Skip to content

chore(lint): use the shared config's turbo, tooling wiring and import policy - #140

Merged
Mearman merged 4 commits into
mainfrom
chore/eslint-overhaul
Oct 3, 2026
Merged

Mearman merged 4 commits into
mainfrom
chore/eslint-overhaul

Conversation

@Mearman

@Mearman Mearman commented Oct 3, 2026

Copy link
Copy Markdown
Member

Turning on the options @exadev/eslint-config already offers found real problems, fixed in this PR as separate commits:

  • The build and typecheck turbo tasks read tsconfig.build.json and tsconfig.lint.json but listed only tsconfig.json as an input, so editing either restored a stale cached result.
  • The coverage thresholds sat under a global key vitest does not read, so they enforced nothing. They are now floors at the measured coverage, and the excludes match at any depth.
  • Nothing checked the package shape before a release. prepublishOnly now runs publint and attw (ESM-only profile), the repository URL uses the git+ form publint asks for, and the public test script delegates to turbo like the others. The redundant test:run script is gone and vitest watch mode moves to test:watch, which CONTRIBUTING already named.
  • An import policy keeps test helpers and src/test-support out of shipped code.

The shared config's root tooling check cannot hold together with the turbo script convention for knip, so it is off with the reason in the config; reported as ExaDev/eslint-config#110.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-10-03T08:39:55.261771Z 2817540 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

…to turbo

The package shape was never checked before a release. prepublishOnly now
runs publint and attw, and the repository URL uses the git+ form publint
asks for. The public test script now delegates to turbo like the others,
the redundant test:run script is gone, and vitest in watch mode moves to
test:watch, which CONTRIBUTING already referred to.
The tasks read tsconfig.build.json and tsconfig.lint.json through tsc
but listed only tsconfig.json as an input, so editing either restored a
stale cached result.
The thresholds sat under a global key vitest does not read, so they
enforced nothing, and the exclude list used bare directory names that
miss nested copies. The floors are the measured coverage rounded down,
and the excludes match at any depth.
… policy

Turns on the turbo script and cache rules, the publish-time tooling
checks and hooks check, and an import policy that keeps test helpers out
of shipped code. The root tooling check is off because it cannot hold
together with the turbo convention for knip.
@Mearman
Mearman force-pushed the chore/eslint-overhaul branch from 597f7e2 to 2817540 Compare October 3, 2026 08:36
@Mearman

Mearman commented Oct 3, 2026

Copy link
Copy Markdown
Member Author

@codex security review

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review

Security review completed. No security issues were found in this pull request.

Reviewed commit: 281754003d

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@Mearman
Mearman merged commit cbb855d into main Oct 3, 2026
22 checks passed
@Mearman
Mearman deleted the chore/eslint-overhaul branch October 3, 2026 08:42
@Mearman

Mearman commented Oct 3, 2026

Copy link
Copy Markdown
Member Author

🎉 This PR is included in version 1.41.4 🎉

The release is available on:

Installation

npm install -g markmv@1.41.4

Security & Supply Chain

✅ OIDC Trusted Publishing: published from CI with no long-lived npm token
✅ SBOM: Software Bill of Materials included in release
✅ NPM Provenance: Published with npm provenance attestations

Test Coverage

This release includes comprehensive test coverage reports. View coverage details in the release assets.

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant