Skip to content

feat: command and flag industry standard refactor - #71

Merged
wiebe-vandendriessche merged 2 commits into
mainfrom
feat/unified-logging
Oct 8, 2026
Merged

wiebe-vandendriessche merged 2 commits into
mainfrom
feat/unified-logging

Conversation

@wiebe-vandendriessche

Copy link
Copy Markdown
Member

Summary

Replaces the per-command --log-level with a single logging setup, separates interactive UIs from log output, and makes commands and flags consistent across the CLI. Breaking changes are intentional ahead of v1.

Logging

  • Global -q/--quiet and -v/--verbose (-v info, -vv debug), also settable as config keys quiet/verbose or AIBOMGEN_QUIET/AIBOMGEN_VERBOSE. --log-level is removed.
  • One log/slog logger writing to stderr, with debug lines for:
    • HF requests (URL, status, duration; the token is never logged)
    • scanner hits and rejected IDs
    • metadata fields applied
    • completeness checks
    • merge dedup
    • vuln-scan results
  • The "Using config file" line now only shows with -v.
  • New version subcommand, since -v is now taken. --version still works.

Interactive mode vs. logging

  • Results go to stdout. Logs, prompts and TUIs (model selector, enrich forms, confirmations) go to stderr.
  • Log lines are held while a prompt or TUI is open and printed when it closes, so -vv works with interactive mode.
  • Prompts only run when stdin and stderr are terminals. Otherwise (CI, pipes, new global --no-input) the command fails up front with a hint (--file, --yes, model IDs).
  • Spinners are only animated on a terminal without -v, so redirected output has no escape codes.
  • Ctrl-C in any prompt exits 0 with "Operation cancelled". Before, it exited 1, and in a dataset form enrich just moved on to the next dataset.
  • Enricher warnings go through the logger instead of plain stdout prints.

Consistency fixes (breaking)

  • Positional input: scan [dir], validate|completeness|enrich|vuln-scan [file], generate [model-id...], merge [aibom...]. -i/-m/--aibom still work; giving both a single input and -i is an error. Extra positional args used to be silently ignored.
  • --json on validate, completeness and vuln-scan. It replaces completeness --plain-summary.
  • Confirmations: -y/--yes on enrich and vuln-scan replaces --no-preview and vuln-scan --interactive.
  • enrich: --strategy is removed. --file <yaml> selects file mode, and the hidden ./config/enrichment.yaml fallback is gone.
  • Removed deprecated flags: -f/--format (input) on enrich/validate/completeness/vuln-scan/merge, --output-format, and validate --check-model-card.
  • merge: --deduplicate (default on) becomes --no-deduplicate.
  • Config keys renamed to match their flags: generate.model-ids → model-id, merge.aiboms → aibom.
  • --hf-mode is hidden; it stays available for the CI smoke test.
  • Hugging Face flags: --hf-token, --hf-base-url and --hf-timeout now exist on all four HF commands (generate and scan gain --hf-base-url). Unset values fall back to the standard HF_TOKEN / HF_ENDPOINT env vars.
  • Help shows real flag defaults instead of the "(default X)" text with fallback code behind it.
  • Error messages no longer start with --; fang displayed them as --Input.

Bugs fixed along the way

  • With no config file loaded, enrich had no HF timeout (its default was 0). It's now 10s everywhere; vuln-scan used 15s.
  • enrich --refetch defaulted to false as a flag but true in defaults.yaml, so behaviour depended on the working directory. It's now true.

README, config/defaults.yaml and the CI smoke test are updated. The CI summary line now comes from completeness --json | jq instead of --plain-summary.

Related issue

Closes #69

Type of change

Breaking change (flags and config keys renamed or removed), new feature (logging, --json, positional input, --no-input, --yes, version) and bug fixes (enrich timeout and refetch defaults, Ctrl-C exit code).

  • go test ./... passes locally (also with -race)
  • go build ./... passes locally
  • README updated for the user-facing changes
  • No unrelated changes included

Copilot AI balanced review requested due to automatic review settings October 8, 2026 09:42

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Copilot AI balanced review requested due to automatic review settings October 8, 2026 09:55

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@wiebe-vandendriessche
wiebe-vandendriessche merged commit 4bb61b4 into main Oct 8, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Enhancement] Replace --log-level with a unified -q / -v / -vv logging mechanism across all commands

2 participants