Hub rules-ant-design

rules-ant-design

v2 public Verified

Ant Design

Ant Design is a React UI framework that contains a set of high-quality components and demos for building rich, interactive user interfaces. These rules govern component usage, design system alignment, and accessibility for AI-assisted development.

@sigmashakeinc 2 pulls 6 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-ant-design →
Severity
3 error 3 warn 0 info
demo.cast
Ant Design is a React UI framework that contains a set of high-quality components and demos for building rich, interactive user interfaces. These rules govern component usage, design system alignment, and accessibility for AI-assisted development.

Rules index

6 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

ant-design

ant-design-deprecated-moment-js-usage warning log

Detected usage of 'moment.js'. While not a direct security vulnerability, 'moment.js' is considered a legacy library with a larger bundle size and mutable objects that can lead to subtle bugs. Ant Design and the React community generally recommend 'dayjs' or native 'Date' objects for date/time handling. Consider migrating to 'dayjs' for better performance, smaller bundle size, and modern immutable date practices.

Rule source requires an active Pro or Enterprise subscription.
ant-design-input-password-visibility-toggle-disabled warning log

Detected 'Input.Password' with 'visibilityToggle' explicitly set to 'false'. Disabling the password visibility toggle can negatively impact user experience and make it harder for users to verify their input, potentially leading to mistyped passwords and account lockouts. It is generally recommended to keep this feature enabled (which is the default behavior) to improve usability and reduce user frustration.

Rule source requires an active Pro or Enterprise subscription.
ant-design-legacy-form-create warning log

Detected usage of Ant Design v3 'Form.create()'. This Higher-Order Component (HOC) API is deprecated in Ant Design v4 and later. Please migrate to the modern 'Form' component and 'useForm' hook for improved maintainability, better performance, and full compatibility with React hooks. Using legacy APIs can lead to unexpected behavior, compatibility issues, or missed security updates in newer environments.

Rule source requires an active Pro or Enterprise subscription.
ant-design-unsanitized-html-in-alert-message-notification error block

Detected direct HTML string (e.g., template literal with '<') being passed to Ant Design 'message', 'notification', or 'Alert' components' content/message/description props. This is a high-risk XSS vulnerability if the HTML originates from user input. Ensure all user-supplied content is rigorously sanitized using a library like 'dompurify' before being rendered as HTML in these components.

Rule source requires an active Pro or Enterprise subscription.
ant-design-upload-missing-before-upload-validation error block

Detected Ant Design 'Upload' component without a 'beforeUpload' prop. This is a critical security risk as it allows users to upload any file type or size without client-side validation, potentially leading to Denial of Service (DoS), malware uploads, or other server-side vulnerabilities. Implement robust 'beforeUpload' logic to validate file type, size, and potentially content before the upload proceeds.

Rule source requires an active Pro or Enterprise subscription.
ant-design-xss-dangerously-set-inner-html error block

Detected 'dangerouslySetInnerHTML'. This is a critical Cross-Site Scripting (XSS) vulnerability if the content is not thoroughly sanitized. Always use a robust sanitization library like 'dompurify' to process any user-supplied or untrusted HTML before rendering. Prefer Ant Design's safe props or React's text rendering mechanisms where possible to avoid direct HTML injection.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v2
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
1d7223fa5d1e235412991afa423ed33464c186d64faee6fab61af219eab6b4ea
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-ant-design/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-ant-design. The published version only bumps when a maintainer resyncs.

No commit history available.