Hub rules-wrangler

rules-wrangler

v1 public Verified

Wrangler

Wrangler is Cloudflare's CLI for deploying Workers, managing D1, KV, R2, and Durable Objects. These rules protect AI agents from destructive remote-database operations, secrets leakage in wrangler.toml, missing compatibility dates, public-bucket misconfiguration, and production deploys without environment gates.

@sigmashakeinc 0 pulls 30 rules published Apr 19, 2026 synced Sep 27, 2026 sigmashakeinc/rules/rulesets/rules-wrangler →
Severity
16 error 11 warn 3 info
demo.cast
Wrangler is Cloudflare's CLI for deploying Workers, managing D1, KV, R2, and Durable Objects. These rules protect AI agents from destructive remote-database operations, secrets leakage in wrangler.toml, missing compatibility dates, public-bucket misconfiguration, and production deploys without environment gates.

Rules index

30 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

wrangler

worker-cache-personalized-response warning ask

Caching responses that depend on Authorization/Cookie headers without varying cache key leaks one user's response to another.

Rule source requires an active Pro or Enterprise subscription.
worker-crypto-weak-random error block

`Math.random()` is not cryptographically secure — it's predictable. Use `crypto.randomUUID()` or `crypto.getRandomValues()` (Web Crypto is available on Workers without import).

Rule source requires an active Pro or Enterprise subscription.
worker-d1-string-concat-query error block

D1 SQL injection: template-literal interpolation or `+` concatenation in `.prepare()`/`.exec()` is injectable. Use parameterized queries: `db.prepare('SELECT * FROM t WHERE id = ?').bind(id)`.

Rule source requires an active Pro or Enterprise subscription.
worker-durable-object-no-blockconcurrency info log

Durable Object handlers that initialize state from storage should wrap the load in `this.state.blockConcurrencyWhile(async () => {...})` in the constructor to prevent request handlers from observing partially-loaded state.

Rule source requires an active Pro or Enterprise subscription.
worker-env-log error block

Logging the entire `env` object exposes every bound secret (from `wrangler secret put`) to `wrangler tail`, Logpush, and any connected Logs-to-SIEM pipeline. Log specific non-secret fields only.

Rule source requires an active Pro or Enterprise subscription.
worker-fetch-no-timeout info log

`fetch()` without `AbortSignal.timeout()` relies on Workers' 30s CPU-time ceiling (or subrequest ceiling) — a slow upstream can consume the whole request budget. Add an explicit timeout appropriate to the call.

Rule source requires an active Pro or Enterprise subscription.
worker-fetch-unbounded-subrequest warning log

Workers have a 50-subrequest limit on Free and 1000 on Paid plans — unbounded loops issuing `await fetch()` will throw `Too many subrequests` mid-execution. Batch, parallelize with Promise.all up to the limit, or offload to a Queue.

Rule source requires an active Pro or Enterprise subscription.
worker-opennext-ssrf-cve-2026-3125 error block

CVE-2026-3125: @opennextjs/cloudflare <1.6.3 has an SSRF via path normalization in the /cdn-cgi/image/ handler, letting attackers fetch arbitrary remote URLs through your Worker. Upgrade to the patched release.

Rule source requires an active Pro or Enterprise subscription.
worker-secret-compare-timing-unsafe error block

Comparing a secret/token with `===` leaks length and prefix via timing side-channel (attacker can brute-force byte-by-byte). Use `crypto.subtle.timingSafeEqual(enc(a), enc(b))` (Web Crypto on Workers) after length-checking.

Rule source requires an active Pro or Enterprise subscription.
worker-vite-plugin-secret-leak-ghsa-4pfg error block

GHSA-4pfg-2mw5-f8jx: @cloudflare/vite-plugin <0.1.6 exposes Worker secrets over the dev-server without authentication, so any local process can read them. Upgrade and avoid binding production secrets in `vite dev`.

Rule source requires an active Pro or Enterprise subscription.
wrangler-d1-execute-remote-raw warning ask

Running ad-hoc SQL directly against remote D1 skips review and leaves no migration trail.

Rule source requires an active Pro or Enterprise subscription.
wrangler-d1-migrations-apply-remote warning ask

Applying migrations to a remote (production) D1 database.

Rule source requires an active Pro or Enterprise subscription.
wrangler-d1-remote-destructive error block

Destructive SQL (DROP / TRUNCATE / unbounded DELETE) against --remote D1 is irreversible — D1 has no native point-in-time recovery on lower tiers. Run against --preview or a named preview database first, and always include a WHERE clause on mutations.

Rule source requires an active Pro or Enterprise subscription.
wrangler-deploy-no-env warning ask

`wrangler deploy` without `--env` targets the top-level (production) worker.

Rule source requires an active Pro or Enterprise subscription.
wrangler-hyperdrive-connection-string error block

Hyperdrive connection strings containing DB credentials in wrangler.toml get committed to git. Store the URL with `wrangler hyperdrive create --connection-string=...` (server-side) and reference the binding id; for local dev put the URL in `.dev.vars` (gitignored).

Rule source requires an active Pro or Enterprise subscription.
wrangler-kv-bulk-delete error block

KV deletions are immediate and non-recoverable. Confirm the namespace ID, scope deletion with a prefix, and list keys first via `wrangler kv key list`.

Rule source requires an active Pro or Enterprise subscription.
wrangler-login-interactive warning log

`wrangler login` uses OAuth and requires a browser — it cannot complete in CI. Use CLOUDFLARE_API_TOKEN (scoped to the account/zone/workers) set as a secret environment variable.

Rule source requires an active Pro or Enterprise subscription.
wrangler-main-missing warning log

No `main` entry in wrangler.toml — deploy will fail unless main is passed via CLI. Declare the entry point explicitly for reproducible deploys.

Rule source requires an active Pro or Enterprise subscription.
wrangler-missing-compat-date error block

Missing `compatibility_date` in wrangler.toml. Without it, Workers runtime behavior is undefined and may break on deploy. Set to today's date or a pinned date matching tested behavior.

Rule source requires an active Pro or Enterprise subscription.
wrangler-node-compat-deprecated warning log

node_compat = true (webpack polyfills) is deprecated and removed in wrangler v4. Switch to the `nodejs_compat` compatibility_flag for native workerd Node APIs.

Rule source requires an active Pro or Enterprise subscription.
wrangler-pages-deploy-commit-hash-injection error block

CVE-2026-0933 (GHSA-36p8-mvp6-cv38): `--commit-hash` on `wrangler pages deploy` is passed to a shell and allows OS command injection in wrangler <=3.114.16 and 4.x <=4.59.0. Upgrade wrangler and restrict the value to `[A-Fa-f0-9]+` before passing it.

Rule source requires an active Pro or Enterprise subscription.
wrangler-public-r2-bucket error block

public_bucket = true makes every object in the R2 bucket world-readable via the r2.dev URL. Use a Worker or signed URLs for controlled access. Only enable for exclusively public assets.

Rule source requires an active Pro or Enterprise subscription.
wrangler-r2-bucket-delete error block

`wrangler r2 bucket delete` permanently destroys the bucket and all objects. There is no undo. Use object-level deletion (`wrangler r2 object delete`) if clearing contents, and verify the bucket name.

Rule source requires an active Pro or Enterprise subscription.
wrangler-rollback-force warning ask

`wrangler rollback` reverts the active deployment but does NOT roll back D1 migrations, KV writes, or R2 objects made by the newer version.

Rule source requires an active Pro or Enterprise subscription.
wrangler-secret-in-vars error block

Secrets in wrangler.toml [vars] are committed to git and visible in plaintext on the Cloudflare dashboard. Use `wrangler secret put NAME` (encrypted at rest, env-scoped). The binding name stays identical — only storage changes.

Rule source requires an active Pro or Enterprise subscription.
wrangler-secret-put-echo error block

Piping secrets via `echo | wrangler secret put` writes them to shell history and may appear in `ps` output. Pipe from a file (`wrangler secret put NAME < file`) or use interactive mode, then clear the file.

Rule source requires an active Pro or Enterprise subscription.
wrangler-stale-compat-date warning log

compatibility_date is more than 3 years old. Recent Workers features (nodejs_compat v2, streaming, Python support) require dates >= 2024. Review the runtime changelog before bumping.

Rule source requires an active Pro or Enterprise subscription.
wrangler-tail-prod info log

`wrangler tail` on production streams live request data including headers and URLs — may expose user PII or auth tokens to the terminal and any tee'd logs. Use `--format=json --filter` to scope.

Rule source requires an active Pro or Enterprise subscription.
wrangler-usage-model-removed warning log

`usage_model` in wrangler.toml is ignored as of 2024 — billing is set per-account on the dashboard (Standard/Unbound). Remove this field to avoid confusion.

Rule source requires an active Pro or Enterprise subscription.
wrangler-wildcard-route error block

A bare `*` route catches every request on every zone in the account — it will hijack traffic from unrelated sites. Scope routes: `example.com/api/*` or `*.example.com/*`.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v1
Published
Apr 19, 2026
Source commits
0
Synced
Sep 27, 2026
Hash
39fb979930c4d87f93db32c38bef8315978552ee8f55228d7d2059973a1b1ddf
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-wrangler/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-wrangler. The published version only bumps when a maintainer resyncs.

No commit history available.