Skip to content

ref(eslint-plugin-sdk): Improve no-unsafe-random-apis rule - #25123

Merged
Lms24 merged 2 commits into
developfrom
lms/fix-unsafe-random-apis-rule-gaps
Oct 7, 2026
Merged

Lms24 merged 2 commits into
developfrom
lms/fix-unsafe-random-apis-rule-gaps

Conversation

@Lms24

@Lms24 Lms24 commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Came up in #24903 (comment). This PR makes the no-unsafe-random-apis rule a bit more robust. We now catch:

  • crypto.randomUUID!() and TS casts (as, satisfies, <T>)
  • Optional calls: performance?.now(), crypto?.randomUUID?.()
  • Calls through a global object: globalThis.performance.now(), GLOBAL_OBJ.crypto.randomUUID(), WINDOW.performance?.now()

The rule only matched calls whose callee was a plain `Identifier.prop`
member expression. That missed `crypto.randomUUID!()`, TS casts, access
through a global object like `globalThis.performance.now()`, and code
that passes the function around (`const now = performance.now`,
`.bind`, destructuring) so it can be called outside the wrapper.

Also accept `_INTERNAL_withRandomSafeContext` as a wrapper and drop the
stale `safeRandomGeneratorRunner` file skip.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@Lms24 Lms24 changed the title fix(eslint-plugin-sdk): Close gaps in no-unsafe-random-apis rule ref(eslint-plugin-sdk): Improve no-unsafe-random-apis rule Oct 7, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 3eaf077. Configure here.

Comment thread packages/eslint-plugin-sdk/src/rules/no-unsafe-random-apis.js Outdated
Only catch calls of the unsafe APIs. Flagging `new globalThis.Date()`,
function references and destructuring is overkill, and nothing in the
codebase uses those shapes.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@Lms24
Lms24 marked this pull request as ready for review October 7, 2026 09:36
@Lms24 Lms24 self-assigned this Oct 7, 2026
@Lms24
Lms24 requested review from chargome and logaretm October 7, 2026 09:36

@chargome chargome left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for improving!

@Lms24
Lms24 merged commit a218427 into develop Oct 7, 2026
43 checks passed
@Lms24
Lms24 deleted the lms/fix-unsafe-random-apis-rule-gaps branch October 7, 2026 10:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants