Hub rules-cosmosdb

rules-cosmosdb

v5 public Verified

Cosmosdb

Azure Cosmos DB is a globally distributed, multi-model NoSQL database service for high-performance applications. These rules govern database provisioning, data modeling, and consistency management for AI-driven Azure applications.

@sigmashakeinc 2 pulls 6 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-cosmosdb →
Severity
3 error 2 warn 1 info
demo.cast
Azure Cosmos DB is a globally distributed, multi-model NoSQL database service for high-performance applications. These rules govern database provisioning, data modeling, and consistency management for AI-driven Azure applications.

Rules index

6 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

cosmosdb

cosmosdb-block-unsafe-patterns info log

SELECT * in a Cosmos DB query retrieves the entire document including all properties, increasing RU consumption and data surface. Prefer projections (SELECT c.id, c.name FROM c WHERE ...) to reduce throughput cost and limit data exposure in logs and responses.

Rule source requires an active Pro or Enterprise subscription.
cosmosdb-force-updated-api warning log

DocumentClient is the deprecated Cosmos DB SDK v2 client. Migrate to @azure/cosmos v4 (Node.js), the Azure Cosmos DB SDK for Python 4.x, or the v3 .NET SDK. The new SDKs include improved RBAC support, diagnostic capabilities, and performance improvements.

Rule source requires an active Pro or Enterprise subscription.
cosmosdb-hardcoded-connection-string error block

Hardcoded Cosmos DB connection string (AccountEndpoint + AccountKey) detected (CWE-798). Connection strings embedded in source give anyone with repo access full control of the database. Store the connection string in Azure Key Vault or environment variables and retrieve it at runtime via the Azure SDK DefaultAzureCredential.

Rule source requires an active Pro or Enterprise subscription.
cosmosdb-hardcoded-master-key error block

Hardcoded Cosmos DB master or primary key detected (CWE-798). Master keys grant full read/write access to all containers. Use Managed Identity + RBAC instead of key-based auth where possible, or load the key from Azure Key Vault at startup.

Rule source requires an active Pro or Enterprise subscription.
cosmosdb-nosql-injection error block

Cosmos DB SQL API query built with string interpolation. User-controlled data injected into the query string enables NoSQL injection — attackers can read or delete data from other partitions. Use parameterized queries with the QueryDefinition(query).WithParameter('@param', value) API instead of string concatenation.

Rule source requires an active Pro or Enterprise subscription.
cosmosdb-public-network-access warning log

Cosmos DB account has publicNetworkAccess enabled. This exposes the account endpoint to the public internet. For production workloads, set publicNetworkAccess to Disabled and connect only via Private Endpoints to prevent external access.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
894b6c4518319e5eb3bf723bcdbdb3ffa943a35784056c873614817e5590013e
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-cosmosdb/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-cosmosdb. The published version only bumps when a maintainer resyncs.

No commit history available.