Skip to content

chore(mosaic): add anti-slop lint rules - #10110

Merged
alexcarpenter merged 3 commits into
mainfrom
carp/mosaic-anti-slop-lint
Oct 7, 2026
Merged

alexcarpenter merged 3 commits into
mainfrom
carp/mosaic-anti-slop-lint

Conversation

@alexcarpenter

@alexcarpenter alexcarpenter commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Description

Stacked on #10109. Adds lint rules to @clerk/mosaic that catch common AI-generated code patterns, based on dmmulroy/anti-slop:

  • @typescript-eslint/consistent-type-assertions (assertionStyle: 'never'): no as Type casts. as const is still allowed.
  • @typescript-eslint/switch-exhaustiveness-check
  • sonarjs/no-collapsible-if, no-identical-functions, no-redundant-jump, prefer-single-boolean-return
  • max-lines (1000)
  • no-restricted-properties bans Reflect.get / Reflect.apply

Only the type-assertion rule has existing hits. This PR removes 36 of them:

  • CSS custom property keys never needed the cast.
  • Casting the composite props to Record<string, unknown> was unnecessary.
  • floating-ui's render props don't type the ref it passes at runtime. A new isRef guard replaces casting it.
  • DOM event targets in the drawer, action bar and combobox/autocomplete options use new isElement / isHTMLElement guards in primitives/utils/dom.ts.
  • Accordion and collapsible panels pass their ref without a cast.
  • Object.keys(...) as (keyof T)[] uses the existing keysOf helper, moved to primitives/utils so primitives can use it.
  • src/machines/ (first-factor-machine, sign-in-machine) is removed. Nothing imported it outside its own tests.

The remaining 37 are grandfathered in eslint-suppressions.json. They are mostly generic internals in machine/* and use-render, plus floating-ui interop and refs where removing the cast would change a public prop type.

noUncheckedIndexedAccess follows in #10111.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other: lint tooling

@vercel

vercel Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
clerk-js-sandbox Ready Ready Preview Oct 7, 2026 7:55pm UTC
swingset Ready Ready Preview Oct 7, 2026 7:55pm UTC

Request Review

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository YAML (base), Organization UI (inherited)
  • Review profile: ASSERTIVE
  • Plan: Team
  • Run ID: 3aa63cd6-d416-4529-9e56-5aa2be369429
📥 Commits

Reviewing files that changed from the base of the PR and between c13d350 and c1280dc.

📒 Files selected for processing (30)
  • .changeset/mosaic-anti-slop-lint.md
  • eslint.config.mjs
  • packages/mosaic/eslint-suppressions.json
  • packages/mosaic/src/components/action-bar/action-bar.tsx
  • packages/mosaic/src/components/form/form.machine.ts
  • packages/mosaic/src/components/form/use-form.ts
  • packages/mosaic/src/machines/__tests__/first-factor-machine.test.ts
  • packages/mosaic/src/machines/__tests__/sign-in-machine.test.ts
  • packages/mosaic/src/machines/first-factor-machine.ts
  • packages/mosaic/src/machines/sign-in-machine.ts
  • packages/mosaic/src/primitives/accordion/accordion-panel.tsx
  • packages/mosaic/src/primitives/accordion/accordion-root.tsx
  • packages/mosaic/src/primitives/accordion/accordion-trigger.tsx
  • packages/mosaic/src/primitives/autocomplete/autocomplete-option.tsx
  • packages/mosaic/src/primitives/collapsible/collapsible-panel.tsx
  • packages/mosaic/src/primitives/combobox/combobox-option.tsx
  • packages/mosaic/src/primitives/drawer/use-drawer-drag.ts
  • packages/mosaic/src/primitives/flow/flow-step.tsx
  • packages/mosaic/src/primitives/tabs/tabs-indicator.tsx
  • packages/mosaic/src/primitives/tabs/tabs-list.tsx
  • packages/mosaic/src/primitives/tabs/tabs-panel.tsx
  • packages/mosaic/src/primitives/tabs/tabs-tab.tsx
  • packages/mosaic/src/primitives/utils/dom.test.ts
  • packages/mosaic/src/primitives/utils/dom.ts
  • packages/mosaic/src/primitives/utils/index.ts
  • packages/mosaic/src/primitives/utils/object.ts
  • packages/mosaic/src/primitives/utils/use-render.test.tsx
  • packages/mosaic/src/primitives/utils/use-render.tsx
  • packages/mosaic/src/utils/context.ts
  • references/mosaic-architecture.md
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

💤 Files with no reviewable changes (6)
  • packages/mosaic/src/machines/tests/first-factor-machine.test.ts
  • references/mosaic-architecture.md
  • packages/mosaic/src/machines/tests/sign-in-machine.test.ts
  • packages/mosaic/src/primitives/utils/object.ts
  • packages/mosaic/src/machines/sign-in-machine.ts
  • packages/mosaic/src/machines/first-factor-machine.ts

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 4 reviews per hour.


📝 Walkthrough

Walkthrough

The Mosaic ESLint configuration adds control-flow, type-assertion, exhaustive-switch, file-length, and Reflect checks. The changes add and test DOM and ref type guards, then use them in components before forwarding refs or accessing DOM APIs. Other changes update CSS property keys, utility imports, and context prop merging. The first-factor and sign-in machines, their tests, and a related architecture reference entry are removed.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~25 minutes

Suggested reviewers: maxyinger, ephem

Merge Risk: ⚪ Minimal · up to c1280

This change adds lint rules and replaces type casts with runtime checks. No concrete merge-blocking risk was found.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 23.08% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 13 functions across 22 files. (2 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly and concisely identifies the main change: adding anti-slop lint rules to Mosaic.
Description check ✅ Passed The description directly explains the new lint rules, the removed type assertions, related refactoring, and remaining suppressions.
Full details: Docstring Coverage

Explanation

Docstring coverage is 23.08% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 13 functions across 22 files. (2 skipped: 2 unsupported.)

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@changeset-bot

changeset-bot Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 6276cd3

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-new Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@10110

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@10110

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@10110

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@10110

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@10110

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@10110

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@10110

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@10110

@clerk/expo-biometrics

npm i https://pkg.pr.new/@clerk/expo-biometrics@10110

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@10110

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@10110

@clerk/express

npm i https://pkg.pr.new/@clerk/express@10110

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@10110

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@10110

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@10110

@clerk/mosaic

npm i https://pkg.pr.new/@clerk/mosaic@10110

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@10110

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@10110

@clerk/react

npm i https://pkg.pr.new/@clerk/react@10110

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@10110

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@10110

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@10110

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@10110

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@10110

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@10110

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@10110

commit: 6276cd3

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Worth a discussion if we should have these here or in the files as inline comments? Or maybe we should have these here now for the "todo" after enabling the rule, but any future intentional disables should be inline with a reason? I think I prefer the second and I think there's a rule that enforces adding a reason too which I like.

@alexcarpenter alexcarpenter Oct 7, 2026 •

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah, goal is to chip away at this list. preference to get the rules in place and iterate

@alexcarpenter
alexcarpenter force-pushed the carp/mosaic-anti-slop-lint branch from cb8be77 to 6276cd3 Compare October 7, 2026 19:53
@alexcarpenter
alexcarpenter merged commit 812b8a6 into main Oct 7, 2026
85 of 86 checks passed
@alexcarpenter
alexcarpenter deleted the carp/mosaic-anti-slop-lint branch October 7, 2026 20:41

This branch was successfully deployed

2 active deployments
Preview – swingset — 6276cd31 Deployed Oct 7, 2026 by vercel[bot]
Preview – clerk-js-sandbox — 6276cd31 Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants