improvement(audits): enforce console, helper, render-path, persist, and deployment-flag rules - #8559
Conversation
Runtime code logs through createLogger from @sim/logger. Scripts, CLIs, script-migrations, the logger itself, SDK examples, and tests keep console as their interface. Autofix is disabled so lint --unsafe never silently deletes a console call.
…cate idioms with @sim/utils helpers
…nd width useRef(new X()) built a throwaway X on every render; the refs now lazy-init through ??= as sim-react-performance.md prescribes. Equal h-N w-N pairs become size-N per sim-styling.md.
Adds toError, isRecordLike, filterUndefined, omit, truncate, and escapeRegExp idioms from CLAUDE.md, plus render-path rules: ES2023 array methods in browser code, useRef(new X()), and h-N w-N pairs.
…persist sim-stores.md requires persist to whitelist durable fields; check:zustand-v5 now fails on a persist with no partialize or one that spreads the whole state. canvas-mode was the one store without it.
…t settings surfaces check:client-boundary now fails when a 'use client' module under the workspace, organization, or standalone settings surfaces imports isHosted, isBillingEnabled, isChatEnabled, or an enterprise feature flag from env-flags instead of reading the seeded deployment shape.
…al prefilters The h-N/w-N, toError, and truncate patterns backtrack from every word boundary; a cheap literal test per file keeps the scan at ~1s of CPU.
…missed Allocate Map/Set ref containers once instead of on every render, and drop the redundant processedRemovalIds alias in the toast provider.
…yment-shape rule - check:utils: match useRef(new X()) with nested generics, honor utils-lint-allow above formatter-wrapped statements, drop h-screen/w-screen from the size-N rule, and skip server-only App Router files in the ES2023 rule - deployment-shape rule: cover stores/, hooks/, blocks/ and surface hooks, read namespace imports, derive the flag list from deployment-shape.ts, parse long import clauses whole, and allowlist the panel store's module-init isChatEnabled - zustand persist message names the hoisted-options escape - biome: allow console in *.integration.ts, *.spec.ts, and desktop e2e
…k:utils - move leadingDirective/directiveOn into scripts/source-kind.ts; check:utils uses it instead of its own 'use client' regex, and multi-line block-comment headers now parse - replace the deployment-shape allowlist with a client-boundary-allow annotation on the panel store's isChatEnabled import - exempt all of packages/utils/src by prefix (drops the stale retry.test.ts entry) - build both truncate patterns from one shared fragment and prefilter - add literal prefilters to isRecordLike, fromEntries, and useRef patterns and memoize prefilter results per file - trim the deployment-shape rationale to a CLAUDE.md pointer
…els directly useSpeechToText returns its stable, in-place-filled Float32Array instead of a nullable ref; MicButton and the composer, search, and user-input props follow.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
There was a problem hiding this comment.
All reported issues were addressed across 118 files
Reply with feedback, questions, or to request a fix.
Fix all with cubic | Re-trigger cubic
…state partialize, strip inline directive comments
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
All reported issues were addressed across 122 files
Reply with feedback, questions, or to request a fix.
Fix all with cubic | Re-trigger cubic
…== for filterUndefined, state the .with scope
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
Summary
Enforces written rules that no check covered, without adding scripts: every rule is a Biome rule or a pattern in an existing audit, and every existing violation is fixed (no baselines).
noConsole(Biome, error, no autofix) for runtime code; off where console is the interface (scripts/, tests, CLIs, script migrations, the logger itself, SDK examples). Runtime hits now usecreateLogger(docs routes, OTEL exporter); two justifiedbiome-ignores (the hydration handler wrapsconsole.error; the test-env skip notice must reach the runner)check:utilsnow bans the inline forms oftoError,isRecordLike,omit/filterUndefined, conditionaltruncate, and theescapeRegExpregex; 21 files moved to the shared helpers (identical semantics). Allow annotations now work above formatter-wrapped statementscheck:utils: ES2023 array methods (toSortedetc.) on client paths (server-only route/metadata files excluded), non-lazyuseRef(new X())incl. nested generics (≈38 sites moved to the(ref.current ??= new X())idiom), and equalh-N w-N→size-N(85 pairs; same CSS)check:zustand-v5:persistwithout apartializewhitelist (canvas-mode store fixed; persisted shape unchanged)check:client-boundary: deployment-shape flags read fromenv-flagsin client code ('use client'surfaces,stores/,hooks/,blocks/, namespace imports), flag list derived fromdeployment-shape.ts. The one existing exception,stores/panel/store.tsreadingisChatEnabledat module init, carries a// client-boundary-allow:reason (needs a product decision)Type of Change
Testing
bun run lint,bunx turbo run type-check,bun run check:audits, rootbun run test; vitest on every touched area (home/stream, use-chat, composer, mcp oauth, workflow-diff, tables, browser-session, sim-cli, desktop, emcn)scripts/source-kind.tsdirective classifier is used by both client-path checks; the one exception (stores/panel/store.tsreadingisChatEnabledat module init) uses the script's existing// client-boundary-allow:annotation. Two independent audits plus a /simplify pass: every helper swap is semantically identical; everyuseRefconversion has no reassignment, no pre-init read, and unchanged identity (children receiving a stableMapinstead of a ref);size-*compiled with Tailwind 4 to identical CSSChecklist
test-auditauthoring gate)🤖 Generated with Claude Code