This document outlines the development roadmap for diffguard, organized into phases. Items are prioritized based on user value, complexity, and alignment with project goals.
- Status:
planned|in-progress|complete - Priority:
P0(critical) |P1(high) |P2(medium) |P3(low) - Effort:
S(small, <1 day) |M(medium, 1-3 days) |L(large, 3-7 days) |XL(extra large, >1 week)
Complete the remaining tasks from the comprehensive-test-coverage spec to ensure production readiness.
| Item | Description | Priority | Effort | Status |
|---|---|---|---|---|
| 1.1 | DiffStats accuracy property test | P1 | S | complete |
| 1.2 | Empty diff and context-only diff edge case tests | P1 | S | complete |
| 1.3 | Rule compilation success property test | P1 | S | complete |
| 1.4 | Rule applicability filtering property test | P1 | S | complete |
| 1.5 | Preprocessor line length preservation property test | P1 | S | complete |
| 1.6 | Evaluation count accuracy property test | P1 | S | complete |
| 1.7 | Error condition tests (malformed config, bad patterns) | P1 | M | complete |
| 1.8 | Exit code property tests for all fail_on combinations | P1 | S | complete |
| 1.9 | Markdown rendering property tests | P1 | S | complete |
| 1.10 | GitHub annotation format property tests | P1 | S | complete |
| 1.11 | Config parse fuzz target | P1 | M | complete |
| 1.12 | evaluate_lines fuzz target | P1 | M | complete |
| 1.13 | BDD integration tests for CLI workflows | P1 | M | complete |
| 1.14 | Snapshot tests for JSON receipt output | P2 | S | complete |
| 1.15 | Snapshot tests for GitHub annotation format | P2 | S | complete |
| 1.16 | Mutation testing analysis across all crates | P2 | L | complete |
Add industry-standard output formats for broader CI/CD integration.
| Item | Description | Priority | Effort | Status |
|---|---|---|---|---|
| 2.1 | SARIF output format - Industry standard for static analysis results | P1 | L | complete |
| 2.2 | JUnit XML output - Common CI format for test results | P2 | M | complete |
| 2.3 | CSV/TSV export - Tabular format for spreadsheet analysis | P3 | S | complete |
| 2.4 | SARIF upload GitHub Action integration | P2 | M | complete |
SARIF benefits:
- Native GitHub Security tab integration
- Unified vulnerability dashboard
- Rich code flow and location tracking
- Industry standard (OASIS/NIST)
Improve rule flexibility and user experience.
| Item | Description | Priority | Effort | Status |
|---|---|---|---|---|
| 3.1 | Inline suppression comments (# diffguard:disable=rule.id) |
P1 | M | complete |
| 3.2 | Rule tagging/grouping for selective enable/disable | P2 | M | complete |
| 3.3 | Config file validation CLI command (diffguard validate) |
P2 | S | complete |
| 3.4 | Rule testing framework (example inputs with expected matches) | P2 | L | complete |
| 3.5 | Environment variable expansion in config (${VAR}) |
P3 | S | complete |
| 3.6 | Config inheritance/composition (includes = ["base.toml"]) |
P3 | M | complete |
| 3.7 | Per-directory rule overrides (.diffguard.toml lookup) | P3 | M | complete |
Inline suppression format:
// diffguard:disable=rust.no_unwrap
let value = map.get("key").unwrap(); // Intentional - key guaranteed present
// diffguard:enable=rust.no_unwrapExtend preprocessing support to additional languages.
| Item | Description | Priority | Effort | Status |
|---|---|---|---|---|
| 4.1 | Shell/Bash preprocessing (# comments) | P1 | S | complete |
| 4.2 | PHP preprocessing (// and # comments, various strings) | P2 | M | complete |
| 4.3 | Swift preprocessing (// and /* */ comments) | P2 | S | complete |
| 4.4 | Scala preprocessing (// and /* */ nested comments) | P3 | S | complete |
| 4.5 | SQL preprocessing (-- comments, /* */ blocks) | P3 | M | complete |
| 4.6 | XML/HTML comment preprocessing () | P3 | M | complete |
| 4.7 | YAML/TOML/JSON comment handling | P3 | M | complete |
| 4.8 | Language override flag (--language=rust for non-standard extensions) |
P2 | S | complete |
Add more built-in rules for common patterns.
| Item | Description | Priority | Effort | Status |
|---|---|---|---|---|
| 5.1 | Security-focused rules pack | P1 | L | complete |
| 5.2 | Python: no_breakpoint (breakpoint() calls) | P2 | S | complete |
| 5.3 | Ruby: no_binding_pry, no_byebug | P2 | S | complete |
| 5.4 | Java: no_sout (System.out.println) | P2 | S | complete |
| 5.5 | C#: no_console (Console.WriteLine) | P2 | S | complete |
| 5.6 | Go: no_panic | P2 | S | complete |
| 5.7 | Kotlin: no_println | P2 | S | complete |
| 5.8 | Credential detection rules (API keys, tokens, secrets) | P1 | M | complete |
Security rules pack (5.1) would include:
- Hardcoded IP addresses
- Suspicious URLs
- Common secret patterns
- Insecure function calls (eval, exec, etc.)
Improve developer workflow integration.
| Item | Description | Priority | Effort | Status |
|---|---|---|---|---|
| 6.1 | pre-commit hook integration (pre-commit framework) | P1 | M | complete |
| 6.2 | Git commit-msg hook sample | P3 | S | complete |
| 6.3 | GitHub Action reusable workflow | P1 | M | complete |
| 6.4 | GitLab CI template | P2 | S | complete |
| 6.5 | Azure DevOps pipeline template | P3 | S | complete |
| 6.6 | VS Code extension (basic) | P3 | XL | complete |
| 6.7 | LSP server for IDE integration | P3 | XL | complete |
pre-commit integration (6.1):
repos:
- repo: https://github.com/owner/diffguard
rev: v1.0.0
hooks:
- id: diffguard
args: [check, --base, origin/main]Add visibility into rule performance and effectiveness.
| Item | Description | Priority | Effort | Status |
|---|---|---|---|---|
| 7.1 | Verbose/debug logging (--verbose, --debug) |
P2 | S | complete |
| 7.2 | Performance timing metrics in receipt | P3 | S | complete |
| 7.3 | Rule hit statistics aggregation | P3 | M | complete |
| 7.4 | False positive tracking mechanism | P3 | L | complete |
| 7.5 | Historical trend analysis (cross-run metrics) | P3 | XL | complete |
Enable more sophisticated matching patterns.
| Item | Description | Priority | Effort | Status |
|---|---|---|---|---|
| 8.1 | Multi-line pattern matching (across consecutive lines) | P2 | L | complete |
| 8.2 | Negative patterns (flag if pattern NOT present) | P3 | M | complete |
| 8.3 | Context requirements (require pattern A near pattern B) | P3 | L | complete |
| 8.4 | Semantic severity escalation (warn→error based on context) | P3 | M | complete |
| 8.5 | Rule dependencies (if rule A matches, also check rule B) | P3 | M | complete |
Extend diff analysis capabilities.
| Item | Description | Priority | Effort | Status |
|---|---|---|---|---|
| 9.1 | scope = "deleted" - Flag removal of certain patterns |
P2 | M | complete |
| 9.2 | scope = "modified" - Changed lines only, not pure additions |
P3 | S | complete |
| 9.3 | Non-git diff sources (patch files, arbitrary diffs) | P3 | L | complete |
| 9.4 | Multiple base comparison (--base main --base release/1.0) |
P3 | L | complete |
| 9.5 | Blame-aware filtering (by author, age) | P3 | XL | complete |
Items that may be considered based on community feedback:
- Plugin system - Dynamic rule loading (WASM or native)
- AST-aware rules - Tree-sitter integration for semantic matching
- Auto-fix suggestions - Machine-generated fix recommendations
- Caching layer - Skip unchanged files between runs
- Distributed execution - Parallel processing for large diffs
- Custom severity levels - User-defined beyond info/warn/error
- SBOM integration - Software bill of materials awareness
- License scanning - Built-in license header detection
- Phase 1 complete (full test coverage)
- All P0 items from Phases 2-6
- Stable public API guarantee
- SARIF output
- JUnit XML output
- GitHub Security integration
- Inline suppression comments
- pre-commit integration
- Config validation command
- Multi-line patterns
- Extended language support
- Plugin system (if demand exists)
Contributions welcome! See CONTRIBUTING.md for guidelines.
To propose additions to this roadmap:
- Open an issue describing the feature
- Include use cases and expected behavior
- Tag with
roadmaplabel
Last updated: 2026-02-17