Skip to main content

Version 1.0.0 quality review

This review covers the native rule, process lifecycle, package exports and declarations, tests, documentation, shared tooling, and GitHub release automation. The comparison was made on September 6, 2026 against these repository snapshots:

ReferenceRole in this package
stylelint-plugin-font at c9fe171Stylelint API, repository structure, shared configurations, CI, and documentation infrastructure.
eslint-plugin-file-progress-2 at v5.1.9Display options, seven presets, process summaries, and colored GIF/cast presentations.
stylelint-plugin-css-performance-budget at 73c865bAdditional comparison of package, compatibility, and release conventions.

Findings addressedโ€‹

FindingChange and verification
Seven public TypeDoc members lacked comments.Document metadata fields, the rule registry member, and plugin properties. Every docs build now requires all 40 public reflections to be documented.
The original demonstration was a plain static image.Add 31 colored GIFs with deterministic terminal casts: seven presets and 24 option scenarios covering every setting and spinner style. Check cast contents, GIF hashes, inventory, and the static poster.
README generation would remove the maintainer's badge row.Preserve the badge identities, labels, colors, order, and links in the generator. Replace obsolete pre-publication installation guidance.
Accepted null secondary settings could crash linting.Normalize [true, null] to the defaults and exercise it through Stylelint. A primary null still disables the rule.
Multiple roots could repeat invalid-option diagnostics.Deduplicate validation by processing-result identity across module formats. Test an HTML document containing two style roots.
Numeric descriptor writes bypassed captured worker output.Use worker streams inside workers and release temporary error listeners after completion or failure. Real subprocess tests capture both stdout and stderr, including the single shutdown summary.
Removing a watched working directory could abort progress reporting.Fall back to the supplied filename when the working directory cannot be resolved.
Legacy TypeScript mappings did not match direct CommonJS exports.Point legacy package and preset resolution to CommonJS declarations; test preset properties and public option types with Stylelint 16 legacy resolution and strict NodeNext consumers across both Stylelint majors.
Standalone generated-content checks could use stale builds.Build current source before all demo and synchronization commands, and fail if the generated option-table markers are missing.
Docusaurus inherited vulnerable image parsers.Use the exact, reviewed image-size-next@2.1.1 fork only beneath Docusaurus. Exercise malformed ICNS/JXL/HEIF files in bounded subprocesses and valid SVG/GIF/PNG dimensions. Keep the full dependency review active.
A post-publication GitHub API failure could strand a release.Move npm artifact/provenance verification and GitHub release creation into a separately retryable job. Rerun failed jobs to finish a successful publication without publishing again.
A newer push could cancel an already validated Pages deployment.Let an active Pages deployment finish while subsequent runs wait.

Comparison with the plugin familyโ€‹

The package uses the same published shared configurations, strict TypeScript approach, npm 12 lifecycle allowlist, Node version files, dual module formats, inspector integrations, and owner-controlled reusable workflows as the maintained plugin family. It adds explicit checks for complete API documentation, generated demos, and legacy CommonJS consumers where the original progress implementation needed stronger guarantees.

The runtime remains a native Stylelint rule with no ESLint dependency, CLI wrapper, or public session API. The smaller rule count does not justify importing unrelated rule benchmarks, Electron tooling, or application database commands from a sibling repository. Verification instead concentrates on observational behavior: unchanged CSS, diagnostics, formatter output, fixes, and exit status.

Terminal frames advance when files are observed and replace the previous block in place, including wrapped paths. Terminal dimensions and Node stream write counters prevent the renderer from clearing rows after a resize or intervening formatter output. No animation timers or stream patches are needed. Terminal-emulator tests verify the visible screen as well as the raw CLI report.

Release gatesโ€‹

The main branch requires all three operating-system test jobs, the combined quality/documentation/package job, and CodeQL analysis before merging. Dependabot updates to CodeQL actions are grouped so init and analyze stay on the same release. Manual CI and CodeQL triggers allow validation of commits created by automation that cannot trigger a new push workflow with GITHUB_TOKEN.

npm run release:verify checks source types, all shared-config linters, runtime coverage, malformed documentation images, generated content, the documentation application and public API, package exports, and clean package consumers. CI also runs coverage on Linux, Windows, and macOS, then separately verifies Node 22.0.0 consumers. Each runtime coverage threshold remains 90%.

Consumer checks install the packed artifact with exact Stylelint 16.0.0, current 16.x, exact 17.14.0, and current 17.x. Both ESM and CommonJS entrypoints and all seven preset subpaths are exercised. Legacy TypeScript resolution is tested with Stylelint 16; Stylelint 17 exposes its own types only through modern package exports. CommonJS with Stylelint 17 requires Node 22.12 or newer because of Stylelint's ESM loading requirements.

Release jobs verify the committed version, main-branch ancestry, tag identity, and absence of an existing npm version. Publication uses GitHub OIDC and npm provenance for the exact verified tarball. A subsequent job compares npm's integrity with that tarball and requires its provenance attestation before creating the GitHub Release.

The tarball publish command uses an explicit ./ prefix, as npm 12 otherwise interprets release/package.tgz as GitHub shorthand. The portable npm run release:check-tarball command requires exactly one artifact in release/ and exercises its local tarball argument in a dry run before the publishing job starts. Provenance is disabled only for that non-uploading dry run; the publishing job requires it.

Maintenance boundariesโ€‹

Stylelint Config Inspector 2.3.7 provides an embedded startup favicon and resolves its active icon links from the runtime deployment base. Upstream browser regressions cover startup with JavaScript disabled and root and nested deployments after navigation. This repository uses that release directly; the temporary JavaScript post-processing correction has been removed. Documentation checks still reject root-relative icon links and require the icon files.

The 1.0.1 Windows console correction routes terminal output through Node's console-aware streams. A native code-page-437 reproduction showed corrupted spinner marks and filenames with descriptor writes; the corrected transport preserves Unicode and ANSI output without changing console settings. Regression tests cover both output streams, shutdown output, listener cleanup, and byte-for-byte parity with Stylelint's colored formatter at 80 and 160 columns. The runtime suite now has 63 tests, with 100% statement, line, and function coverage and 95.41% branch coverage.

The documentation parser override is a maintained fork, not an upstream image-size release. Its source delta, exact version, license, API compatibility, and integrity are documented in contributing. Reassess it when Docusaurus adopts a patched parser; it is not shipped as a plugin runtime dependency.

Counts cover observed rule-processing events. Cache skips and parse failures before rule execution are absent; throttling can hide live notifications while counts continue. Long-lived applications aggregate until shutdown. Worker threads have independent JavaScript state and summaries, with output sent through their selected worker stream. No display claims an exact input total, ETA, problem count, or individual-file completion time.