learningcircuit--local-deep-research
7a0da7932b
OSV-Scanner (Scheduled) / scan-scheduled (push) Failing after 0s
Create Release / test-gate (push) Has been cancelled
Create Release / release-gate (push) Has been cancelled
Create Release / ci-gate (push) Has been cancelled
Create Release / version-check (push) Has been cancelled
Create Release / e2e-test-gate (push) Has been cancelled
Create Release / responsive-test-gate (push) Has been cancelled
Create Release / compat-test-gate (push) Has been cancelled
Create Release / compose-integration-gate (push) Has been cancelled
Create Release / vulture-gate (push) Has been cancelled
Create Release / build (push) Has been cancelled
Create Release / provenance (push) Has been cancelled
Create Release / prerelease-docker (push) Has been cancelled
Create Release / publish-docker (push) Has been cancelled
Create Release / create-release (push) Has been cancelled
Create Release / cleanup-changelog (push) Has been cancelled
Create Release / trigger-pypi (push) Has been cancelled
Create Release / monitor-pypi (push) Has been cancelled
Create Release / Clean up orphan prerelease tags and signatures (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-form] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-metrics] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-workflow] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [settings-core] (push) Has been cancelled
CodeQL Advanced / Analyze (javascript-typescript) (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [history-news] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [library] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [link-analytics] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [chat-core] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [chat-lifecycle] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [error-benchmark] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [settings-pages] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) (push) Has been cancelled
Docker Tests (Consolidated) / Accessibility Tests (push) Has been cancelled
Docker Tests (Consolidated) / LLM Unit Tests (push) Has been cancelled
Docker Tests (Consolidated) / LLM Example Tests (push) Has been cancelled
Docker Tests (Consolidated) / Production Image Smoke Test (push) Has been cancelled
Docker Tests (Consolidated) / Infrastructure Tests (push) Has been cancelled
OSSF Scorecard / OSSF Security Scorecard Analysis (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [mobile] (push) Has been cancelled
Backwards Compatibility / Verify Encryption Constants (push) Has been cancelled
Backwards Compatibility / PyPI Version Compatibility (push) Has been cancelled
Backwards Compatibility / Database Migration Tests (push) Has been cancelled
CodeQL Advanced / Analyze (python) (push) Has been cancelled
Docker Tests (Consolidated) / detect-changes (push) Has been cancelled
Docker Tests (Consolidated) / Build Test Image (push) Has been cancelled
Docker Tests (Consolidated) / All Pytest Tests + Coverage (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [accessibility] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [api-crud] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-login] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-pages] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-register] (push) Has been cancelled
136 行
4.2 KiB
YAML
136 行
4.2 KiB
YAML
rules:
|
|
- id: unsafe-requests-get
|
|
patterns:
|
|
- pattern: requests.get(...)
|
|
paths:
|
|
exclude:
|
|
- "**/security/safe_requests.py"
|
|
- "**/tests/**"
|
|
- "**/*_test.py"
|
|
- "**/test_*.py"
|
|
- "**/examples/**"
|
|
message: >-
|
|
Direct requests.get() bypasses SSRF protection.
|
|
Use safe_get() from security module instead.
|
|
Import: from ...security import safe_get
|
|
For localhost services: safe_get(url, allow_localhost=True)
|
|
languages: [python]
|
|
severity: ERROR
|
|
metadata:
|
|
category: security
|
|
cwe: "CWE-918: Server-Side Request Forgery (SSRF)"
|
|
owasp: "A10:2021 - Server-Side Request Forgery"
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/918.html
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
|
|
|
|
- id: unsafe-requests-post
|
|
patterns:
|
|
- pattern: requests.post(...)
|
|
paths:
|
|
exclude:
|
|
- "**/security/safe_requests.py"
|
|
- "**/tests/**"
|
|
- "**/*_test.py"
|
|
- "**/test_*.py"
|
|
- "**/examples/**"
|
|
message: >-
|
|
Direct requests.post() bypasses SSRF protection.
|
|
Use safe_post() from security module instead.
|
|
Import: from ...security import safe_post
|
|
For localhost services: safe_post(url, allow_localhost=True)
|
|
languages: [python]
|
|
severity: ERROR
|
|
metadata:
|
|
category: security
|
|
cwe: "CWE-918: Server-Side Request Forgery (SSRF)"
|
|
owasp: "A10:2021 - Server-Side Request Forgery"
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/918.html
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
|
|
|
|
- id: unsafe-requests-session
|
|
patterns:
|
|
- pattern: requests.Session()
|
|
paths:
|
|
exclude:
|
|
- "**/security/safe_requests.py"
|
|
- "**/tests/**"
|
|
- "**/*_test.py"
|
|
- "**/test_*.py"
|
|
- "**/examples/**"
|
|
message: >-
|
|
Direct requests.Session() bypasses SSRF protection.
|
|
Use SafeSession() from security module instead.
|
|
Import: from ...security import SafeSession
|
|
For localhost services: SafeSession(allow_localhost=True)
|
|
languages: [python]
|
|
severity: ERROR
|
|
metadata:
|
|
category: security
|
|
cwe: "CWE-918: Server-Side Request Forgery (SSRF)"
|
|
owasp: "A10:2021 - Server-Side Request Forgery"
|
|
references:
|
|
- https://cwe.mitre.org/data/definitions/918.html
|
|
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
|
|
|
|
- id: unsafe-requests-put
|
|
patterns:
|
|
- pattern: requests.put(...)
|
|
paths:
|
|
exclude:
|
|
- "**/security/safe_requests.py"
|
|
- "**/tests/**"
|
|
- "**/*_test.py"
|
|
- "**/test_*.py"
|
|
- "**/examples/**"
|
|
message: >-
|
|
Direct requests.put() bypasses SSRF protection.
|
|
Use SafeSession() from security module for HTTP requests.
|
|
languages: [python]
|
|
severity: ERROR
|
|
metadata:
|
|
category: security
|
|
cwe: "CWE-918: Server-Side Request Forgery (SSRF)"
|
|
owasp: "A10:2021 - Server-Side Request Forgery"
|
|
|
|
- id: unsafe-requests-delete
|
|
patterns:
|
|
- pattern: requests.delete(...)
|
|
paths:
|
|
exclude:
|
|
- "**/security/safe_requests.py"
|
|
- "**/tests/**"
|
|
- "**/*_test.py"
|
|
- "**/test_*.py"
|
|
- "**/examples/**"
|
|
message: >-
|
|
Direct requests.delete() bypasses SSRF protection.
|
|
Use SafeSession() from security module for HTTP requests.
|
|
languages: [python]
|
|
severity: ERROR
|
|
metadata:
|
|
category: security
|
|
cwe: "CWE-918: Server-Side Request Forgery (SSRF)"
|
|
owasp: "A10:2021 - Server-Side Request Forgery"
|
|
|
|
- id: unsafe-requests-patch
|
|
patterns:
|
|
- pattern: requests.patch(...)
|
|
paths:
|
|
exclude:
|
|
- "**/security/safe_requests.py"
|
|
- "**/tests/**"
|
|
- "**/*_test.py"
|
|
- "**/test_*.py"
|
|
- "**/examples/**"
|
|
message: >-
|
|
Direct requests.patch() bypasses SSRF protection.
|
|
Use SafeSession() from security module for HTTP requests.
|
|
languages: [python]
|
|
severity: ERROR
|
|
metadata:
|
|
category: security
|
|
cwe: "CWE-918: Server-Side Request Forgery (SSRF)"
|
|
owasp: "A10:2021 - Server-Side Request Forgery"
|