Hub rules-couchdb

rules-couchdb

v5 public Verified

Couchdb

Apache CouchDB is a document-oriented NoSQL database that uses JSON for storage and HTTP for its API. These rules guide AI agents in database replication, view creation, and conflict resolution using MVCC.

@sigmashakeinc 2 pulls 6 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-couchdb →
Severity
4 error 0 warn 2 info
demo.cast
Apache CouchDB is a document-oriented NoSQL database that uses JSON for storage and HTTP for its API. These rules guide AI agents in database replication, view creation, and conflict resolution using MVCC.

Rules index

6 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

couchdb

couchdb-block-unsafe-patterns info log

CouchDB emit() in a map function detected. Ensure the emit key and value do not expose sensitive document fields unnecessarily — emitted data is queryable by any user with read access to the design document's view.

Rule source requires an active Pro or Enterprise subscription.
couchdb-cors-wildcard error block

CouchDB CORS configured with wildcard origins ('*'). Combined with require_valid_user=false or cookie-based auth, this allows any website to make cross-origin requests to your CouchDB instance and read or modify all databases. Restrict CORS to your exact application origin.

Rule source requires an active Pro or Enterprise subscription.
couchdb-eval-in-design-doc error block

eval() or new Function() in a CouchDB design document map/reduce function. Design document code runs inside CouchDB's embedded JavaScript engine with access to all documents. Code injection here can leak all database content or corrupt views. Design docs should use pure, data-driven map/reduce functions with no eval.

Rule source requires an active Pro or Enterprise subscription.
couchdb-force-updated-api info log

db.view() is the legacy CouchDB 1.x Nano/Cradle API. Modern Nano (^10) uses db.view(designName, viewName, params). Verify you are using the current maintained API for your CouchDB version.

Rule source requires an active Pro or Enterprise subscription.
couchdb-hardcoded-credentials error block

Hardcoded CouchDB credentials detected (CWE-798). Credentials in source code are exposed via version control history. Store credentials in environment variables (COUCHDB_USER / COUCHDB_PASSWORD) or a secrets manager and inject at runtime.

Rule source requires an active Pro or Enterprise subscription.
couchdb-require-valid-user error block

CouchDB require_valid_user = false permits unauthenticated access to the database. CouchDB ships in 'Admin Party' mode by default — all requests are admin requests until a user is created. Always set '[couch_httpd_auth] require_valid_user = true' in production and create at least one admin user before exposing the port.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
54deed5962c8125f42a2262aac0899d3e8b2796451c8c43c05c45e6503cd77e5
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-couchdb/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-couchdb. The published version only bumps when a maintainer resyncs.

No commit history available.