Skip to content

Fix/rescript 12 migration - #18

Merged
hyperpolymath merged 4 commits into
mainfrom
fix/rescript-12-migration
May 16, 2026
Merged

Fix/rescript 12 migration#18
hyperpolymath merged 4 commits into
mainfrom
fix/rescript-12-migration

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

No description provided.

hyperpolymath and others added 4 commits May 16, 2026 17:46
ReScript 11->12 migration cleanup: drop vendored LICENSE duplicates and
npm lockfiles, normalise .claude/CLAUDE.md, add .editorconfig/.gitignore.
59 files, committed at user request during the 2026-05-16 estate pass.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…e #private, remove unused externals

The migration to rescript@12 (already declared in package.json devDeps as
^12.0.2) was blocked by three v12 incompatibilities flagged in PR #10's
"out of scope" footer. This commit addresses all three:

  - rescript.json: remove "bsc-flags": ["-bs-super-errors"]. Super-errors
    became the default in rescript@12; the flag is rejected by the new
    compiler. The whole bsc-flags array is removed since no other flags
    were set.

  - src/forges/ForgeAdapter.res: quote the #private polymorphic-variant
    tag in the visibility type. `private` became a reserved keyword in
    rescript@12; the canonical fix is to quote the tag as #"private".
    The variant is only declared at this one site (no constructors or
    pattern-matches elsewhere reference it), so this is a one-line edit.

  - tests/Setup.res: remove the eight unused @val/@set externals on
    process.env. The four @set forms hit a v12 incompatibility
    (tightened external validation rejected the @set @scope tuple-arg
    form for env-var assignment); the four @Val getters were never
    imported (vitest.config.js only references the .res.js path, no
    caller imports Setup.gitlabToken etc.). All env-var manipulation in
    this file already happens via the %%raw block, so the externals are
    dead code.

Verified no other file imports Setup.gitlabToken / Setup.setGitlabToken
etc. — grep "Setup\." returned only vitest.config.js's setupFiles entry.

This unblocks the rescript@12 build that PR #10 deliberately punted to
a separate task.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…fig/gitignore

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@hyperpolymath
hyperpolymath merged commit 411bf89 into main May 16, 2026
3 of 4 checks passed
@github-actions

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 48 issues detected

Severity Count
🔴 Critical 8
🟠 High 28
🟡 Medium 12

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Stray AI.a2ml in root -- use 0-AI-MANIFEST.a2ml only",
    "type": "banned",
    "file": "AI.a2ml",
    "action": "delete",
    "rule_module": "root_hygiene",
    "severity": "high"
  },
  {
    "reason": "Required file missing",
    "type": "missing",
    "file": "SECURITY.md",
    "action": "create",
    "rule_module": "root_hygiene",
    "severity": "high"
  },
  {
    "reason": "Issue in codeql.yml",
    "type": "missing_workflow",
    "file": "codeql.yml",
    "action": "create",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Issue in scorecard.yml",
    "type": "missing_workflow",
    "file": "scorecard.yml",
    "action": "create",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Issue in quality.yml",
    "type": "missing_workflow",
    "file": "quality.yml",
    "action": "create",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Issue in mirror.yml",
    "type": "missing_workflow",
    "file": "mirror.yml",
    "action": "create",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Required file missing (condition: public_repo)",
    "type": "missing_requirement",
    "file": "SECURITY.md",
    "action": "create",
    "rule_module": "cicd_rules",
    "severity": "high"
  },
  {
    "reason": "Required file missing (condition: public_repo)",
    "type": "missing_requirement",
    "file": ".github/workflows/scorecard.yml",
    "action": "create",
    "rule_module": "cicd_rules",
    "severity": "high"
  },
  {
    "reason": "String.to_existing_atom with user input exhausts atom table -- use to_existing_atom (1 occurrences, CWE-400)",
    "type": "elixir_atom_from_user",
    "file": "/home/runner/work/claude-integrations/claude-integrations/firefox-lsp/lib/lsp/server.ex",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "eval() -- arbitrary code execution (1 occurrences, CWE-94)",
    "type": "js_eval",
    "file": "/home/runner/work/claude-integrations/claude-integrations/firefox-mcp/extension-mv3/background.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "critical"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath
hyperpolymath deleted the fix/rescript-12-migration branch May 20, 2026 21:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant