Skip to content

eslint-factory: detect ternary-wrapped env numeric parse assignments in NaN-check rule - #50512

Closed
pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/require-nan-check-after-env-numeric-parse
Closed

pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/require-nan-check-after-env-numeric-parse

Conversation

Copilot AI commented Aug 5, 2026 •

Copy link
Copy Markdown
Contributor

The require-nan-check-after-env-numeric-parse rule missed variables initialized by a conditional expression that wraps the parse call, allowing unvalidated NaN to bypass numeric guards (e.g., file-size checks). This change closes that AST-shape gap while preserving existing behavior for ternary-inside-argument cases.

  • Rule update: handle ConditionalExpression initializers

    • Extended VariableDeclarator tracking to also inspect init when it is a ternary.
    • If either branch (consequent or alternate) is a numeric-parse-from-env call, the declared variable is now tracked as requiring downstream NaN/finite validation.
  • Coverage update: add explicit invalid case

    • Added an invalid test for the wrapped-call pattern:
      • const maxSizeKB = process.env.FOO ? parseInt(process.env.FOO, 10) : 10240;
    • Verifies the rule reports when no NaN/finite check is present.
  • Regression safety: existing supported ternary shape remains valid

    • Kept and preserved behavior for ternary-inside-parse-argument patterns such as:
      • parseInt(process.env.DELAY ? process.env.DELAY : "1000", 10)
// now detected as requiring NaN/finite validation
const maxSizeKB = process.env.FOO
  ? parseInt(process.env.FOO, 10)
  : 10240;

Copilot AI changed the title [WIP] Fix NAN check detection for conditional env parse cases eslint-factory: detect ternary-wrapped env numeric parse assignments in NaN-check rule Aug 5, 2026
Copilot AI requested a review from pelikhan August 5, 2026 07:16
@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Hey @Copilot 👋 — thanks for working on the require-nan-check-after-env-numeric-parse rule enhancement! The plan looks solid and addresses the AST-shape gap for ternary-wrapped env numeric parse assignments.

This PR is currently in draft status with only the initial plan commit. To move forward:

  • Push the implementation — Add the rule update to detect ConditionalExpression initializers (extending VariableDeclarator tracking).
  • Add test coverage — Include the explicit invalid test case for the wrapped-call pattern (const maxSizeKB = process.env.FOO ? parseInt(...) : 10240;) mentioned in the plan.
  • Verify regression safety — Ensure existing ternary-inside-parse-argument patterns remain valid.

Once the code changes are pushed, this should be ready for review. The plan is clear about what needs to be done and why! 🚀

Generated by ✅ Contribution Check · auto · 49.3 AIC · ⌖ 5.05 AIC · ⊞ 8.8K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

require-nan-check-after-env-numeric-parse: ternary-wrapped env parse escapes detection, risking silent bypass of file-size guard

2 participants