Hub rules-webpack

rules-webpack

v4 public Verified

webpack

webpack is a static module bundler for modern JavaScript applications. These rules govern plugin safety, security configurations, and build performance for AI agents.

@sigmashakeinc 2 pulls 8 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-webpack →
Severity
5 error 3 warn 0 info
demo.cast
webpack is a static module bundler for modern JavaScript applications. These rules govern plugin safety, security configurations, and build performance for AI agents.

Rules index

8 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

webpack

webpack-block-unsafe-patterns warning ask

RISK: 'eval-source-map' devtool generates source maps inside eval() calls — this bypasses Content Security Policies that forbid eval (unsafe-eval) and increases bundle parse time. FIX: use 'source-map' for production (external .map file) or 'cheap-module-source-map' for development.

Rule source requires an active Pro or Enterprise subscription.
webpack-deny-devserver-allowed-hosts-all error block

RISK: `allowedHosts: 'all'` / `disableHostCheck: true` in webpack-dev-server disables DNS-rebinding protection — a malicious site can use DNS rebinding to read your local bundle source and make API requests to the dev server on your behalf. FIX: restrict to explicit hostnames or keep the default (localhost only).

Rule source requires an active Pro or Enterprise subscription.
webpack-deny-devserver-expose-all-interfaces error block

RISK: `devServer.host: '0.0.0.0'` exposes the webpack-dev-server on all network interfaces, making your local source and HMR WebSocket accessible to any host on the same network. FIX: keep host at 'localhost' (default); use an explicit ngrok/Tailscale tunnel if remote access is needed.

Rule source requires an active Pro or Enterprise subscription.
webpack-deny-environment-plugin-secret error block

RISK: Inlining environment variables that contain server-side secrets (SECRET/PASSWORD/PRIVATE_KEY) via EnvironmentPlugin or DefinePlugin bakes them into the client bundle — every visitor's browser receives them (CWE-312). FIX: prefix only public, browser-safe vars (e.g. REACT_APP_* or NEXT_PUBLIC_*); keep secrets server-side.

Rule source requires an active Pro or Enterprise subscription.
webpack-deny-eval-devtool-production error block

RISK: An 'eval*' devtool in a production webpack config causes the output bundle to wrap every module in eval() strings. This violates any `script-src` CSP that omits 'unsafe-eval' and leaks full source code in the browser DevTools. FIX: set devtool to 'source-map' for production so source maps are in external .map files, never in eval strings.

Rule source requires an active Pro or Enterprise subscription.
webpack-deny-untrusted-public-path error block

RISK: An absolute `output.publicPath` pointing to a third-party domain (not your own CDN) loads your application chunks from an untrusted origin — if that origin is compromised, all visitors execute attacker-controlled JavaScript. FIX: use a relative publicPath ('/' or './') or your own controlled CDN origin with Subresource Integrity hashes.

Rule source requires an active Pro or Enterprise subscription.
webpack-force-updated-api warning log

optimization.noEmitOnErrors was renamed to optimization.emitOnErrors (inverted) in webpack 5. Using the old key is silently ignored, defeating the intent. FIX: replace with `optimization: { emitOnErrors: false }` (webpack 5+).

Rule source requires an active Pro or Enterprise subscription.
webpack-warn-source-map-loader-secret warning log

ADVISORY: `source-map-loader` without an `exclude` pattern will attempt to follow sourceMappingURL references in every dependency, including node_modules — this can pull in source maps containing internal upstream comments or accidentally bundle files outside the project root. FIX: restrict with `exclude: /node_modules/`.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v4
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
bc5057625da61915254e0e3e84589b4bca066b1e4b78a4932316f5f24c9bc270
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-webpack/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-webpack. The published version only bumps when a maintainer resyncs.

No commit history available.