HNHacker News
TopNewBestAskShowJobs

wschoi

40 karma · joined October 20, 2017

submissionscomments
wschoi··on Show HN: How to ensure code quality of Vue.js app
Hi. DeepScan is a static analyzer that understands the execution and data flow of JavaScript programs.

It has dedicated rules for Vue.js app. For example, an uninitialized property of Vue instance is detected as follows:

  Vue.component('Hello', {
    template: '<div>Hello</div>',
    methods: {
      log() {
        // VUE_UNINITIALIZED_INSTANCE_PROPERTY alarm:
        //   The '$el' property of a Vue instance is not yet initialized.
        //   Consider not using the property during the execution of 'created()'.
        console.log(this.$el); 
      }
    },
    created() { this.log(); }
  });
Also, DeepScan aggressively filters out low impact issues and tries to report actual code problems. I hope that DeepScan is helpful in ensuring the code quality of Vue.js app.
wschoi··on DeepScan now supports 100+ rules for JavaScript and React
Also, you can use editor plugins:

- Visual Studio Code: https://marketplace.visualstudio.com/items?itemName=DeepScan...

- Atom: https://atom.io/packages/atom-deepscan

wschoi··on DeepScan now supports 100+ rules for JavaScript and React
It's a SaaS. You can analyze your GitHub repositories on the web. Or you can check code snippet using demo feature at https://deepscan.io/demo/
wschoi··on Show HN: How to ensure JavaScript code quality
Sorry, no gitlab integration yet. It is on the next year roadmap.

In the meantime, you can try editor plugins if you are using Visual Studio Code or Atom.

Check https://deepscan.io/docs/get-started/basics/#non-github for details.

wschoi··on Show HN: How to ensure JavaScript code quality
Thanks for the helpful comment!

1) We will consider adding explanation like "Note that 'x' is declared in function scope. Consider using 'let' declaration if you intended block scope".

2) Yes. Directly showing warnings in the GitHub site would be a nice feature. We will consider it in our roadmap.

wschoi··on Show HN: How to ensure JavaScript code quality
Thanks for the comment. We will add those facts to documents in the next release, which is planned on the end of this month.
wschoi··on Show HN: How to ensure JavaScript code quality
No. DeepScan concentrates on runtime errors and does not cover security issues currently.
wschoi··on Show HN: How to ensure JavaScript code quality
We are planning to support Bitbucket and GitLab in long term.

You can check out more detail in https://deepscan.io/docs/get-started/basics/#non-github

wschoi··on Show HN: How to ensure JavaScript code quality
We have a npm cli pacakage but currently provide it to limited partners only. In the future, we are considering to include it under paid plan.
wschoi··on Show HN: How to ensure JavaScript code quality
I feel the same that it can be overwhelming to apply linters to legacy code base. While developing DeepScan, we tried to aggresively filter-out low impact issues and common coding patterns that are not actual problems.
wschoi··on Show HN: How to ensure JavaScript code quality
If you are using Atom or Visual Studio Code, you can try the following plugins:

- Visual Studio Code: https://marketplace.visualstudio.com/items?itemName=DeepScan...

- Atom: https://atom.io/packages/atom-deepscan

wschoi··on Show HN: How to ensure JavaScript code quality
While DeepScan finds some type-related errors, it focuses on finding issues orthogonal to type checking.

For comparison with Java, DeepScan is like FindBugs.

Check the reply that I have wrote for shamas.

wschoi··on Show HN: How to ensure JavaScript code quality
DeepScan runs data-flow analysis that is somewhat orthogonal to the type checking of Flow.

For example, BAD_MIN_MAX_FUNC rule detects an error in the following code, which is beyond type checking.

  x = Math.min(0, Math.max(100, x)); // BAD_MIN_MAX_FUNC alarm. The result is always 0.

The main diffrenece with JIRA ticket management is that it operates using information from code itself.

For example, it automatically tracks fixed and newly detected issues by a feature called historical defect merging.