You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Core code changed? - Tested with other Redocly products (internal contributions only)
New package installed? - Tested in different environments (browser/node)
Documentation update has been considered
Security
The security impact of the change has been considered
Code follows company security practices and guidelines
Note
Medium Risk
Adds a new custom lint rule and refactors several runtime validation/type-guard call sites (including resolver/bundler paths) to use isPlainObject, which could change behavior for edge cases involving null/arrays and example.externalValue handling.
Overview Introduces a custom Oxlint plugin ruleoxlint-redocly-plugin/no-typeof-object (wired via .oxlintrc.json) to ban typeof x === 'object' comparisons and push callers toward more precise checks.
Refactors affected code paths to use isPlainObject instead of ad-hoc typeof/array checks (e.g., mTLS CLI option parsing, InfoOverride, entity rule validation, and OAS2 required-field logic), and updates core ref/external example handling with tighter typings (adds Oas3Example exports, narrows isExternalValue, and adjusts deletion/casting).
Type updates: loosens Oas3Example.value to optional and tightens examples shapes in respect-core to Record<string, Oas3Example> with safer extraction/undefined returns.
Reviewed by Cursor Bugbot for commit b59b1cc. Bugbot is set up for automated code reviews on this repo. Configure here.
Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.
This PR includes no changesets
When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What/Why/How?
no-typeof-objectcode linting rule to prevent arrays accidentally slipping throughtype ... 'object'comparison.Testing
E2E passed here.
Check yourself
Security
Note
Medium Risk
Adds a new custom lint rule and refactors several runtime validation/type-guard call sites (including resolver/bundler paths) to use
isPlainObject, which could change behavior for edge cases involvingnull/arrays andexample.externalValuehandling.Overview
Introduces a custom Oxlint plugin rule
oxlint-redocly-plugin/no-typeof-object(wired via.oxlintrc.json) to bantypeof x === 'object'comparisons and push callers toward more precise checks.Refactors affected code paths to use
isPlainObjectinstead of ad-hoctypeof/array checks (e.g., mTLS CLI option parsing,InfoOverride, entity rule validation, and OAS2 required-field logic), and updates core ref/external example handling with tighter typings (addsOas3Exampleexports, narrowsisExternalValue, and adjusts deletion/casting).Type updates: loosens
Oas3Example.valueto optional and tightensexamplesshapes inrespect-coretoRecord<string, Oas3Example>with safer extraction/undefined returns.Reviewed by Cursor Bugbot for commit b59b1cc. Bugbot is set up for automated code reviews on this repo. Configure here.