Repository navigation
Conversation
The rule was disabled with a TODO to re-enable once oxlint supported inline
disable for jsPlugin rules. oxlint 1.57 supports it (verified: a `new RegExp`
line errors, the same line with `// oxlint-disable-next-line
sdk/no-regexp-constructor` is suppressed), so re-enable it (`off` -> `error`).
The rule guards against `RegExp` construction from unsafe/user input (ReDoS).
Both pre-existing uses are constant patterns, not user input:
- debugsymbolicator.ts: refactored the static `new RegExp([...].join('|'))` to
an equivalent regex literal (same source and flags, verified) — no suppression
needed.
- sentryMetroSerializer.ts: kept `new RegExp` with a justified inline disable; it
builds the matcher from the shared DEBUG_ID_PLACE_HOLDER constant (DRY), and
`replaceAll` isn't available under this file's `lib: es7`.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Contributor
Semver Impact of This PR⚪ None (no version bump detected) 📋 Changelog PreviewThis is how your changes will appear in the changelog.
🤖 This preview updates automatically when you update the PR. |
Contributor
antonis
marked this pull request as ready for review
October 5, 2026 12:58
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
📢 Type of change
📜 Description
Re-enables the
sdk/no-regexp-constructorlint rule, which was turned off inpackages/core/.oxlintrc.jsonwith:The blocker is gone — oxlint 1.57 supports inline-disable for jsPlugin rules — so the rule is re-enabled (
off→error) and the two pre-existingnew RegExpuses are handled:debugsymbolicator.ts— the staticnew RegExp(['ReactNativeRenderer-dev\\.js$', 'MessageQueue\\.js$'].join('|'))is rewritten as an equivalent regex literal/ReactNativeRenderer-dev\.js$|MessageQueue\.js$/. No suppression needed.sentryMetroSerializer.ts— keepsnew RegExpwith a justified// oxlint-disable-next-line. It builds the matcher from the sharedDEBUG_ID_PLACE_HOLDERconstant (single source of truth), andreplaceAllisn't available under this file'slib: ["es7"].💡 Motivation and Context
💚 How did you test it?
📝 Checklist
sendDefaultPIIis enabled.🔮 Next steps