Hub rules-astro

rules-astro

v5 public Verified

Astro

Astro is a modern web framework for building fast, content-focused websites. These rules govern component islands, static site generation, and performance optimization for AI-assisted Astro development.

@sigmashakeinc 2 pulls 8 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-astro →
Severity
4 error 4 warn 0 info
demo.cast
Astro is a modern web framework for building fast, content-focused websites. These rules govern component islands, static site generation, and performance optimization for AI-assisted Astro development.

Rules index

8 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

astro

astro-api-route-missing-method-check warning log

Astro API endpoint does not check the HTTP method. Endpoints that mutate state (POST/PUT/DELETE) must verify the method to prevent cross-site request forgery (CSRF) and unintended GET-triggered side effects. FIX: Check 'request.method' at the top of the handler and return 405 for unexpected methods. For state-mutating routes also validate a CSRF token or require a custom header (e.g. 'X-Requested-With').

Rule source requires an active Pro or Enterprise subscription.
astro-client-env-variable-misuse warning log

Misuse of environment variables in Astro component. 'process.env' is a Node.js global and generally not available or correctly processed in client-side Astro components or islands. For environment variables, use 'import.meta.env' (e.g., 'import.meta.env.PUBLIC_MY_VAR'). Ensure client-side variables are prefixed with 'PUBLIC_' in your '.env' file.

Rule source requires an active Pro or Enterprise subscription.
astro-deprecated-fetch-content warning log

Deprecated API usage: 'Astro.fetchContent()' is no longer recommended. Use 'Astro.glob()' for querying local content files (e.g., Markdown, MDX). 'Astro.glob()' offers better performance and a more consistent API. Example: const posts = await Astro.glob('../pages/**/*.md');

Rule source requires an active Pro or Enterprise subscription.
astro-hardcoded-secret-key error block

RISK: Hardcoded secret/API key detected in source. Committing credentials to VCS exposes them in git history permanently — the average time-to-exploit for leaked secrets is under 5 minutes (GitGuardian 2025). FIX: Use environment variables (import.meta.env.SECRET_VAR for server-only, PUBLIC_ prefix for client-safe values) and load them at runtime. Never commit secrets.

Rule source requires an active Pro or Enterprise subscription.
astro-insecure-target-blank warning log

Insecure link detected: Links with 'target="_blank"' should always include 'rel="noopener noreferrer"' to prevent tabnabbing (reverse tabnabbing) attacks. This prevents the opened page from gaining partial control over the opener page. Add 'rel="noopener noreferrer"' to all such links.

Rule source requires an active Pro or Enterprise subscription.
astro-path-traversal-fs-params error block

Potential Path Traversal vulnerability detected. Using 'fs' module functions (e.g., readFile, writeFile) with paths derived directly from 'Astro.params' without strict sanitization and validation can allow attackers to access or modify arbitrary files on the server. Always sanitize and validate user-supplied path segments to ensure they stay within intended directories.

Rule source requires an active Pro or Enterprise subscription.
astro-server-secret-in-public-env error block

RISK: A PUBLIC_ prefixed environment variable name contains a secret-sounding term (SECRET/KEY/TOKEN/PASSWORD/PRIVATE). In Astro, PUBLIC_ variables are embedded in the client bundle and shipped to every browser visitor — they are not secret. FIX: Remove the PUBLIC_ prefix and access the variable only in server-side code (.ts, server API routes, or the frontmatter fence), or rename it to a non-secret purpose.

Rule source requires an active Pro or Enterprise subscription.
astro-xss-set-html-unsanitized error log

Potential Cross-Site Scripting (XSS) vulnerability detected. Using 'set:html' with untrusted or unsanitized input can lead to arbitrary code execution in the user's browser. Always sanitize user-generated or external content using a library like 'dompurify' or 'sanitize-html' before injecting it via 'set:html'. Example: <div set:html={DOMPurify.sanitize(userContent)} />

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
ca0fc96ac6e57cb3a1eead05525636879fea70f84247fc71024f3a3ff4b7ff97
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-astro/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-astro. The published version only bumps when a maintainer resyncs.

No commit history available.