fix(oa009): resolve the declaration guard the way PD001 does - #1241
Merged
Merged
Conversation
OA009 suppresses itself when an override anchors a source import that is not declared, because removing the override would create a phantom that PD001 would then report. That guard resolved declarations against the root manifest only, while PD001 now resolves against the nearest enclosing workspace member, so the two rules disagreed: a package declared in apps/web/package.json made PD001 correctly fall silent while OA009 kept suppressing itself, and a genuinely redundant floor went unreported by either. The guard now calls the shared undeclaredImportFiles from phantom-utils, so both rules answer the declaration question the same way. This also fixes a second, smaller problem in the same lines. OA009 carried its own private getDeclaredPackages reading only dependencies and devDependencies, while the shared one in phantom-utils reads four sections. A package declared only as a peerDependency was invisible to the guard and suppressed the rule. The duplicate is deleted. rootDeclared is computed once rather than per override entry. Verified end to end on a workspace fixture where the member declares the package and the root does not: main reports a false PD001 and no OA009, and after this it reports OA009 and no PD001. Across the tracked examples the only other change is analog, where PD002 drops from 10 to 5, and all five removed are declared in apps/docs-app/package.json so they were false positives; the five that remain are declared nowhere. Closes #1118
sonukapoor
force-pushed
the
bugfix/issue-1118-oa009-declaration-guard
branch
from
September 28, 2026 11:22
a475d24 to
8086350
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
OA009 suppresses itself when an override anchors a source import that is not declared, since removing the override would create a phantom PD001 would then report. That guard resolved declarations against the root manifest only, while PD001 (as of #1114) resolves against the nearest enclosing workspace member. So the two rules disagreed: a package declared in
apps/web/package.jsonmade PD001 correctly fall silent while OA009 kept suppressing itself, and a genuinely redundant override floor went unreported by either rule.The guard now calls the shared
undeclaredImportFilesfromphantom-utils, so both rules answer the declaration question the same way.Same lines, second smaller problem: OA009 carried its own private
getDeclaredPackagesreading onlydependenciesanddevDependencies, while the shared one reads four sections. A package declared only as apeerDependencywas invisible to the guard and suppressed the rule. That duplicate is deleted.rootDeclaredis now computed once rather than per override entry.On a workspace fixture where the member declares the package and the root does not,
mainreports a false PD001 and no OA009; with this it reports OA009 and no PD001. Across the tracked examples the only other change isanalog, where PD002 drops from 10 to 5, and all five removed are declared inapps/docs-app/package.jsonso they were false positives. The five that remain are declared nowhere.Closes #1118