You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: CHANGELOG.md
+6Lines changed: 6 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,6 +5,11 @@ All notable changes to this project will be documented in this file.
5
5
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
6
6
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
7
7
8
+
## [0.24.13] - 2026-08-01
9
+
10
+
### Fixed
11
+
- Destructuring variable declarations (`const { a, b } = expr` / `const [a, b] = expr`) are now decomposed into their individual bindings for both symbol and export extraction. Previously `getDeclName` only handled plain identifiers and returned `""` for binding patterns, so destructured names were registered as neither symbols nor exports — they simply didn't exist in the file model. That silently broke taint propagation through a very common pattern: e.g. `export const { store, startSagas, … } = createStore()` in `gdc-analytical-designer-runtime`'s `reduxStore.ts`. A runtime change to the reducers feeding `createStore` tainted `createStore`, but the taint could not reach `store`/`startSagas`/…, so the package reported **0 affected exports** and nothing propagated to the AD module/harness (or the dashboards harness that embeds it) — a false negative. Each destructured binding is now emitted as a symbol/export; renames (`{ a: b }` → `b`), rest elements (`...x`), nested patterns and array holes are handled. To stay precise, a binding's symbol span is the **initializer expression** (not the whole statement), so the sibling binding names don't bleed into the compared body and cross-link in the AST diff — each binding is attributed exactly to the initializer it destructures.
12
+
8
13
## [0.24.12] - 2026-07-30
9
14
10
15
### Fixed
@@ -382,6 +387,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
0 commit comments