PSComplexity

0.5.2

Cyclomatic and cognitive complexity for PowerShell. Cognitive complexity implements the SonarSource metric in full (nesting-aware -- the better signal for "hard to understand"), scoring every reference example exactly as published, and extends it for PowerShell constructs the specification does not cover: ForEach-Object and Where-Object, the && and || pipeline chains,
Cyclomatic and cognitive complexity for PowerShell. Cognitive complexity implements the SonarSource metric in full (nesting-aware -- the better signal for "hard to understand"), scoring every reference example exactly as published, and extends it for PowerShell constructs the specification does not cover: ForEach-Object and Where-Object, the && and || pipeline chains, and ?? and ??=. Measures per unit (function/filter, class method/constructor, initialised class property, + script body) via the PowerShell AST; ships a Test-PSComplexity gate for CI.
Show more

Minimum PowerShell version

7.0

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Module -Name PSComplexity

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

Install-PSResource -Name PSComplexity

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

(c) Fortigi. MIT licensed.

Package Details

Author(s)

  • Fortigi

Tags

complexity cyclomatic cognitive code-quality ast metrics maintainability lint ci

Functions

Measure-PSComplexity Test-PSComplexity

PSEditions

Core

Dependencies

This module has no dependencies.

Release Notes

0.5.2: **The SARIF log is now accepted by GitHub Advanced Security for Azure DevOps, and the README shows how to run the gate on Azure Pipelines.** Checked with the SARIF validator's Azure DevOps and GitHub Advanced Security rule sets, the log failed two rules and now passes them: the tool carries a `fullName` (name and version), which Azure DevOps requires, and each rule carries a `help` text, which GitHub Advanced Security requires. Nothing else in the log changed -- same rules, same results, same fingerprints -- so existing alerts are not reopened. One rule is left failing on purpose: the log carries no `automationDetails`, i.e. no category. On GitHub a category in the file overrides the one the upload step names, so writing one would make two PSComplexity uploads in one repository replace each other. **On Azure DevOps, set `Category` on `AdvancedSecurity-Publish@1`**; that is where it comes from. New in the README, with a complete `examples/azure-pipelines.yml`: the gate on Azure Pipelines, publishing the SARIF to Advanced Security or -- without it -- to the *SARIF SAST Scans Tab* extension, why the publishing step needs `condition: succeededOrFailed()`, and how to gate a pull request on the files it changed when Azure Pipelines checks out shallow and detached. **Three internal lookups return an empty array rather than `$null`.** PowerShell unrolls a returned collection, so an empty result reached the caller as `$null` and a single result as a bare item, although one of them documented the opposite. Every caller iterated with `foreach`, which forgives both, so no measurement was ever wrong; a future caller using a pipeline would have run its body once over `$null`. No score moves and no command changed. Full changelog: https://github.com/Fortigi/PSComplexity/blob/main/CHANGELOG.md

FileList

Version History

Version Downloads Last updated
0.5.2 (current version) 8 10/10/2026
0.5.1 816 8/28/2026
0.5.0 31 8/27/2026
0.4.0 5 8/27/2026
0.3.0 22 8/22/2026
0.2.0 11 8/17/2026
0.1.0 703 7/3/2026
Show more