Local by default
A scan runs on your machine. It does not upload source code, execute repository code, or write to the repository.
Emendant is published on npm. Run it from the root of a repository with Node.js 20 or later:
npx emendant scannpx fetches the package and runs it, so there is nothing to install first, and there is no account and no sign-in. Add it to a project when you want it in CI, and pin it there:
npm install --save-dev emendantEmendant reads the repository’s manifests and lockfiles, selects applicable changes from the feed, and structurally matches affected uses. A result is reported only when the feed describes the change and the code can be attributed to that package.
Local by default
A scan runs on your machine. It does not upload source code, execute repository code, or write to the repository.
Evidence, not guesses
Every finding links to a curated change entry and, where needed, carries a trace back to the package import.
Built for CI
Stable JSON output and explicit exit codes let a pipeline distinguish a clean scan, findings, and a tool error.
Emendant matches TypeScript and JavaScript repositories against curated changes to six AI SDKs: ai, openai, @anthropic-ai/sdk, langchain, @langchain/core, and @google/genai. It understands npm, pnpm, and Yarn projects, including declared workspaces and aliased npm installs. PyPI dependency detection exists, but Python matching and feed coverage are deferred.
Coverage grows without a new release of the tool. Entries are published as signed snapshots, and emendant feed update picks them up.