Hub rules-chef

rules-chef

v2 public Verified

Chef

Chef is an infrastructure automation platform. These rules govern cookbook structure, recipe definitions, and security best practices for AI-assisted Chef automation.

@sigmashakeinc 2 pulls 7 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-chef →
Severity
4 error 3 warn 0 info
demo.cast
Chef is an infrastructure automation platform. These rules govern cookbook structure, recipe definitions, and security best practices for AI-assisted Chef automation.

Rules index

7 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

chef

chef-command-injection-execute error block

Potential command injection vulnerability detected in 'execute' resource. Using unsanitized node attributes directly in shell commands can lead to arbitrary code execution. Sanitize all external inputs using shell_escape or prefer Chef's built-in resources over raw 'execute' for common tasks.

Rule source requires an active Pro or Enterprise subscription.
chef-deprecated-node-set warning log

Deprecated use of 'node.set' in recipes. 'node.set' overrides all other attribute precedence levels and can lead to unexpected behavior or security issues if used improperly. Prefer 'node.default' for setting defaults or 'node.override' with caution for explicit overrides.

Rule source requires an active Pro or Enterprise subscription.
chef-foodcritic-style-violation warning log

Chef style guide violation (Foodcritic FC019). Access node attributes using `node['attribute']` not `node.attribute` for consistency and to avoid potential method conflicts. Consider running Foodcritic for full style and best practice checks.

Rule source requires an active Pro or Enterprise subscription.
chef-hardcoded-secrets error block

Hardcoded sensitive data (e.g., passwords, API keys) detected. This is a critical security vulnerability. Use Chef Vault or encrypted data bags for secret management. Never store secrets directly in recipes or attributes.

Rule source requires an active Pro or Enterprise subscription.
chef-insecure-file-permissions warning log

Insecure file/directory permissions. Resources like 'file', 'directory', or 'template' should explicitly define a secure 'mode' (e.g., '0644' for files, '0755' for directories) to prevent unintended access. Omitting 'mode' can result in overly permissive defaults.

Rule source requires an active Pro or Enterprise subscription.
chef-insecure-http-request-no-ssl-verify error block

Insecure HTTP request with SSL verification disabled. Using 'verify_ssl :verify_none' exposes your system to Man-in-the-Middle attacks. Always ensure SSL verification is enabled for production environments.

Rule source requires an active Pro or Enterprise subscription.
chef-insecure-remote-file-no-checksum error block

Remote file download without checksum verification. Downloading files without a 'checksum' attribute makes your system vulnerable to Man-in-the-Middle attacks or corrupted files. Always specify a strong checksum (e.g., SHA256) for remote files.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v2
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
1fc1df166baf2c78c923905ba1f09940931c11192c939f0d8ae9c52d82ecf207
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-chef/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-chef. The published version only bumps when a maintainer resyncs.

No commit history available.