denisidoro/navi
64.3
Adequate · 27 September 2026
3.3k
lines of production code
Rust
primary language
4
measurements over time
What this system is
Navi is a command-line tool that provides interactive cheatsheet suggestions for shell commands, integrating directly with Bash, Zsh, Fish, PowerShell, Elvish, and Nushell. It allows users to query and insert code snippets via a fuzzy finder interface, supporting variable substitution and preview rendering. The system manages cheatsheet sources through local files and Git repositories, with a unified configuration system and structured logging for reliability.
How it got here
2019–2020 — Rust rewrite and infrastructure setup
12 changes.
The project underwent a significant architectural shift by rewriting core components in Rust, introducing structured data models, and implementing a new CLI repository management system. This period also established essential development infrastructure, including comprehensive test suites, shell integration plugins, and automated release scripts, while removing legacy shell-based cheat sheets.
2021–2026 — CLI architecture and shell integration
9 changes.
The project refactored its core architecture by unifying the configuration system with strict precedence rules and restructuring command logic into modular actors. New features were introduced to enhance shell integration, including dedicated subcommands for plugin installation, interactive snippet previews with variable substitution, and comprehensive tmux-based integration tests.
Features
Add preview command for rendering snippets with variable substitution
Introduces a new \preview\ command module that renders code snippets with syntax highlighting and interactive variable substitution. The command parses input lines or stdin to extract tags, comments, and snippets, then iterates through bracketed variables (e.g., \\<var\>\) to display their current values or look them up via a finder process. It supports multiple variables in a single snippet, highlighting the active variable differently from inactive ones, and allows for additional shell commands to be executed after the preview output.
src/commands/preview · high confidence
Add shell widgets for Bash, Zsh, Fish, PowerShell, Elvish, and Nushell
This change introduces new shell integration plugins that allow users to invoke the Navi widget directly from their command line. It adds specific plugin files for Bash (including a legacy fallback for versions \< 4), Zsh, Fish (with smart replace and Fish 4+ compatibility), PowerShell, Elvish, and Nushell. Each plugin binds a key (typically Ctrl+g) to trigger the widget, which queries Navi for suggestions based on the current command context and inserts the result into the terminal.
shell · high confidence
Introduce \`navi repo\` commands for managing cheatsheet repositories
Users can now manage cheatsheet sources directly from the CLI using the new \navi repo\ subcommands. The \navi repo add \<uri\>\ command allows importing cheatsheets from a Git repository, offering an interactive selection of files to import or an option to import all files at once. The \navi repo browse\ command provides a curated list of featured cheatsheet repositories to discover and import. These commands are implemented in Rust, replacing the previous shell-based implementation, and handle cloning, file selection, and copying of \.cheat\ files to the local cheats directory.
src · high confidence
Introduce shared common utilities module
A new \src/common\ module has been added to centralize shared functionality across the application. This includes helpers for clipboard operations (\clipboard.rs\), file system interactions with Windows UNC path support (\fs.rs\), Git repository metadata extraction and cloning (\git.rs\), hashing (\hash.rs\), shell command execution with multi-shell support (\shell.rs\), terminal width detection (\terminal.rs\), and URL opening (\url.rs\).
src/common · high confidence
Introduce structured data models for cheatsheets and fetching
The \src/structures\ module now defines the core data types used by the application, including \Item\ for representing individual cheatsheet entries (with tags, comments, and snippets), \VariableMap\ for managing variable suggestions and their implicit dependencies, and the \Fetcher\ trait with a \StaticFetcher\ implementation for retrieving cheatsheet content. These structures provide the foundational data handling logic for parsing and serving cheatsheet data.
src/structures · high confidence
Introduction of DNS common library with component and tracing modules
A new \dns\_common\ library has been added to the project, providing foundational utilities for the application. This includes a \Component\ trait and \AsAny\ helper for type-erased object handling, as well as a \TracingConfig\ struct for configuring logging behavior (time and level). These additions support the ongoing effort to merge dependencies within the navigation system.
_src/libs/dns\common · high confidence
New 'func' command module with map, widget, and URL utilities
A new 'func' command module has been introduced, providing a unified interface for several utility functions. Users can now access 'url::open' to open URLs, 'welcome' for the main core functionality, 'widget::last\_command' to process and display the last command with specific character replacements, 'map::expand' to format input using sed and tr, and 'temp' for temporary file operations. This module consolidates these disparate utilities under a single command structure, allowing for easier invocation and management of these tools.
src/commands/func · high confidence
New developer and release utility scripts
The project now includes a set of new shell scripts in the \scripts/\ directory to streamline development and distribution workflows. \scripts/install\ provides a comprehensive installation mechanism that supports downloading precompiled binaries with SHA256 verification or building from source via Cargo, while \scripts/make\ offers convenient \make install\ and \make uninstall\ targets. \scripts/release\ automates the cross-compilation of binaries for various platforms using \cross\ and handles packaging into \.zip\ or \.tar.gz\ archives. Additionally, \scripts/docker\ facilitates testing in a minimal Alpine Linux environment, \scripts/dot\ manages dotfile synchronization, and \scripts/test\ executes the test suite.
scripts · high confidence
New info and shell subcommands for configuration examples and plugin code
The CLI now includes \info\ and \shell\ subcommands. The \info\ command allows users to print examples of cheatsheets and configuration files, as well as display the default paths for cheatsheets and configuration (with older path commands marked as deprecated). The \shell\ command prints the shell integration plugin code for supported shells (Bash, Zsh, Fish, Elvish, Nushell, and PowerShell), enabling users to easily install or update the navi shell widget.
src/commands · high confidence
New serialization and terminal display logic for items
The \src/deser\ module has been introduced to handle the serialization and terminal rendering of items. It adds specific logic for Raycast integration (encoding/decoding items with hash validation) and terminal output (formatting tags, comments, and snippets with configurable column widths and color styling). This includes utilities for handling newlines, calculating Unicode-aware string widths, and limiting text length with ellipsis for display.
src/deser · high confidence
Removals
Removal of shell command cheat sheets
The cheat sheets for awk, crontab, docker, git, kubernetes, mysql, network, and tar have been removed from the sheets directory. Users will no longer have access to these quick-reference guides for common shell commands and system administration tasks within this location.
sheets · high confidence
Behavioural changes
Core command logic refactored into actor and module structure
The core command implementation has been restructured into a new \actor.rs\ module and a \mod.rs\ entry point. This change introduces logic to handle shell-specific preview commands (supporting PowerShell, cmd.exe, fish, and default shells) and implements a \--prevent-interpolation\ flag that allows users to skip variable substitution in snippets. It also refactors how variable suggestions are fetched and displayed in the finder interface.
src/commands/core · high confidence
Improved error handling and tealdeer support for cheat.sh and tldr clients
The cheat.sh and tldr client implementations in src/clients now provide more detailed error messages when external commands fail or return unexpected results. For tldr, a new configuration option allows users to enable tealdeer as the recommended client, addressing compatibility issues with older tldr clients that do not support markdown output.
src/clients · high confidence
Refactored finder module to support fzf and skim with configurable post-processing
The \src/finder\ module has been restructured into \mod.rs\, \post.rs\, and \structures.rs\ to decouple the selection interface from output processing. Users can now choose between \fzf\ and \skim\ via the \FinderChoice\ enum, with the system automatically handling binary invocation (\fzf\ vs \sk\) and specific argument differences (e.g., preview window height). The new \post.rs\ module handles post-choice manipulation, allowing users to apply custom map functions and column extraction logic to the selected text. Additionally, the module enforces a minimum \fzf\ version (0.23.1) to ensure compatibility with the preview window layout, exiting with a warning if an older version is detected.
src/finder · high confidence
Structured logging with file output and user-friendly error reporting
The application now uses the \tracing\ ecosystem for structured logging, writing debug logs to a \navi.log\ file inside the user's configuration directory (and skipping logging if the config directory does not exist). Additionally, unhandled errors in the main entry point are now wrapped in a \FileAnIssue\ error type that displays a clear message directing users to file a GitHub issue, replacing previous generic error handling.
src/bin · high confidence
Unified configuration system with priority-based resolution
The configuration loading logic has been refactored into a structured system that resolves settings from three sources: CLI arguments, environment variables, and YAML files. The resolution priority is strictly CLI \> Environment \> YAML, ensuring that explicit command-line flags always override environment variables, which in turn override the configuration file. This change introduces dedicated modules for parsing CLI arguments (using clap), environment variables, and YAML content, and adds a \source\ field to the configuration to indicate which file or source was ultimately used. Users can now rely on a consistent precedence model for settings like paths, finder options, and style preferences.
src/config · high confidence
Test coverage
Add integration and unit test infrastructure for navi; Add tmux-driven integration tests for shell plugins; Added test cases for cheats and SSH configurations; Added test coverage for cheat sheet parsing and variable handling.
Dependencies
Initial dependency manifest and lockfile for navi v2.25.0-beta1
This change introduces the Cargo.toml and Cargo.lock files for the navi project, establishing the dependency graph for version 2.25.0-beta1. The project targets the Rust 2021 edition and relies on clap 4.2.1 for CLI argument parsing, crossterm 0.28.1 for terminal control, and serde 1.0.219 with serde\_yaml 0.9.21 for configuration handling. Additional dependencies include regex 1.7.3 for pattern matching, anyhow 1.0.70 and thiserror 2.0.0 for error handling, and tracing 0.1.41 for logging. The manifest also defines build features to disable command execution and repository management.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 42 → 64 (+22.1)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 94 (-6.1)
- Architecture 91 (new)
- Maturity 59 → 56 (-3.3)
- Readiness 30 → 63 (+33.6)
- Security 38 → 70 (+32.1)
Resolved (16)
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- LLM evaluation failed
- No automated tests
- No exposed public API
- No tests found
- Test reliability not included
New (49)
- Documentation: no project overview (docs/contributions/bugs/README.md)
- Duplicated block (14 lines × 2) (src/clients/cheatsh.rs)
- FinderChoice::call (cognitive 28) (src/finder/mod.rs)
- FinderChoice::call (cyclomatic 26) (src/finder/mod.rs)
- FixmeComment (src/filesystem.rs)
- FunctionTooLong: navi::commands::core::actor::prompt_finder (src/commands/core/actor.rs)
- Further sole-owners (lower concentration)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Input::run (cognitive 17) (src/commands/preview/var.rs)
- Medium CVE: RUSTSEC-2025-0055 (Cargo.lock)
- …and 29 more
Changes since last survey
- 4 commits — 2 feature/other, 2 fixes
By area
- (repo) — 2 commits
- src/config — 1 commit
- tests/shell — 1 commit
Notable commits
- fix: Merge pull request #1039 from GauravS11112003/fix/1017-fish-widget
- fix: Merge pull request #1044 from kentcb/help-fix
- change: Fix minor typo in help output.
- change: fish: stop the widget reopening fzf over its own best match
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
denisidoro/navi was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 7389f9544b9cbbf845acadb96c1b18a13ca988c4 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.