Skip to content

Make image processing automation-safe - #43

Merged
343dev merged 8 commits into
mainfrom
improvement/cli-safety
Sep 24, 2026
Merged

343dev merged 8 commits into
mainfrom
improvement/cli-safety

Conversation

@343dev

@343dev 343dev commented Sep 24, 2026

Copy link
Copy Markdown
Owner

This PR makes Optimizt safer and more predictable in scripts, CI pipelines, and workflows that modify filesystems.

  • Create and validate the complete operation plan before you load configuration or modify files.
  • Reject missing or unsupported explicit inputs.
  • Reject unsafe generated names, output collisions, escaping symlinks, and overlapping output mappings.
  • Reject replacement targets that have multiple hard links.
  • Write outputs atomically.
  • Preserve existing permissions and preserve ownership when the operating system permits it.
  • Continue independent operations after one operation fails.
  • Return a nonzero exit status if an operation fails.
  • Reserve stdout for help and version output.
  • Send status, progress, warnings, errors, and summaries to stderr.
  • Disable animated progress and terminal decoration when output is redirected.
  • Handle SIGINT and SIGTERM gracefully.
  • Terminate encoder processes that support cancellation.
  • Improve CLI help, validation errors, codec diagnostics, summaries, and debug output.
  • Add the --no-color and --debug options.
  • Expand integration tests for process behavior, operation planning, filesystem safety, interruption, supported formats, and redirected output.
  • Update the README, changelog, migration guide, development environment, and CI configuration.

Breaking changes

  • Validation, filesystem, configuration, and processing failures now cause exit status 1.
  • Image-processing output now goes to stderr.
  • During image processing, stdout remains empty.
  • Missing or inaccessible operands now cause failures. Optimizt no longer ignores them.
  • Explicit files with unsupported extensions now cause failures.
  • Optimizt continues to ignore unsupported files that it finds during directory traversal.
  • The --force option now requires --avif or --webp.
  • Optimizt now rejects unsafe prefixes, suffixes, and generated filenames. It no longer sanitizes them.
  • Custom CJS configuration files must define an object for the selected optimize or convert mode.
  • Optimizt rejects unsafe output mappings before processing starts.
  • Optimizt also rejects replacement targets that have multiple hard links.

See MIGRATION.md for migration instructions and detailed filesystem behavior.

Implementation notes

  • lib/prepare-operation-plan.js now controls operation planning and preflight validation.
  • Optimizt uses write-file-atomic to replace output files.
  • Processing functions return structured outcomes.
  • Summaries and exit statuses do not depend on parsed log output.
  • A failed operation does not discard successful independent operations.
  • Conversion summaries report generated bytes separately from optimization savings.
  • The CI matrix includes Windows.

Validate and plan filesystem operations before loading configuration, preserve independent successful work after runtime failures, write outputs atomically, and expose reliable process statuses and stream separation.

Align local and CI validation and document the new process, filesystem, and integration contracts.

BREAKING CHANGE: processing diagnostics now use stderr, invalid operands and runtime failures return non-zero status, unsafe output mappings are rejected, and generated names are no longer sanitized.
@343dev 343dev self-assigned this Sep 24, 2026
Comment thread optimize.js
@343dev
343dev merged commit a2a3748 into main Sep 24, 2026
9 checks passed
@343dev
343dev deleted the improvement/cli-safety branch September 24, 2026 11:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant