PSComplexity.psd1
|
@{ RootModule = 'PSComplexity.psm1' ModuleVersion = '0.5.2' GUID = '961aa886-4f8e-40c0-9d25-68fd4c52e69f' Author = 'Fortigi' CompanyName = 'Fortigi' Copyright = '(c) Fortigi. MIT licensed.' Description = 'Cyclomatic and cognitive complexity for PowerShell. Cognitive complexity implements the SonarSource metric in full (nesting-aware -- the better signal for "hard to understand"), scoring every reference example exactly as published, and extends it for PowerShell constructs the specification does not cover: ForEach-Object and Where-Object, the && and || pipeline chains, and ?? and ??=. Measures per unit (function/filter, class method/constructor, initialised class property, + script body) via the PowerShell AST; ships a Test-PSComplexity gate for CI.' PowerShellVersion = '7.0' CompatiblePSEditions = @('Core') FunctionsToExport = @('Measure-PSComplexity', 'Test-PSComplexity') CmdletsToExport = @() VariablesToExport = @() AliasesToExport = @() PrivateData = @{ PSData = @{ Tags = @('complexity', 'cyclomatic', 'cognitive', 'code-quality', 'ast', 'metrics', 'maintainability', 'lint', 'ci') LicenseUri = 'https://github.com/Fortigi/PSComplexity/blob/main/LICENSE' ProjectUri = 'https://github.com/Fortigi/PSComplexity' ReleaseNotes = '0.5.2: **The SARIF log is now accepted by GitHub Advanced Security for Azure DevOps, and the README shows how to run the gate on Azure Pipelines.** Checked with the SARIF validator''s Azure DevOps and GitHub Advanced Security rule sets, the log failed two rules and now passes them: the tool carries a `fullName` (name and version), which Azure DevOps requires, and each rule carries a `help` text, which GitHub Advanced Security requires. Nothing else in the log changed -- same rules, same results, same fingerprints -- so existing alerts are not reopened. One rule is left failing on purpose: the log carries no `automationDetails`, i.e. no category. On GitHub a category in the file overrides the one the upload step names, so writing one would make two PSComplexity uploads in one repository replace each other. **On Azure DevOps, set `Category` on `AdvancedSecurity-Publish@1`**; that is where it comes from. New in the README, with a complete `examples/azure-pipelines.yml`: the gate on Azure Pipelines, publishing the SARIF to Advanced Security or -- without it -- to the *SARIF SAST Scans Tab* extension, why the publishing step needs `condition: succeededOrFailed()`, and how to gate a pull request on the files it changed when Azure Pipelines checks out shallow and detached. **Three internal lookups return an empty array rather than `$null`.** PowerShell unrolls a returned collection, so an empty result reached the caller as `$null` and a single result as a bare item, although one of them documented the opposite. Every caller iterated with `foreach`, which forgives both, so no measurement was ever wrong; a future caller using a pipeline would have run its body once over `$null`. No score moves and no command changed. Full changelog: https://github.com/Fortigi/PSComplexity/blob/main/CHANGELOG.md' } } } |