Dependency health diagnostic tool for the MoonBit ecosystem
# 1. Clone this repo
git clone https://github.com/Tino-hue/moonmark.git
cd moonmark
# 2. Build the JS bundle (one-time, ~10s)
moon build --target js
# 3. Audit the included healthy example (run from project root)
node _build/js/debug/build/depsight.js audit --target-pkg examples/healthy_projectcd /path/to/your-project # a directory containing moon.mod
node /path/to/depsight.js audit # or use --target-pkg /path/to/your-project from this repo| Tool | Version | Purpose |
|---|---|---|
| MoonBit CLI | latest (≥ 0.1.20260827) | Compile depsight and your project |
| Node.js | ≥ 18.x | Run the built JS bundle |
| Git | any | Clone source |
# macOS / Linux
MOONBIT_INSTALL_VERSION=latest curl -fsSL https://cli.moonbitlang.cn/install/unix.sh | bash
# Windows (PowerShell)
$env:MOONBIT_INSTALL_VERSION = 'latest'
irm https://cli.moonbitlang.cn/install/powershell.ps1 | iexgit clone https://github.com/Tino-hue/moonmark.git
cd moonmark
moon build --target jsmoon add Tino-hue/depsightAll commands below assume you ran cd moonmark && moon build --target js first, and your working directory is the project root (otherwise the relative _build/... path won't resolve). For an absolute path you can run node /anywhere/_build/js/debug/build/depsight.js audit directly.
# 查看依赖树(ASCII 格式)
node _build/js/debug/build/depsight.js tree [package]
node _build/js/debug/build/depsight.js tree --depth 3
# 运行依赖审计(终端彩色输出)
node _build/js/debug/build/depsight.js audit
# JSON 格式输出(供 CI 消费)
node _build/js/debug/build/depsight.js audit --json
# 生成完整报告
node _build/js/debug/build/depsight.js report
node _build/js/debug/build/depsight.js report --html -o report.html
node _build/js/debug/build/depsight.js report --json -o report.json
# 检查可更新的依赖包
node _build/js/debug/build/depsight.js outdated
# 追溯谁依赖了某个包
node _build/js/debug/build/depsight.js why moonbitlang/core
# 快速健康检查(CI 一行输出)
node _build/js/debug/build/depsight.js check
# SARIF 格式输出(GitHub Code Scanning)
node _build/js/debug/build/depsight.js audit --sarif# 健康分低于 80 时返回 exit code 1
node _build/js/debug/build/depsight.js audit --fail-on-score 80
# 发现 critical 问题时返回 exit code 1
node _build/js/debug/build/depsight.js audit --fail-on-critical
# 离线模式(仅使用本地缓存)
node _build/js/debug/build/depsight.js audit --offline --cache-dir ./cache- name: Dependency Health Audit
run: node depsight.js audit --html -o depsight-report.html
- uses: actions/upload-artifact@v4
with:
name: depsight-report
path: depsight-report.html| Scale | Nodes | Graph Build | Analysis | Report Render | End-to-End |
|---|---|---|---|---|---|
| Small | 5 | < 50 ms | < 20 ms | < 100 ms | < 200 ms |
| Medium | 50 | < 200 ms | < 100 ms | < 500 ms | < 1 s |
| Large | 200 | < 1 s | < 500 ms | < 2 s | < 5 s |
# 构建 JS 产物
moon build --target js
# 运行测试(267 个,秒级完成)
moon test --target js
# 运行所有测试(含 8 个性能测试,约 30-60 秒)
moon test --target js --no-skip
# 格式化检查
moon fmt --check
# 运行 linter(JS target only;wasm-gc 不支持 JS FFI)
moon check --target js# From the project root, after `moon build --target js`
# 1. Healthy project — score should be 90+
node _build/js/debug/build/depsight.js audit --target-pkg examples/healthy_project
# 2. Outdated dependencies — demonstrates VERSION-001 diagnostics
node _build/js/debug/build/depsight.js audit --target-pkg examples/outdated_project
# 3. Risky project — 5+ diagnostic codes, fully offline (F06)
# Triggers: CYCLE-001, LICENSE-001, LICENSE-002, DEPRECATED-001, DEPRECATED-002
# Also demonstrates outdated dependency (freshness downgrade via _latest_version)
node _build/js/debug/build/depsight.js audit --offline --target-pkg examples/risky_project├── parse/ # moon.mod parser & Module data structure
├── fetch/ # Registry abstraction & GitHub raw content fetcher
├── graph/ # Dependency graph, builder, topological sort, cycle detection
├── analyze/ # Core analysis engine (semver, license, deprecated, health score, size)
├── report/ # Diagnostic data structure (Critical/Warning/Info)
├── cli/ # CLI argument parsing & command dispatch
├── examples/ # healthy_project / outdated_project / risky_project fixtures
└── main.mbt # Entry point# 国内镜像(GitHub Actions 默认使用,避免 403)
MOONBIT_INSTALL_VERSION=latest curl -fsSL https://cli.moonbitlang.cn/install/unix.sh | bashInstall
Download zipDependency health diagnostic tool for the MoonBit ecosystem