Hub rules-frontend

rules-frontend

v3 public Verified

Frontend

Community-governed security ruleset for Frontend

@sigmashakeinc 0 pulls 7 rules published Apr 10, 2026 synced Sep 27, 2026 sigmashakeinc/rules/rulesets/rules-frontend →
Severity
2 error 4 warn 1 info
demo.cast
Community-governed security ruleset for Frontend

Rules index

7 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

react

audit-csp-missing warning log

next.config file lacks a Content-Security-Policy header. Without CSP, XSS payloads can load external scripts or exfiltrate data. Add a 'Content-Security-Policy' header in the headers() async function with at minimum 'default-src self', a nonce-based script-src, and 'upgrade-insecure-requests'.

Rule source requires an active Pro or Enterprise subscription.
block-dangerously-set-inner-html warning log

dangerouslySetInnerHTML bypasses React's built-in XSS sanitization — CWE-79. Any unsanitized string passed to __html will be interpreted as HTML and can execute attacker-controlled scripts. If rich text is required, use a vetted sanitizer (DOMPurify) and pass the result: dangerouslySetInnerHTML={{ __html: DOMPurify.sanitize(input) }}.

Rule source requires an active Pro or Enterprise subscription.
block-eval-usage error block

eval() in frontend code — CWE-94 / CWE-79. eval() executes an arbitrary string as code; if any part of the string derives from user input or a third-party source it is a direct XSS/code-injection vector. Replace dynamic code execution with data-driven logic, a safe expression evaluator, or JSON.parse for structured data.

Rule source requires an active Pro or Enterprise subscription.
block-innerhtml-direct-assign warning log

Direct .innerHTML assignment — CWE-79. Assigning user-controlled strings to .innerHTML injects raw HTML into the DOM and executes any embedded scripts. Prefer .textContent for plain text, or sanitize with DOMPurify before assigning to innerHTML.

Rule source requires an active Pro or Enterprise subscription.
block-new-function-constructor error block

new Function() is equivalent to eval() — CWE-94. It constructs a callable function from a string, executing arbitrary code. Any user-controlled string passed to it is a code injection vector. Rewrite using pure functions, closures, or a sandboxed interpreter with a restricted grammar.

Rule source requires an active Pro or Enterprise subscription.
block-unsafe-redirect warning log

Potential open redirect using user-controlled query parameter — CWE-601. Passing request params directly to window.location or redirect() allows an attacker to redirect users to a phishing site. Validate the target URL against an allowlist of trusted origins before redirecting.

Rule source requires an active Pro or Enterprise subscription.
warn-nextjs-server-action-validation info log

Next.js Server Action detected without visible Zod validation. Server Actions receive untrusted client input directly — validate every argument with Zod (or equivalent) before using it in queries or mutations to prevent injection and unexpected data shapes.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v3
Published
Apr 10, 2026
Source commits
0
Synced
Sep 27, 2026
Hash
0b277b293b257470659b71458f23d8444a6ca6465734a29f98c1a192cd457f33
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-frontend/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-frontend. The published version only bumps when a maintainer resyncs.

No commit history available.