Hub rules-circleci

rules-circleci

v1 public Verified

Circleci

CircleCI is a modern continuous integration and delivery platform. These rules govern config.yml structure, job definitions, and security for AI-assisted CircleCI automation.

@sigmashakeinc 2 pulls 7 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-circleci →
Severity
7 error 0 warn 0 info
demo.cast
CircleCI is a modern continuous integration and delivery platform. These rules govern config.yml structure, job definitions, and security for AI-assisted CircleCI automation.

Rules index

7 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

circleci

circleci-deny-add-ssh-keys-without-fingerprints error block

CRITICAL: Using 'add_ssh_keys' without specifying 'fingerprints' for host key checking is a critical security vulnerability, exposing your build to man-in-the-middle attacks. An attacker could impersonate the SSH host and intercept or manipulate data. AI-generated code must always include 'fingerprints' to verify the authenticity of the SSH host and prevent such attacks.

Rule source requires an active Pro or Enterprise subscription.
circleci-deny-eval-injection error block

CRITICAL: Using 'eval' in CircleCI run steps is a severe command injection vulnerability. It allows arbitrary code execution if any part of the evaluated string comes from untrusted sources (e.g., parameters, environment variables, or external inputs). AI-generated code must strictly avoid 'eval'. Instead, use explicit commands, secure scripting techniques, or dedicated CircleCI orbs for dynamic operations.

Rule source requires an active Pro or Enterprise subscription.
circleci-deny-insecure-shell-config error block

HIGH: Using '/bin/sh' or 'sh' as the default shell in CircleCI jobs can lead to unexpected behavior and security issues due to its simpler parsing rules and lack of robust error handling compared to Bash. It's strongly recommended to use a more secure and predictable shell with options like 'bash -eo pipefail'. AI-generated code should specify a secure shell configuration.

Rule source requires an active Pro or Enterprise subscription.
circleci-deny-path-traversal-in-paths error block

CRITICAL: Using 'path: ../' (path traversal) in CircleCI configuration (e.g., for 'store_artifacts', 'persist_to_workspace', 'attach_workspace', or other file operations) is a severe security vulnerability. It allows access to directories outside the intended project scope, potentially leading to data leakage, overwriting critical system files, or arbitrary file creation. AI-generated code must use strictly relative paths within the project directory and avoid path traversal sequences.

Rule source requires an active Pro or Enterprise subscription.
circleci-deny-sensitive-data-in-logs error block

CRITICAL: Exposing sensitive environment variables (e.g., API tokens, secrets, private keys) in build logs via 'echo $VAR' is a severe security vulnerability. Even if CircleCI attempts to redact some known secrets, custom or less common secrets might be exposed. AI-generated code must never echo secrets to logs. Use secure contexts for secrets and avoid direct output or logging of sensitive data.

Rule source requires an active Pro or Enterprise subscription.
circleci-deny-unnecessary-sudo error block

HIGH: Using 'sudo' in CircleCI run steps grants elevated privileges and should be avoided unless absolutely critical and justified. Most operations within a Docker container or a CircleCI executor do not require 'sudo'. AI-generated code should avoid 'sudo' to minimize the attack surface and adhere to the principle of least privilege.

Rule source requires an active Pro or Enterprise subscription.
circleci-deny-unpinned-docker-images error block

CRITICAL: Using ':latest' or ':alpine' as Docker image tags in CircleCI leads to non-reproducible builds and introduces security vulnerabilities if the underlying image changes unexpectedly. While some specific images might use 'alpine' as a base, relying on a floating 'alpine' tag is insecure. AI-generated code must pin Docker image versions to specific, immutable tags (e.g., 'cimg/node:16.14.2' instead of 'cimg/node:latest' or 'cimg/base:2023.08'). If 'alpine' is used as a base, ensure it's a specific version like 'alpine:3.14'.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v1
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
5d7dcdfae61b9fa06de8fa30eb801517288281f255bd909aba264016411a7d07
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-circleci/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-circleci. The published version only bumps when a maintainer resyncs.

No commit history available.