fix: use node resolver to prevent escaped traversal errors - #506
Conversation
📝 WalkthroughWalkthroughUpdated a lint suppression comment in the config builder and refactored the computation of the internal base path in Metro resolvers by replacing context-dependent resolver calls with Node's Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes Possibly related PRs
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
🧹 Nitpick comments (2)
packages/uniwind/src/metro/resolvers.ts (1)
47-53: Consider extracting the duplicated base-path resolution.The identical
try/catchblock is duplicated in bothnativeResolver(lines 47-53) andwebResolver(lines 95-101). A small helper would keep both paths in sync if the strategy evolves again.♻️ Proposed refactor
let cachedInternalBasePath: string | null = null + +const getInternalBasePath = () => { + if (cachedInternalBasePath === null) { + try { + cachedInternalBasePath = dirname(require.resolve('uniwind/package.json')) + } catch { + cachedInternalBasePath = '' + } + } + return cachedInternalBasePath +}Then replace both inline blocks with
const basePath = getInternalBasePath()and usebasePathin the subsequent checks.🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@packages/uniwind/src/metro/resolvers.ts` around lines 47 - 53, Extract the duplicated try/catch resolution into a small helper (e.g., getInternalBasePath) that returns the dirname of require.resolve('uniwind/package.json') or '' on failure and uses a module-scoped cache similar to cachedInternalBasePath; then replace the inline blocks inside nativeResolver and webResolver with const basePath = getInternalBasePath() (or use the cached value returned) and update subsequent checks to reference basePath so both resolvers share the same resolution logic.packages/uniwind/src/core/config/config.common.ts (1)
104-107: Lint suppression correction is appropriate; underscore prefix would align with existing conventions.The change to
typescript/no-unused-varscorrectly addresses the unused parameter. However, this file already uses underscore prefixes for intentionally unused parameters (line 109:_: GenerateStyleSheetsCallback), whileupdateInsetsandupdateCSSVariablesuse lint suppression comments. For consistency:Optional refactor for consistency
- // oxlint-disable-next-line typescript/no-unused-vars - updateInsets(insets: Insets) { + updateInsets(_insets: Insets) { // noop }This matches the pattern at line 109 and eliminates the suppression comment entirely.
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@packages/uniwind/src/core/config/config.common.ts` around lines 104 - 107, Replace the inline lint suppression for unused parameters with the underscore-prefixed parameter naming used elsewhere: change the signatures of updateInsets(insets: Insets) and updateCSSVariables(cssVars: CSSVariables) to use _insets and _cssVars respectively (matching the existing pattern used for _: GenerateStyleSheetsCallback) so the compiler understands the parameters are intentionally unused and the types remain declared without needing the typescript/no-unused-vars disable comment.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Nitpick comments:
In `@packages/uniwind/src/core/config/config.common.ts`:
- Around line 104-107: Replace the inline lint suppression for unused parameters
with the underscore-prefixed parameter naming used elsewhere: change the
signatures of updateInsets(insets: Insets) and updateCSSVariables(cssVars:
CSSVariables) to use _insets and _cssVars respectively (matching the existing
pattern used for _: GenerateStyleSheetsCallback) so the compiler understands the
parameters are intentionally unused and the types remain declared without
needing the typescript/no-unused-vars disable comment.
In `@packages/uniwind/src/metro/resolvers.ts`:
- Around line 47-53: Extract the duplicated try/catch resolution into a small
helper (e.g., getInternalBasePath) that returns the dirname of
require.resolve('uniwind/package.json') or '' on failure and uses a
module-scoped cache similar to cachedInternalBasePath; then replace the inline
blocks inside nativeResolver and webResolver with const basePath =
getInternalBasePath() (or use the cached value returned) and update subsequent
checks to reference basePath so both resolvers share the same resolution logic.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 822e3733-db72-4ec8-9494-0126e361004a
📒 Files selected for processing (2)
packages/uniwind/src/core/config/config.common.tspackages/uniwind/src/metro/resolvers.ts
|
🚀 This pull request is included in v1.6.3. See Release v1.6.3 for release notes. |
Xcode 27 rejects deployment targets below iOS 15.0, and SDK 55 left the resource bundle targets of PostHog, SDWebImage, ReachabilitySwift, RNSVG and RNCAsyncStorage at their podspecs' 9.0-13.4, failing the archive. SDK 57 raises them (expo/expo#47562). Apps built against the iOS 27 SDK also crash at launch without the UIKit scene lifecycle, which SDK 57 turns on through expo-build-properties' enableSceneSupport; SDK 58 makes it the default, so the setting goes then. - expo 57.0.23, react-native 0.86.3, and every expo-* and native module on its SDK 57 pin. React moves to 19.2.3 at the root and in frontend and admin, since react-native 0.86 needs it. - uniwind 1.12.0: 1.6.1 tripped Metro's "Unexpectedly escaped traversal" in this Bun monorepo (uni-stack/uniwind#506). - expo-router renamed Route to RoutePath, and app code imports React Navigation through expo-router/react-navigation. The unused @react-navigation/* packages are gone. - EAS builds on Node 22.13.0, the floor for react-native 0.85+. - react-native-qrcode-svg 6.3.24 accepts react-native-svg 15. - eslint-config-expo stays on 55: 57 turns on React Compiler rules that flag 52 existing errors, a separate cleanup. - The iOS app carries the Sign in with Apple entitlement. The native fingerprint changes, so this ships as a store build. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
fixes #505
Summary by CodeRabbit