Hub rules-weaviate

rules-weaviate

v4 public Verified

Weaviate

Weaviate is an open-source vector database that allows you to store data objects and vector embeddings. These rules govern schema definitions, query efficiency, and indexing best practices for AI agents.

@sigmashakeinc 2 pulls 7 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-weaviate →
Severity
5 error 2 warn 0 info
demo.cast
Weaviate is an open-source vector database that allows you to store data objects and vector embeddings. These rules govern schema definitions, query efficiency, and indexing best practices for AI agents.

Rules index

7 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

weaviate

weaviate-block-unsafe-patterns warning ask

RISK: Enabling Weaviate anonymous access removes all authentication controls — any network-reachable client can read, write, and delete all objects in every collection. FIX: configure authentication (API key or OIDC) and explicitly grant only the required roles.

Rule source requires an active Pro or Enterprise subscription.
weaviate-deny-anon-access-yaml error block

RISK: AUTHENTICATION_ANONYMOUS_ACCESS_ENABLED=true disables all authentication in Weaviate — the database is fully public to anyone who can reach the port. FIX: disable anonymous access and configure either API keys (AUTHENTICATION_APIKEY_ENABLED=true) or OIDC (AUTHENTICATION_OIDC_ENABLED=true).

Rule source requires an active Pro or Enterprise subscription.
weaviate-deny-delete-all-objects error ask

RISK: deleteAllObjects() or schema.deleteAll() permanently removes all data in every collection — there is no undo and no confirmation prompt in the API. FIX: delete only specific collections by name; confirm the target and take a backup export first.

Rule source requires an active Pro or Enterprise subscription.
weaviate-deny-graphql-string-concat error block

RISK: Constructing Weaviate GraphQL queries by string concatenation with user-supplied values is a GraphQL injection vector — an attacker can close the query and append arbitrary operations. FIX: use the typed query builder (weaviate.graphql.get().withWhere()) or pass user values only through typed .withWhere() filter arguments.

Rule source requires an active Pro or Enterprise subscription.
weaviate-deny-grpc-no-tls error block

RISK: Weaviate gRPC connections without TLS transmit data (including vectors and object payloads) in plaintext over the network — data in transit is subject to interception (CWE-319). FIX: configure TLS certificates for the gRPC listener and use weaviate-client with secure: true.

Rule source requires an active Pro or Enterprise subscription.
weaviate-deny-hardcoded-api-key error block

RISK: Hardcoded Weaviate API keys or OIDC client secrets in source code are committed to version control and exposed to anyone with repo access (CWE-798). FIX: read the key from an environment variable (process.env.WEAVIATE_API_KEY / os.environ['WEAVIATE_API_KEY']) and keep the value in a gitignored .env or a secrets manager.

Rule source requires an active Pro or Enterprise subscription.
weaviate-warn-unauthenticated-backup warning log

ADVISORY: Triggering a Weaviate backup without authentication context means the backup request will fail if auth is enabled, or succeed on an unauthenticated instance. FIX: always authenticate with a key/OIDC token that has the backup/manage permission, and store backup artifacts in a private bucket.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v4
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
56b4e04652df7d402eec8c6e5ad28fd97bd2a84aca2947b7eb1bd25e72a28ce7
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-weaviate/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-weaviate. The published version only bumps when a maintainer resyncs.

No commit history available.