Skip to content

1.8.1: detect TanStack Start/Router/Query in production - #5

Merged
deepu0 merged 2 commits into
mainfrom
feat/tanstack-detection
Sep 26, 2026
Merged

deepu0 merged 2 commits into
mainfrom
feat/tanstack-detection

Conversation

@kiro-agent

@kiro-agent kiro-agent Bot commented Sep 26, 2026

Copy link
Copy Markdown

WhatStack 1.8.1 — TanStack in production

1.8.0 only recognised TanStack from package names in asset URLs
(@tanstack/react-query@…) and from dev-only globals. Production apps ship
hashed chunks, so real TanStack Start, Router and Query apps showed nothing:
tanstack.com itself reported only Tailwind, Sentry and Google Analytics.

What changed

  • TanStack Router / Start production globals. Production apps expose
    window.__TSR_ROUTER__ (a router with routesById + buildLocation) and
    window.__TSS_START_OPTIONS__. 1.8.0 looked for __TANSTACK_ROUTER__ /
    __TANSTACK_START__, which don't exist in production builds.
  • A bounded React-tree walk. TanStack Query, data routers, Redux and Apollo
    have no global in production, but their clients are passed to a provider
    component. The MAIN-world probe walks the React tree from the root fiber
    (at most 6,000 fibers or 25 ms) and accepts only objects with the library's
    shape: a QueryClient has getQueryCache + getMutationCache, a TanStack
    router has routesById + buildLocation, a React Router data router has
    routes, navigate, subscribe and state, a Redux store has
    dispatch / getState / subscribe, an Apollo client has watchQuery /
    query / cache. Works when React hydrates document (TanStack Start).
  • Manual chunk names (tanstack-router-B-OQbHRF.js, tanstack-query-….js)
    count as evidence; image names still never do.
  • Foreign webpack globals. A consent banner's webpackChunk_osano_… on a
    Vite-built TanStack Start site is shown as low, like Parcel on Next.js in 1.8.0.

Measured (real extension, headless Chromium)

Site 1.8.0 1.8.1
tanstack.com Tailwind, Sentry, GA, Cloudflare TanStack Start, Router, Query, React, Tailwind, Sentry, GA, Cloudflare
railway.com — (not in corpus) TanStack Start, Router, Query, React, … (webpack from a consent banner → low)
bolt.new React, React Router 7.18.2, … … + TanStack Query
onlyfrontendjobs.com Next.js, React, … … + TanStack Query (confirmed: @tanstack/react-query in its package.json)
airbnb.com, flipkart.com React, React Router … + Redux
netflix.com React, Webpack, Emotion … + Apollo Client
spotify.com React, React Router, … … + Redux, TanStack Query

No other result in the 49-site golden corpus changed (nextjs.org's Vercel hint
came from a lazily loaded image and did not load during the second capture).

Not verifiable from here

  • chatgpt.com (logged out) is OpenAI's own lightweight "Octane" shell, with
    no TanStack, React Router or Remix markers. The logged-in app may differ.
  • lovable.dev serves a Cloudflare challenge to headless browsers.

Both can be checked in a real browser; see the README.

- read the production globals __TSR_ROUTER__ and __TSS_START_OPTIONS__
  (1.8.0 looked for dev-only names that production never sets)
- bounded React-tree walk (6k fibers / 25 ms) finds provider clients with
  no global: TanStack Query, TanStack Router, React Router data routers,
  Redux, Apollo — shape-checked, works when React hydrates document
- manual chunk names tanstack-router-*.js / tanstack-query-*.js
- foreign webpack globals on Vite-based TanStack Start are low
- corpus: + tanstack.com, railway.com, bolt.new; all 49 sites recaptured
- 1.8.1

@xhawk-ai xhawk-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📋 Review Summary — Not ready to merge

1 medium finding would be worth fixing before merging.

Findings

  1. Medium Testing The nextjs.org corpus update makes npm test fail ▶
Fix with agent prompt
These are the findings from a code review of this pull request.

## 1. The nextjs.org corpus update makes npm test fail
Path: tests/corpus/nextjs.org.json
Line: 18

Issue: This snapshot removes `vercel:high`, but `tests/corpus/sites.json` still lists `vercel` as a required hit for `nextjs.org`; `tests/corpus.test.js` gives `sites.json` precedence over the per-record `expect`, so `npm test` fails with `nextjs.org: expected vercel`.
Suggested fix:
- Update `tests/corpus/sites.json` so the `nextjs.org` expectation matches the new capture, or restore a Vercel signal/snapshot entry if Vercel is still intended to be required.

---

For each finding above, determine whether it is valid and should be fixed. If so, fix it directly. Where a finding offers several remedies, pick one and say why. Leave the pull request's own changed files alone unless a fix requires touching them.

Summary

The change adds production TanStack Start/Router globals, React-fiber provider scanning, TanStack chunk-name signatures, and corpus updates for the 1.8.1 release. The detection implementation is mostly coherent, but the committed corpus expectations are internally inconsistent: the Next.js capture no longer reports Vercel while the corpus manifest still requires it, so the offline test suite fails before merge.

Commands

Re-review the latest changes:

@xhawk-ai review again

Resolve all review threads and post a summary:

@xhawk-ai resolve all

"tailwind:high",
"turbopack:high",
"vercel:high"
"turbopack:high"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Medium Testing
The nextjs.org corpus update makes npm test fail

This snapshot removes vercel:high, but tests/corpus/sites.json still lists vercel as a required hit for nextjs.org; tests/corpus.test.js gives sites.json precedence over the per-record expect, so npm test fails with nextjs.org: expected vercel.

Suggestions

Update tests/corpus/sites.json so the nextjs.org expectation matches the new capture, or restore a Vercel signal/snapshot entry if Vercel is still intended to be required.

@deepu0
deepu0 merged commit 2aadebc into main Sep 26, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants