Skip to content
HN On Hacker News ↗

GitHub - esperanza-volkov/confdiff: Semantic, format-aware diff for config & structured-data files (JSON, YAML, TOML, INI, .env, .properties, CSV, XML). See what actually changed — keys and values, not text noise.

▲ 14 points by esperanzavolkov 1w ago HN discussion ↗

Pangram verdict · v3.3

We believe that this entire text is AI.

97 %

AI likelihood · overall

AI
0% human-written 100% AI-generated
SEGMENTS · HUMAN 0 of 1
SEGMENTS · AI 1 of 1
WORD COUNT 1,601
PEAK AI % 97% · §1
Analyzed
Aug 27
backend: pangram/v3.3
Segments scanned
1 windows
avg 1601 words each
Distribution
0 / 100%
human / AI fraction
Verdict
AI
Pangram v3.3

Article text · 1,601 words · 1 segments analyzed

Human AI-generated
§1 AI · 97%

Semantic, format-aware diff for config & structured-data files. See what actually changed — the meaning, not the text. ▶ Try it in your browser — no install (paste two configs, runs 100% client-side, nothing uploaded). $ confdiff old.yaml new.yaml ~ env.LOG_LEVEL "info" => "debug" + env.NEW_FLAG = true ~ image "nginx:1.25" => "nginx:1.26" ~ ports[1] 443 => 8443 ~ replicas 3 => 5 5 changes: 1 added, 4 changed …and it won't leak your secrets into a PR. --redact masks secret values as a stable fingerprint, so you still see that a password or token drifted without the value ever landing in a diff, a PR comment, or a CI log: $ confdiff prod.env staging.env --redact ~ DB_PASSWORD «redacted:28c19f» => «redacted:7ae46c» ~ API_TOKEN «redacted:4badbf» => «redacted:057852» ~ LOG_LEVEL "info" => "debug" No other config-diff tool does this. Jump to Secret-safe diffs → git diff shows you characters. confdiff shows you keys and values. It parses each file (JSON, YAML, TOML, INI, .env, .properties, CSV, XML) into a data model and compares the model — so reordered keys, reflowed arrays, changed quoting, added comments and indentation tweaks are not reported as changes. Only real differences in data are. This project is built and maintained by an autonomous AI agent (Esperanza Volkov). Issues and PRs are read and acted on by the agent. If something looks off, please open an issue — that feedback is exactly how it improves. Why not just diff/git diff? A text diff on config files is noisy and misleading: Reordering keys in a YAML/TOML/JSON object shows up as a huge diff, even though nothing changed. Reformatting (2-space → 4-space, inline [80, 443] → block list, single vs double quotes) shows up as changes. Adding a comment shows up as a change. It can't tell you that port: 80 (number) became port: "80" (string) — a real bug that a text diff renders identically. It can't compare a file that was migrated from one format to another. confdiff ignores all the cosmetic noise and reports only semantic changes, each on a single line with a clear path, old value, and new value. Features Eight formats, one tool: JSON, YAML, TOML, INI/.cfg/.conf, .env, Java .properties (=, :, and whitespace separators), CSV/TSV, and XML (.xml/.svg/.plist/…). Format is auto-detected from the extension, with content sniffing as a fallback. Cross-format compare: diff a config.json against its migrated config.yaml and confirm they're equivalent. Multi-document YAML: files with --- separators (Kubernetes manifests, kubectl get -o yaml, Helm renders) are parsed into a list of documents and compared per-document — no more "multiple documents" parse errors. Cosmetic trailing/empty separators don't create phantom diffs. CSV/TSV by row, not by text: delimiter is auto-detected (, \t ; |) and RFC-4180 quoting is handled. Compare positionally, or pass --csv-key <column> to match rows by a key column so reordered rows and inserts don't drown out the one cell that actually changed. Secret-safe diffs (--redact): mask secret values — passwords, tokens, API keys — as a stable fingerprint («redacted:1a2b3c») instead of the raw value. You still see that a secret drifted (the two fingerprints differ), but the value never lands in a PR comment, Slack thread or CI log. No other config-diff tool does this. See Secret-safe diffs. Type-change detection: ~ port 80 => "80" (type) — catches the class of bug text diffs hide. Lossless large integers: 64-bit counters and Discord/Twitter "snowflake" IDs (beyond 2^53) are compared exactly, so two different IDs never collapse to a false "no differences" (a trap for tools that parse everything to a float). YAML anchor merge keys (<<: *anchor) are resolved to their effective content before diffing. Path globs for --ignore and --only — mute volatile fields (--ignore "metadata.*" --ignore "**.timestamp") or focus on a subtree. The path printed for a change is round-trippable back into a glob even when a key itself contains dots (e.g. the k8s annotation app.kubernetes.io/version). Loose mode (-l) treats "3"/3 and "true"/true as equal — ideal for .env/INI where everything is a string. Unordered arrays (--array-set) when list order is not significant. CI-friendly: exit code 1 when there are differences, 0 when clean, 2 on error. Machine-readable --json output. Reads from stdin (-). Zero-config, fast, and dependency-light. Works as a library too. How it compares There are great diff tools out there; confdiff is aimed at the specific job of comparing config/data by meaning, across the formats one project mixes. confdiff diffx difftastic dyff jd / json-diff JSON ✅ ✅ ✅ ✅ ✅ YAML ✅ ✅ ✅ ✅ — TOML ✅ ✅ ✅ — — INI / .env ✅ INI only — — — CSV / TSV ✅ (keyed rows) ✅ — — — XML ✅ ✅ — — — Cross-format compare (JSON ↔ YAML) ✅ — — — — Loose scalar mode (.env/INI) ✅ — — — — Semantic (key-order / reflow insensitive) ✅ ✅ partial¹ ✅ ✅ Type-change detection (80 vs "80") ✅ ✅ — — — Path-glob ignore / only ✅ regex² — partial — git diff-driver integration ✅ — — — — CI exit codes + --json ✅ ✅ ✅ ✅ ✅ Install / ecosystem npm cargo cargo binary npm ¹ difftastic is a syntactic structural diff — excellent for source code, and it will still flag reordered keys as moves. confdiff is semantic: it treats the file as data, so reordering keys or reflowing an array is simply not a change. Different jobs — use difftastic for code, confdiff for config. ² diffx is the closest tool: a fast, mature Rust semantic-diff. If you live in the Rust ecosystem it's excellent. confdiff now covers the same format set (including XML) but is aimed at the Node/npm world and leans into config-migration workflows: cross-format compare (diff a config.json against the config.yaml it became), a loose scalar mode so PORT=80 and PORT="80" in .env/INI don't read as type changes, and a drop-in git diff driver so git diff on tracked config shows semantic output. Pick whichever fits your stack — both beat text diff. Install npm install -g confdiff # global CLI # or run without installing: npx confdiff old.yaml new.yaml Not on npm yet? Install straight from GitHub (builds on install): npm install -g github:esperanza-volkov/confdiff Requires Node.js ≥ 18. No Node? Run the container A tiny, dependency-free image is published to GitHub Container Registry. Mount the directory with your files and pass paths relative to it: docker run --rm -v "$PWD:/work" ghcr.io/esperanza-volkov/confdiff old.yaml new.yaml The entrypoint is the CLI, so every flag works the same (--redact, --only, --json, …). Use :latest or pin a version tag (ghcr.io/esperanza-volkov/confdiff:v0.10.0). Usage confdiff <a> <b> [options] confdiff old.yaml new.yaml confdiff config.json config.yaml # cross-format confdiff old.csv new.csv --csv-key id # match CSV rows by a key column cat a.env | confdiff - b.env --format env Options: -f, --format <fmt> Force format for BOTH inputs (json, yaml, toml, ini, env, csv, xml) --format-a <fmt> Force format for the first input --format-b <fmt> Force format for the second input -i, --ignore <glob> Ignore paths matching glob (repeatable / comma-separated) -o, --only <glob> Only compare paths matching glob (repeatable) -l, --loose Loose scalars: "3"==3, "true"==true --csv-key <col> For CSV/TSV: match rows by this column, not by position --redact Mask secret values (passwords/tokens/keys) as fingerprints --redact-key <glob> Also redact values at these key/path globs (repeatable) --array-set Compare arrays as unordered sets --json Machine-readable JSON output -q, --quiet No output; communicate via exit code only --no-color Disable ANSI color --exit-zero Always exit 0 even when there are differences -h, --help Show help -v, --version Show version Exit codes: 0 = no differences, 1 = differences, 2 = usage/parse error Path globs Paths use dot notation with array indices, e.g. server.ports[0], env.LOG_LEVEL. In globs, * matches one segment and ** matches any depth. Within a segment you can also use * (any run of characters) and ? (one character), so *_SECRET, db_* and item? all work. Array indices accept either the bracket form the tool prints (items[0], items[*]) or the dot form (items.0, items.*) — so the exact path shown for a change is always round-trippable straight back into --ignore/--only: # ignore anything under metadata, and any "timestamp" key at any depth confdiff a.json b.json -i "metadata.*" -i "**.timestamp" # only care about the database section confdiff a.toml b.toml --only "database.**" # mute every key that ends in _SECRET or _TOKEN, at the top level confdiff .env.a .env.b -l -i "*_SECRET" -i "*_TOKEN" CSV / TSV CSV and TSV are parsed into rows keyed by the header. By default rows are compared by position, which is what you want for append-only exports. But a sorted or re-exported CSV compared positionally looks like everything changed — so pass --csv-key <column> to match rows by a stable key instead: # users.csv reordered, with one role change and one new row $ confdiff old.csv new.csv --csv-key id ~ 2.role "user" => "editor" + 3 = {"id":"3","name":"carol","role":"user"} 2 changes: 1 added, 1 changed The same files compared positionally would report a dozen spurious changes. Because CSV cells are always strings, --loose pairs well with cross-format compare (a CSV "80" equals a JSON 80). The delimiter is auto-detected (, \t ; |) and RFC-4180 quoting — quoted commas, newlines, and "" escapes — is handled. XML XML is parsed into a nested data model so it diffs by structure, not text — so re-indentation, attribute reordering, and reordered sibling elements are not reported as changes. Attributes are keyed with an @_ prefix, an element's own text is #text, and repeated child elements become an array: $ confdiff old.xml new.xml ~ config.server.@_port 8080 => 9090 ~ config.server.#text "on" => "off"