Hub rules-cassandra

rules-cassandra

v5 public Verified

Cassandra

Apache Cassandra is a free and open-source, distributed, wide-column store, NoSQL database management system. These rules govern data modeling, query optimization, and cluster configuration for AI-assisted Cassandra management.

@sigmashakeinc 2 pulls 11 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-cassandra →
Severity
7 error 4 warn 0 info
demo.cast
Apache Cassandra is a free and open-source, distributed, wide-column store, NoSQL database management system. These rules govern data modeling, query optimization, and cluster configuration for AI-assisted Cassandra management.

Rules index

11 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

cassandra

cassandra-cql-injection-session-execute-concat error block

RISK: String concatenation in session.execute() enables CQL injection. FIX: Use prepared statements — session.prepare("SELECT ... WHERE id=?").bind(id) — so driver parameter binding handles escaping.

Rule source requires an active Pro or Enterprise subscription.
cassandra-cql-injection-simple-statement error block

RISK: String concatenation into SimpleStatement is a CQL injection vector — an attacker who controls the concatenated value can add arbitrary CQL clauses to read/modify/drop data. FIX: Use prepared statements with bound parameters: session.prepare("SELECT ... WHERE id=?").bind(id).

Rule source requires an active Pro or Enterprise subscription.
cassandra-cql-style-uppercase-keywords warning log

Style: CQL keywords found in lowercase. Convention is to write CQL keywords (SELECT, FROM, WHERE, INSERT, etc.) in uppercase for readability and consistency.

Rule source requires an active Pro or Enterprise subscription.
cassandra-dangerous-truncate error block

RISK: TRUNCATE permanently deletes every row in the table/keyspace without a WHERE clause and cannot be rolled back. FIX: Use DELETE ... WHERE for targeted removal. If a full wipe is genuinely required, confirm backups exist and add an explicit human-approval gate in the deployment pipeline.

Rule source requires an active Pro or Enterprise subscription.
cassandra-deprecated-compact-storage warning log

RISK: COMPACT STORAGE is deprecated since Cassandra 4.0 and removed in 5.0 — tables using it cannot be altered and are incompatible with several CQL features and drivers. FIX: Create new tables without COMPACT STORAGE; migrate existing ones with 'ALTER TABLE ... DROP COMPACT STORAGE' before upgrading.

Rule source requires an active Pro or Enterprise subscription.
cassandra-hardcoded-credentials-java error block

RISK: Cassandra client credentials (username + password) hardcoded in Java source are committed to VCS and visible to anyone with repo access (CWE-798). FIX: Load credentials at runtime from environment variables, a secrets manager (Vault, AWS Secrets Manager), or a config file excluded from VCS.

Rule source requires an active Pro or Enterprise subscription.
cassandra-insecure-authenticator error block

RISK: AllowAllAuthenticator permits any client with any password to connect — effectively no authentication. FIX: Set authenticator: PasswordAuthenticator (or a custom LDAP/Kerberos authenticator) and create per-service credentials with minimum required privileges.

Rule source requires an active Pro or Enterprise subscription.
cassandra-insecure-authorizer error block

RISK: AllowAllAuthorizer grants every authenticated client full read/write/admin access to all keyspaces — there is no access control. FIX: Set authorizer: CassandraAuthorizer and assign roles with GRANT on only the keyspaces/tables each service needs.

Rule source requires an active Pro or Enterprise subscription.
cassandra-insecure-client-encryption-disabled warning log

RISK: Client-to-node encryption disabled — data, credentials, and CQL queries travel in plaintext on the network. FIX: Set 'client_encryption_options.enabled: true' and configure 'keystore'/'truststore' paths; enforce 'require_client_auth: true' for mTLS in sensitive environments.

Rule source requires an active Pro or Enterprise subscription.
cassandra-internode-encryption-disabled warning log

RISK: internode_encryption: none means gossip traffic between Cassandra nodes (including replication writes) is unencrypted. In a multi-datacenter or cloud deployment an attacker on the same network segment can read and inject replication data. FIX: Set internode_encryption: all (or 'dc' for cross-DC only) and configure node keystore/truststore.

Rule source requires an active Pro or Enterprise subscription.
cassandra-unrestricted-rpc-address error block

RISK: rpc_address: 0.0.0.0 binds Cassandra's native CQL port to all interfaces, exposing it to untrusted networks. FIX: Bind rpc_address to a specific internal IP; restrict port 9042 with firewall rules so only application servers can reach it.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
d06bf83e01ee737fa21ebf40c2f3a1cefd42d9d1ccfe5a21f2a6068a20a36efa
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-cassandra/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-cassandra. The published version only bumps when a maintainer resyncs.

No commit history available.