fix(audits): close guardrail detector gaps and correct guidance from release review - #8571
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
There was a problem hiding this comment.
All reported issues were addressed across 18 files
Reply with feedback, questions, or to request a fix.
Fix all with cubic | Re-trigger cubic
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
All reported issues were addressed across 18 files
Reply with feedback, questions, or to request a fix.
Fix all with cubic | Re-trigger cubic
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
All reported issues were addressed across 18 files
Reply with feedback, questions, or to request a fix.
Fix all with cubic | Re-trigger cubic
eb1c59b to
4322e38
Compare
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
All reported issues were addressed across 20 files
Reply with feedback, questions, or to request a fix.
Fix all with cubic | Re-trigger cubic
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
9e4a00d to
eb15627
Compare
….with rule; unwrap cast partialize
…l .with calls and defaulted partialize params
…whole state as leaks
…nts, fix && partialize false positive - check:utils drops the ES2023 call-site detector; every tsconfig keeps lib at ES2022 so tsc rejects toSorted/with by type, and the check now fails a tsconfig that raises lib past it (the #5340 cause) - check:zustand-v5 treats only the right side of && as a returned value - check:explicit-any counts group-level and bare lint biome-ignore suppressions, and no longer pairs a deleted file with an unrelated new one as a rename - check:file-names drops its rule-matched rename hint, which pointed new violations at old baseline entries - check:comment-hygiene skips the parse for files with no possible hit and scans untracked files - inline the single-consumer source-kind helper and two leftover ref aliases - CLAUDE.md naming states the check:file-names scope; /ship runs type-check
eb15627 to
93ef435
Compare
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
All reported issues were addressed across 30 files
Reply with feedback, questions, or to request a fix.
Fix all with cubic | Re-trigger cubic
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
All reported issues were addressed across 30 files
Reply with feedback, questions, or to request a fix.
Fix all with cubic | Re-trigger cubic
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
Summary
Fixes the review findings on the release PR that apply to the guardrail and guidance work (#8557, #8559).
Audit detector gaps
check:zustand-v5:partializemust be a real property of the options argument, so a comment, state field, or store name containing the word no longer satisfies it; destructured-rest whole-state partializers (({ ...s }) => ({ ...s })) are now caughtcheck:client-boundary: env-flags is matched by resolving the import (relative paths included), and a namespace import of env-flags in client code is refused outright, since its reads (flags.x,flags['x'], destructuring) cannot be enumeratedcheck:utils:.with(i, value)is flagged whenever its second argument is not a function literal, which catches variable indexes while still passing OpenTelemetry'scontext.with(ctx, () => …)check:application-graph: a guarded prefix counts as alive only if it still contains a runtime module, so leftover.integration.ts,.d.ts, or test-only folders no longer keep a dead guard greencheck:guidance-refs: wildcard export targets substitute every*, matching Node's resolutionGuidance accuracy
origin/stagingexplicitlycanonicalParamIdrule matchesblocks.test.ts(only a subblock without its owncanonicalParamIdmay not share the id)inputClassNameexample points at a file that uses it; add-settings-page's expected grep matches are exactly what the grep returns; sim-settings-pages names where a section's description actually lives; sim-url-state links back to sim-queries; add-block-preview uses the full pathType of Change
Testing
partializeforms, named env-flags imports, OTelcontext.withcallbacks, Drizzle.with) still passbun run lint, block-registry check,bun run check:audits(58),docs-manifest:check, rootbun run testChecklist
test-auditauthoring gate)🤖 Generated with Claude Code