[eslint-refiner] ESLint Refiner Daily Report — 2026-09-26 #63567
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by ESLint Refiner. A newer discussion is available at Discussion #63782. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Overview
Daily refinement pass over the 62 registered
gh-aw-customESLint rules ineslint-factory, grounded against the live corpus inactions/setup/js/**. Today's angle: cross-referenced all 62 rule names against the full run history and foundrequire-escaped-regexp-interpolationhad never been reviewed — a first audit surfaced a real, broadly-applicable gap with 5 of 6 live occurrences already needing manualeslint-disable-next-lineworkarounds.Key metrics
require-escaped-regexp-interpolationregex-fragment-constant recognition gap8f0d376([docs] docs: unbloat GitHub Actions primer #63530) — 9th consecutive all-insertions shallow-clone squash artifact; git-log-based change detection remains unusable in this repoToday's finding: require-escaped-regexp-interpolation
This rule requires values interpolated into a
new RegExp()template literal to be passed through a regex-escaping helper first (guards against unintended matches / ReDoS with attacker-controlled input). It correctly recognizes escape-helper calls, the canonical.replace(/[.*+?^${}()|[\]\\]/g, "\\$&")form,escaped-prefixed names, and safe literal constants — but has no path to recognize a deliberately-authored regex-fragment constant (aconstwhose value is itself valid regex syntax, e.g. a character class meant to be composed into a larger pattern).Live grounding detail
sanitize_content_core.cjs:305URL_AUTHORITY_CHARsanitize_content_core.cjs:338URL_START_DELIMITERSsanitize_content_core.cjs:541URL_START_DELIMITERSsanitize_content_core.cjs:691fc,fenceLenmodel_aliases.cjs:41VERSION_SUFFIX_PATTERNglob_pattern_helpers.cjs:75regexPatternhandle_agent_failure.cjs:71AWF_API_PROXY_HOST_RE_SOURCE5 of 6 sites already carry hand-written disable comments with nearly identical rationale — strong signal the team already treats this as a known false-positive class. The 6th (
handle_agent_failure.cjs:71, buildingCOPILOT_ORG_BILLING_ERROR_RE) is structurally identical but has no suppression at all, meaning it currently sits as an untriaged warning (the rule iswarn, noterror, so it doesn't fail CI).Filed issue proposing the rule recognize a regex-fragment naming convention (
_PATTERN/_RE/_RE_SOURCE/_CHAR/_DELIMITERSsuffixes, mirroring the existingescaped-prefix convention) and/or well-formed-regex-source literal detection. This would close the live gap and let all 5 manual disable comments be removed.Also investigated and ruled out: bare
RegExp(...)calls withoutnew(same visitor gap — the rule only listens forNewExpression— but zero live occurrences in the corpus, so not filed per the workflow's ungrounded-theory policy).Chronic / carried items (unchanged, no action needed)
Tracking notes
require-invalid-date-check-before-compare, created 2026-09-21) and #62560 (no-string-fallback-for-non-string-message, created 2026-09-22) remain open; both are approaching their typical ~1-week first-expiry window based on prior recurrences in this series.require-fetch-response-body-try-catchchain-unwrap gap) filed 2026-09-25, still open.try-catch-rule-utils.ts's sharedVariableDeclaration-suggestion gap (affects ~14 fs-sync/child-process rules,#57868/#59891) andno-json-stringify-equality's indirect-variable gap (#57869/#59892). Both require a source-level fix this workflow cannot submit (no PR-capable safe-output) — flagging again for a human or PR-capable workflow to pick up.#61044, and therequire-spawnsync-error-checkfix behind the (now-closed)#61543history. This workflow has noclose_issue/add_commentsafe-output to reconcile that — needs a human or PR-capable workflow pass.core-method-resolve.ts's multi-hop alias-chain theory (would affect 7 consumer rules) remains a real but ungrounded structural gap after 3 dedicated checks — retained as latent-only.Next actions
#62317and#62560for expiry over the next few days; refile as 2nd-generation recurrences only if they expire still-unfixed.try-catch-rule-utils.tsandno-json-stringify-equalitysource-level gaps directly via a PR.All reactions