Skip to content

chore(core): Re-enable sdk/no-regexp-constructor lint rule - #6841

Open
antonis wants to merge 1 commit into
mainfrom
chore/reenable-no-regexp-constructor
Open

antonis wants to merge 1 commit into
mainfrom
chore/reenable-no-regexp-constructor

Conversation

@antonis

@antonis antonis commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

📢 Type of change

  • Bugfix
  • New feature
  • Enhancement
  • Refactoring

📜 Description

Re-enables the sdk/no-regexp-constructor lint rule, which was turned off in packages/core/.oxlintrc.json with:

// TODO: Re-enable once oxlint supports inline disable for jsPlugin rules
// Only 2 intentional uses exist (debugsymbolicator.ts, sentryMetroSerializer.ts)
"sdk/no-regexp-constructor": "off"

The blocker is gone — oxlint 1.57 supports inline-disable for jsPlugin rules — so the rule is re-enabled (off → error) and the two pre-existing new RegExp uses are handled:

  • debugsymbolicator.ts — the static new RegExp(['ReactNativeRenderer-dev\\.js$', 'MessageQueue\\.js$'].join('|')) is rewritten as an equivalent regex literal /ReactNativeRenderer-dev\.js$|MessageQueue\.js$/. No suppression needed.
  • sentryMetroSerializer.ts — keeps new RegExp with a justified // oxlint-disable-next-line. It builds the matcher from the shared DEBUG_ID_PLACE_HOLDER constant (single source of truth), and replaceAll isn't available under this file's lib: ["es7"].

💡 Motivation and Context

  • TODO cleanup

💚 How did you test it?

  • CI

📝 Checklist

  • I added tests to verify changes.
  • No new PII added or SDK only sends newly added PII if sendDefaultPII is enabled.
  • I updated the docs if needed.
  • I updated the wizard if needed.
  • All tests passing.
  • Public API changes reviewed by another Mobile SDK team member or implemented according to the develop docs spec.
  • No breaking changes.

🔮 Next steps

The rule was disabled with a TODO to re-enable once oxlint supported inline
disable for jsPlugin rules. oxlint 1.57 supports it (verified: a `new RegExp`
line errors, the same line with `// oxlint-disable-next-line
sdk/no-regexp-constructor` is suppressed), so re-enable it (`off` -> `error`).

The rule guards against `RegExp` construction from unsafe/user input (ReDoS).
Both pre-existing uses are constant patterns, not user input:

- debugsymbolicator.ts: refactored the static `new RegExp([...].join('|'))` to
  an equivalent regex literal (same source and flags, verified) — no suppression
  needed.
- sentryMetroSerializer.ts: kept `new RegExp` with a justified inline disable; it
  builds the matcher from the shared DEBUG_ID_PLACE_HOLDER constant (DRY), and
  `replaceAll` isn't available under this file's `lib: es7`.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Semver Impact of This PR

⚪ None (no version bump detected)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


  • chore(core): Re-enable sdk/no-regexp-constructor lint rule by antonis in #6841
  • chore(deps): update JavaScript SDK to v10.76.0 by antonis in #6831
  • chore(expo): bump sample to Expo 57.0.26 by antonis in #6838
  • chore(deps): Bump basic-ftp to 6.2.2 by alwx in #6837
  • fix(core): Mark package as side-effect free by devclaimjuimperai in #6829
  • chore(deps): bump getsentry/craft/.github/workflows/changelog-preview.yml from 2.31.0 to 2.33.1 by dependabot in #6833
  • chore(deps): bump gradle/actions/setup-gradle from 6.3.0 to 6.4.0 by dependabot in #6834
  • chore(deps): bump getsentry/craft from 2.31.2 to 2.33.1 by dependabot in #6835
  • chore(deps): bump getsentry/github-workflows/validate-pr from 4013fc6e1aeb1be1f9d3b4d232624f0ec1afa613 to 36c729264d2edc29ebae61950c50e1e9f043ad7e by dependabot in #6832
  • fix(android): Settle initNativeReactNavigationNewFrameTracking promise by antonis in #6823
  • fix(spotlight): Forward image attachments to Spotlight by antonis in #6818
  • fix(ios): Prevent crash when initialized with an invalid DSN by antonis in #6825
  • chore(core): Resolve non-actionable TODOs by antonis in #6826
  • chore(core): resolve stale TODO comments by antonis in #6819
  • fix(profiling): Populate Hermes runtime version on JS profiles by antonis in #6817

🤖 This preview updates automatically when you update the PR.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor
Fails
🚫 Pull request is not ready for merge, please add the "ready-to-merge" label to the pull request

Generated by 🚫 dangerJS against a95166a

@antonis
antonis marked this pull request as ready for review October 5, 2026 12:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant