Hub rules-dart

rules-dart

v5 public Verified

Dart

Dart is a client-optimized language for fast apps on any platform, primarily used with Flutter. These rules govern sound null safety, performance optimization, and cross-platform application development.

@sigmashakeinc 2 pulls 10 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-dart →
Severity
7 error 3 warn 0 info
demo.cast
Dart is a client-optimized language for fast apps on any platform, primarily used with Flutter. These rules govern sound null safety, performance optimization, and cross-platform application development.

Rules index

10 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

dart

no-bad-tls-certificate-dart error block

RISK: Overriding badCertificateCallback to return true disables TLS certificate validation, making the app vulnerable to man-in-the-middle attacks (CVE class: improper certificate validation, CWE-295). FIX: Remove the callback override and fix the underlying certificate issue; for development use a trusted local CA.

Rule source requires an active Pro or Enterprise subscription.
no-cleartext-http-dart error log

Cleartext HTTP transmits data without encryption. Use HTTPS for all production network calls. Android and iOS enforce HTTPS by default in production.

Rule source requires an active Pro or Enterprise subscription.
no-dart-mirrors error log

dart:mirrors enables runtime reflection and is not available in Flutter production builds (tree-shaking incompatible). It also significantly increases binary size. Use code generation (build_runner) instead.

Rule source requires an active Pro or Enterprise subscription.
no-force-unwrap-dart warning log

The ! (null assertion) operator throws a Null check operator used on a null value exception. Use ?. for safe access or ?? for defaults rather than forcing non-null.

Rule source requires an active Pro or Enterprise subscription.
no-hardcoded-secrets-dart error log

Hardcoded secrets in Dart/Flutter are compiled into the app binary and extractable with tools like apktool. Use --dart-define for build-time secrets or fetch from a secure backend.

Rule source requires an active Pro or Enterprise subscription.
no-insecure-random-dart warning log

RISK: dart:math Random() uses a predictable PRNG seeded from the system clock, making it unsuitable for generating tokens, session IDs, or nonces. FIX: Use Random.secure() which delegates to the OS cryptographically secure random source.

Rule source requires an active Pro or Enterprise subscription.
no-insecure-shared-prefs warning log

SharedPreferences stores data in plaintext. Use flutter_secure_storage for passwords, tokens, and other sensitive values — it uses Keychain on iOS and EncryptedSharedPreferences on Android.

Rule source requires an active Pro or Enterprise subscription.
no-path-traversal-dart error block

RISK: Constructing a File() path directly from user-supplied input enables path traversal (CWE-22) — an attacker can read or overwrite arbitrary files outside the intended directory by supplying '../' sequences. FIX: Validate and sanitize the path with p.normalize() and check that it starts with the expected base directory before use.

Rule source requires an active Pro or Enterprise subscription.
no-process-run-shell-dart error log

Running sh/bash with user-provided arguments enables command injection. Pass commands as explicit argument lists without shell involvement.

Rule source requires an active Pro or Enterprise subscription.
no-sql-interpolation-dart error block

String interpolation in SQLite rawQuery enables SQL injection. Use parameterized queries: db.rawQuery('SELECT * FROM t WHERE id = ?', [id])

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
03db709f3069cd4d404c19750dfb924ff7a6af92163d0623d3112fd0f9b48c72
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-dart/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-dart. The published version only bumps when a maintainer resyncs.

No commit history available.