Hub rules-bootstrap

rules-bootstrap

v5 public Verified

Bootstrap

Bootstrap is a powerful, feature-packed frontend toolkit. These rules govern grid layout, component usage, and responsive design best practices for AI-assisted Bootstrap development.

@sigmashakeinc 2 pulls 7 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-bootstrap →
Severity
3 error 4 warn 0 info
demo.cast
Bootstrap is a powerful, feature-packed frontend toolkit. These rules govern grid layout, component usage, and responsive design best practices for AI-assisted Bootstrap development.

Rules index

7 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

bootstrap

bootstrap-deprecated-sanitizer-whitelist warning log

Deprecated Bootstrap sanitizer option 'whitelist' detected. In Bootstrap 5, the 'whitelist' option for sanitization has been replaced by 'allowList'. Update your sanitizer configuration to use 'allowList' for improved clarity and compatibility with modern Bootstrap versions.

Rule source requires an active Pro or Enterprise subscription.
bootstrap-disable-sanitizer error block

Potential Cross-Site Scripting (XSS) vulnerability: 'data-bs-sanitize="false"' explicitly disables Bootstrap's built-in sanitizer for tooltips/popovers. This is highly dangerous if content is user-supplied. Ensure all dynamic content is thoroughly sanitized using a robust library like DOMPurify, or remove this attribute to enable Bootstrap's default sanitization.

Rule source requires an active Pro or Enterprise subscription.
bootstrap-google-js-style-var warning log

Google JavaScript Style Guide violation: Use of 'var' keyword detected. The Google JavaScript Style Guide recommends using 'const' or 'let' instead of 'var' for block-scoped variable declarations. Update to 'const' or 'let' for better scope management and code clarity.

Rule source requires an active Pro or Enterprise subscription.
bootstrap-html-content-risk warning log

Potential Cross-Site Scripting (XSS) risk: 'data-bs-html="true"' allows HTML content in Bootstrap components (e.g., tooltips, popovers). If this content is derived from untrusted user input, it creates an XSS vector. Ensure any HTML rendered via this attribute is strictly sanitized using a library like DOMPurify or only originates from trusted sources. Prefer 'data-bs-html="false"' or 'textContent' for untrusted input.

Rule source requires an active Pro or Enterprise subscription.
bootstrap-javascript-scheme-injection error block

Critical Cross-Site Scripting (XSS) vulnerability: 'javascript:' scheme detected in 'href' or 'data-bs-target' attribute. This allows direct execution of arbitrary JavaScript code. Never use 'javascript:' URLs with untrusted input. Remove this pattern and use proper event handlers or secure navigation methods.

Rule source requires an active Pro or Enterprise subscription.
bootstrap-legacy-jquery-import warning log

Legacy jQuery script import detected. Bootstrap 5+ does not require jQuery — including it adds unnecessary overhead and a larger attack surface. For new Bootstrap 5+ projects, prefer vanilla JavaScript. If you need jQuery for legacy reasons, ensure it is up-to-date (>=3.7.x) to avoid known XSS vulnerabilities.

Rule source requires an active Pro or Enterprise subscription.
bootstrap-unsafe-innerhtml-user-input error block

RISK: Assigning user-influenced or dynamic content to innerHTML is a classic XSS vector (CWE-79). If the value originates from user input, an API response, or a URL parameter it can inject arbitrary HTML/JS. FIX: Use element.textContent for plain text, or sanitize with DOMPurify.sanitize() before assigning to innerHTML.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
f29e4924f1593ffd7f02ea5468e75d0f0d998283a524f410052a88385983f4b7
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-bootstrap/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-bootstrap. The published version only bumps when a maintainer resyncs.

No commit history available.