Note
Inspiration taken from the ToB semgrep-rules repo. 💡
Clone this repository, navigate to the root folder of your project, and run individual rules using the command below :
$ semgrep --config /path/to/semgrep-rules/semgreprule.ymlRules with taint in the name make use of taint mode, and should be run with dataflow analysis enabled.
$ semgrep --config /path/to/semgrep-rules/semgreprule.yml --dataflow-tracesTo run all rules from the cloned repository:
$ semgrep --config /path/to/semgrep-rules/ .| ID | Taint | Playground | Impact | Confidence | Description |
|---|---|---|---|---|---|
| capacitor-logging-production-js.yaml | 🛝🔗 | 🟧 | 🌗 | The production flag for loggingBehavior is misleading and will produce full logs to the browser or device log. |
|
| vitejs-process-env-direct-use.yaml | 🛝🔗 | 🟥 | 🌕 | Directly passing process.env to ViteJS is dangerous as backend environment variables may be leaked into frontend JS bundles. |
|
| vitejs-process-env-direct-use-tainted.yaml | yes | 🛝🔗 | 🟥 | 🌕 | Directly passing process.env to ViteJS is dangerous as backend environment variables may be leaked into frontend JS bundles. |
| vitejs-loadenv-direct-use.yaml | 🛝🔗 | 🟥 | 🌕 | Directly passing process.env to ViteJS via an empty prefix loadEnv call matches all environment variables. This could potentially result in backend environment variables being leaked into frontend JS bundles. |
|
| vitejs-loadenv-direct-use-tainted.yaml | yes | 🛝🔗 | 🟥 | 🌕 | Directly passing process.env to ViteJS via an empty prefix loadEnv call matches all environment variables. This could potentially result in backend environment variables being leaked into frontend JS bundles. |
| nextjs-auth0.yaml | yes | 🟧 | 🌕 | Session information may be exposed within the frontend DOM via improper usage of props |
Important
Hopefully more stuff will get added later on! :)
To run tests, use either the Playground UI or local CLI ie:
$ semgrep --test --config test.yaml test.ts # for single files
