[eslint-refiner] ESLint Refiner daily report — 2026-09-29 #64187
Closed
Replies: 1 comment
|
This discussion was automatically closed because it expired on 2026-09-30T05:34:46.847Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
ESLint Refiner — daily report (2026-09-29)
One new issue filed today after grounding a fresh gap in
no-github-request-interpolated-route's Octokit-client detection; one long-standing chronic theory was retired after its 2nd unfixed expiry.Key metrics
#62317/ arithmetic-derived-duration, 2nd expiry)5c74985([docs] docs: unbloat MCP gateway changelog #64145) — 12th consecutive shallow-clone squash artifact; git-log diffing remains unusable for change detectionNew issue: fallback-expression Octokit client aliases bypass detection
no-github-request-interpolated-routeresolves the route argument through alias chains fine (that side was fixed via #49913), but its client-detection side (isOctokitSourceExpression/isIdentifierBoundToOctokitClient) only recognizes single-hop direct aliases —const x = github,const x = getOctokit(...),const x = context.github— exactly what its own test suite covers (lines 242–335). A client bound via a fallback expression (x || github, or a ternary) is invisible to the rule, so a.request()call through it gets zero route-safety analysis regardless of how dynamic the route is.Live grounding detail
actions/setup/js/update_activation_comment.cjs:206-211—const fallbackClient = options.targetGithubClient || github;thenfallbackClient.request("POST /repos/{owner}/{repo}/issues/{issue_number}/comments", {...}). Today's route is a static literal (no live misfire), but the call site currently receives no analysis at all from this rule.actions/setup/js/sub_issue_helpers.cjs:15—return githubClient || github;, the same fallback-client idiom, confirming it recurs in this codebase (this one only reaches.graphql(), out of the rule's scope, but shows the pattern isn't a one-off).Proposed fix: extend the Octokit-source check to recurse into
LogicalExpression.rightandConditionalExpression.consequent/.alternate, mirroring how the route side already recurses intoBinaryExpressionfor string concatenation.Retired theme
#62317(require-invalid-date-check-before-comparearithmetic-derived-duration, recurrence of#60757) expirednot_plannedon 2026-09-28 — its 2nd expiry without a fix landing. Per the established precedent for repeatedly-expired-but-ungrounded-enough-not-to-refile themes (no-json-stringify-equality#57869/#59892,try-catch-rule-utils.ts#57868/#59891), this is now retired from the refiling rotation; it will only be mentioned in future reports, not reopened a 3rd time.Watching for next run
#62560(no-string-fallback-for-non-string-messagealias-FP, recurrence of#60757) is now 7 days old — at the historical ~1-week first-expiry window. If it expires unfixed, that would be its 2nd expiry and it should likewise be retired rather than refiled.#61044,#61543, and now effectively this pattern for expired-not-fixed items too) — this workflow only hascreate_issue/create_discussion/missing_tool/missing_data/noop, noclose_issueor PR-authoring capability, so it cannot close stale issues or submit the long-standingtry-catch-rule-utils.tsVariableDeclaration-suggestion fix itself. Flagging again for a human or PR-capable workflow to pick up.Investigated, no issue filed
no-json-stringify-set-or-map's binding resolution (getConstSetOrMapBindingKind) only tracksconstVariableDeclaratorinitializers — a Set/Map returned from a helper function (loadCustomSafeOutputJobTypes,buildAllowedFieldSet,parseAllowedPullRequests,getRecentCollaborators, etc.) or received as a function parameter (e.g. the ~15-file-widetemporaryIdMapidiom) would escape detection if directlyJSON.stringify'd. Checked every producer function and every Set/Map-typed JSDoc@paramsite for an adjacentJSON.stringifycall — zero live hits. Real structural gap, but ungrounded; not filed, kept as a candidate for re-scanning if the corpus grows a matching call site.Next actions
#62560expiry status at the start of next run.no-caught-error-interpolation,prefer-structured-clone,require-lastindex-reset-before-global-exec-loop,no-empty-catch-block,require-fs-close-sync.try-catch-rule-utils.tssuggestion gap and the close-issue-on-fix gap both need a human or a differently-scoped workflow.All reactions