Repository navigation
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
Hey Current Status
Before marking ready for review, ensure:
Once the code changes are in place, this should be straightforward to review since the scope is narrow and well-defined. Looking forward to it!
|
shell options as shell-enabled in child_process command rule
|
@copilot resolve the merge conflicts on this branch. |
There was a problem hiding this comment.
🟡 Not ready to approve
Restore the deleted workflows and correctly distinguish global from shadowed undefined.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
This review doesn't count toward merge requirements. Sign up for the private preview to control whether Copilot approvals count.
Pull request overview
Updates the ESLint rule to conservatively detect computed shell options.
Changes:
- Treats computed
shellvalues as potentially enabled. - Adds regression coverage.
- Unintentionally deletes three compiled workflows.
File summaries
| File | Description |
|---|---|
no-child-process-interpolated-command.ts |
Updates shell detection; shadowed undefined remains a bypass. |
no-child-process-interpolated-command.test.ts |
Adds computed-shell regression cases. |
notion-issue-summary.lock.yml |
Deletes compiled workflow. |
firewall.lock.yml |
Deletes compiled workflow. |
example-permissions-warning.lock.yml |
Deletes compiled workflow. |
Review details
Suppressed comments (3)
.github/workflows/notion-issue-summary.lock.yml:1
- This deletion is outside the stated rule-and-test scope and removes the compiled Notion Issue Summary workflow while its
.mdsource and status-page link remain. Restore the generated lock file (regenerate it from the source if necessary) so the workflow is not disabled by this lint-rule fix.
.github/workflows/firewall.lock.yml:1 - This deletion is outside the stated rule-and-test scope and removes the compiled Firewall workflow while its
.mdsource and status-page link remain. Restore the generated lock file (regenerate it from the source if necessary) so the workflow is not disabled by this lint-rule fix.
.github/workflows/example-permissions-warning.lock.yml:1 - This deletion is outside the stated rule-and-test scope and removes the compiled permissions example workflow while its
.mdsource and status-page link remain. Restore the generated lock file (regenerate it from the source if necessary) so the workflow is not disabled by this lint-rule fix.
- Files reviewed: 8/271 changed files
- Comments generated: 1
- Review effort level: Balanced
We're testing this review assessment. Please use 👍 or 👎 to tell us if it's correct.
| return prop.value.value === true || typeof prop.value.value === "string"; | ||
| } | ||
|
|
||
| return !(prop.value.type === AST_NODE_TYPES.Identifier && prop.value.name === "undefined"); |
The
no-child-process-interpolated-commandrule only recognized literalshell: trueor string values forspawn*/execFile*, so computedshellexpressions silently bypassed detection. This left common patterns likeshell: process.platform === "win32"unreported even when the command string was interpolated or concatenated.Rule behavior
getShellPropertyValueto treat non-literalshell:values conservatively as possibly shell-enabled.shell: trueandshell: "/bin/sh"still report.shell: falsestill does not report.shell: undefinedstill does not report.Coverage added
shellvalues on shell-conditional methods:shell: isWindowsshell: process.platform === "win32"shell: cond ? true : falseExample
This now reports
interpolatedCommand, matching the rule’s conservative handling of other possibly-shell-enabled option shapes such as spreads.