Some checks failed
AOC Guard CI / aoc-guard (push) Has been cancelled
AOC Guard CI / aoc-verify (push) Has been cancelled
Docs CI / lint-and-preview (push) Has been cancelled
Mirror Thin Bundle Sign & Verify / mirror-sign (push) Has been cancelled
Concelier Attestation Tests / attestation-tests (push) Has been cancelled
Export Center CI / export-ci (push) Has been cancelled
- Implement unit tests for RichGraphPublisher to verify graph publishing to CAS. - Implement unit tests for RichGraphWriter to ensure correct writing of canonical graphs and metadata. feat: Implement AOC Guard validation logic - Add AOC Guard validation logic to enforce document structure and field constraints. - Introduce violation codes for various validation errors. - Implement tests for AOC Guard to validate expected behavior. feat: Create Console Status API client and service - Implement ConsoleStatusClient for fetching console status and streaming run events. - Create ConsoleStatusService to manage console status polling and event subscriptions. - Add tests for ConsoleStatusClient to verify API interactions. feat: Develop Console Status component - Create ConsoleStatusComponent for displaying console status and run events. - Implement UI for showing status metrics and handling user interactions. - Add styles for console status display. test: Add tests for Console Status store - Implement tests for ConsoleStatusStore to verify event handling and state management.
35 lines
1.1 KiB
YAML
35 lines
1.1 KiB
YAML
rules:
|
|
- id: semgrep.eval.js
|
|
languages: [javascript, typescript]
|
|
message: "Potential eval / Function sink"
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: eval($EXPR)
|
|
- pattern: Function($ARGS, $BODY)
|
|
- pattern: vm.runInNewContext($EXPR, ...)
|
|
- id: semgrep.template.js
|
|
languages: [javascript, typescript]
|
|
message: "Template rendering with user-controlled input"
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: res.render($TEMPLATE, $CTX)
|
|
- pattern: reply.view($TEMPLATE, $CTX)
|
|
- id: semgrep.exec.py
|
|
languages: [python]
|
|
message: "Potential exec/eval sink"
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: eval($EXPR)
|
|
- pattern: exec($EXPR)
|
|
- id: semgrep.template.py
|
|
languages: [python]
|
|
message: "Template rendering with user-controlled input"
|
|
severity: WARNING
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: render_template($NAME, **$KWARGS)
|
|
- pattern: Template($X).render(...)
|