Skip to content

chore: add react-doctor scanner - #6925

Merged
lkostrowski merged 1 commit into
mainfrom
lkostrowski/react-doctor-npm-script
Sep 3, 2026
Merged

chore: add react-doctor scanner#6925
lkostrowski merged 1 commit into
mainfrom
lkostrowski/react-doctor-npm-script

Conversation

@lkostrowski

Copy link
Copy Markdown
Member

Adds react-doctor as a dev dependency plus a pnpm run react-doctor script for scanning React correctness, performance, security and a11y issues. Pinned to 0.9.11 — 0.9.13 exists but falls inside the repo's minimumReleaseAge quarantine window.

Scope of the change

  • I confirm I added ripples for changes (see src/ripples) or my feature doesn't contain any user-facing changes
  • I used analytics "trackEvent" for important events

Adds react-doctor as a dev dependency plus a `pnpm run react-doctor`
script for scanning React correctness, performance, security and a11y
issues. Pinned to 0.9.11 — 0.9.13 exists but falls inside the repo's
minimumReleaseAge quarantine window.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@lkostrowski
lkostrowski requested review from a team and magul September 3, 2026 08:07
@lkostrowski
lkostrowski enabled auto-merge (squash) September 3, 2026 08:07
@changeset-bot

changeset-bot Bot commented Sep 3, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 43e0824

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedreact-doctor@​0.9.11991009696100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @sentry/node-core is 60.0% likely obfuscated

Confidence: 0.60

Location: Package overview

From: pnpm-lock.yamlnpm/react-doctor@0.9.11npm/@sentry/node-core@10.70.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@sentry/node-core@10.70.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Differences Found

⚠️ 101 packages or licenses were added.

Expand
License	Package
Apache-2.0	@apm-js-collab/code-transformer
Apache-2.0	@apm-js-collab/tracing-hooks
Apache-2.0	@opentelemetry/instrumentation
Apache-2.0	@opentelemetry/sdk-trace
Apache-2.0	detect-libc
Apache-2.0	import-in-the-middle
Apache-2.0	semifies
BSD-2-Clause	json-schema-typed
BSD-3-Clause	fast-uri
ISC	@iarna/toml
ISC	@shaderfrog/glsl-parser
ISC	meriyah
MIT	@apm-js-collab/code-transformer-bundler-plugins
MIT	@astrojs/compiler
MIT	@oxc-parser/binding-android-arm-eabi
MIT	@oxc-parser/binding-android-arm64
MIT	@oxc-parser/binding-darwin-arm64
MIT	@oxc-parser/binding-darwin-x64
MIT	@oxc-parser/binding-freebsd-x64
MIT	@oxc-parser/binding-linux-arm-gnueabihf
MIT	@oxc-parser/binding-linux-arm-musleabihf
MIT	@oxc-parser/binding-linux-arm64-gnu
MIT	@oxc-parser/binding-linux-arm64-musl
MIT	@oxc-parser/binding-linux-ppc64-gnu
MIT	@oxc-parser/binding-linux-riscv64-gnu
MIT	@oxc-parser/binding-linux-riscv64-musl
MIT	@oxc-parser/binding-linux-s390x-gnu
MIT	@oxc-parser/binding-linux-x64-gnu
MIT	@oxc-parser/binding-linux-x64-musl
MIT	@oxc-parser/binding-openharmony-arm64
MIT	@oxc-parser/binding-wasm32-wasi
MIT	@oxc-parser/binding-win32-arm64-msvc
MIT	@oxc-parser/binding-win32-ia32-msvc
MIT	@oxc-parser/binding-win32-x64-msvc
MIT	@oxc-project/types
MIT	@oxlint/binding-android-arm-eabi
MIT	@oxlint/binding-android-arm64
MIT	@oxlint/binding-darwin-arm64
MIT	@oxlint/binding-darwin-x64
MIT	@oxlint/binding-freebsd-x64
MIT	@oxlint/binding-linux-arm-gnueabihf
MIT	@oxlint/binding-linux-arm-musleabihf
MIT	@oxlint/binding-linux-arm64-gnu
MIT	@oxlint/binding-linux-arm64-musl
MIT	@oxlint/binding-linux-ppc64-gnu
MIT	@oxlint/binding-linux-riscv64-gnu
MIT	@oxlint/binding-linux-riscv64-musl
MIT	@oxlint/binding-linux-s390x-gnu
MIT	@oxlint/binding-linux-x64-gnu
MIT	@oxlint/binding-linux-x64-musl
MIT	@oxlint/binding-openharmony-arm64
MIT	@oxlint/binding-win32-arm64-msvc
MIT	@oxlint/binding-win32-ia32-msvc
MIT	@oxlint/binding-win32-x64-msvc
MIT	@sentry/conventions
MIT	@sentry/node
MIT	@sentry/node-core
MIT	@sentry/opentelemetry
MIT	@sentry/server-utils
MIT	@types/esrecurse
MIT	agent-install
MIT	ajv-formats
MIT	astring
MIT	atomically
MIT	conf
MIT	confbox
MIT	debounce-fn
MIT	dot-prop
MIT	env-paths
MIT	mimic-function
MIT	module-details-from-path
MIT	oxc-parser
MIT	oxlint
MIT	require-from-string
MIT	require-in-the-middle
MIT	stubborn-fs
MIT	stubborn-utils
MIT	tagged-tag
MIT	uint8array-extras
MIT	vscode-jsonrpc
MIT	vscode-languageserver
MIT	vscode-languageserver-protocol
MIT	vscode-languageserver-textdocument
MIT	vscode-uri
MIT	when-exit
MIT	yoga-layout
MPL-2.0 lightningcss
MPL-2.0 lightningcss-android-arm64
MPL-2.0 lightningcss-darwin-arm64
MPL-2.0 lightningcss-darwin-x64
MPL-2.0 lightningcss-freebsd-x64
MPL-2.0 lightningcss-linux-arm-gnueabihf
MPL-2.0 lightningcss-linux-arm64-gnu
MPL-2.0 lightningcss-linux-arm64-musl
MPL-2.0 lightningcss-linux-x64-gnu
MPL-2.0 lightningcss-linux-x64-musl
MPL-2.0 lightningcss-win32-arm64-msvc
MPL-2.0 lightningcss-win32-x64-msvc
SEE LICENSE IN LICENSE	deslop-js
SEE LICENSE IN LICENSE	oxlint-plugin-react-doctor
SEE LICENSE IN LICENSE	react-doctor

Summary

Expand
License Name Package Count Packages
0BSD 1
Packages
  • tslib
CC0-1.0 1
Packages
  • type-fest
MIT/X11 1
Packages
  • nub
MPL-1.1 1
Packages
  • harmony-reflect
Public Domain 1
Packages
  • jsonify
Python-2.0 1
Packages
  • argparse
WTFPL 1
Packages
  • utf8-byte-length
CC-BY-4.0 2
Packages
  • @saleor/macaw-ui
  • caniuse-lite
BlueOak-1.0.0 5
Packages
  • glob
  • lru-cache
  • minimatch
  • minipass
  • path-scurry
SEE LICENSE IN LICENSE 5
Packages
  • deslop-js
  • oxlint-plugin-react-doctor
  • posthog-js
  • react-doctor
  • spawndamnit
<<missing>> 9
Packages
  • @sentry/cli
  • @sentry/cli-darwin
  • @sentry/cli-linux-arm
  • @sentry/cli-linux-arm64
  • @sentry/cli-linux-i686
  • @sentry/cli-linux-x64
  • @sentry/cli-win32-arm64
  • @sentry/cli-win32-i686
  • @sentry/cli-win32-x64
MPL-2.0 13
Packages
  • dompurify
  • lightningcss
  • lightningcss-android-arm64
  • lightningcss-darwin-arm64
  • lightningcss-darwin-x64
  • lightningcss-freebsd-x64
  • lightningcss-linux-arm-gnueabihf
  • lightningcss-linux-arm64-gnu
  • lightningcss-linux-arm64-musl
  • lightningcss-linux-x64-gnu
  • lightningcss-linux-x64-musl
  • lightningcss-win32-arm64-msvc
  • lightningcss-win32-x64-msvc
BSD-2-Clause 23
Packages
  • browser-process-hrtime
  • css-select
  • css-what
  • domelementtype
  • domhandler
  • domutils
  • dotenv
  • dotenv-expand
  • entities
  • escodegen
  • eslint-scope
  • espree
  • esprima
  • esrecurse
  • estraverse
  • esutils
  • json-schema-typed
  • nth-check
  • regjsparser
  • stringify-object
  • And 3 more...
BSD-3-Clause 52
Packages
  • @protobufjs/aspromise
  • @protobufjs/base64
  • @protobufjs/codegen
  • @protobufjs/eventemitter
  • @protobufjs/fetch
  • @protobufjs/float
  • @protobufjs/inquire
  • @protobufjs/path
  • @protobufjs/pool
  • @protobufjs/utf8
  • @saleor/app-sdk
  • @sentry/cli
  • @sentry/cli-darwin
  • @sentry/cli-linux-arm
  • @sentry/cli-linux-arm64
  • @sentry/cli-linux-i686
  • @sentry/cli-linux-x64
  • @sentry/cli-win32-i686
  • @sentry/cli-win32-x64
  • @sinonjs/commons
  • And 32 more...
ISC 52
Packages
  • @iarna/toml
  • @istanbuljs/load-nyc-config
  • @shaderfrog/glsl-parser
  • anymatch
  • boolbase
  • cli-width
  • cliui
  • electron-to-chromium
  • fastq
  • flatted
  • fs.realpath
  • get-caller-file
  • get-own-enumerable-property-symbols
  • glob
  • glob-parent
  • graceful-fs
  • inflight
  • inherits
  • ini
  • isexe
  • And 32 more...
Apache-2.0 72
Packages
  • @apm-js-collab/code-transformer
  • @apm-js-collab/tracing-hooks
  • @editorjs/editorjs
  • @eslint/config-array
  • @eslint/config-helpers
  • @eslint/core
  • @eslint/object-schema
  • @eslint/plugin-kit
  • @humanfs/core
  • @humanfs/node
  • @humanwhocodes/module-importer
  • @humanwhocodes/retry
  • @opentelemetry/api
  • @opentelemetry/api-logs
  • @opentelemetry/core
  • @opentelemetry/exporter-logs-otlp-http
  • @opentelemetry/instrumentation
  • @opentelemetry/otlp-exporter-base
  • @opentelemetry/otlp-transformer
  • @opentelemetry/resources
  • And 52 more...
MIT 1396
Packages
  • @adobe/css-tools
  • @apm-js-collab/code-transformer-bundler-plugins
  • @apollo/client
  • @ardatan/relay-compiler
  • @astrojs/compiler
  • @babel/code-frame
  • @babel/compat-data
  • @babel/core
  • @babel/generator
  • @babel/helper-annotate-as-pure
  • @babel/helper-compilation-targets
  • @babel/helper-create-class-features-plugin
  • @babel/helper-globals
  • @babel/helper-member-expression-to-functions
  • @babel/helper-module-imports
  • @babel/helper-module-transforms
  • @babel/helper-optimise-call-expression
  • @babel/helper-plugin-utils
  • @babel/helper-replace-supers
  • @babel/helper-skip-transparent-expression-wrappers
  • And 1376 more...

@codecov

codecov Bot commented Sep 3, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 58.18%. Comparing base (74c10cc) to head (43e0824).
⚠️ Report is 4 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #6925      +/-   ##
==========================================
- Coverage   58.19%   58.18%   -0.01%     
==========================================
  Files        3389     3388       -1     
  Lines       73488    73482       -6     
  Branches    19305    18941     -364     
==========================================
- Hits        42763    42757       -6     
- Misses      28847    30566    +1719     
+ Partials     1878      159    -1719     
Flag Coverage Δ
storybook 54.14% <ø> (-0.07%) ⬇️
units 51.73% <ø> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@lkostrowski lkostrowski added the skip changeset Use if your changes doesn't need entry in changelog label Sep 3, 2026
@lkostrowski
lkostrowski merged commit d168166 into main Sep 3, 2026
32 of 34 checks passed
@lkostrowski
lkostrowski deleted the lkostrowski/react-doctor-npm-script branch September 3, 2026 10:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip changeset Use if your changes doesn't need entry in changelog

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants