spf13/cobra
64.3
Adequate · 24 September 2026
6k
lines of production code
Go
primary language
5
measurements over time
What this system is
This system is a command-line interface library that enhances user interaction through dynamic shell completions and automated documentation generation. It provides tools to display context-sensitive help messages during shell completion and supports generating command documentation in multiple formats, including Markdown, man pages, and YAML. The system relies on standard Go dependencies to manage flags and parse input.
Features
Introduce ActiveHelp support for shell completions
Users can now display dynamic, context-sensitive help messages during shell completion. The library adds an \active\_help.go\ module that provides \AppendActiveHelp\ and \GetActiveHelpConfig\ functions, allowing completion scripts to inject special \\activeHelp\\ prefixed strings into the completion output. This enables tools to show helpful hints or instructions to the user as they type, controlled via environment variables like \\*\_ACTIVE\_HELP\. The change also includes corresponding tests in \active\_help\_test.go\ to verify this new behavior.
(repo-wide) · high confidence
New doc package for generating command documentation in multiple formats
The \doc\ package now provides functions to generate command documentation in Markdown, man page, ReST, and YAML formats. Users can use \GenMarkdown\, \GenMan\, \GenReST\, and \GenYaml\ to produce structured documentation for their Cobra commands, with support for custom link handlers and file preprenders. The package includes comprehensive tests for each format and utility functions for sorting and formatting.
doc · high confidence
Dependencies
Updated Go dependencies and build configuration
The project's Go module dependencies have been updated to specific versions: go-md2man v2.0.6, mousetrap v1.1.0, pflag v1.0.9, and yaml v3.0.4. The Go version requirement has been set to 1.15.
(dependencies) · medium confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 66 → 64 (-1.2)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 80 → 87 (+6.7)
- Architecture 100 → 100 (+0.0)
- Maturity 42 → 41 (-0.7)
- Readiness 91 → 80 (-11.4)
- Security 92 → 90 (-2.6)
Resolved (12)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (11 lines × 2) (command.go)
- Duplicated block (11 lines × 3) (doc/yaml_docs.go)
- Duplicated block (12 lines × 3) (doc/man_docs.go)
- Duplicated block (14 lines × 2) (doc/md_docs.go)
- Duplicated block (6 lines × 2) (cobra.go)
- Duplicated block (7 lines × 2) (command.go)
- Medium CVE: GO-2021-0263 (go.mod)
- No exposed public API
- Off-boarding risk: anonymized user #1
- Test reliability not included
New (37)
- ClassTooLong: Command (command.go)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (cobra.go)
- Duplicated block (10 lines × 3) (doc/md_docs.go)
- Duplicated block (12 lines × 2) (command.go)
- Duplicated block (12–14 lines × 3) (doc/man_docs.go)
- Duplicated block (5 lines × 2) (doc/md_docs.go)
- Duplicated block (6 lines × 2) (command.go)
- Duplicated block (6 lines × 4) (bash_completionsV2.go)
- Duplicated block (9 lines × 2) (bash_completionsV2.go)
- FixmeComment (cobra.go)
- FixmeComment (cobra.go)
- FixmeComment (cobra.go)
- FixmeComment (command_test.go)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 17 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
spf13/cobra was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit adbc8813901bba65827259daa8e22ff94ec1f30e — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-923689c465cf.