Skip to content

[ENG-4061] Scan component scripts for imports and bound unproven flows - #309

Merged
patchstackdave merged 1 commit into
mainfrom
fix/map-completeness-bounds
Sep 29, 2026
Merged

patchstackdave merged 1 commit into
mainfrom
fix/map-completeness-bounds

Conversation

@patchstackdave

Copy link
Copy Markdown
Contributor

Refs ENG-4061

Single-file components are in the import inventory

.vue, .svelte and .astro files were not walked at all, so their imports were missing while coverage.importsComplete stayed true. Now:

  • every <script> block and Astro --- frontmatter is scanned for imports, with lines reported in the component file;
  • a component whose script cannot be delimited (an unterminated <script> or frontmatter fence) counts in importCoverageGaps.unscannableFiles, and a computed import in one counts in unresolvableImports. Either makes the inventory incomplete;
  • a skipped directory that holds only components now counts as holding source;
  • a coverage note says components are scanned for imports only. Endpoints, inputs and sinks inside them are not analysed.

Unproven flows are bounded

Unproven flows (anything other than exact-local / transformed-local) pair every input with every sink, so a wide endpoint could produce tens of thousands of them.

  • An endpoint now keeps at most 200 unproven flows, and a map at most 1,000.
  • Proven flows are always kept.
  • An endpoint that left flows out is marked flowsTruncated: true, and a coverage note says how many endpoints were affected. The field is only emitted when something was left out.

For example, a 300-field × 300-sink handler now maps to about 0.15 MB, down from about 56 MB.

Validation: full suite (3,450 passed, 7 skipped), typecheck, build. New regression tests fail on main, and each rule has its own test.

🤖 Generated with Claude Code

Vue, Svelte and Astro single-file components are now part of the import
inventory: their script blocks and Astro frontmatter are scanned for
imports, a component whose script cannot be delimited counts as an
unscannable file, and a skipped directory that holds components counts
as holding source. Components are scanned for imports only, which the
coverage notes now say.

Unproven flows grow with inputs times sinks, so an endpoint keeps at
most 200 of them and a map at most 1000. Proven flows are always kept.
An endpoint that left flows out is marked flowsTruncated.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderbuds

coderbuds Bot commented Sep 28, 2026

Copy link
Copy Markdown

Adds component import scanning and unproven flow bounding with solid testing.

🎯 Quality: 100% Elite · 📦 Size: Large — consider splitting if possible

📈 This month: Your 160th PR — above team average · Averaging Excellent

See how your team is trending →

@patchstackdave
patchstackdave merged commit fc37c58 into main Sep 29, 2026
18 checks passed
@patchstackdave
patchstackdave deleted the fix/map-completeness-bounds branch September 29, 2026 09:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants