Hub rules-droneci

rules-droneci

v5 public Verified

Droneci

Drone CI is a container-native continuous integration platform using YAML-based configuration. These rules govern the definition of pipelines, secret management, and automated testing in ephemeral CI environments.

@sigmashakeinc 2 pulls 5 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-droneci →
Severity
3 error 2 warn 0 info
demo.cast
Drone CI is a container-native continuous integration platform using YAML-based configuration. These rules govern the definition of pipelines, secret management, and automated testing in ephemeral CI environments.

Rules index

5 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

droneci

droneci-command-injection error block

Drone pipeline commands detected. Verify that no step interpolates untrusted event payload fields (e.g. commit message, branch name) into shell commands — these fields can be attacker-controlled in pull-request triggered builds and lead to command injection.

Rule source requires an active Pro or Enterprise subscription.
droneci-privileged-container error block

RISK: privileged: true in a Drone pipeline step gives the container full access to the host kernel — equivalent to running as root on the CI node. This has been used to escape CI sandboxes and exfiltrate secrets from the host. FIX: Remove privileged: true; if Docker-in-Docker is required, use a rootless DinD image or a dedicated daemon socket.

Rule source requires an active Pro or Enterprise subscription.
droneci-pull-request-trust warning log

RISK: Pipelines triggered on pull_request events from untrusted forks can expose secrets if the pipeline uses from_secret references without the 'trusted' repo setting. FIX: Enable 'trusted: true' only on the main repo, not forks; use Drone's allow_failure or a separate signing pipeline for PRs from forks.

Rule source requires an active Pro or Enterprise subscription.
droneci-secret-in-env-literal error block

RISK: Hardcoding a secret value directly in the .drone.yml file exposes it in version control history permanently. FIX: Use Drone secret references — environment: { MY_SECRET: { from_secret: my_secret_name } } — and store the value in the Drone secrets UI or a Vault plugin.

Rule source requires an active Pro or Enterprise subscription.
droneci-unpinned-plugin-image warning log

RISK: Unpinned or ':latest' plugin images in Drone pipelines introduce reproducibility and supply-chain risks — a re-push of the upstream image can silently change pipeline behavior or inject malicious code. FIX: Pin all images to an explicit version tag or SHA digest: image: plugins/s3:1.1.0.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
d4ec46bf8c44cd502ea6a7e9ec426bce24c5c227b36de7ead6b1d6dfe49b9d5a
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-droneci/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-droneci. The published version only bumps when a maintainer resyncs.

No commit history available.