooling. Use --reporters ai to activate it.
  • MCP Server enhancements — the Model Context Protocol server now exposes a jscpd://statistics resource and supports a recheck endpoint so AI agents can trigger a rescan without restarting the process.
  • Apex & CFML language support — jscpd can now detect duplicate code in Salesforce Apex and ColdFusion Markup Language (CFML) files (closes #​83, #​619).
  • GDScript support — detect copy-paste duplication in Godot Engine GDScript files.
  • HTML reporter footer — the HTML report now displays a branded footer with the jscpd version and a sponsor link.
  • --noTips flag — suppress the usage-tip messages that appear after a detection run.
  • CI: Node.js 22.x / 24.x — continuous integration updated to test against the latest Node.js LTS and current releases.
Performance
  • Tokenizer — grammars are now loaded lazily, hot paths are O(n), and the spark-md5 dependency has been removed in favour of a lighter built-in implementation. Startup time and memory usage are noticeably reduced on large codebases.
  • Replaced the vendored reprism syntax library with the official prismjs npm package, shrinking the installed footprint.
Bug Fixes
  • Restored the correct start.line expectation for weak-mode clone detection.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@w3nl

w3nl commented May 10, 2026

Copy link
Copy Markdown
Contributor

Snyk checks have passed. No issues have been found so far.

StatusScan Engine Critical High Medium LowTotal (0)
Open Source Security0000 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@codacy-production

codacy-productionBot commented May 10, 2026

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics0 complexity · 0 duplication

MetricResults
Complexity0
Duplication0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0886e4a to 612af4cCompareMay 12, 2026 08:40
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.1.0chore(deps): update dependency jscpd to v4.1.1May 12, 2026
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.1.1chore(deps): update dependency jscpd to v4.2.0May 14, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch 2 times, most recently from 12e0d4f to 0b3832dCompareMay 15, 2026 17:43
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.0chore(deps): update dependency jscpd to v4.2.1May 15, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0b3832d to 90f5afbCompareMay 15, 2026 21:00
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.1chore(deps): update dependency jscpd to v4.2.2May 15, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 90f5afb to 398abebCompareMay 17, 2026 12:56
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.2chore(deps): update dependency jscpd to v4.2.3May 17, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 398abeb to e743d77CompareMay 25, 2026 18:45
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.3chore(deps): update dependency jscpd to v4.2.4May 25, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from e743d77 to ece9b15CompareJune 7, 2026 17:50
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.4chore(deps): update dependency jscpd to v4.2.5Jun 7, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from ece9b15 to 0c388fbCompareAugust 11, 2026 22:33
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0c388fb to 92c33f1CompareAugust 13, 2026 17:56
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.5chore(deps): update dependency jscpd to v4.3.0Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@w3nl
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore(deps): update dependency jscpd to v4.3.0 - #229

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jscpd-4.x-lockfile
Open

chore(deps): update dependency jscpd to v4.3.0#229
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jscpd-4.x-lockfile

Conversation

@renovate

@renovaterenovateBot commented May 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
jscpd (source)4.0.94.3.0ageconfidence

Release Notes

kucherenko/jscpd (jscpd)

v4.3.0

Compare Source

New Features
  • Color auto-detection — ANSI colors are disabled automatically when stdout is not a TTY (piped or redirected output), with new --colors / --no-colors flags and a colors config key to override. Precedence: explicit flag/config → FORCE_COLORNO_COLOR → TTY detection. The statistics table is covered too. (#​893, #​899)
  • jscpd-server: MCP protocol revision 2026-07-28 — migrated to the official MCP SDK v2 with the stateless 2026-07-28 revision and a legacy fallback for 2025-era clients, DNS-rebinding protection (Origin/Host allowlists with --allowed-origin/--allowed-host) on both /mcp and the REST API, a loopback default bind (127.0.0.1), and a hardened start/stop lifecycle. (#​902)
Bug Fixes
  • consoleFull no longer prints clones twice — the progress announcer is skipped for reporters that print every clone themselves (ai, consoleFull); jscpd-server shares the same wiring. (#​900)
  • Inclusive source line counts — fixes off-by-one line counts in statistics and reports. (#​881)
  • jscpd-server log colors — server output now respects NO_COLOR/FORCE_COLOR and TTY detection like the CLI.
Security
  • Resolved all 27 open Dependabot alerts on transitive dependencies (fast-uri, hono, js-yaml, brace-expansion, nanoid, postcss, ip-address, body-parser and others) by restoring the pnpm override mechanism — overrides now live in pnpm-workspace.yaml, where pnpm 10 actually reads them. CI installs use --frozen-lockfile so lockfile drift fails loudly.
Thank You ❤️

This release was shaped by community contributions — huge thanks to:


v4.2.5

Compare Source

Bug Fixes
  • JSON reporter duplicate token countstokens was always reported as 0 in JSON output; now computed from token positions (end.position - start.position) (#​801).
  • Gitignore parent-directory walk.gitignore files in parent directories up to the repo root are now read and combined with scan-directory .gitignore files. Also reads .git/info/exclude and the global core.excludesFile for full parity with Git's ignore resolution (#​741).
  • Commander v15 migration — CLI option parsing migrated from direct property access (cli.minTokens, etc.) to the cli.opts() API required by Commander v8+. The --no-gitignore / --gitignore flag handling was rewritten to use Commander's native negation support instead of rawArgs inspection.
  • Vitest 4.1.0 — bumped from 3.2.4 to address CVE-2026-47429.
  • Commander v15 — bumped from v5 to v15, enabling modern Node.js compatibility.
  • Pug 3.0.4, node-sarif-builder 4.1.0, nodemon 3.1.14 — dependency bumps for security and compatibility.

v4.2.4

Compare Source

v4.2.3

Compare Source

v4.2.2

Compare Source

v4.2.1

Compare Source

v4.2.0

Compare Source

Breaking Changes
  • Vue SFC tokenization.vue files are no longer tokenized as markup. Each block is now dispatched to its own sub-format: <script>javascript, <script lang="ts">typescript, <template>markup, <style>css, <style lang="scss">scss, <style lang="less">less. Clone reports for .vue files now appear under these resolved sub-format names. Any tooling or configuration that relied on .vue clones being reported under markup must be updated.
  • --formatsExts users — custom mappings that pointed .vue to markup (e.g. "formatsExts": { "markup": ["vue"] }) will no longer take effect because .vue is handled by the dedicated vue format processor. Remove or update such mappings.
New Features
  • Custom tokenizer backend — replaced the prismjs npm package with a self-contained reprism-based grammar engine. ~11.5% faster tokenization on real projects (avg 1126 ms → 997 ms on a 548-file, 223-format scan).
  • Cross-format detection — Vue SFC (.vue), Svelte (.svelte), Astro (.astro), and Markdown files are now tokenized per-block/per-section. A <script> block in a .vue file can match a .ts file; a fenced code block in Markdown can match a .py file.
  • 223 supported formats — Apex, CFML/ColdFusion, GDScript, Svelte, Astro, and 70+ additional languages added (up from 152). See FORMATS.md.
  • Shebang detection — extensionless executable scripts (e.g. /usr/bin/env python3) are auto-detected by their #! shebang line and tokenized in the correct language.
  • --store-path — configure a custom directory for the LevelDB cache, eliminating collisions when multiple jscpd processes run in parallel on the same machine.
  • --skipComments — shorthand flag for --mode weak, which strips comments before detection.
  • --formats-names — map specific filenames (e.g. Makefile, Dockerfile) to a detection format.
Bug Fixes
  • Entire-file duplicates silently dropped (@jscpd/core#​728) — RabinKarp flushed the pending clone on a store hit at end-of-file instead of on a miss. Files that are complete copies of each other were undetected. Fixed.
  • ReDoS hang on Lisp/Elisp files (@jscpd/tokenizer#​737) — the Lisp string regex /"(?:[^"\\]*|\\.)*"/ could catastrophically backtrack (O(2ⁿ)) on unterminated strings. Replaced with a linear /"(?:[^"\\]|\\[\s\S])*"/ pattern.
  • Process crash on malformed package.json (#​739) — readJSONSync threw an unhandled SyntaxError when package.json contained invalid JSON, killing the process. Now emits a warning and continues with an empty config.
  • Vue SFC cross-file detection broken — the detector used the file-level format (vue) as the store namespace for all SFC blocks, preventing a <script> block in one .vue file from ever matching a <script> block in another. The namespace now reflects each block's resolved sub-format.
  • Vue SFC incorrect column numbers — tokens on the first line of a block carried block-relative column 1 instead of file-absolute column numbers. Fixed in @jscpd/tokenizer.
  • 50 dependency security vulnerabilities remediated across the monorepo (Dependabot batches).
Known Limitations
  • Malformed SFC blocks (e.g. unclosed tags, invalid attributes) are silently skipped and do not contribute tokens.

v4.1.1

Compare Source

v4.1.0

Compare Source

New Features
  • AI Reporter — new ai reporter that produces compact, token-efficient clone output specifically designed for feeding results into language models and AI tooling. Use --reporters ai to activate it.
  • MCP Server enhancements — the Model Context Protocol server now exposes a jscpd://statistics resource and supports a recheck endpoint so AI agents can trigger a rescan without restarting the process.
  • Apex & CFML language support — jscpd can now detect duplicate code in Salesforce Apex and ColdFusion Markup Language (CFML) files (closes #​83, #​619).
  • GDScript support — detect copy-paste duplication in Godot Engine GDScript files.
  • HTML reporter footer — the HTML report now displays a branded footer with the jscpd version and a sponsor link.
  • --noTips flag — suppress the usage-tip messages that appear after a detection run.
  • CI: Node.js 22.x / 24.x — continuous integration updated to test against the latest Node.js LTS and current releases.
Performance
  • Tokenizer — grammars are now loaded lazily, hot paths are O(n), and the spark-md5 dependency has been removed in favour of a lighter built-in implementation. Startup time and memory usage are noticeably reduced on large codebases.
  • Replaced the vendored reprism syntax library with the official prismjs npm package, shrinking the installed footprint.
Bug Fixes
  • Restored the correct start.line expectation for weak-mode clone detection.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@w3nl

w3nl commented May 10, 2026

Copy link
Copy Markdown
Contributor

Snyk checks have passed. No issues have been found so far.

StatusScan Engine Critical High Medium LowTotal (0)
Open Source Security0000 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@codacy-production

codacy-productionBot commented May 10, 2026

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics0 complexity · 0 duplication

MetricResults
Complexity0
Duplication0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0886e4a to 612af4cCompareMay 12, 2026 08:40
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.1.0chore(deps): update dependency jscpd to v4.1.1May 12, 2026
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.1.1chore(deps): update dependency jscpd to v4.2.0May 14, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch 2 times, most recently from 12e0d4f to 0b3832dCompareMay 15, 2026 17:43
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.0chore(deps): update dependency jscpd to v4.2.1May 15, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0b3832d to 90f5afbCompareMay 15, 2026 21:00
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.1chore(deps): update dependency jscpd to v4.2.2May 15, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 90f5afb to 398abebCompareMay 17, 2026 12:56
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.2chore(deps): update dependency jscpd to v4.2.3May 17, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 398abeb to e743d77CompareMay 25, 2026 18:45
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.3chore(deps): update dependency jscpd to v4.2.4May 25, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from e743d77 to ece9b15CompareJune 7, 2026 17:50
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.4chore(deps): update dependency jscpd to v4.2.5Jun 7, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from ece9b15 to 0c388fbCompareAugust 11, 2026 22:33
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0c388fb to 92c33f1CompareAugust 13, 2026 17:56
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.5chore(deps): update dependency jscpd to v4.3.0Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@w3nl
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): update dependency jscpd to v4.3.0 - #229

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jscpd-4.x-lockfile
Open

chore(deps): update dependency jscpd to v4.3.0#229
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jscpd-4.x-lockfile

Conversation

@renovate

@renovaterenovateBot commented May 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
jscpd (source)4.0.94.3.0ageconfidence

Release Notes

kucherenko/jscpd (jscpd)

v4.3.0

Compare Source

New Features
  • Color auto-detection — ANSI colors are disabled automatically when stdout is not a TTY (piped or redirected output), with new --colors / --no-colors flags and a colors config key to override. Precedence: explicit flag/config → FORCE_COLORNO_COLOR → TTY detection. The statistics table is covered too. (#​893, #​899)
  • jscpd-server: MCP protocol revision 2026-07-28 — migrated to the official MCP SDK v2 with the stateless 2026-07-28 revision and a legacy fallback for 2025-era clients, DNS-rebinding protection (Origin/Host allowlists with --allowed-origin/--allowed-host) on both /mcp and the REST API, a loopback default bind (127.0.0.1), and a hardened start/stop lifecycle. (#​902)
Bug Fixes
  • consoleFull no longer prints clones twice — the progress announcer is skipped for reporters that print every clone themselves (ai, consoleFull); jscpd-server shares the same wiring. (#​900)
  • Inclusive source line counts — fixes off-by-one line counts in statistics and reports. (#​881)
  • jscpd-server log colors — server output now respects NO_COLOR/FORCE_COLOR and TTY detection like the CLI.
Security
  • Resolved all 27 open Dependabot alerts on transitive dependencies (fast-uri, hono, js-yaml, brace-expansion, nanoid, postcss, ip-address, body-parser and others) by restoring the pnpm override mechanism — overrides now live in pnpm-workspace.yaml, where pnpm 10 actually reads them. CI installs use --frozen-lockfile so lockfile drift fails loudly.
Thank You ❤️

This release was shaped by community contributions — huge thanks to:


v4.2.5

Compare Source

Bug Fixes
  • JSON reporter duplicate token countstokens was always reported as 0 in JSON output; now computed from token positions (end.position - start.position) (#​801).
  • Gitignore parent-directory walk.gitignore files in parent directories up to the repo root are now read and combined with scan-directory .gitignore files. Also reads .git/info/exclude and the global core.excludesFile for full parity with Git's ignore resolution (#​741).
  • Commander v15 migration — CLI option parsing migrated from direct property access (cli.minTokens, etc.) to the cli.opts() API required by Commander v8+. The --no-gitignore / --gitignore flag handling was rewritten to use Commander's native negation support instead of rawArgs inspection.
  • Vitest 4.1.0 — bumped from 3.2.4 to address CVE-2026-47429.
  • Commander v15 — bumped from v5 to v15, enabling modern Node.js compatibility.
  • Pug 3.0.4, node-sarif-builder 4.1.0, nodemon 3.1.14 — dependency bumps for security and compatibility.

v4.2.4

Compare Source

v4.2.3

Compare Source

v4.2.2

Compare Source

v4.2.1

Compare Source

v4.2.0

Compare Source

Breaking Changes
  • Vue SFC tokenization.vue files are no longer tokenized as markup. Each block is now dispatched to its own sub-format: <script>javascript, <script lang="ts">typescript, <template>markup, <style>css, <style lang="scss">scss, <style lang="less">less. Clone reports for .vue files now appear under these resolved sub-format names. Any tooling or configuration that relied on .vue clones being reported under markup must be updated.
  • --formatsExts users — custom mappings that pointed .vue to markup (e.g. "formatsExts": { "markup": ["vue"] }) will no longer take effect because .vue is handled by the dedicated vue format processor. Remove or update such mappings.
New Features
  • Custom tokenizer backend — replaced the prismjs npm package with a self-contained reprism-based grammar engine. ~11.5% faster tokenization on real projects (avg 1126 ms → 997 ms on a 548-file, 223-format scan).
  • Cross-format detection — Vue SFC (.vue), Svelte (.svelte), Astro (.astro), and Markdown files are now tokenized per-block/per-section. A <script> block in a .vue file can match a .ts file; a fenced code block in Markdown can match a .py file.
  • 223 supported formats — Apex, CFML/ColdFusion, GDScript, Svelte, Astro, and 70+ additional languages added (up from 152). See FORMATS.md.
  • Shebang detection — extensionless executable scripts (e.g. /usr/bin/env python3) are auto-detected by their #! shebang line and tokenized in the correct language.
  • --store-path — configure a custom directory for the LevelDB cache, eliminating collisions when multiple jscpd processes run in parallel on the same machine.
  • --skipComments — shorthand flag for --mode weak, which strips comments before detection.
  • --formats-names — map specific filenames (e.g. Makefile, Dockerfile) to a detection format.
Bug Fixes
  • Entire-file duplicates silently dropped (@jscpd/core#​728) — RabinKarp flushed the pending clone on a store hit at end-of-file instead of on a miss. Files that are complete copies of each other were undetected. Fixed.
  • ReDoS hang on Lisp/Elisp files (@jscpd/tokenizer#​737) — the Lisp string regex /"(?:[^"\\]*|\\.)*"/ could catastrophically backtrack (O(2ⁿ)) on unterminated strings. Replaced with a linear /"(?:[^"\\]|\\[\s\S])*"/ pattern.
  • Process crash on malformed package.json (#​739) — readJSONSync threw an unhandled SyntaxError when package.json contained invalid JSON, killing the process. Now emits a warning and continues with an empty config.
  • Vue SFC cross-file detection broken — the detector used the file-level format (vue) as the store namespace for all SFC blocks, preventing a <script> block in one .vue file from ever matching a <script> block in another. The namespace now reflects each block's resolved sub-format.
  • Vue SFC incorrect column numbers — tokens on the first line of a block carried block-relative column 1 instead of file-absolute column numbers. Fixed in @jscpd/tokenizer.
  • 50 dependency security vulnerabilities remediated across the monorepo (Dependabot batches).
Known Limitations
  • Malformed SFC blocks (e.g. unclosed tags, invalid attributes) are silently skipped and do not contribute tokens.

v4.1.1

Compare Source

v4.1.0

Compare Source

New Features
  • AI Reporter — new ai reporter that produces compact, token-efficient clone output specifically designed for feeding results into language models and AI tooling. Use --reporters ai to activate it.
  • MCP Server enhancements — the Model Context Protocol server now exposes a jscpd://statistics resource and supports a recheck endpoint so AI agents can trigger a rescan without restarting the process.
  • Apex & CFML language support — jscpd can now detect duplicate code in Salesforce Apex and ColdFusion Markup Language (CFML) files (closes #​83, #​619).
  • GDScript support — detect copy-paste duplication in Godot Engine GDScript files.
  • HTML reporter footer — the HTML report now displays a branded footer with the jscpd version and a sponsor link.
  • --noTips flag — suppress the usage-tip messages that appear after a detection run.
  • CI: Node.js 22.x / 24.x — continuous integration updated to test against the latest Node.js LTS and current releases.
Performance
  • Tokenizer — grammars are now loaded lazily, hot paths are O(n), and the spark-md5 dependency has been removed in favour of a lighter built-in implementation. Startup time and memory usage are noticeably reduced on large codebases.
  • Replaced the vendored reprism syntax library with the official prismjs npm package, shrinking the installed footprint.
Bug Fixes
  • Restored the correct start.line expectation for weak-mode clone detection.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@w3nl

w3nl commented May 10, 2026

Copy link
Copy Markdown
Contributor

Snyk checks have passed. No issues have been found so far.

StatusScan Engine Critical High Medium LowTotal (0)
Open Source Security0000 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@codacy-production

codacy-productionBot commented May 10, 2026

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics0 complexity · 0 duplication

MetricResults
Complexity0
Duplication0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0886e4a to 612af4cCompareMay 12, 2026 08:40
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.1.0chore(deps): update dependency jscpd to v4.1.1May 12, 2026
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.1.1chore(deps): update dependency jscpd to v4.2.0May 14, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch 2 times, most recently from 12e0d4f to 0b3832dCompareMay 15, 2026 17:43
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.0chore(deps): update dependency jscpd to v4.2.1May 15, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0b3832d to 90f5afbCompareMay 15, 2026 21:00
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.1chore(deps): update dependency jscpd to v4.2.2May 15, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 90f5afb to 398abebCompareMay 17, 2026 12:56
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.2chore(deps): update dependency jscpd to v4.2.3May 17, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 398abeb to e743d77CompareMay 25, 2026 18:45
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.3chore(deps): update dependency jscpd to v4.2.4May 25, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from e743d77 to ece9b15CompareJune 7, 2026 17:50
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.4chore(deps): update dependency jscpd to v4.2.5Jun 7, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from ece9b15 to 0c388fbCompareAugust 11, 2026 22:33
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0c388fb to 92c33f1CompareAugust 13, 2026 17:56
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.5chore(deps): update dependency jscpd to v4.3.0Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@w3nl
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): update dependency jscpd to v4.3.0 - #229

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jscpd-4.x-lockfile
Open

chore(deps): update dependency jscpd to v4.3.0#229
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jscpd-4.x-lockfile

Conversation

@renovate

@renovaterenovateBot commented May 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
jscpd (source)4.0.94.3.0ageconfidence

Release Notes

kucherenko/jscpd (jscpd)

v4.3.0

Compare Source

New Features
  • Color auto-detection — ANSI colors are disabled automatically when stdout is not a TTY (piped or redirected output), with new --colors / --no-colors flags and a colors config key to override. Precedence: explicit flag/config → FORCE_COLORNO_COLOR → TTY detection. The statistics table is covered too. (#​893, #​899)
  • jscpd-server: MCP protocol revision 2026-07-28 — migrated to the official MCP SDK v2 with the stateless 2026-07-28 revision and a legacy fallback for 2025-era clients, DNS-rebinding protection (Origin/Host allowlists with --allowed-origin/--allowed-host) on both /mcp and the REST API, a loopback default bind (127.0.0.1), and a hardened start/stop lifecycle. (#​902)
Bug Fixes
  • consoleFull no longer prints clones twice — the progress announcer is skipped for reporters that print every clone themselves (ai, consoleFull); jscpd-server shares the same wiring. (#​900)
  • Inclusive source line counts — fixes off-by-one line counts in statistics and reports. (#​881)
  • jscpd-server log colors — server output now respects NO_COLOR/FORCE_COLOR and TTY detection like the CLI.
Security
  • Resolved all 27 open Dependabot alerts on transitive dependencies (fast-uri, hono, js-yaml, brace-expansion, nanoid, postcss, ip-address, body-parser and others) by restoring the pnpm override mechanism — overrides now live in pnpm-workspace.yaml, where pnpm 10 actually reads them. CI installs use --frozen-lockfile so lockfile drift fails loudly.
Thank You ❤️

This release was shaped by community contributions — huge thanks to:


v4.2.5

Compare Source

Bug Fixes
  • JSON reporter duplicate token countstokens was always reported as 0 in JSON output; now computed from token positions (end.position - start.position) (#​801).
  • Gitignore parent-directory walk.gitignore files in parent directories up to the repo root are now read and combined with scan-directory .gitignore files. Also reads .git/info/exclude and the global core.excludesFile for full parity with Git's ignore resolution (#​741).
  • Commander v15 migration — CLI option parsing migrated from direct property access (cli.minTokens, etc.) to the cli.opts() API required by Commander v8+. The --no-gitignore / --gitignore flag handling was rewritten to use Commander's native negation support instead of rawArgs inspection.
  • Vitest 4.1.0 — bumped from 3.2.4 to address CVE-2026-47429.
  • Commander v15 — bumped from v5 to v15, enabling modern Node.js compatibility.
  • Pug 3.0.4, node-sarif-builder 4.1.0, nodemon 3.1.14 — dependency bumps for security and compatibility.

v4.2.4

Compare Source

v4.2.3

Compare Source

v4.2.2

Compare Source

v4.2.1

Compare Source

v4.2.0

Compare Source

Breaking Changes
  • Vue SFC tokenization.vue files are no longer tokenized as markup. Each block is now dispatched to its own sub-format: <script>javascript, <script lang="ts">typescript, <template>markup, <style>css, <style lang="scss">scss, <style lang="less">less. Clone reports for .vue files now appear under these resolved sub-format names. Any tooling or configuration that relied on .vue clones being reported under markup must be updated.
  • --formatsExts users — custom mappings that pointed .vue to markup (e.g. "formatsExts": { "markup": ["vue"] }) will no longer take effect because .vue is handled by the dedicated vue format processor. Remove or update such mappings.
New Features
  • Custom tokenizer backend — replaced the prismjs npm package with a self-contained reprism-based grammar engine. ~11.5% faster tokenization on real projects (avg 1126 ms → 997 ms on a 548-file, 223-format scan).
  • Cross-format detection — Vue SFC (.vue), Svelte (.svelte), Astro (.astro), and Markdown files are now tokenized per-block/per-section. A <script> block in a .vue file can match a .ts file; a fenced code block in Markdown can match a .py file.
  • 223 supported formats — Apex, CFML/ColdFusion, GDScript, Svelte, Astro, and 70+ additional languages added (up from 152). See FORMATS.md.
  • Shebang detection — extensionless executable scripts (e.g. /usr/bin/env python3) are auto-detected by their #! shebang line and tokenized in the correct language.
  • --store-path — configure a custom directory for the LevelDB cache, eliminating collisions when multiple jscpd processes run in parallel on the same machine.
  • --skipComments — shorthand flag for --mode weak, which strips comments before detection.
  • --formats-names — map specific filenames (e.g. Makefile, Dockerfile) to a detection format.
Bug Fixes
  • Entire-file duplicates silently dropped (@jscpd/core#​728) — RabinKarp flushed the pending clone on a store hit at end-of-file instead of on a miss. Files that are complete copies of each other were undetected. Fixed.
  • ReDoS hang on Lisp/Elisp files (@jscpd/tokenizer#​737) — the Lisp string regex /"(?:[^"\\]*|\\.)*"/ could catastrophically backtrack (O(2ⁿ)) on unterminated strings. Replaced with a linear /"(?:[^"\\]|\\[\s\S])*"/ pattern.
  • Process crash on malformed package.json (#​739) — readJSONSync threw an unhandled SyntaxError when package.json contained invalid JSON, killing the process. Now emits a warning and continues with an empty config.
  • Vue SFC cross-file detection broken — the detector used the file-level format (vue) as the store namespace for all SFC blocks, preventing a <script> block in one .vue file from ever matching a <script> block in another. The namespace now reflects each block's resolved sub-format.
  • Vue SFC incorrect column numbers — tokens on the first line of a block carried block-relative column 1 instead of file-absolute column numbers. Fixed in @jscpd/tokenizer.
  • 50 dependency security vulnerabilities remediated across the monorepo (Dependabot batches).
Known Limitations
  • Malformed SFC blocks (e.g. unclosed tags, invalid attributes) are silently skipped and do not contribute tokens.

v4.1.1

Compare Source

v4.1.0

Compare Source

New Features
  • AI Reporter — new ai reporter that produces compact, token-efficient clone output specifically designed for feeding results into language models and AI tooling. Use --reporters ai to activate it.
  • MCP Server enhancements — the Model Context Protocol server now exposes a jscpd://statistics resource and supports a recheck endpoint so AI agents can trigger a rescan without restarting the process.
  • Apex & CFML language support — jscpd can now detect duplicate code in Salesforce Apex and ColdFusion Markup Language (CFML) files (closes #​83, #​619).
  • GDScript support — detect copy-paste duplication in Godot Engine GDScript files.
  • HTML reporter footer — the HTML report now displays a branded footer with the jscpd version and a sponsor link.
  • --noTips flag — suppress the usage-tip messages that appear after a detection run.
  • CI: Node.js 22.x / 24.x — continuous integration updated to test against the latest Node.js LTS and current releases.
Performance
  • Tokenizer — grammars are now loaded lazily, hot paths are O(n), and the spark-md5 dependency has been removed in favour of a lighter built-in implementation. Startup time and memory usage are noticeably reduced on large codebases.
  • Replaced the vendored reprism syntax library with the official prismjs npm package, shrinking the installed footprint.
Bug Fixes
  • Restored the correct start.line expectation for weak-mode clone detection.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@w3nl

w3nl commented May 10, 2026

Copy link
Copy Markdown
Contributor

Snyk checks have passed. No issues have been found so far.

StatusScan Engine Critical High Medium LowTotal (0)
Open Source Security0000 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@codacy-production

codacy-productionBot commented May 10, 2026

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics0 complexity · 0 duplication

MetricResults
Complexity0
Duplication0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0886e4a to 612af4cCompareMay 12, 2026 08:40
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.1.0chore(deps): update dependency jscpd to v4.1.1May 12, 2026
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.1.1chore(deps): update dependency jscpd to v4.2.0May 14, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch 2 times, most recently from 12e0d4f to 0b3832dCompareMay 15, 2026 17:43
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.0chore(deps): update dependency jscpd to v4.2.1May 15, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0b3832d to 90f5afbCompareMay 15, 2026 21:00
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.1chore(deps): update dependency jscpd to v4.2.2May 15, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 90f5afb to 398abebCompareMay 17, 2026 12:56
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.2chore(deps): update dependency jscpd to v4.2.3May 17, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 398abeb to e743d77CompareMay 25, 2026 18:45
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.3chore(deps): update dependency jscpd to v4.2.4May 25, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from e743d77 to ece9b15CompareJune 7, 2026 17:50
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.4chore(deps): update dependency jscpd to v4.2.5Jun 7, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from ece9b15 to 0c388fbCompareAugust 11, 2026 22:33
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0c388fb to 92c33f1CompareAugust 13, 2026 17:56
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.5chore(deps): update dependency jscpd to v4.3.0Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@w3nl
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore(deps): update dependency jscpd to v4.3.0 - #229

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jscpd-4.x-lockfile
Open

chore(deps): update dependency jscpd to v4.3.0#229
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jscpd-4.x-lockfile

Conversation

@renovate

@renovaterenovateBot commented May 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
jscpd (source)4.0.94.3.0ageconfidence

Release Notes

kucherenko/jscpd (jscpd)

v4.3.0

Compare Source

New Features
  • Color auto-detection — ANSI colors are disabled automatically when stdout is not a TTY (piped or redirected output), with new --colors / --no-colors flags and a colors config key to override. Precedence: explicit flag/config → FORCE_COLORNO_COLOR → TTY detection. The statistics table is covered too. (#​893, #​899)
  • jscpd-server: MCP protocol revision 2026-07-28 — migrated to the official MCP SDK v2 with the stateless 2026-07-28 revision and a legacy fallback for 2025-era clients, DNS-rebinding protection (Origin/Host allowlists with --allowed-origin/--allowed-host) on both /mcp and the REST API, a loopback default bind (127.0.0.1), and a hardened start/stop lifecycle. (#​902)
Bug Fixes
  • consoleFull no longer prints clones twice — the progress announcer is skipped for reporters that print every clone themselves (ai, consoleFull); jscpd-server shares the same wiring. (#​900)
  • Inclusive source line counts — fixes off-by-one line counts in statistics and reports. (#​881)
  • jscpd-server log colors — server output now respects NO_COLOR/FORCE_COLOR and TTY detection like the CLI.
Security
  • Resolved all 27 open Dependabot alerts on transitive dependencies (fast-uri, hono, js-yaml, brace-expansion, nanoid, postcss, ip-address, body-parser and others) by restoring the pnpm override mechanism — overrides now live in pnpm-workspace.yaml, where pnpm 10 actually reads them. CI installs use --frozen-lockfile so lockfile drift fails loudly.
Thank You ❤️

This release was shaped by community contributions — huge thanks to:


v4.2.5

Compare Source

Bug Fixes
  • JSON reporter duplicate token countstokens was always reported as 0 in JSON output; now computed from token positions (end.position - start.position) (#​801).
  • Gitignore parent-directory walk.gitignore files in parent directories up to the repo root are now read and combined with scan-directory .gitignore files. Also reads .git/info/exclude and the global core.excludesFile for full parity with Git's ignore resolution (#​741).
  • Commander v15 migration — CLI option parsing migrated from direct property access (cli.minTokens, etc.) to the cli.opts() API required by Commander v8+. The --no-gitignore / --gitignore flag handling was rewritten to use Commander's native negation support instead of rawArgs inspection.
  • Vitest 4.1.0 — bumped from 3.2.4 to address CVE-2026-47429.
  • Commander v15 — bumped from v5 to v15, enabling modern Node.js compatibility.
  • Pug 3.0.4, node-sarif-builder 4.1.0, nodemon 3.1.14 — dependency bumps for security and compatibility.

v4.2.4

Compare Source

v4.2.3

Compare Source

v4.2.2

Compare Source

v4.2.1

Compare Source

v4.2.0

Compare Source

Breaking Changes
  • Vue SFC tokenization.vue files are no longer tokenized as markup. Each block is now dispatched to its own sub-format: <script>javascript, <script lang="ts">typescript, <template>markup, <style>css, <style lang="scss">scss, <style lang="less">less. Clone reports for .vue files now appear under these resolved sub-format names. Any tooling or configuration that relied on .vue clones being reported under markup must be updated.
  • --formatsExts users — custom mappings that pointed .vue to markup (e.g. "formatsExts": { "markup": ["vue"] }) will no longer take effect because .vue is handled by the dedicated vue format processor. Remove or update such mappings.
New Features
  • Custom tokenizer backend — replaced the prismjs npm package with a self-contained reprism-based grammar engine. ~11.5% faster tokenization on real projects (avg 1126 ms → 997 ms on a 548-file, 223-format scan).
  • Cross-format detection — Vue SFC (.vue), Svelte (.svelte), Astro (.astro), and Markdown files are now tokenized per-block/per-section. A <script> block in a .vue file can match a .ts file; a fenced code block in Markdown can match a .py file.
  • 223 supported formats — Apex, CFML/ColdFusion, GDScript, Svelte, Astro, and 70+ additional languages added (up from 152). See FORMATS.md.
  • Shebang detection — extensionless executable scripts (e.g. /usr/bin/env python3) are auto-detected by their #! shebang line and tokenized in the correct language.
  • --store-path — configure a custom directory for the LevelDB cache, eliminating collisions when multiple jscpd processes run in parallel on the same machine.
  • --skipComments — shorthand flag for --mode weak, which strips comments before detection.
  • --formats-names — map specific filenames (e.g. Makefile, Dockerfile) to a detection format.
Bug Fixes
  • Entire-file duplicates silently dropped (@jscpd/core#​728) — RabinKarp flushed the pending clone on a store hit at end-of-file instead of on a miss. Files that are complete copies of each other were undetected. Fixed.
  • ReDoS hang on Lisp/Elisp files (@jscpd/tokenizer#​737) — the Lisp string regex /"(?:[^"\\]*|\\.)*"/ could catastrophically backtrack (O(2ⁿ)) on unterminated strings. Replaced with a linear /"(?:[^"\\]|\\[\s\S])*"/ pattern.
  • Process crash on malformed package.json (#​739) — readJSONSync threw an unhandled SyntaxError when package.json contained invalid JSON, killing the process. Now emits a warning and continues with an empty config.
  • Vue SFC cross-file detection broken — the detector used the file-level format (vue) as the store namespace for all SFC blocks, preventing a <script> block in one .vue file from ever matching a <script> block in another. The namespace now reflects each block's resolved sub-format.
  • Vue SFC incorrect column numbers — tokens on the first line of a block carried block-relative column 1 instead of file-absolute column numbers. Fixed in @jscpd/tokenizer.
  • 50 dependency security vulnerabilities remediated across the monorepo (Dependabot batches).
Known Limitations
  • Malformed SFC blocks (e.g. unclosed tags, invalid attributes) are silently skipped and do not contribute tokens.

v4.1.1

Compare Source

v4.1.0

Compare Source

New Features
  • AI Reporter — new ai reporter that produces compact, token-efficient clone output specifically designed for feeding results into language models and AI tooling. Use --reporters ai to activate it.
  • MCP Server enhancements — the Model Context Protocol server now exposes a jscpd://statistics resource and supports a recheck endpoint so AI agents can trigger a rescan without restarting the process.
  • Apex & CFML language support — jscpd can now detect duplicate code in Salesforce Apex and ColdFusion Markup Language (CFML) files (closes #​83, #​619).
  • GDScript support — detect copy-paste duplication in Godot Engine GDScript files.
  • HTML reporter footer — the HTML report now displays a branded footer with the jscpd version and a sponsor link.
  • --noTips flag — suppress the usage-tip messages that appear after a detection run.
  • CI: Node.js 22.x / 24.x — continuous integration updated to test against the latest Node.js LTS and current releases.
Performance
  • Tokenizer — grammars are now loaded lazily, hot paths are O(n), and the spark-md5 dependency has been removed in favour of a lighter built-in implementation. Startup time and memory usage are noticeably reduced on large codebases.
  • Replaced the vendored reprism syntax library with the official prismjs npm package, shrinking the installed footprint.
Bug Fixes
  • Restored the correct start.line expectation for weak-mode clone detection.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@w3nl

w3nl commented May 10, 2026

Copy link
Copy Markdown
Contributor

Snyk checks have passed. No issues have been found so far.

StatusScan Engine Critical High Medium LowTotal (0)
Open Source Security0000 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@codacy-production

codacy-productionBot commented May 10, 2026

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics0 complexity · 0 duplication

MetricResults
Complexity0
Duplication0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0886e4a to 612af4cCompareMay 12, 2026 08:40
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.1.0chore(deps): update dependency jscpd to v4.1.1May 12, 2026
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.1.1chore(deps): update dependency jscpd to v4.2.0May 14, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch 2 times, most recently from 12e0d4f to 0b3832dCompareMay 15, 2026 17:43
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.0chore(deps): update dependency jscpd to v4.2.1May 15, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0b3832d to 90f5afbCompareMay 15, 2026 21:00
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.1chore(deps): update dependency jscpd to v4.2.2May 15, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 90f5afb to 398abebCompareMay 17, 2026 12:56
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.2chore(deps): update dependency jscpd to v4.2.3May 17, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 398abeb to e743d77CompareMay 25, 2026 18:45
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.3chore(deps): update dependency jscpd to v4.2.4May 25, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from e743d77 to ece9b15CompareJune 7, 2026 17:50
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.4chore(deps): update dependency jscpd to v4.2.5Jun 7, 2026
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from ece9b15 to 0c388fbCompareAugust 11, 2026 22:33
@renovate
renovateBotforce-pushed the renovate/jscpd-4.x-lockfile branch from 0c388fb to 92c33f1CompareAugust 13, 2026 17:56
@renovaterenovateBot changed the title chore(deps): update dependency jscpd to v4.2.5chore(deps): update dependency jscpd to v4.3.0Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@w3nl