Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
[eslint-miner] eslint-factory: add prefer-structured-clone rule for actions/setup/js #50530
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[eslint-miner] eslint-factory: add prefer-structured-clone rule for actions/setup/js #50530
Changes from all commits
e60e305File filter
Filter by extension
Conversations
Uh oh!
There was an error while loading. Please reload this page.
Jump to
Uh oh!
There was an error while loading. Please reload this page.
There are no files selected for viewing
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
[/tdd] The inline comment on lines 28–30 is misleading: it says "still matched today" but this case is in the
validarray (i.e. it is not flagged). The phrase implies the rule fires on this input, which is the opposite of what happens —JSON.parse(JSON.stringify(obj), reviver)is correctly excluded because the outerparsecall has 2 arguments.💡 Suggested clarification
@copilot please address this.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This comment is self-contradictory: it claims the reviver case is "still matched today" but the test lists it under
valid(i.e., not flagged) — the opposite claim.💡 Details
The outer
JSON.parse(JSON.stringify(obj), reviver)call has two arguments, sonode.arguments.length !== 1triggers an early return in the rule — it is never matched, for a different reason than the comment implies. The comment focuses on the inner stringify call's argument count, but the actual disqualifier here is the outer parse call's secondreviverargument. Clarify the comment to state that the parse call itself is excluded due to its own arg count, rather than saying it is "matched" and excluded downstream.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This matches on the bare identifier name
JSONwith no scope/binding resolution, so a locally shadowed or aliasedJSONwill be falsely flagged and auto-fixed tostructuredClone(...), silently changing runtime behavior.💡 Details
isJsonParseCall/isPlainJsonStringifyCallonly checkcallee.object.name === "JSON"textually, with no scope analysis. If any enclosing scope shadows the globalJSON(e.g. a parameter, destructure, or test double namedJSON), the rule still matches, and because this rule ships an auto-suggestfixer (not just a warning), applying it rewrites to the real globalstructuredClone, which is not equivalent to the shadowed value — actively breaking code rather than just warning about it.Fix: resolve
JSONvia scope (e.g. checkcontext.sourceCode.getScope(node)for a local binding namedJSONand bail out) before reporting/fixing.Uh oh!
There was an error while loading. Please reload this page.