Hub rules-backend

rules-backend

v5 public Verified

Backend

Community-governed security ruleset for Backend

@sigmashakeinc 0 pulls 7 rules published Apr 10, 2026 synced Sep 27, 2026 sigmashakeinc/rules/rulesets/rules-backend →
Severity
4 error 3 warn 0 info
demo.cast
Community-governed security ruleset for Backend

Rules index

7 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

api

audit-cors-wildcard warning log

RISK: CORS wildcard (*) allows any origin to make credentialed cross-origin requests to this API — a broad exposure for APIs that use cookies or Authorization headers. FIX: Restrict to an explicit origin allowlist and set Access-Control-Allow-Credentials: false unless genuinely needed.

Rule source requires an active Pro or Enterprise subscription.
block-hardcoded-api-key error block

RISK: Hardcoded credential in source — secrets committed to VCS are recoverable from git history forever and weaponized within minutes of exposure (GitGuardian 2025). FIX: Load from environment variables (process.env / os.environ) or a secrets manager; never hard-code credentials.

Rule source requires an active Pro or Enterprise subscription.
block-path-traversal-req-param error block

RISK: File-system call using a value from request params/query/body without sanitization enables path traversal (CWE-22). An attacker can supply '../../etc/passwd' to read arbitrary files. FIX: Resolve the path with path.resolve(baseDir, userInput), verify the result starts with baseDir, and reject any path that escapes the allowed directory.

Rule source requires an active Pro or Enterprise subscription.
block-raw-sql-injection error block

RISK: SQL query built by string concatenation is injectable (CWE-89). An attacker can manipulate the concatenated value to read/modify/drop any table the DB user can reach. FIX: Use parameterized queries — prisma, typeorm, or db.query('SELECT ... WHERE id = ?', [id]) — never build SQL with '+'.

Rule source requires an active Pro or Enterprise subscription.
warn-missing-authz-middleware warning log

RISK: Route file with state-mutating endpoints (POST/PUT/PATCH/DELETE) does not appear to import or reference any authentication or authorization middleware. Missing authz is the #1 API vulnerability (OWASP API3:2023). FIX: Apply an authentication guard to all non-public mutating routes and verify the caller's role/permissions before executing.

Rule source requires an active Pro or Enterprise subscription.
warn-ssrf-fetch-user-input warning ask

RISK: HTTP fetch/request using a URL derived from user input is a Server-Side Request Forgery (SSRF) vector (CWE-918) — an attacker can reach internal services (AWS IMDS, internal databases, localhost admin ports). FIX: Validate the URL against a strict allowlist of known-safe hosts before making the request; reject private IP ranges and localhost.

Rule source requires an active Pro or Enterprise subscription.
warn-unsafe-deserialization error block

RISK: eval() / YAML.load() (without safeLoad) / pickle.load() execute arbitrary code when given untrusted input (CWE-502/CWE-94). FIX: Replace eval() with JSON.parse() or a safe expression evaluator; use YAML.safeLoad() / yaml.safe_load(); replace pickle with JSON or a schema-validated format.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 10, 2026
Source commits
0
Synced
Sep 27, 2026
Hash
378bfb1861ff7131002e52f30dd033594adfcfd568b0c30d362b88c7f1695336
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-backend/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-backend. The published version only bumps when a maintainer resyncs.

No commit history available.