Skip to content

urlcode review follows static relative imports into project modules - #1150

Merged
jimhoyd merged 1 commit into
mainfrom
claude/review-follow-imports-les1dm
Oct 7, 2026
Merged

jimhoyd merged 1 commit into
mainfrom
claude/review-follow-imports-les1dm

Conversation

@jimhoyd

@jimhoyd jimhoyd commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

Requested by Jimmy · project thread

Closes #1141.

Problem and change

Before: urlcode review scanned only the module a route names. Session, rate-limit and header plumbing kept in a helper or behind a re-export (export { default } from './lib/session.mjs') produced observations: [], which read as "nothing to review".

After: review follows the route module's static relative imports (import … from './x', export … from '../x') into project modules and runs the same signals there. Limits: at most 6 hops from a route module and 128 imported modules; only .//../ specifiers to .js/.mjs/.ts/.mts files whose real path is inside the project and not under node_modules; never packages, dynamic import(), CommonJS or files outside the project; nothing is executed.

How:

  • A finding in an imported module names that file as source, the routes that reach it as routes (with each route's effective policy still deciding native-alternative vs manual-review), and the route modules as importedFrom.
  • New top-level imports: {read, notRead, note?}. When a cap leaves modules unread, note says "N imported project modules were not read …"; the HTML report adds a check for it and shows "imported by" on findings.
  • moduleCount now counts route modules plus imported modules read.
  • docs/TOOLING.md#project-review describes the new scope.

Verification

  • test/review.test.ts: the [Request]: Evaluate current composition discovery against peer-bin application plumbing #1137 repro now finds the session code behind the re-export; new tests for a module shared by two routes with different policies, the never-followed cases (outside project, node_modules, package, dynamic import), and both caps with the exact note.
  • npm run lint, typecheck, typecheck:tooling, npm run check pass.
  • npm run test:proof:native and npm run test:ecosystem (which read review --json) pass unchanged.
  • npm test: 1435 pass, 2 fail locally (disk-full, hermetic-accounts), both because the container's Node ships SQLite 3.50.4, which the store refuses; unrelated to this change.

Compatibility and security

review JSON gains imports and optional importedFrom; existing fields keep their meaning (moduleCount now includes imported modules). No YAML, permission or runtime change. Review stays read-only and non-executing.

  • Changes match the documented portable contract; docs/examples are updated where needed.
  • Relevant tests and package checks pass, or limitations are explained above.
  • No credentials, customer data or private project material are included.
  • Runtime/starter changes remain aligned where applicable.

🤖 Generated with Claude Code

https://claude.ai/code/session_018b6Nd9EChnYTHdh9Rqiv6L


Generated by Claude Code

)

urlcode review read only the module a route names, so session, rate-limit
and header plumbing in imported helpers or behind a re-export yielded no
observations. It now follows static relative imports into project modules
(at most 6 hops, 128 imported modules; never packages, node_modules,
dynamic imports or files outside the project; nothing executed), reports
each finding with the file it was found in, the routes that reach it and
importedFrom, and reports imports {read, notRead, note} so a cap that left
modules unread is visible.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018b6Nd9EChnYTHdh9Rqiv6L
@jimhoyd jimhoyd self-assigned this Oct 7, 2026
@jimhoyd
jimhoyd marked this pull request as ready for review October 7, 2026 19:45
@jimhoyd
jimhoyd merged commit 0b45e6a into main Oct 7, 2026
21 checks passed
@jimhoyd
jimhoyd deleted the claude/review-follow-imports-les1dm branch October 7, 2026 20:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Request]: urlcode review reads only a route's entry module, so plumbing in imported modules yields zero observations

2 participants