Hub rules-esbuild

rules-esbuild

v5 public Verified

Esbuild

esbuild is an extremely fast JavaScript bundler and minifier written in Go. These rules govern the configuration of high-performance build pipelines, code splitting, and optimization for modern web development.

@sigmashakeinc 2 pulls 5 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-esbuild →
Severity
2 error 2 warn 1 info
demo.cast
esbuild is an extremely fast JavaScript bundler and minifier written in Go. These rules govern the configuration of high-performance build pipelines, code splitting, and optimization for modern web development.

Rules index

5 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

esbuild

esbuild-allow-overwrite error block

esbuild allowOverwrite: true permits the bundler to silently overwrite its own input files — CWE-732. If the entryPoint and outfile resolve to the same path, the source file is destroyed with no warning. Remove this option; set distinct outdir/outfile paths to prevent accidental source destruction.

Rule source requires an active Pro or Enterprise subscription.
esbuild-banner-footer-injection warning log

esbuild banner/footer injects raw JS into every output chunk — CWE-94. If any part of the banner/footer string is derived from external input (environment variables, config files), it could inject arbitrary code into the bundle. Ensure the banner/footer is a static, trusted literal string.

Rule source requires an active Pro or Enterprise subscription.
esbuild-build-sync warning log

esbuild.buildSync() blocks the Node.js event loop for the entire build duration. In a server or CLI tool that handles concurrent requests this will cause request timeouts. Prefer the async esbuild.build() API which runs the build in a worker thread without blocking.

Rule source requires an active Pro or Enterprise subscription.
esbuild-define-secret-bake error block

Sensitive value baked into bundle via esbuild define: — CWE-798. Values passed to define: are inlined as string literals into every output file, making them visible to anyone who can read the bundle (including browsers). Serve secrets from the backend at runtime; never bake them into client-side bundles.

Rule source requires an active Pro or Enterprise subscription.
esbuild-drop-console-log info log

esbuild drop: ['console'] removes all console.* calls at build time. This is valid for production builds but removes all debugging output including error logging. Ensure you have a structured server-side logging strategy before stripping client-side console calls entirely.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
0b9d1943a07536bff1b5b8530b0361a83db8a30feb4534bda1841fa8c9ea3104
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-esbuild/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-esbuild. The published version only bumps when a maintainer resyncs.

No commit history available.