Hub rules-bitbucket-actions

rules-bitbucket-actions

v5 public Verified

Bitbucket-actions

Bitbucket Pipelines/Actions is a CI/CD service built into Bitbucket. These rules govern pipeline configurations, step definitions, and security for AI-assisted Bitbucket automation.

@sigmashakeinc 2 pulls 8 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-bitbucket-actions →
Severity
7 error 1 warn 0 info
demo.cast
Bitbucket Pipelines/Actions is a CI/CD service built into Bitbucket. These rules govern pipeline configurations, step definitions, and security for AI-assisted Bitbucket automation.

Rules index

8 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

bitbucket-actions

bitbucket-actions-command-injection-unquoted-variable error block

RISK: $BITBUCKET_BRANCH used unquoted in a script: block — a malicious branch name causes shell command injection (CWE-78). FIX: Always quote Bitbucket variables: "${BITBUCKET_BRANCH}" or use printf %%q for robust escaping.

Rule source requires an active Pro or Enterprise subscription.
bitbucket-actions-curl-pipe-shell error block

RISK: Piping a remote download directly into a shell executes untrusted code without inspection — a compromised upstream URL becomes RCE in the pipeline (supply-chain attack, CWE-494). FIX: Download the script explicitly, verify its SHA-256 checksum against a pinned value, then execute.

Rule source requires an active Pro or Enterprise subscription.
bitbucket-actions-disable-ssl-verification error block

RISK: Disabling TLS verification exposes pipeline traffic to MITM attacks. FIX: Remove --insecure / -k / --no-check-certificate; supply a custom CA bundle with --cacert if needed.

Rule source requires an active Pro or Enterprise subscription.
bitbucket-actions-hardcoded-secret-in-variables error block

RISK: Plaintext secret hardcoded in the 'variables:' block — anyone with read access to the repo can see it, and it persists in git history. FIX: Use Bitbucket Repository Variables (repo settings > Repository variables) and reference them as $VARIABLE_NAME; never embed secret values inline.

Rule source requires an active Pro or Enterprise subscription.
bitbucket-actions-insecure-docker-image-tag error block

RISK: Pinning to ':latest' causes non-reproducible builds and silently pulls unreviewed upstream changes that may include vulnerabilities or supply-chain backdoors. FIX: Pin to an immutable digest or exact version tag (e.g. node:20.14.0-alpine3.20).

Rule source requires an active Pro or Enterprise subscription.
bitbucket-actions-insecure-eval-usage error block

RISK: eval on a variable in a pipeline script is a command-injection sink — if any upstream value (branch name, commit message, env var) reaches it, arbitrary commands run with pipeline credentials. FIX: Replace with case/esac dispatch or array-based command construction.

Rule source requires an active Pro or Enterprise subscription.
bitbucket-actions-secrets-exposure-in-logs error block

RISK: 'set -x' or 'printenv' in a pipeline step will echo all environment variables — including Bitbucket repository variables (secrets) — to the build log. FIX: Remove 'set -x' from steps that reference secrets; restrict debug tracing to non-secret steps.

Rule source requires an active Pro or Enterprise subscription.
bitbucket-actions-unpinned-pipe warning log

RISK: Bitbucket pipe without a pinned semantic version (x.y.z) always fetches the latest tag, which may pull breaking or malicious changes on re-run. FIX: Pin pipes to an exact version, e.g. 'atlassian/aws-s3-deploy:1.6.0', and review changelogs before bumping.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
00d5aac944e20caacaafd9d1efbf94e7a248ea1f9f2e5debb71f08817635b3cb
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-bitbucket-actions/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-bitbucket-actions. The published version only bumps when a maintainer resyncs.

No commit history available.