{
  "markdown": "# jscpd\n\n[![npm version](https://img.shields.io/npm/v/jscpd?color=brightgreen)](https://www.npmjs.com/package/jscpd)\n[![npm downloads](https://img.shields.io/npm/dm/jscpd?color=brightgreen)](https://www.npmjs.com/package/jscpd)\n[![Crates.io Version](https://img.shields.io/crates/v/jscpd?color=green)](https://crates.io/crates/jscpd)\n![NPM License](https://img.shields.io/npm/l/jscpd)\n[![jscpd CI](https://github.com/kucherenko/jscpd/actions/workflows/rust.yml/badge.svg)](https://github.com/kucherenko/jscpd/actions/workflows/rust.yml)\n[![Socket Badge](https://socket.dev/api/badge/npm/package/jscpd)](https://socket.dev/npm/package/jscpd)\n[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/kucherenko/jscpd/badge)](https://scorecard.dev/viewer/?uri=github.com/kucherenko/jscpd)\n[![OpenSSF Best Practices](https://www.bestpractices.dev/projects/14188/badge)](https://www.bestpractices.dev/projects/14188)\n\n> Copy/paste detector for programming source code. 220+ formats, Rust engine, self-contained binary, AI-ready with MCP server and token-efficient reporter.\n\n**Documentation:** https://jscpd.dev\n\njscpd implements the [Rabin-Karp](https://en.wikipedia.org/wiki/Rabin%E2%80%93Karp_algorithm) algorithm to find duplicated code blocks across files.\n\n## Quick Start\n\n```bash\n# macOS / Linux\ncurl -fsSL https://jscpd.dev/install.sh | bash\n\n# Windows (PowerShell)\nirm https://jscpd.dev/install.ps1 | iex\n\n# No install — run once with npx (Node.js)\nnpx jscpd .\n```\n\nThen scan a project:\n\n```bash\njscpd /path/to/code\n```\n\n### Other install methods\n\n| Method | Command | Notes |\n|--------|---------|-------|\n| npm | `npm install -g jscpd` | Installs the `jscpd` command; prebuilt binary, no Node.js at runtime |\n| npm (`cpd` command) | `npm install -g cpd` | Same binary, exposed as `cpd` |\n| Cargo | `cargo install jscpd` | Builds from crates.io; installs both `jscpd` and `cpd` |\n| Homebrew | `brew install jscpd` | macOS / Linux |\n| Nix | `nix run github:kucherenko/jscpd -- /path/to/code` | Or `nix profile install github:kucherenko/jscpd` |\n| Docker | `docker run --rm -v \"$PWD:/src\" ghcr.io/kucherenko/jscpd .` | Multi-arch image built from the release binaries |\n\n### GitHub Action\n\n```yaml\n- uses: kucherenko/jscpd@v5\n  with:\n    threshold: 5\n```\n\nUploads SARIF results to GitHub Code Scanning by default. See [CI & Pre-Commit Hooks](docs/ci-and-hooks.md) for all inputs and outputs.\n\n## Documentation\n\n| Document | Description |\n|----------|-------------|\n| [Rust engine](docs/rust.md) | Installation, CLI reference, reporters, baseline, summary, blame, config file |\n| [AI-Ready](docs/ai-ready.md) | AI reporter, agent skills, MCP server |\n| [Programming API](docs/api.md) | Rust API (`cpd-finder` crate) |\n| [CI & Pre-Commit Hooks](docs/ci-and-hooks.md) | GitHub Action, Docker image, pre-commit hooks |\n| [Packages](docs/packages.md) | npm packages and crates that make up a release |\n| [Supported formats](FORMATS.md) | All 224 formats with their file extensions |\n\n## Features\n\njscpd v5 is a Rust engine that ships as a self-contained binary — no runtime required — under two npm names ([`jscpd`](https://www.npmjs.com/package/jscpd) installs the `jscpd` command, [`cpd`](https://www.npmjs.com/package/cpd) installs `cpd`), on [crates.io](https://crates.io/crates/jscpd), Homebrew, Nix, Docker, and as a GitHub Action.\n\n- **224 language formats** with cross-format detection (Vue SFC, Svelte, Astro, Markdown) and `--cross-formats` groups to match clones across JavaScript and TypeScript\n- **Prebuilt for 8 platforms** — macOS arm64/x64, Linux arm64/x64 (glibc and musl), Windows arm64/x64\n- **15 reporters**: `console`, `console-full`, `json`, `xml`, `csv`, `html`, `markdown`, `badge`, `sarif`, `codeclimate`, `openmetrics`, `ai`, `xcode`, `threshold`, `silent`\n- **Clone baseline** — gate CI on *new* duplication only. `--baseline .jscpd-baseline.json` with `--fail-on-new-clones[=N]` tolerates legacy clones and fails the build on regressions; `--baseline-from-ref origin/main` does the same without a committed file (see [docs](docs/rust.md#baseline))\n- **GitLab-ready reporters** — `codeclimate` (`gl-code-quality-report.json`) and `openmetrics` (`jscpd-metrics.txt`) plug into `artifacts:reports`\n- **Git blame** with side-by-side author comparison (`--blame --reporters console-full`)\n- **`--summary`** — codebase summary: top files and folders by tokens, lines, size, and a complexity estimate — refactoring hotspots straight from the scan (see [docs](docs/rust.md#summary))\n- **`--mcp`** — built-in MCP server over stdio: point your AI assistant at the binary and it can check snippets for duplication against your codebase (see [docs](docs/ai-ready.md#stdio-transport-rust-v5))\n- **AI reporter** — token-efficient output for LLM pipelines (~79% fewer tokens than console)\n- **`--skip-isolated`** — ignore duplication between monorepo folders owned by different teams\n- **`--workers`** — control parallelism for file tokenization and detection (default: all CPU cores)\n- **Config discovery** — `.jscpd.json`, `.config/jscpd.json`, or the `jscpd` key in `package.json`\n\nSee the [Rust docs](docs/rust.md) for the full CLI reference and [`rust/CHANGELOG.md`](rust/CHANGELOG.md) for release notes.\n\n### Looking for v4?\n\njscpd v4 (TypeScript engine, Node.js API, LevelDB/Redis stores) is maintained on the [`master-v4`](https://github.com/kucherenko/jscpd/tree/master-v4) branch and published as `jscpd@4` / the `latest-4` dist-tag. [README-v4.md](README-v4.md) describes it in one page (install, CLI, API, packages, maintenance policy); the same content is at https://jscpd.dev/getting-started/v4.\n\n## Packages\n\n| Package | Registry | Description |\n|---------|----------|-------------|\n| [jscpd](rust/jscpd) | [npm](https://www.npmjs.com/package/jscpd) | Installs the `jscpd` command (prebuilt binary via platform packages) |\n| [cpd](rust) | [npm](https://www.npmjs.com/package/cpd) | Installs the `cpd` command (same binary) |\n| [jscpd-\\<platform\\>](rust/npm) | npm | Platform binary packages pulled in as optional dependencies: `jscpd-darwin-arm64`, `jscpd-darwin-x64`, `jscpd-linux-x64-gnu`, `jscpd-linux-arm64-gnu`, `jscpd-linux-x64-musl`, `jscpd-linux-arm64-musl`, `jscpd-windows-x64-msvc`, `jscpd-windows-arm64-msvc` |\n| [jscpd](rust/crates/cpd) | [crates.io](https://crates.io/crates/jscpd) | CLI crate; installs both `jscpd` and `cpd` binaries |\n| [cpd-core](rust/crates/cpd-core) | [crates.io](https://crates.io/crates/cpd-core) | Detection algorithm (Rabin-Karp rolling hash), data models |\n| [cpd-tokenizer](rust/crates/cpd-tokenizer) | [crates.io](https://crates.io/crates/cpd-tokenizer) | Source code tokenization (224 formats) |\n| [cpd-finder](rust/crates/cpd-finder) | [crates.io](https://crates.io/crates/cpd-finder) | File walking, orchestration, git blame — the library entry point |\n| [cpd-reporter](rust/crates/cpd-reporter) | [crates.io](https://crates.io/crates/cpd-reporter) | Output formatting (15 reporters) |\n\n## Who Uses jscpd\n\nThe `jscpd` npm package is downloaded **10M+ times per month**, and [~5,000 repositories](https://github.com/kucherenko/jscpd/network/dependents) declare it on GitHub's dependents graph.\n\n**Bundled by analysis platforms:**\n\n- [GitHub Super Linter](https://github.com/super-linter/super-linter) — official GitHub linter aggregator, bundles jscpd as its copy/paste detector and runs it by default; 15,500+ workflow files on GitHub reference Super Linter (as of Sep 2026)\n- [MegaLinter](https://github.com/oxsecurity/megalinter) — open-source linter aggregator for CI, ships jscpd in every flavor including `ci_light`\n- [Codacy](https://www.codacy.com/) — automated code analysis platform, jscpd powers the duplication engine\n\n**Explicitly enabled in Super Linter** (`VALIDATE_JSCPD: true`) **by dozens of public repositories, including:**\n\n- [A2A](https://github.com/a2aproject/A2A) — Google's Agent2Agent protocol (25k+ stars)\n- [RimSort](https://github.com/RimSort/RimSort) — mod manager for RimWorld (1.2k+ stars); also runs jscpd directly with its own `.jscpd.json`\n- [Contact Center AI samples](https://github.com/GoogleCloudPlatform/contact-center-ai-samples) — official Google Cloud samples, with a dedicated jscpd config\n- [Drifty](https://github.com/SaptarshiSarkar12/Drifty) — open-source download manager\n\n**Used in notable projects:**\n\n- [OpenClaw](https://github.com/openclaw/openclaw) — personal AI assistant, runs jscpd as a duplication gate in its check scripts\n- [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness) — DeepSeek's plugin harness, jscpd config in CI\n- [degit](https://github.com/Rich-Harris/degit) — Rich Harris's project scaffolder\n- [MEGA webclient](https://github.com/meganz/webclient) — the MEGA.nz web client\n- [Microsoft TypeAgent](https://github.com/microsoft/TypeAgent)\n- [Salesforce DX VS Code](https://github.com/forcedotcom/salesforcedx-vscode)\n- [Alibaba AppWorks](https://github.com/apptools-lab/AppWorks) — embeds jscpd as a library\n- [OVHcloud manager](https://github.com/ovh/manager) — OVHcloud's customer control panel\n- [KiroCrew](https://github.com/kirodotdev/KiroCrew) — self-improving persistent development workspace\n\n## Benchmark\n\nCompared against other copy/paste detectors on the `fixtures/` corpus (547 files, 150+ formats), default thresholds, wall-clock time on Apple Silicon:\n\n| Tool | Time | Files | Clones | Dup Lines |\n|------|------|-------|--------|-----------|\n| jscpd | 84ms | 347 | 212 | 9,133 |\n| jscpd-rs | 111ms | 360 | 222 | 10,317 |\n| Duplo | 162ms | 319 | 518 | 13,049 |\n| Fallow dupes | 164ms | 34 | 10 | 3,137 |\n| Simian | 964ms | 547 | 424 | 15,351 |\n| PMD CPD | 35.980s | 71 | 56 | 2,267 |\n\nMethodology, cross-format detection and AI-token-efficiency comparisons: [benchmark/BENCHMARK.md](benchmark/BENCHMARK.md). Re-run with [`benchmark/benchmark.sh`](benchmark/benchmark.sh).\n\n## AI-Ready Features\n\njscpd integrates into AI-powered workflows through three mechanisms:\n\n### AI Reporter\n\nToken-efficient output for LLM pipelines (~79% fewer tokens than the default console reporter):\n\n```bash\njscpd --reporters ai /path/to/source              # compact clone list\njscpd --reporters ai --summary /path/to/source    # + compact codebase summary\n```\n\n### Agent Skills\n\nTwo installable skills that teach AI coding assistants how to use jscpd and refactor detected duplications:\n\n| Skill | Purpose | Install |\n|-------|---------|---------|\n| [`jscpd`](skills/jscpd/SKILL.md) | Tool reference — CLI options, AI reporter format, config syntax | `npx skills add kucherenko/jscpd --skill jscpd` |\n| [`dry-refactoring`](skills/dry-refactoring/SKILL.md) | Guided refactoring workflow — read clones, choose strategy, apply, verify | `npx skills add kucherenko/jscpd --skill dry-refactoring` |\n\nAfter installation, ask your agent to \"find and fix code duplication\" and it will invoke jscpd with the right options and act on the results.\n\n### MCP Server\n\n`jscpd --mcp /path/to/project` scans once and serves the Model Context Protocol over stdio, so an assistant can check any snippet for duplication against the codebase on demand.\n\nSee [AI-Ready docs](docs/ai-ready.md) for full details.\n\n## Contributing\n\nSee [CONTRIBUTING.md](CONTRIBUTING.md) for the development setup, test policy, and pull request requirements. In short:\n\n```bash\ncd rust\ncargo nextest run --workspace\ncargo clippy --workspace --all-targets -- -D warnings\ncargo fmt --all --check\n```\n\nSecurity issues go through the [security policy](SECURITY.md), not public issues.\n\n## Backers\n\nThank you to all our backers! 🙏 [[Become a backer](https://opencollective.com/jscpd#backer)]\n\n<a href=\"https://opencollective.com/jscpd#backers\" target=\"_blank\"><img src=\"https://opencollective.com/jscpd/backers.svg?width=890\"></a>\n\n## Sponsors\n\nSupport this project by becoming a sponsor. Your logo will show up here with a link to your website. [[Become a sponsor](https://opencollective.com/jscpd#sponsor)]\n\n<a href=\"https://opencollective.com/jscpd/sponsor/0/website\" target=\"_blank\"><img src=\"https://opencollective.com/jscpd/sponsor/0/avatar.svg\"></a>\n<a href=\"https://opencollective.com/jscpd/sponsor/1/website\" target=\"_blank\"><img src=\"https://opencollective.com/jscpd/sponsor/1/avatar.svg\"></a>\n<a href=\"https://opencollective.com/jscpd/sponsor/2/website\" target=\"_blank\"><img src=\"https://opencollective.com/jscpd/sponsor/2/avatar.svg\"></a>\n<a href=\"https://opencollective.com/jscpd/sponsor/3/website\" target=\"_blank\"><img src=\"https://opencollective.com/jscpd/sponsor/3/avatar.svg\"></a>\n<a href=\"https://opencollective.com/jscpd/sponsor/4/website\" target=\"_blank\"><img src=\"https://opencollective.com/jscpd/sponsor/4/avatar.svg\"></a>\n<a href=\"https://opencollective.com/jscpd/sponsor/5/website\" target=\"_blank\"><img src=\"https://opencollective.com/jscpd/sponsor/5/avatar.svg\"></a>\n<a href=\"https://opencollective.com/jscpd/sponsor/6/website\" target=\"_blank\"><img src=\"https://opencollective.com/jscpd/sponsor/6/avatar.svg\"></a>\n<a href=\"https://opencollective.com/jscpd/sponsor/7/website\" target=\"_blank\"><img src=\"https://opencollective.com/jscpd/sponsor/7/avatar.svg\"></a>\n<a href=\"https://opencollective.com/jscpd/sponsor/8/website\" target=\"_blank\"><img src=\"https://opencollective.com/jscpd/sponsor/8/avatar.svg\"></a>\n<a href=\"https://opencollective.com/jscpd/sponsor/9/website\" target=\"_blank\"><img src=\"https://opencollective.com/jscpd/sponsor/9/avatar.svg\"></a>\n\n\n## License\n\n[MIT](LICENSE) © Andrey Kucherenko\n",
  "bytes": 13449,
  "sha": "54b08ae2643c1fe04ec1d6ba03c6bb11fe67459a1bb563c13c2c27f6c05122c0",
  "repo_slug": "kucherenko/jscpd",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/skl_kucherenko_jscpd_jscpd_228de4cd/readme"
}