From 4c35018c6d3f2e806c93f10ce1c1da6a8119cfb1 Mon Sep 17 00:00:00 2001 From: Priyanshu Doshi Date: Wed, 19 Aug 2026 23:38:31 +0530 Subject: [PATCH 1/2] chore: enable DeepSource javascript analyzer DeepSource was activated on this repo but no .deepsource.toml existed, so only the secrets analyzer ran. Both analysis runs reported FAILURE and the 35 findings surfaced were all in docs, test fixtures and playwright configs. Enables the javascript analyzer with the react plugin and typescript dialect so DeepSource actually analyses src/. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_012ML3xbVUA9NjDJzAB71qVc --- .deepsource.toml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) create mode 100644 .deepsource.toml diff --git a/.deepsource.toml b/.deepsource.toml new file mode 100644 index 000000000..9a9fb5a74 --- /dev/null +++ b/.deepsource.toml @@ -0,0 +1,18 @@ +version = 1 + +[[analyzers]] +name = "javascript" +enabled = true + + [analyzers.meta] + plugins = ["react"] + environment = ["nodejs", "browser", "jest"] + dialect = "typescript" + +[[analyzers]] +name = "secrets" +enabled = true + +[[analyzers]] +name = "test-coverage" +enabled = false From 048362ae8544c53eb494f2cd7af1a560dfcce776 Mon Sep 17 00:00:00 2001 From: Priyanshu Doshi Date: Fri, 21 Aug 2026 13:40:32 +0530 Subject: [PATCH 2/2] chore: gitignore .scannerwork/ The SonarCloud scanner writes .scannerwork/ (.sonar_lock, report-task.txt) into the repo root on a local run. It was untracked but not ignored, so a `git add -A` would sweep scanner scratch into a commit. Sits next to the existing .jscpd-report/ entry, which covers the same class of local analysis output. --- .gitignore | 1 + 1 file changed, 1 insertion(+) diff --git a/.gitignore b/.gitignore index 8dfeeeb45..908ad4594 100644 --- a/.gitignore +++ b/.gitignore @@ -67,3 +67,4 @@ package-lock.json # code-analysis output .jscpd-report/ +.scannerwork/