ci: add safesql ratchet (#44678)

We are currently migrating to the safeSql utility for all SQL arguments
of executeSql. During the migration, executeSql will continue to accept
plain strings for backwards compatibility. Adding a custom ESLint rule
so we can ratchet this and prevent new calls of executeSql with plain
strings.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added SQL safety validation throughout the application to enforce
secure query construction and prevent SQL-related vulnerabilities
* Introduced type-aware linting to identify and catch type-related
issues during development and continuous integration processes

* **Chores**
* Enhanced continuous integration pipeline with improved code quality
enforcement

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
This commit is contained in:
Charis authored and GitHub committed 2026-04-09 15:32:33 -04:00
1 parent 5d013cb2f6
commit bf46092290
6 files changed
+264 -5

No files matched your search

@@ -44,3 +44,8 @@ jobs:
- name: Run ratchet script
run: pnpm --filter studio run lint:ratchet
- name: Run type-aware ratchet script
env:
NODE_OPTIONS: --max-old-space-size=4096
run: pnpm --filter studio run lint:ratchet:type-checks