Hub rules-chroma

rules-chroma

v5 public Verified

Chroma

Chroma is an open-source embedding database. These rules govern collection management, embedding storage, and retrieval optimization for AI-assisted ChromaDB development.

@sigmashakeinc 2 pulls 6 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-chroma →
Severity
3 error 3 warn 0 info
demo.cast
Chroma is an open-source embedding database. These rules govern collection management, embedding storage, and retrieval optimization for AI-assisted ChromaDB development.

Rules index

6 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

chroma

chroma-block-unsafe-patterns warning ask

Potentially unsafe pattern detected in chroma code: "Chroma(persist_directory=". Review the use case — this may indicate a security risk, a deprecated API, or a misconfiguration. Confirm the write is intentional.

Rule source requires an active Pro or Enterprise subscription.
chroma-force-updated-api warning log

You are using an outdated API for chroma. Please upgrade to the newer API.

Rule source requires an active Pro or Enterprise subscription.
chroma-no-hardcoded-auth-token error block

Hardcoded Chroma authentication token detected (CWE-798). Embedding bearer tokens or credentials directly in source code leaks them via version control. Load the token from an environment variable (e.g. os.environ['CHROMA_TOKEN']) or a secrets manager.

Rule source requires an active Pro or Enterprise subscription.
chroma-no-http-remote-connection error block

Plaintext HTTP connection to a remote Chroma server transmits embeddings and metadata in cleartext, exposing sensitive data to network interception (CWE-319). Use HTTPS (ssl=True or an https:// host) for any non-localhost Chroma deployment.

Rule source requires an active Pro or Enterprise subscription.
chroma-no-metadata-injection error block

Chroma 'where' filter constructed via string formatting or concatenation with an external variable. Chroma's filter engine evaluates the where dict server-side; injecting attacker-controlled keys or values can bypass collection access controls (CWE-943). Build the where dict from a validated allowlist of fields and literal values.

Rule source requires an active Pro or Enterprise subscription.
chroma-no-unauthenticated-remote-client warning log

Remote Chroma HttpClient instantiated without authentication settings. Unauthenticated Chroma HTTP endpoints allow any network-adjacent host to read, write, or delete all collections (CWE-306). Pass chromadb.Settings with chroma_client_auth_provider and credentials, or restrict the Chroma server to localhost.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
156d8af9fefdd76c6b4f454ea7a8605e7c82899e82e7fb4830aefae73a94e974
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-chroma/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-chroma. The published version only bumps when a maintainer resyncs.

No commit history available.