Hub rules-cypress

rules-cypress

v5 public Verified

Cypress

Cypress is a modern end-to-end testing framework for web applications. These rules govern the creation of robust integration and E2E tests, emphasizing best practices for assertions, network intercepting, and test isolation.

@sigmashakeinc 2 pulls 5 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-cypress →
Severity
3 error 2 warn 0 info
demo.cast
Cypress is a modern end-to-end testing framework for web applications. These rules govern the creation of robust integration and E2E tests, emphasizing best practices for assertions, network intercepting, and test isolation.

Rules index

5 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

cypress

cypress-deprecated-server warning log

cy.server() was removed in Cypress 12. Use cy.intercept() to stub and spy on network requests instead.

Rule source requires an active Pro or Enterprise subscription.
cypress-exec-injection error block

RISK: cy.exec() with string concatenation or template-literal interpolation of test variables is command injection — an attacker-controlled fixture value can run arbitrary shell commands on the test runner host. FIX: Pass only literal command strings to cy.exec(); parameterize via a safe task in cypress/support/commands.ts instead.

Rule source requires an active Pro or Enterprise subscription.
cypress-exec-shell-usage warning ask

cy.exec() runs shell commands on the Cypress test runner host. Review the command to ensure it does not interpolate any test fixture or user-controlled value (command injection risk). Confirm the write is intentional.

Rule source requires an active Pro or Enterprise subscription.
cypress-hardcoded-credentials error log

RISK: Hardcoded credentials in cy.request() calls are committed to version control and visible in CI logs. FIX: Store credentials in Cypress environment variables (cypress.env.json / CYPRESS_* env vars) and reference them via Cypress.env('MY_SECRET').

Rule source requires an active Pro or Enterprise subscription.
cypress-no-eval error block

RISK: eval() in test code can be exploited if fixture data or API responses containing attacker-controlled strings reach the eval call, enabling XSS/RCE in the test runner. FIX: Use Cypress commands and assertions instead of eval; parse structured data with JSON.parse().

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
7494a054fa73ebf58a4e2501b7ec6720cd3e098a63494d77f909d7708805f577
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-cypress/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-cypress. The published version only bumps when a maintainer resyncs.

No commit history available.