Skip to content

fix: validate CLI configuration before scanning - #180

Merged
rogerdigital merged 1 commit into
mainfrom
fix/v1-cli-config-validation
Sep 17, 2026
Merged

rogerdigital merged 1 commit into
mainfrom
fix/v1-cli-config-validation

Conversation

@rogerdigital

Copy link
Copy Markdown
Owner

Summary

Implements B1 of the 1.0.0 release readiness plan. JSON.parse(raw) as CliConfig only bypassed the type system: an array root was accepted, and a string threshold like largeMarkdownBytes: "garbage" could silently produce zero findings. Configuration is now validated as unknown at the JSON boundary:

  • The root must be a non-null, non-array object.
  • All five numeric settings must be finite non-negative integers (0 allowed, no string coercion).
  • List options must be arrays of strings; baselinePath must be a string.
  • Existing scanner/severity/failOn/per-scanner-folder checks are preserved; unknown keys stay ignored.

Invalid configuration exits 2 before the vault is scanned, even when a CLI option would override the invalid field. docs/cli.md documents the contract.

Validation

  • TDD: 18 invalid-config cases observed failing (the scan ran against a missing vault instead of validating), then passing; valid-zero/positive threshold cases keep findings.
  • Full gate: npm run lint && npm run lint:obsidian-warnings && npm run build && npm test — 941 tests pass.

@rogerdigital
rogerdigital merged commit 23dd895 into main Sep 17, 2026
1 check passed
@rogerdigital
rogerdigital deleted the fix/v1-cli-config-validation branch September 17, 2026 17:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant