Skip to content

chore: replace eslint with oxlint - #431

Merged
claude[bot] merged 2 commits into
mainfrom
oxlint
Sep 18, 2026
Merged

claude[bot] merged 2 commits into
mainfrom
oxlint

Conversation

@claude

@claude claude Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

Requested by Samuel Attard · Slack thread

Before: eslint 8 + standard-with-typescript were declared as devDependencies with a legacy .eslintrc.json, but nothing ever ran them; yarn lint was prettier-only.

After: yarn lint runs oxlint --type-aware (via oxlint-tsgolint) and then the existing prettier check, so CI and the pre-commit hook actually lint; eslint and its five plugins/configs are gone.

  • Removed eslint, @typescript-eslint/eslint-plugin, eslint-config-standard-with-typescript, eslint-plugin-import, eslint-plugin-n, eslint-plugin-promise; added oxlint@^1.81.0, oxlint-tsgolint@^7.0.2001. Deleted .eslintrc.json.
  • Added .oxlintrc.json mirroring chore: replace eslint with oxlint github-app-auth-action#174 (correctness category, typescript/import/node/promise/vitest plugins, no-floating-promises, etc.). typescript/no-require-imports is off for spec/** (JSON fixtures) and scripts/** (CommonJS postinstall script); no-non-null-assertion is warn (9 existing sites).
  • Scripts: lint = oxlint + prettier check, new lint:fix; lint-staged now runs oxlint and prettier on staged files (the old entry ran prettier --write **/*.ts, ignoring the staged list).
  • Fixed the real findings: 4 floating promises (void), 7 'x' as 'x' -> as const, unused import/catch bindings, String -> string, require('what-the-diff') -> import with an ambient declaration, a redundant triple-slash reference, an unknown[] template interpolation, and a conditional expect in operations.spec.ts.
  • Test-suite fix surfaced by the linter: afterEach called expect(nock.isDone(), msg) with no matcher, so the "all interceptors used" check never asserted anything. It now .toBe(true) (all 93 tests still pass), and beforeEach awaits robot.load(trop).

Verified locally with yarn lint, yarn build, and yarn test (8 files, 93 tests passing).

Drops vs. standard-with-typescript not carried over: the style-only rules (explicit-function-return-type, strict-boolean-expressions, naming-convention, member-delimiter-style, etc.) since prettier owns formatting here and these were never enforced.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Dp8HUuTkriy2qNUP2GNgcs


Generated by Claude Code

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Dp8HUuTkriy2qNUP2GNgcs
@socket-security

socket-security Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedoxlint-tsgolint@​7.0.20011001009791100
Addedoxlint@​1.81.0991009196100

View full report

@claude
claude Bot marked this pull request as ready for review September 12, 2026 23:56
@claude
claude Bot requested a review from a team as a code owner September 12, 2026 23:56
@claude
claude Bot enabled auto-merge (squash) September 12, 2026 23:56

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good — this is a mechanical lint-toolchain swap (eslint → oxlint) plus the small source fixes it surfaced. Reviewed the .oxlintrc.json config, package.json/lint-staged script changes, the void/as const/import fixes in src/, and the yarn.lock diff (removed eslint packages, added the legitimate oxc-project oxlint/oxlint-tsgolint native-binding packages). Checked the log-util.ts message-join change specifically: `${message}` on an array already calls Array.prototype.join(',') under the hood, so .join(',') is behaviorally identical, not a functional change. The nock.isDone() assertion fix in spec/index.spec.ts is a genuine test-correctness improvement (previously asserted nothing) and the PR author reports all 93 tests still pass.

Extended reasoning...

Overview

This PR replaces the project's (unused) eslint setup with oxlint: deletes .eslintrc.json, adds .oxlintrc.json, updates package.json scripts/devDependencies/lint-staged config, regenerates yarn.lock, and applies the small source-level fixes the new linter surfaced across src/Queue.ts, src/index.ts, src/utils.ts, src/utils/checks-util.ts, src/utils/log-util.ts, typings/ambient.d.ts, and two spec files, plus a trivial vitest.config.ts cleanup.

Security risks

No security-sensitive code paths (auth, crypto, permissions) are touched. The only dependency-security angle is the new oxlint/oxlint-tsgolint devDependencies and their platform-native binding packages in yarn.lock; these match the well-known oxc-project naming/versioning scheme and are devDependencies only (not shipped to production), so risk is low. A socket-security bot comment appeared on the PR timeline (its content wasn't available to this review), but nothing in the lockfile diff looked anomalous.

Level of scrutiny

Config/tooling-only PR with mechanical, easily verifiable source changes (fire-and-forget void, as const literal-type narrowing, dropping unused catch bindings, a require → import swap with an added ambient module declaration, and a template-literal-to-.join change that I confirmed is behavior-preserving for arrays). This warrants a lighter level of scrutiny than a feature/logic PR, and I was able to reason through every functional-looking diff line directly.

Other factors

The test-suite fix (making the dangling nock.isDone() expectation actually assert .toBe(true)) is a real improvement to test rigor, and the PR author states all 93 tests still pass locally, which is consistent with the low-risk nature of the surrounding fixes. No outstanding CHANGES_REQUESTED or unaddressed reviewer objections are indicated in the timeline metadata provided.

Resolves the conflict with #432/#433 (stacked-PR backports) and brings
main's new code under the oxlint rules:

- src/index.ts: keep main's single-PR/stack dispatch in the manual
  backport command and mark both fire-and-forget calls with `void`
  (typescript/no-floating-promises), as the branch did for the
  pre-existing call. Same for the new backportStackToLabel loop.
- src/index.ts: stringify caught errors explicitly in the new log
  templates (typescript/restrict-template-expressions).
- spec/index.spec.ts: drop the unused backportStackToBranch import.
- spec/index.spec.ts: the branch turned the previously inert
  `expect(nock.isDone(), ...)` into a real assertion. Capture
  nock.pendingMocks() before nock.cleanAll() so a failing test cannot
  leak persisted interceptors into later tests, and remove the labels
  interceptor of the stacked-label test, which no code path requests
  for a `labeled` event on a PR targeting the default branch.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Dp8HUuTkriy2qNUP2GNgcs

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@claude
claude Bot merged commit 9e6c61a into main Sep 18, 2026
7 checks passed
@claude
claude Bot deleted the oxlint branch September 18, 2026 07:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants