Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

oxlint rollout: bugs found in the baseline, and next rules to evaluate

Open
#836 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
25/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
typescript
Domain
ci-cd, cli, tooling

Research direction

Start with the rollout plan and the files named in the issue: src/tags.ts, src/roles-cmd.ts, src/cache-cmd.ts, src/import-local.ts, and the lint configuration used by #839. Run oxlint 1.85.0 on main to confirm the warning counts, then check #837, #839, and #840 before choosing work. Done means the selected fix has its required tests or CLI run and the relevant lint or output behavior is verified.

Written by the indexing model from the issue text.

Description

Follow-up to #828. oxlint 1.85.0 with its default rules reports 145 warnings on main at 7c834ce4. The PR that adds the CI gate fixes all of them without suppression comments. Most are mechanical, or dead code that can be deleted with no behavior change. A few are real bugs, so they get their own fix PRs, which merge before the gate goes on. This issue tracks those bugs, related bugs found during the triage, and the rules to evaluate next.

Bugs reported by the linter

no-unused-vars flagged an options parameter that is never read. In both cases the parameter carries the global --dry-run, which --help describes as "Preview mode, no changes made".

Command Where What happens
teamai tags subscribe <tag> --dry-run src/tags.ts:103 Writes subscribedTags to the config and resets lastPullRev. Prints "Subscribed to: …" with no [dry-run] marker.
teamai tags unsubscribe <tag> --dry-run src/tags.ts:137 Removes the subscription from the config and resets lastPullRev.

Both have been there since the commands were added in 5dc9e818 (MR !90). tagsAdd and tagsRemove in the same file do check options.dryRun (tags.ts:198, tags.ts:252).

Found during triage (not reported by the linter)

Problem Where What happens
roles set ignores --dry-run src/roles-cmd.ts:180 Saves primaryRole and additionalRoles to the local config and resets lastPullRev. The linter misses it because the function reads options.add. It's the same bug as the two above, so it gets fixed in the same PR.
tags list counts namespaces as skills src/tags.ts:264 getTeamSkillCount counts the top-level folders under skills/. With the namespace layout, skills/hai/{a,b,c} with one tagged skill reports 0 untagged skills instead of 2. collectTeamSkillNames (src/uninstall.ts:175) already walks both layouts.
Chinese strings in CLI output src/cache-cmd.ts, src/import-local.ts (无缓存条目), 总计: … (teamai import --cache-status) and the 新标题: prompt in the interactive import review break the rule that CLI output is English.

Plan

The bug fixes and the CI gate are merged. The remaining items are the next rule sets, one PR each.

  • fix(tags,roles): make --dry-run work in tags subscribe, tags unsubscribe and roles set, with a failing test for each command and one real-CLI run. #837 (merged)
  • ci(lint): add oxlint with the default rules and fail CI on any warning. Closes #828. #839 (merged)
  • fix(tags): count skills in both the flat and namespace layouts in tags list. #837, second commit (merged)
  • fix(cache,import): English output in import --cache-status / --cache-gc, the GC skip reason and the interactive import review. #840 (merged)
  • ci(lint): enable the suspicious and perf categories with the off list below (100 warnings to fix).
  • ci(lint): enable type-aware linting with no-floating-promises and no-misused-promises (24 warnings). #863 (open, waiting for review)
  • ci(lint): anti-slop rules, one at a time.

Next rules to evaluate

The gate starts with oxlint's default rules only. These are candidates for later, each in its own PR, after checking whether its warnings are worth acting on:

  • anti-slop (dmmulroy/anti-slop): the rules on unvalidated input, which cluster in the files where most fixes land (see #828). Add them one rule at a time, starting as a warning count that must not go up.

  • oxlint suspicious + perf categories: measured on #839 (oxlint 1.85.0), suspicious gives 539 warnings and perf 1,005. Most come from rules that do not find bugs here, so turn those off:

    Rule Prod Tests Decision
    no-await-in-loop 833 159 off: sequential awaits are deliberate in a CLI (git, prompts, ordered writes), and the rule cannot tell
    unicorn/no-array-sort 80 90 off: the 31 prod sites that sort an existing binding all sort a local array built in the same function; none mutates a caller's array. toSorted would also need lib ES2023
    unicorn/consistent-function-scoping 24 196 off: moves closures to an outer scope; style, not a bug class
    no-underscore-dangle 18 36 off: conflicts with the repo's _ convention (_setLogFilePath, _resetState)
    oxc/no-map-spread 8 0 off: micro-optimisation
    no-shadow 19 39 on: a shadowed name hides one still in use, e.g. a destructured field hiding the imported dataHomeKey() (team-push.ts:854) and an inner events hiding the array being iterated (dashboard-collector.ts:1870). 6 of the 19 are redundant await import('./utils/logger.js') in index.ts, which already imports log

    With that list, 100 warnings remain (51 prod, 49 tests):

    Rule Prod Tests
    no-shadow 19 39
    preserve-caught-error (rethrow without cause) 22 0
    unicorn/no-array-reverse 7 1
    unicorn/prefer-array-find 0 4
    no-useless-concat 0 3
    no-useless-constructor 2 0
    no-unmodified-loop-condition 1 0
    unicorn/prefer-set-has, unicorn/require-module-specifiers 0 2

    Small enough for one PR under the same zero-warning gate. Check the no-unmodified-loop-condition hit first: a loop whose condition never changes may be a real bug.

  • Type-aware rules (oxlint --type-aware, needs the oxlint-tsgolint devDependency): typescript/no-floating-promises and typescript/no-misused-promises stay on. In a CLI a promise nobody awaits is an error nobody sees, or a process that exits before its write lands, and tsc reports neither. Measured on #839 (oxlint 1.85.0, oxlint-tsgolint 7.0.2003): 24 warnings (5 prod including scripts/, 19 tests), and the run takes about 1.4 s. The prod hits are async setTimeout/setInterval callbacks in dashboard.ts (3), the array returned by splice in import-repo-list.ts:149, and scripts/mock-teamai-server.mjs:54; none looks like a lost error yet, but each needs a look.

Dominant language
TypeScript
Stars
5k
Forks
376
Avg merge
13h 21m
Merged PRs (30d)
288

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Tencent/teamai-cli

All issues in Tencent/teamai-cli

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.