Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11), free to diverge. Tree copied sans upstream .git; upstream remote added for future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19. Preserves docs/ARCHITECTURE.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
231 lines
6.3 KiB
JavaScript
231 lines
6.3 KiB
JavaScript
#!/usr/bin/env node
|
|
|
|
// Advises on ineffective or suspicious dynamic import patterns.
|
|
import { promises as fs } from "node:fs";
|
|
import path from "node:path";
|
|
import ts from "typescript";
|
|
import {
|
|
collectTypeScriptFilesFromRoots,
|
|
resolveRepoRoot,
|
|
runAsScript,
|
|
toLine,
|
|
} from "./lib/ts-guard-utils.mjs";
|
|
|
|
const repoRoot = resolveRepoRoot(import.meta.url);
|
|
const defaultRoots = [path.join(repoRoot, "src"), path.join(repoRoot, "extensions")];
|
|
|
|
function readStringLiteral(node) {
|
|
if (ts.isStringLiteral(node) || ts.isNoSubstitutionTemplateLiteral(node)) {
|
|
return node.text;
|
|
}
|
|
return null;
|
|
}
|
|
|
|
function isTypeOnlyImportDeclaration(node) {
|
|
const clause = node.importClause;
|
|
if (!clause) {
|
|
return false;
|
|
}
|
|
if (clause.isTypeOnly) {
|
|
return true;
|
|
}
|
|
if (clause.name) {
|
|
return false;
|
|
}
|
|
const bindings = clause.namedBindings;
|
|
return (
|
|
Boolean(bindings) &&
|
|
ts.isNamedImports(bindings) &&
|
|
bindings.elements.length > 0 &&
|
|
bindings.elements.every((element) => element.isTypeOnly)
|
|
);
|
|
}
|
|
|
|
function isTypeOnlyExportDeclaration(node) {
|
|
if (node.isTypeOnly === true) {
|
|
return true;
|
|
}
|
|
const clause = node.exportClause;
|
|
return (
|
|
Boolean(clause) &&
|
|
ts.isNamedExports(clause) &&
|
|
clause.elements.length > 0 &&
|
|
clause.elements.every((element) => element.isTypeOnly)
|
|
);
|
|
}
|
|
|
|
function readDeclarationName(node) {
|
|
if (
|
|
(ts.isFunctionDeclaration(node) ||
|
|
ts.isMethodDeclaration(node) ||
|
|
ts.isVariableDeclaration(node)) &&
|
|
node.name &&
|
|
ts.isIdentifier(node.name)
|
|
) {
|
|
return node.name.text;
|
|
}
|
|
|
|
if (ts.isPropertyAssignment(node)) {
|
|
if (ts.isIdentifier(node.name) || ts.isStringLiteral(node.name)) {
|
|
return node.name.text;
|
|
}
|
|
}
|
|
|
|
return null;
|
|
}
|
|
|
|
function isIgnoredTestHelperContent(content) {
|
|
return /\bfrom\s+["']vitest["']/.test(content) || /\bfrom\s+["']@vitest\//.test(content);
|
|
}
|
|
|
|
function isIgnoredTestHelperPath(filePath) {
|
|
const normalized = filePath.split(path.sep).join("/");
|
|
const base = path.basename(filePath);
|
|
return (
|
|
normalized.includes("/test/") ||
|
|
/(?:^|[./-])test(?:[./-]|$)/.test(base) ||
|
|
base.includes("test-support") ||
|
|
base.includes("test-harness") ||
|
|
base.includes("test-helper") ||
|
|
base.includes("test-mocks")
|
|
);
|
|
}
|
|
|
|
/**
|
|
* Finds dynamic import advisories in a single source file.
|
|
*/
|
|
export function findDynamicImportAdvisories(content, fileName = "source.ts") {
|
|
const sourceFile = ts.createSourceFile(fileName, content, ts.ScriptTarget.Latest, true);
|
|
const staticRuntimeImports = new Map();
|
|
const dynamicImports = new Map();
|
|
const directExecuteImports = [];
|
|
const declarationStack = [];
|
|
|
|
const addLine = (map, specifier, line) => {
|
|
const lines = map.get(specifier) ?? [];
|
|
lines.push(line);
|
|
map.set(specifier, lines);
|
|
};
|
|
|
|
const visit = (node) => {
|
|
const declarationName = readDeclarationName(node);
|
|
if (declarationName) {
|
|
declarationStack.push(declarationName);
|
|
}
|
|
|
|
if (
|
|
ts.isImportDeclaration(node) &&
|
|
ts.isStringLiteral(node.moduleSpecifier) &&
|
|
!isTypeOnlyImportDeclaration(node)
|
|
) {
|
|
addLine(staticRuntimeImports, node.moduleSpecifier.text, toLine(sourceFile, node));
|
|
}
|
|
|
|
if (
|
|
ts.isExportDeclaration(node) &&
|
|
node.moduleSpecifier &&
|
|
ts.isStringLiteral(node.moduleSpecifier) &&
|
|
!isTypeOnlyExportDeclaration(node)
|
|
) {
|
|
addLine(staticRuntimeImports, node.moduleSpecifier.text, toLine(sourceFile, node));
|
|
}
|
|
|
|
if (
|
|
ts.isCallExpression(node) &&
|
|
node.expression.kind === ts.SyntaxKind.ImportKeyword &&
|
|
node.arguments.length > 0
|
|
) {
|
|
const specifier = readStringLiteral(node.arguments[0]);
|
|
if (specifier) {
|
|
const line = toLine(sourceFile, node);
|
|
addLine(dynamicImports, specifier, line);
|
|
if (declarationStack.includes("execute")) {
|
|
directExecuteImports.push({
|
|
line,
|
|
reason: `direct dynamic import of "${specifier}" inside execute path; move it behind a cached loader`,
|
|
});
|
|
}
|
|
}
|
|
}
|
|
|
|
ts.forEachChild(node, visit);
|
|
if (declarationName) {
|
|
declarationStack.pop();
|
|
}
|
|
};
|
|
|
|
visit(sourceFile);
|
|
|
|
const advisories = [...directExecuteImports];
|
|
for (const [specifier, dynamicLines] of dynamicImports) {
|
|
const staticLines = staticRuntimeImports.get(specifier);
|
|
if (staticLines?.length) {
|
|
advisories.push({
|
|
line: dynamicLines[0],
|
|
reason: `runtime static + dynamic import of "${specifier}" (static line ${staticLines[0]})`,
|
|
});
|
|
}
|
|
if (dynamicLines.length > 1) {
|
|
advisories.push({
|
|
line: dynamicLines[0],
|
|
reason: `repeated direct dynamic import of "${specifier}" (${dynamicLines.length} callsites: ${dynamicLines.join(", ")})`,
|
|
});
|
|
}
|
|
}
|
|
return advisories;
|
|
}
|
|
|
|
/**
|
|
* Collects dynamic import advisories across configured source roots.
|
|
*/
|
|
export async function collectDynamicImportAdvisories(options = {}) {
|
|
const roots = options.roots ?? defaultRoots;
|
|
const files = await collectTypeScriptFilesFromRoots(roots, {
|
|
extraTestSuffixes: [".suite.ts"],
|
|
});
|
|
const advisories = [];
|
|
for (const filePath of files) {
|
|
if (isIgnoredTestHelperPath(filePath)) {
|
|
continue;
|
|
}
|
|
const content = await fs.readFile(filePath, "utf8");
|
|
if (isIgnoredTestHelperContent(content)) {
|
|
continue;
|
|
}
|
|
for (const advisory of findDynamicImportAdvisories(content, filePath)) {
|
|
advisories.push({
|
|
path: path.relative(repoRoot, filePath),
|
|
...advisory,
|
|
});
|
|
}
|
|
}
|
|
return advisories;
|
|
}
|
|
|
|
/**
|
|
* Runs the dynamic import advisory check.
|
|
*/
|
|
export async function main(argv = process.argv.slice(2)) {
|
|
const fail = argv.includes("--fail");
|
|
const json = argv.includes("--json");
|
|
const advisories = await collectDynamicImportAdvisories();
|
|
|
|
if (json) {
|
|
console.log(JSON.stringify({ advisories }, null, 2));
|
|
} else if (advisories.length === 0) {
|
|
console.log("No dynamic import advisories found.");
|
|
} else {
|
|
console.log(`Dynamic import advisories (${advisories.length}):`);
|
|
for (const advisory of advisories) {
|
|
console.log(`- ${advisory.path}:${advisory.line} ${advisory.reason}`);
|
|
}
|
|
console.log("Advisory only. Use --fail when ratcheting this into a hard check.");
|
|
}
|
|
|
|
if (fail && advisories.length > 0) {
|
|
process.exit(1);
|
|
}
|
|
}
|
|
|
|
runAsScript(import.meta.url, main);
|