Hub rules-deno

rules-deno

v5 public Verified

Deno

Deno is a modern, secure runtime for JavaScript and TypeScript built in Rust. These rules assist AI agents in module management, security permissions, and building high-performance server-side applications.

@sigmashakeinc 2 pulls 7 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-deno →
Severity
4 error 3 warn 0 info
demo.cast
Deno is a modern, secure runtime for JavaScript and TypeScript built in Rust. These rules assist AI agents in module management, security permissions, and building high-performance server-side applications.

Rules index

7 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

deno

deno-allow-all-flag error block

RISK: --allow-all (-A) grants the Deno script unrestricted access to the filesystem, network, environment, subprocess execution, and FFI — it completely defeats Deno's security model. FIX: Grant only the specific permissions needed (--allow-net=api.example.com, --allow-read=./data, etc.).

Rule source requires an active Pro or Enterprise subscription.
deno-command-injection error block

RISK: Interpolating variables into Deno.Command arguments enables command injection — if the value is user-controlled, an attacker can execute arbitrary host commands. FIX: Always pass command arguments as explicit string literals or a validated allowlist; never build command strings by concatenation.

Rule source requires an active Pro or Enterprise subscription.
deno-deprecated-buffer warning log

Deno.Buffer is removed. Use the WHATWG Streams API (ReadableStream/WritableStream) or Buffer from the Deno standard library (https://deno.land/std/io/buffer.ts) instead.

Rule source requires an active Pro or Enterprise subscription.
deno-dynamic-remote-import warning log

RISK: Dynamic imports from user-supplied or runtime-assembled URLs allow loading and executing untrusted remote code, bypassing the lock file and integrity checks. FIX: Import from locked URLs declared in deno.json/deno.lock; if dynamic imports are required, validate against an explicit allowlist of trusted origins.

Rule source requires an active Pro or Enterprise subscription.
deno-eval-usage error block

RISK: eval() and new Function() execute arbitrary strings as code. In Deno, this also circumvents the permission model — even without --allow-run, eval can perform operations within the already-granted permissions. FIX: Avoid eval entirely; use explicit logic, JSON.parse() for data, or a sandboxed interpreter if dynamic evaluation is required.

Rule source requires an active Pro or Enterprise subscription.
deno-hardcoded-secrets error log

RISK: Hardcoded secrets are committed to version control and visible in logs and deployment artifacts. FIX: Read secrets via Deno.env.get('MY_SECRET'); store them in a .env file (gitignored) or a secrets manager and grant --allow-env=MY_SECRET.

Rule source requires an active Pro or Enterprise subscription.
deno-run-deprecated warning ask

Deno.run() is deprecated and removed in Deno 2. Use Deno.Command instead. Also verify that any user-provided values are not interpolated into the command (command injection risk).

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
41a36305ff460838028ef9c6f04b3b3d9ed6dacfcd9017441656e090ea91c778
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-deno/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-deno. The published version only bumps when a maintainer resyncs.

No commit history available.