Files
git.stella-ops.org/bench/reachability-benchmark/baselines/semgrep/rules.yaml
StellaOps Bot c11d87d252
Some checks failed
AOC Guard CI / aoc-guard (push) Has been cancelled
AOC Guard CI / aoc-verify (push) Has been cancelled
Docs CI / lint-and-preview (push) Has been cancelled
Mirror Thin Bundle Sign & Verify / mirror-sign (push) Has been cancelled
Concelier Attestation Tests / attestation-tests (push) Has been cancelled
Export Center CI / export-ci (push) Has been cancelled
feat: Add tests for RichGraphPublisher and RichGraphWriter
- Implement unit tests for RichGraphPublisher to verify graph publishing to CAS.
- Implement unit tests for RichGraphWriter to ensure correct writing of canonical graphs and metadata.

feat: Implement AOC Guard validation logic

- Add AOC Guard validation logic to enforce document structure and field constraints.
- Introduce violation codes for various validation errors.
- Implement tests for AOC Guard to validate expected behavior.

feat: Create Console Status API client and service

- Implement ConsoleStatusClient for fetching console status and streaming run events.
- Create ConsoleStatusService to manage console status polling and event subscriptions.
- Add tests for ConsoleStatusClient to verify API interactions.

feat: Develop Console Status component

- Create ConsoleStatusComponent for displaying console status and run events.
- Implement UI for showing status metrics and handling user interactions.
- Add styles for console status display.

test: Add tests for Console Status store

- Implement tests for ConsoleStatusStore to verify event handling and state management.
2025-12-01 07:34:50 +02:00

35 lines
1.1 KiB
YAML

rules:
- id: semgrep.eval.js
languages: [javascript, typescript]
message: "Potential eval / Function sink"
severity: WARNING
patterns:
- pattern-either:
- pattern: eval($EXPR)
- pattern: Function($ARGS, $BODY)
- pattern: vm.runInNewContext($EXPR, ...)
- id: semgrep.template.js
languages: [javascript, typescript]
message: "Template rendering with user-controlled input"
severity: WARNING
patterns:
- pattern-either:
- pattern: res.render($TEMPLATE, $CTX)
- pattern: reply.view($TEMPLATE, $CTX)
- id: semgrep.exec.py
languages: [python]
message: "Potential exec/eval sink"
severity: WARNING
patterns:
- pattern-either:
- pattern: eval($EXPR)
- pattern: exec($EXPR)
- id: semgrep.template.py
languages: [python]
message: "Template rendering with user-controlled input"
severity: WARNING
patterns:
- pattern-either:
- pattern: render_template($NAME, **$KWARGS)
- pattern: Template($X).render(...)