core/validators/package.validator.ts

core/validators/package.validator.ts is a file in GovLab Docs. 51 lines of code and 16 definitions.

import { dirname, extname, join } from "node:path";
import type { DeadScriptRef } from "#types/finding.types";
import { existsSync } from "node:fs";
import { isPlainRecord } from "#core/predicates/record.predicate";
import { readJsonSafe } from "#core/loaders/base.loader";
import { tokenizeCommand } from "#core/lexers/shell.lexer";

const SCRIPT_PATH_EXTENSIONS: ReadonlySet<string> = new Set([".js", ".mjs", ".cjs", ".ts", ".sh"]);
const TOKEN_EDGES: ReadonlySet<string> = new Set(['"', "'", "`", ";", ",", "(", ")"]);
const PATH_BREAKERS: readonly string[] = ["*", "{", "}", "<", ">", "$", "://"];
const PATH_SEPARATOR = "/";
const FLAG_PREFIX = "-";
const SCOPE_PREFIX = "@";
const VENDOR_PREFIX = "node_modules/";

const trimToken = function trimToken(token: string): string {
    let start = 0;
    let end = token.length;
    while (start < end && TOKEN_EDGES.has(token.charAt(start))) {
        start += 1;
    }
    while (end > start && TOKEN_EDGES.has(token.charAt(end - 1))) {
        end -= 1;
    }
    return token.slice(start, end);
};

const isScriptPath = function isScriptPath(token: string): boolean {
    if (!token.includes(PATH_SEPARATOR) || token.startsWith(FLAG_PREFIX) || token.startsWith(SCOPE_PREFIX)) {
        return false;
    }
    if (token.startsWith(VENDOR_PREFIX) || PATH_BREAKERS.some((breaker) => token.includes(breaker))) {
        return false;
    }
    return SCRIPT_PATH_EXTENSIONS.has(extname(token).toLowerCase());
};

const scriptTokens = function scriptTokens(command: unknown): string[] {
    return typeof command === "string"
        ? [...new Set(tokenizeCommand(command).map(trimToken).filter(isScriptPath))]
        : [];
};

export const deadScriptRefs = function deadScriptRefs(pkgPath: string): DeadScriptRef[] {
    const pkg = readJsonSafe(pkgPath);
    const scripts = isPlainRecord(pkg) ? pkg["scripts"] : undefined;
    if (!isPlainRecord(scripts)) {
        return [];
    }
    const pkgDir = dirname(pkgPath);
    return Object.entries(scripts).flatMap(([script, command]) =>
        scriptTokens(command)
            .filter((path) => !existsSync(join(pkgDir, path)))
            .map((path) => ({ path, script })),
    );
};