项目文件夹

文件
wehub-resource-sync 7a0da7932b
OSV-Scanner (Scheduled) / scan-scheduled (push) Failing after 0s
Create Release / test-gate (push) Has been cancelled
Create Release / release-gate (push) Has been cancelled
Create Release / ci-gate (push) Has been cancelled
Create Release / version-check (push) Has been cancelled
Create Release / e2e-test-gate (push) Has been cancelled
Create Release / responsive-test-gate (push) Has been cancelled
Create Release / compat-test-gate (push) Has been cancelled
Create Release / compose-integration-gate (push) Has been cancelled
Create Release / vulture-gate (push) Has been cancelled
Create Release / build (push) Has been cancelled
Create Release / provenance (push) Has been cancelled
Create Release / prerelease-docker (push) Has been cancelled
Create Release / publish-docker (push) Has been cancelled
Create Release / create-release (push) Has been cancelled
Create Release / cleanup-changelog (push) Has been cancelled
Create Release / trigger-pypi (push) Has been cancelled
Create Release / monitor-pypi (push) Has been cancelled
Create Release / Clean up orphan prerelease tags and signatures (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-form] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-metrics] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-workflow] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [settings-core] (push) Has been cancelled
CodeQL Advanced / Analyze (javascript-typescript) (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [history-news] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [library] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [link-analytics] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [chat-core] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [chat-lifecycle] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [error-benchmark] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [settings-pages] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) (push) Has been cancelled
Docker Tests (Consolidated) / Accessibility Tests (push) Has been cancelled
Docker Tests (Consolidated) / LLM Unit Tests (push) Has been cancelled
Docker Tests (Consolidated) / LLM Example Tests (push) Has been cancelled
Docker Tests (Consolidated) / Production Image Smoke Test (push) Has been cancelled
Docker Tests (Consolidated) / Infrastructure Tests (push) Has been cancelled
OSSF Scorecard / OSSF Security Scorecard Analysis (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [mobile] (push) Has been cancelled
Backwards Compatibility / Verify Encryption Constants (push) Has been cancelled
Backwards Compatibility / PyPI Version Compatibility (push) Has been cancelled
Backwards Compatibility / Database Migration Tests (push) Has been cancelled
CodeQL Advanced / Analyze (python) (push) Has been cancelled
Docker Tests (Consolidated) / detect-changes (push) Has been cancelled
Docker Tests (Consolidated) / Build Test Image (push) Has been cancelled
Docker Tests (Consolidated) / All Pytest Tests + Coverage (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [accessibility] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [api-crud] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-login] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-pages] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-register] (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 13:08:55 +08:00

2.9 KiB

LDR Custom Security Rules

This directory contains custom Semgrep security rules specific to Local Deep Research (LDR).

Rules Overview

ldr-security.yaml

LDR-specific security rules covering:

  1. Hardcoded Secrets

    • Detects API keys, passwords, tokens in source code
    • Severity: ERROR
    • CWE-798
  2. SQL Injection Prevention

    • Detects string concatenation in SQL queries
    • Enforces parameterized queries via SQLAlchemy
    • Severity: ERROR
    • CWE-89
  3. Code Injection

    • Detects dangerous use of eval/exec
    • Prevents arbitrary code execution
    • Severity: ERROR
    • CWE-95
  4. Command Injection

    • Detects unsafe use of os.system, shell=True
    • Enforces subprocess with argument lists
    • Severity: ERROR
    • CWE-78
  5. Path Traversal

    • Detects unsanitized user input in file paths
    • Prevents directory traversal attacks
    • Severity: WARNING
    • CWE-22
  6. Unsafe Deserialization

    • Detects unsafe YAML/pickle loading
    • Prevents code execution via deserialization
    • Severity: ERROR
    • CWE-502
  7. Weak Randomness

    • Detects use of random module for security
    • Enforces secrets module for crypto operations
    • Severity: WARNING
    • CWE-338
  8. Debug Mode in Production

    • Detects Flask debug=True
    • Prevents information disclosure
    • Severity: ERROR
    • CWE-489
  9. SSRF Prevention

    • Detects URL fetching operations
    • Reminds to validate URLs
    • Severity: WARNING
    • CWE-918
  10. XSS Prevention

    • Detects user input in HTML context
    • Enforces proper escaping
    • Severity: WARNING
    • CWE-79
  11. CSRF Protection

    • Detects POST endpoints
    • Reminds to enable CSRF protection
    • Severity: INFO
    • CWE-352
  12. Credential Logging

    • Detects passwords in log statements
    • Prevents credential disclosure
    • Severity: ERROR
    • CWE-532

Usage

These rules are automatically run by the Semgrep CI/CD workflow:

# Run locally
semgrep --config=.semgrep/rules/ src/

# Run with standard rules
semgrep --config=p/security-audit --config=.semgrep/rules/ src/

Adding New Rules

To add new custom rules:

  1. Create a new YAML file in .semgrep/rules/
  2. Follow Semgrep rule syntax
  3. Test the rule: semgrep --config=.semgrep/rules/your-rule.yaml src/
  4. Document the rule in this README

Rule Template

rules:
  - id: your-rule-id
    pattern: |
      # Your pattern here
    message: Description of the security issue
    languages: [python]
    severity: ERROR  # or WARNING, INFO
    metadata:
      category: security
      cwe: "CWE-XXX: Description"
      owasp: "AXX:2021 - Category"

References