New
Introducing React Bench, see how different models perform on React code

react-doctor/unused-dev-dependency

A development dependency has no detected project usage

Status
Active
Category
Maintainability
Assessment
Evidence-required risk
Required evidence
source code, repository context
Default configuration
Disabled until configured
Default severity
warn
Show technical metadata
Scope
All supported frameworks
Active when
full project scans when explicitly configured
Tags
project-analysis
Priority
24 (P3)
Source
react-doctor-core
Rule set
oxlint-plugin-react-doctor 0.9.3 (prompt schema 2)
On this page

Validation prompt

Confirm the detector match and collect the required evidence before deciding whether an edit is warranted.

This opt-in project rule reports a package from devDependencies when source, scripts, config files, plugins, and known tool conventions do not use it. Confirm CI commands, editor tooling, generated configuration, and release automation before accepting the finding. Reject tools invoked outside the scanned repository.

Evidence boundary

The diagnostic proves only that the detector’s modeled source pattern matched. It does not prove runtime impact, product intent, rendered failure, or that one remediation is correct.

Establish the environment, repository policy, exceptions, and required rendered or runtime evidence before deciding the occurrence.

Record one outcome:

  • Confirmed failure: The required evidence establishes the violation.
  • Rejected: A documented exception or false-positive predicate applies.
  • Needs evidence: Named evidence can still be collected.
  • Unavailable: Required evidence cannot be collected in this run.
  • Waived with evidence: An authorized, scoped exception applies to an established failure.
  • Observation: The review records an optional tradeoff without claiming a defect.

A waiver records its scope, authority, evidence, and review condition. It is not a pass or false positive.

Default severity is registry metadata. Use the occurrence’s JSON severity after repository configuration when ordering real findings.

Review a candidate correction

Apply this candidate correction only after the required evidence confirms the risk.

Reported pattern

{
  "devDependencies": {
    "eslint": "^9.0.0",
    "@faker-js/faker": "^9.0.0"
  }
}

Candidate corrected pattern

{
  "devDependencies": {
    "eslint": "^9.0.0"
  }
}

Fix prompt

Apply this candidate correction only after the required evidence confirms the risk.

Remove the confirmed unused development dependency with the repository's package manager. Update the lockfile, then run a full React Doctor scan and every affected build, test, lint, and release command.

Repository-wide copy prompt

Use this repository-wide prompt only after validating each occurrence. For one occurrence, use the guidance above.

Show repository-wide prompt

Fix every confirmed react-doctor/unused-dev-dependency diagnostic in the current repository.

Required change:

  • Remove the confirmed unused development dependency with the repository's package manager. Update the lockfile, then run a full React Doctor scan and every affected build, test, lint, and release command.

Validation before editing:

This opt-in project rule reports a package from devDependencies when source, scripts, config files, plugins, and known tool conventions do not use it. Confirm CI commands, editor tooling, generated configuration, and release automation before accepting the finding. Reject tools invoked outside the scanned repository.

Constraints:

  • Confirm every occurrence independently.
  • Make the smallest change that addresses the root cause.
  • Preserve unrelated behavior, interfaces, content, and semantics.
  • Reuse existing project conventions and components.
  • Do not suppress the rule merely to clear the report.

Assessment:

  • Record detector evidence, applicability, missing evidence, and one outcome: Confirmed failure, Rejected, Needs evidence, Unavailable, Waived with evidence, or Observation.

Verification:

  • Run focused tests and every repository-mandated check.
  • Run React Doctor and confirm the diagnostic no longer appears from changed code.
  • Run an unfiltered scan of the affected scope before claiming no cross-category regression.
  • Report checks that were not run instead of claiming they passed.