learningcircuit--local-deep-research
7a0da7932b
OSV-Scanner (Scheduled) / scan-scheduled (push) Failing after 0s
Create Release / test-gate (push) Has been cancelled
Create Release / release-gate (push) Has been cancelled
Create Release / ci-gate (push) Has been cancelled
Create Release / version-check (push) Has been cancelled
Create Release / e2e-test-gate (push) Has been cancelled
Create Release / responsive-test-gate (push) Has been cancelled
Create Release / compat-test-gate (push) Has been cancelled
Create Release / compose-integration-gate (push) Has been cancelled
Create Release / vulture-gate (push) Has been cancelled
Create Release / build (push) Has been cancelled
Create Release / provenance (push) Has been cancelled
Create Release / prerelease-docker (push) Has been cancelled
Create Release / publish-docker (push) Has been cancelled
Create Release / create-release (push) Has been cancelled
Create Release / cleanup-changelog (push) Has been cancelled
Create Release / trigger-pypi (push) Has been cancelled
Create Release / monitor-pypi (push) Has been cancelled
Create Release / Clean up orphan prerelease tags and signatures (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-form] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-metrics] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-workflow] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [settings-core] (push) Has been cancelled
CodeQL Advanced / Analyze (javascript-typescript) (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [history-news] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [library] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [link-analytics] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [chat-core] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [chat-lifecycle] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [error-benchmark] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [settings-pages] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) (push) Has been cancelled
Docker Tests (Consolidated) / Accessibility Tests (push) Has been cancelled
Docker Tests (Consolidated) / LLM Unit Tests (push) Has been cancelled
Docker Tests (Consolidated) / LLM Example Tests (push) Has been cancelled
Docker Tests (Consolidated) / Production Image Smoke Test (push) Has been cancelled
Docker Tests (Consolidated) / Infrastructure Tests (push) Has been cancelled
OSSF Scorecard / OSSF Security Scorecard Analysis (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [mobile] (push) Has been cancelled
Backwards Compatibility / Verify Encryption Constants (push) Has been cancelled
Backwards Compatibility / PyPI Version Compatibility (push) Has been cancelled
Backwards Compatibility / Database Migration Tests (push) Has been cancelled
CodeQL Advanced / Analyze (python) (push) Has been cancelled
Docker Tests (Consolidated) / detect-changes (push) Has been cancelled
Docker Tests (Consolidated) / Build Test Image (push) Has been cancelled
Docker Tests (Consolidated) / All Pytest Tests + Coverage (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [accessibility] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [api-crud] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-login] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-pages] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-register] (push) Has been cancelled
2.9 KiB
2.9 KiB
LDR Custom Security Rules
This directory contains custom Semgrep security rules specific to Local Deep Research (LDR).
Rules Overview
ldr-security.yaml
LDR-specific security rules covering:
-
Hardcoded Secrets
- Detects API keys, passwords, tokens in source code
- Severity: ERROR
- CWE-798
-
SQL Injection Prevention
- Detects string concatenation in SQL queries
- Enforces parameterized queries via SQLAlchemy
- Severity: ERROR
- CWE-89
-
Code Injection
- Detects dangerous use of eval/exec
- Prevents arbitrary code execution
- Severity: ERROR
- CWE-95
-
Command Injection
- Detects unsafe use of os.system, shell=True
- Enforces subprocess with argument lists
- Severity: ERROR
- CWE-78
-
Path Traversal
- Detects unsanitized user input in file paths
- Prevents directory traversal attacks
- Severity: WARNING
- CWE-22
-
Unsafe Deserialization
- Detects unsafe YAML/pickle loading
- Prevents code execution via deserialization
- Severity: ERROR
- CWE-502
-
Weak Randomness
- Detects use of random module for security
- Enforces secrets module for crypto operations
- Severity: WARNING
- CWE-338
-
Debug Mode in Production
- Detects Flask debug=True
- Prevents information disclosure
- Severity: ERROR
- CWE-489
-
SSRF Prevention
- Detects URL fetching operations
- Reminds to validate URLs
- Severity: WARNING
- CWE-918
-
XSS Prevention
- Detects user input in HTML context
- Enforces proper escaping
- Severity: WARNING
- CWE-79
-
CSRF Protection
- Detects POST endpoints
- Reminds to enable CSRF protection
- Severity: INFO
- CWE-352
-
Credential Logging
- Detects passwords in log statements
- Prevents credential disclosure
- Severity: ERROR
- CWE-532
Usage
These rules are automatically run by the Semgrep CI/CD workflow:
# Run locally
semgrep --config=.semgrep/rules/ src/
# Run with standard rules
semgrep --config=p/security-audit --config=.semgrep/rules/ src/
Adding New Rules
To add new custom rules:
- Create a new YAML file in
.semgrep/rules/ - Follow Semgrep rule syntax
- Test the rule:
semgrep --config=.semgrep/rules/your-rule.yaml src/ - Document the rule in this README
Rule Template
rules:
- id: your-rule-id
pattern: |
# Your pattern here
message: Description of the security issue
languages: [python]
severity: ERROR # or WARNING, INFO
metadata:
category: security
cwe: "CWE-XXX: Description"
owasp: "AXX:2021 - Category"