Hub rules-vite

rules-vite

v3 public Verified

Vite

Vite is a frontend build tool that provides a fast and modern development experience. These rules govern dev server security and build optimization best practices for AI agents.

@sigmashakeinc 2 pulls 7 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-vite →
Severity
3 error 4 warn 0 info
demo.cast
Vite is a frontend build tool that provides a fast and modern development experience. These rules govern dev server security and build optimization best practices for AI agents.

Rules index

7 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

vite

vite-no-allowed-hosts-all error block

RISK: Setting allowedHosts to 'all' or true disables Vite's DNS rebinding protection — any hostname (including attacker-controlled domains that resolve to your loopback address) can access the dev server and read local source files. FIX: remove allowedHosts or list only specific hostnames you control. Vite 5.4+ blocks all unknown hosts by default for this reason.

Rule source requires an active Pro or Enterprise subscription.
vite-no-cors-wildcard warning log

RISK: Setting cors:true or cors:{origin:'*'} on the Vite dev server or preview allows any origin to make credentialed cross-origin requests to your dev environment — this can leak session tokens or API responses to malicious pages open in the same browser. FIX: restrict to specific origins (e.g., cors:{origin:'http://localhost:3001'}) in dev configs.

Rule source requires an active Pro or Enterprise subscription.
vite-no-define-secrets error block

RISK: Hardcoding a secret value in Vite's 'define' object inlines it as a string literal in the browser bundle — it is shipped to every end-user and visible in browser DevTools. FIX: use VITE_ prefixed environment variables from a .env file for non-sensitive build-time constants; never bundle secrets — move sensitive operations to a server-side API.

Rule source requires an active Pro or Enterprise subscription.
vite-no-preview-host-exposed warning log

RISK: Exposing the Vite preview server on all interfaces (0.0.0.0 or host:true) makes the production-preview build accessible to any host on the network — unlike the dev server, the preview server has no HMR protections and serves the compiled bundle with all substituted constants. FIX: leave preview.host unset (binds to 127.0.0.1) or explicitly set it to '127.0.0.1'.

Rule source requires an active Pro or Enterprise subscription.
vite-no-proxy-ssl-disabled warning log

RISK: Setting secure:false in a Vite proxy config disables TLS certificate verification for the proxied backend — a self-signed or mis-issued cert silently passes, enabling MITM attacks against the proxied API. FIX: install a valid certificate for the backend, or use a local CA (mkcert) for development; only disable TLS verification in an isolated, non-networked environment.

Rule source requires an active Pro or Enterprise subscription.
vite-warn-fs-strict-false error block

Disabling server.fs.strict allows the Vite dev server to serve files outside of the workspace root. This is a potential directory traversal risk if not tightly controlled.

Rule source requires an active Pro or Enterprise subscription.
vite-warn-server-host warning log

Setting server.host to true exposes the Vite dev server on the local network. Ensure you are not working on a public or untrusted network, as this allows others to access your development environment.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v3
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
ab22bdd051ec0b24f8739676491d21792267a84adf7bac35bfc144c765a16ad3
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-vite/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-vite. The published version only bumps when a maintainer resyncs.

No commit history available.