Skip to content

fix(audits): close guardrail detector gaps and correct guidance from release review - #8571

Merged
waleedlatif1 merged 9 commits into
stagingfrom
fix/guardrail-review-followups
Oct 2, 2026
Merged

waleedlatif1 merged 9 commits into
stagingfrom
fix/guardrail-review-followups

Conversation

@waleedlatif1

Copy link
Copy Markdown
Collaborator

Summary

Fixes the review findings on the release PR that apply to the guardrail and guidance work (#8557, #8559).

Audit detector gaps

  • check:zustand-v5: partialize must be a real property of the options argument, so a comment, state field, or store name containing the word no longer satisfies it; destructured-rest whole-state partializers (({ ...s }) => ({ ...s })) are now caught
  • check:client-boundary: env-flags is matched by resolving the import (relative paths included), and a namespace import of env-flags in client code is refused outright, since its reads (flags.x, flags['x'], destructuring) cannot be enumerated
  • check:utils: .with(i, value) is flagged whenever its second argument is not a function literal, which catches variable indexes while still passing OpenTelemetry's context.with(ctx, () => …)
  • check:application-graph: a guarded prefix counts as alive only if it still contains a runtime module, so leftover .integration.ts, .d.ts, or test-only folders no longer keep a dead guard green
  • check:guidance-refs: wildcard export targets substitute every *, matching Node's resolution

Guidance accuracy

  • babysit: the merge-conflict path now says to rebase onto origin/staging explicitly
  • add-block / add-connector: the canonicalParamId rule matches blocks.test.ts (only a subblock without its own canonicalParamId may not share the id)
  • sim-styling inputClassName example points at a file that uses it; add-settings-page's expected grep matches are exactly what the grep returns; sim-settings-pages names where a section's description actually lives; sim-url-state links back to sim-queries; add-block-preview uses the full path

Type of Change

  • Bug fix

Testing

  • Each detector change proven with throwaway probes: every newly flagged case was missed by the previous script; legitimate look-alikes (real partialize forms, named env-flags imports, OTel context.with callbacks, Drizzle .with) still pass
  • bun run lint, block-registry check, bun run check:audits (58), docs-manifest:check, root bun run test

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

🤖 Generated with Claude Code

@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Oct 2, 2026 7:28pm UTC

Request Review

@greptile-apps

greptile-apps Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Low risk] Updates documentation and guidance rules.

The PR appears safe to merge; no new actionable issue or outstanding previous finding remains.

Summary

The PR tightens audit detectors and corrects developer guidance. Since the previous review, the only changes clarify the ES2023 array-method guidance in its Claude and Cursor copies. No new actionable issue was identified.

Reviews (9) · Last reviewed commit: "chore(guidance): scope the ES2023 tsc gu..."

Comment thread scripts/check-zustand-v5-selectors.ts Outdated
Comment thread scripts/check-zustand-v5-selectors.ts Outdated
Comment thread scripts/check-zustand-v5-selectors.ts Outdated
Comment thread scripts/check-utils-enforcement.ts Outdated
Comment thread scripts/check-utils-enforcement.ts Outdated
Comment thread scripts/check-application-graph.ts

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 18 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread scripts/check-zustand-v5-selectors.ts Outdated
Comment thread .claude/rules/sim-react-performance.md Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

Comment thread scripts/check-utils-enforcement.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 18 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread scripts/check-zustand-v5-selectors.ts
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

Comment thread scripts/check-utils-enforcement.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 18 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread .agents/skills/add-block/SKILL.md Outdated
Comment thread scripts/check-utils-enforcement.ts Outdated
Comment thread scripts/check-zustand-v5-selectors.ts
Comment thread scripts/check-utils-enforcement.ts Outdated
@waleedlatif1
waleedlatif1 force-pushed the fix/guardrail-review-followups branch from eb1c59b to 4322e38 Compare October 2, 2026 17:30
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 20 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread scripts/check-zustand-v5-selectors.ts
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

Comment thread scripts/check-zustand-v5-selectors.ts

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 20 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 force-pushed the fix/guardrail-review-followups branch from 9e4a00d to eb15627 Compare October 2, 2026 18:25
…l .with calls and defaulted partialize params
…nts, fix && partialize false positive

- check:utils drops the ES2023 call-site detector; every tsconfig keeps lib at ES2022 so tsc rejects toSorted/with by type, and the check now fails a tsconfig that raises lib past it (the #5340 cause)
- check:zustand-v5 treats only the right side of && as a returned value
- check:explicit-any counts group-level and bare lint biome-ignore suppressions, and no longer pairs a deleted file with an unrelated new one as a rename
- check:file-names drops its rule-matched rename hint, which pointed new violations at old baseline entries
- check:comment-hygiene skips the parse for files with no possible hit and scans untracked files
- inline the single-consumer source-kind helper and two leftover ref aliases
- CLAUDE.md naming states the check:file-names scope; /ship runs type-check
@waleedlatif1
waleedlatif1 force-pushed the fix/guardrail-review-followups branch from eb15627 to 93ef435 Compare October 2, 2026 18:57
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

Comment thread scripts/check-utils-enforcement.ts

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 30 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread scripts/check-utils-enforcement.ts
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

Comment thread scripts/check-utils-enforcement.ts

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 30 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread .cursor/rules/sim-react-performance.mdc Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 30 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit 24b4957 into staging Oct 2, 2026
33 checks passed
@waleedlatif1
waleedlatif1 deleted the fix/guardrail-review-followups branch October 2, 2026 19:38

This branch was successfully deployed

1 active deployment
Preview — a11e051c Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant