Skip to content

Observability ​

@scruple/observability checks logging and telemetry calls.

sh
pnpm add -D @scruple/observability
ts
import { defineConfig } from "@scruple/core";
import { observability } from "@scruple/observability";

export default defineConfig({
  parser,
  provider,
  plugins: { observability: observability() },
  rules: { "observability/no-sensitive-logs": "warn" },
});
RuleChecks
observability/no-sensitive-logsSensitive values emitted without redaction
observability/no-unactionable-errorsError events missing operation or failure evidence
observability/require-operation-contextEvents without a stable operation identity
observability/require-stable-telemetry-namesDynamic event, span, or metric names
observability/no-duplicate-error-reportingThe same caught failure reported twice

All rules accept threshold, minConfidence, and custom call-pattern options. threshold is always a { warning, error } object. Custom patterns extend the built-in patterns. minConfidence defaults to 0.7.

observability/no-sensitive-logs ​

Reviews detected log and telemetry calls for visibly sensitive emitted values without effective masking, allowlisting, hashing for disclosure control, or redaction. threshold defaults to { warning: 0.9, error: 0.97 }.

observability/no-unactionable-errors ​

Reviews only error/fatal logs and exception telemetry. An actionable event identifies the failed operation and preserves useful failure evidence. threshold defaults to { warning: 0.85, error: 0.95 }.

observability/require-operation-context ​

Checks log and telemetry events other than setAttribute and setAttributes for a specific message or structured field naming the operation. IDs and status alone do not identify it. threshold defaults to { warning: 0.8, error: 0.95 }.

observability/require-stable-telemetry-names ​

Reviews recognized event, span, and metric-name arguments for dynamic or unbounded values. Stable literals and visibly bounded route templates are accepted; unresolved constants and helpers cause abstention.

observability/no-duplicate-error-reporting ​

Reviews catch handlers with at least two recognized reports that directly reference the same catch binding. Distinct errors and visible intentional dual-emission policy are accepted or abstained on.

ts
rules: {
  "observability/no-sensitive-logs": ["warn", { loggingCallPatterns: [/^audit\.write$/u] }],
}

Released under the MIT License.