[eslint-refiner] ESLint Refiner daily report - 2026-09-23 #62880
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by ESLint Refiner. A newer discussion is available at Discussion #63108. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
ESLint Refiner — daily report (2026-09-23)
Overview: disciplined 0-issue run. The day's only open-issue expiry (
#61044) turned out to be a genuine upstream fix rather than routine bot housekeeping, and a second, previously-unfiled latent finding was independently confirmed fixed too. One new structural theory was explored across 7 rules sharing a common utility but found zero live grounding, so it was documented rather than filed.Key metrics
eslint-factory-labeled issues: 6 (down from 7;#61044dropped off — confirmed fixed, not just expired)What changed upstream
prefer-actions-exec-over-child-process(#61044fixed): the rule now has an explicitrequiresShimCjs()early-return that exempts files requiring./shim.cjs(which only polyfillscore/context, never@actions/exec'sexecglobal) — with 2 new dedicated test cases. This directly fixes the dual-mode false-positive flagged back on 2026-09-15.require-http-response-error-listener: the addListener-as-alias-for-.on()andreq.on("response", cb)chained idiom (flagged 2026-09-09) is also already handled in current source (LISTENER_METHODSincludesaddListener;getResponseEventCallbackwalks the chained form). All 4 live call sites in the corpus (handle_agent_failure.cjs:1847,mcp_cli_bridge.cjs:248,start_mcp_gateway.cjs:560,mount_mcp_as_cli.cjs:245) are correctly guarded.New theory investigated (not filed — zero live grounding)
core-method-resolve.tsmulti-hop alias-chain gap — shared by 7 consumer rules:no-core-error-then-process-exit,no-core-error-then-process-exitcode,no-core-error-then-setfailed,no-core-exportvariable-non-string,no-core-setoutput-non-string,no-setfailed-then-exit-zero,require-return-after-core-setfailed.isCoreAliasIdentifier()'s variable branch resolves exactly one hop of aliasing back to a directcorebinding or a JSDoc-annotated DI parameter (e.g.const c = core;orconst c = coreArg;both work). A second hop —const a = core; const b = a; b.setFailed(...)— is not recognized, because the intermediateais aVariabledef, not aParameter, so the JSDoc slow-path check fails.This is a real structural limitation with a wide blast radius (7 rules), but grepping the full non-test corpus found zero occurrences of even single-hop
const x = core;-style aliasing — the codebase either referencescoredirectly or uses the JSDoc DI-parameter pattern (7 files) without further re-aliasing. Retained as a documented latent theory in repo-memory; will only be worth filing if a live single-hop alias appears first.Chronic gaps reconfirmed unchanged (2+ expiries — not refiled, needs a source PR)
try-catch-rule-utils.ts:SAFE_WRAPPABLE_STATEMENT_TYPESstill only coversExpressionStatement/ReturnStatement, so aVariableDeclarationstatement (e.g.const x = fs.readFileSync(...)) gets no wrap-in-try-catch suggestion. Affects ~14 fs-sync/child-process-family rules. Twice filed and expired (#57868/#59891).no-json-stringify-equality: still requires both operands of===/!==to be directJSON.stringify(...)calls; comparing via an intermediate variable escapes detection. Twice filed and expired (#57869/#59892).Both require a source-level fix beyond this workflow's
create_issue/create_discussioncapabilities (nocreate_pull_requestsafe-output available) — flagging here for a human or PR-capable workflow to pick up.Still-open issues (no fresh expiries today)
#62560—no-string-fallback-for-non-string-message: alias type-narrowing false positive#62317—require-invalid-date-check-before-compare: arithmetic-derived duration recurrence#61543—require-spawnsync-error-check:CHILD_PROCESS_OBJECTSalias gap#61542—require-fetch-response-body-try-catch: chain-unwrap gap#61285—require-error-code-in-thrown-error:ERROR_CODE_PATTERNvocabulary mismatch#61284—require-error-code-in-thrown-error: nested-alias bypassNext actions
#61044proves an expiry can mean a real fix landed, not just bot housekeeping.core-method-resolve.tsmulti-hop alias theory only if a live single-hopcorealias appears in the corpus.try-catch-rule-utils.ts,no-json-stringify-equality) need a source PR from a workflow with write access — this workflow will keep flagging them in reports rather than re-filing a 3rd time.Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
api.anthropic.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.
All reactions