项目文件夹

文件
wehub-resource-sync 7a0da7932b
OSV-Scanner (Scheduled) / scan-scheduled (push) Failing after 0s
Create Release / test-gate (push) Has been cancelled
Create Release / release-gate (push) Has been cancelled
Create Release / ci-gate (push) Has been cancelled
Create Release / version-check (push) Has been cancelled
Create Release / e2e-test-gate (push) Has been cancelled
Create Release / responsive-test-gate (push) Has been cancelled
Create Release / compat-test-gate (push) Has been cancelled
Create Release / compose-integration-gate (push) Has been cancelled
Create Release / vulture-gate (push) Has been cancelled
Create Release / build (push) Has been cancelled
Create Release / provenance (push) Has been cancelled
Create Release / prerelease-docker (push) Has been cancelled
Create Release / publish-docker (push) Has been cancelled
Create Release / create-release (push) Has been cancelled
Create Release / cleanup-changelog (push) Has been cancelled
Create Release / trigger-pypi (push) Has been cancelled
Create Release / monitor-pypi (push) Has been cancelled
Create Release / Clean up orphan prerelease tags and signatures (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-form] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-metrics] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-workflow] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [settings-core] (push) Has been cancelled
CodeQL Advanced / Analyze (javascript-typescript) (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [history-news] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [library] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [link-analytics] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [chat-core] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [chat-lifecycle] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [error-benchmark] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [settings-pages] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) (push) Has been cancelled
Docker Tests (Consolidated) / Accessibility Tests (push) Has been cancelled
Docker Tests (Consolidated) / LLM Unit Tests (push) Has been cancelled
Docker Tests (Consolidated) / LLM Example Tests (push) Has been cancelled
Docker Tests (Consolidated) / Production Image Smoke Test (push) Has been cancelled
Docker Tests (Consolidated) / Infrastructure Tests (push) Has been cancelled
OSSF Scorecard / OSSF Security Scorecard Analysis (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [mobile] (push) Has been cancelled
Backwards Compatibility / Verify Encryption Constants (push) Has been cancelled
Backwards Compatibility / PyPI Version Compatibility (push) Has been cancelled
Backwards Compatibility / Database Migration Tests (push) Has been cancelled
CodeQL Advanced / Analyze (python) (push) Has been cancelled
Docker Tests (Consolidated) / detect-changes (push) Has been cancelled
Docker Tests (Consolidated) / Build Test Image (push) Has been cancelled
Docker Tests (Consolidated) / All Pytest Tests + Coverage (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [accessibility] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [api-crud] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-login] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-pages] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-register] (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 13:08:55 +08:00

136 行
4.2 KiB
YAML

rules:
- id: unsafe-requests-get
patterns:
- pattern: requests.get(...)
paths:
exclude:
- "**/security/safe_requests.py"
- "**/tests/**"
- "**/*_test.py"
- "**/test_*.py"
- "**/examples/**"
message: >-
Direct requests.get() bypasses SSRF protection.
Use safe_get() from security module instead.
Import: from ...security import safe_get
For localhost services: safe_get(url, allow_localhost=True)
languages: [python]
severity: ERROR
metadata:
category: security
cwe: "CWE-918: Server-Side Request Forgery (SSRF)"
owasp: "A10:2021 - Server-Side Request Forgery"
references:
- https://cwe.mitre.org/data/definitions/918.html
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
- id: unsafe-requests-post
patterns:
- pattern: requests.post(...)
paths:
exclude:
- "**/security/safe_requests.py"
- "**/tests/**"
- "**/*_test.py"
- "**/test_*.py"
- "**/examples/**"
message: >-
Direct requests.post() bypasses SSRF protection.
Use safe_post() from security module instead.
Import: from ...security import safe_post
For localhost services: safe_post(url, allow_localhost=True)
languages: [python]
severity: ERROR
metadata:
category: security
cwe: "CWE-918: Server-Side Request Forgery (SSRF)"
owasp: "A10:2021 - Server-Side Request Forgery"
references:
- https://cwe.mitre.org/data/definitions/918.html
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
- id: unsafe-requests-session
patterns:
- pattern: requests.Session()
paths:
exclude:
- "**/security/safe_requests.py"
- "**/tests/**"
- "**/*_test.py"
- "**/test_*.py"
- "**/examples/**"
message: >-
Direct requests.Session() bypasses SSRF protection.
Use SafeSession() from security module instead.
Import: from ...security import SafeSession
For localhost services: SafeSession(allow_localhost=True)
languages: [python]
severity: ERROR
metadata:
category: security
cwe: "CWE-918: Server-Side Request Forgery (SSRF)"
owasp: "A10:2021 - Server-Side Request Forgery"
references:
- https://cwe.mitre.org/data/definitions/918.html
- https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html
- id: unsafe-requests-put
patterns:
- pattern: requests.put(...)
paths:
exclude:
- "**/security/safe_requests.py"
- "**/tests/**"
- "**/*_test.py"
- "**/test_*.py"
- "**/examples/**"
message: >-
Direct requests.put() bypasses SSRF protection.
Use SafeSession() from security module for HTTP requests.
languages: [python]
severity: ERROR
metadata:
category: security
cwe: "CWE-918: Server-Side Request Forgery (SSRF)"
owasp: "A10:2021 - Server-Side Request Forgery"
- id: unsafe-requests-delete
patterns:
- pattern: requests.delete(...)
paths:
exclude:
- "**/security/safe_requests.py"
- "**/tests/**"
- "**/*_test.py"
- "**/test_*.py"
- "**/examples/**"
message: >-
Direct requests.delete() bypasses SSRF protection.
Use SafeSession() from security module for HTTP requests.
languages: [python]
severity: ERROR
metadata:
category: security
cwe: "CWE-918: Server-Side Request Forgery (SSRF)"
owasp: "A10:2021 - Server-Side Request Forgery"
- id: unsafe-requests-patch
patterns:
- pattern: requests.patch(...)
paths:
exclude:
- "**/security/safe_requests.py"
- "**/tests/**"
- "**/*_test.py"
- "**/test_*.py"
- "**/examples/**"
message: >-
Direct requests.patch() bypasses SSRF protection.
Use SafeSession() from security module for HTTP requests.
languages: [python]
severity: ERROR
metadata:
category: security
cwe: "CWE-918: Server-Side Request Forgery (SSRF)"
owasp: "A10:2021 - Server-Side Request Forgery"