Skip to content

fix(oa009): resolve the declaration guard the way PD001 does - #1241

Merged
sonukapoor merged 1 commit into
mainfrom
bugfix/issue-1118-oa009-declaration-guard
Sep 28, 2026
Merged

sonukapoor merged 1 commit into
mainfrom
bugfix/issue-1118-oa009-declaration-guard

Conversation

@sonukapoor

Copy link
Copy Markdown
Collaborator

OA009 suppresses itself when an override anchors a source import that is not declared, since removing the override would create a phantom PD001 would then report. That guard resolved declarations against the root manifest only, while PD001 (as of #1114) resolves against the nearest enclosing workspace member. So the two rules disagreed: a package declared in apps/web/package.json made PD001 correctly fall silent while OA009 kept suppressing itself, and a genuinely redundant override floor went unreported by either rule.

The guard now calls the shared undeclaredImportFiles from phantom-utils, so both rules answer the declaration question the same way.

Same lines, second smaller problem: OA009 carried its own private getDeclaredPackages reading only dependencies and devDependencies, while the shared one reads four sections. A package declared only as a peerDependency was invisible to the guard and suppressed the rule. That duplicate is deleted. rootDeclared is now computed once rather than per override entry.

On a workspace fixture where the member declares the package and the root does not, main reports a false PD001 and no OA009; with this it reports OA009 and no PD001. Across the tracked examples the only other change is analog, where PD002 drops from 10 to 5, and all five removed are declared in apps/docs-app/package.json so they were false positives. The five that remain are declared nowhere.

Closes #1118

OA009 suppresses itself when an override anchors a source import that is not
declared, because removing the override would create a phantom that PD001
would then report. That guard resolved declarations against the root
manifest only, while PD001 now resolves against the nearest enclosing
workspace member, so the two rules disagreed: a package declared in
apps/web/package.json made PD001 correctly fall silent while OA009 kept
suppressing itself, and a genuinely redundant floor went unreported by
either.

The guard now calls the shared undeclaredImportFiles from phantom-utils, so
both rules answer the declaration question the same way.

This also fixes a second, smaller problem in the same lines. OA009 carried
its own private getDeclaredPackages reading only dependencies and
devDependencies, while the shared one in phantom-utils reads four sections.
A package declared only as a peerDependency was invisible to the guard and
suppressed the rule. The duplicate is deleted.

rootDeclared is computed once rather than per override entry.

Verified end to end on a workspace fixture where the member declares the
package and the root does not: main reports a false PD001 and no OA009,
and after this it reports OA009 and no PD001. Across the tracked examples
the only other change is analog, where PD002 drops from 10 to 5, and all
five removed are declared in apps/docs-app/package.json so they were false
positives; the five that remain are declared nowhere.

Closes #1118
@sonukapoor
sonukapoor force-pushed the bugfix/issue-1118-oa009-declaration-guard branch from a475d24 to 8086350 Compare September 28, 2026 11:22
@sonukapoor
sonukapoor merged commit ac68de3 into main Sep 28, 2026
6 checks passed
@sonukapoor
sonukapoor deleted the bugfix/issue-1118-oa009-declaration-guard branch September 28, 2026 11:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(oa009): declaration guard resolves against the root manifest, diverging from PD001

1 participant