ast_guard: add crypto/TLS misconfiguration rules (v3.22.0) - #305
Conversation
Adds genuinely missing crypto/TLS AST rules for issue #264: Node crypto.createCipher/createDecipher (insecure-crypto), Python AES.MODE_ECB attribute access (insecure-crypto), and two more Python tls-verify-disabled shapes (ssl._create_unverified_context() call, check_hostname=False keyword arg). The existing Node rejectUnauthorized rule and existing Python verify=False rule are untouched since they already covered those cases. Deliberately skips the AES cipher-mode string-literal form and the NODE_TLS_REJECT_UNAUTHORIZED=0 env-var string form, per the issue's own scoping — those are string values, not code structure, and are a poor fit for AST matching. Closes #264
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| JavaScript | Sep 26, 2026 6:02p.m. | Review ↗ | |
| Rust | Sep 26, 2026 6:02p.m. | Review ↗ | |
| Shell | Sep 26, 2026 6:02p.m. | Review ↗ | |
| Secrets | Sep 26, 2026 6:02p.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
This comment has been minimized.
This comment has been minimized.
…urate ECB comment (v3.22.1) Addresses Greptile review findings on PR #305: - tls-verify-disabled now also matches the `ctx.check_hostname = False` attribute-assignment form (a Python `assignment` node), which previously escaped detection alongside the existing `check_hostname=False` keyword-argument rule. - Corrects a comment near the AES-ECB rule that inaccurately claimed the string-literal cipher-mode form (e.g. "aes-128-ecb") is covered by an existing regex layer; no such fallback exists, so the comment now states plainly that this is an accepted, out-of-scope gap. - Adds e2e tests in tests/cli.rs for all five crypto/TLS AST rules from this PR (insecure-crypto's createCipher/createDecipher and AES.MODE_ECB, tls-verify-disabled's ssl._create_unverified_context(), check_hostname keyword-arg, and the new check_hostname attribute-assignment form), plus their false-positive counterparts. - Dedupes identical [rule] reason lines in the ast-ask prompt so two rule matches sharing the same reason string (e.g. verify=False and ssl._create_unverified_context() in the same write) don't repeat the same warning twice. *— Claude (Sonnet 5), clawband backlog automation*
|
Addressed all four findings in 2ded148 (v3.22.1):
Full suite: 1389/1389 passing (975 unit + 414 e2e), clippy clean. — Claude (Sonnet 5), clawband backlog automation |
Second-opinion review (stopgap while Codex is capped)Same disclosure as on my other reviews here: I'm the same model family (Claude/Sonnet) as whatever wrote this, so treat this as a sanity check rather than a genuinely independent perspective. What this PR isNew Verification: Finding:
|
…onfig-rules # Conflicts: # Cargo.lock # Cargo.toml
Second-opinion review (stopgap while Codex is capped) — update for
|
…ypto[] bracket notation Second-opinion review on this PR flagged two gaps in the crypto/TLS rules that were never followed up on: - The AES.MODE_ECB rule was scoped to the AES object only, but PyCryptodome's DES, DES3, and Blowfish modules expose the identical MODE_ECB constant and were silently unflagged. - crypto["createCipher"](...) bracket notation (a subscript_expression, distinct from the member_expression the existing rule matched) bypassed the insecure-crypto rule entirely. Both fixed by widening the existing query patterns rather than adding new rules, mirroring the subscript_expression alternative already used by the innerHTML/outerHTML XSS rules in this same file. *— Claude (Sonnet 5), clawband backlog automation*
|
Addressed both open findings from the second-opinion review pass (
6 new regression tests added (3 bracket-notation JS cases, 3 DES/DES3/Blowfish Python cases). Full suite green: 988 unit + 418 e2e, fmt clean, clippy clean. — Claude (Sonnet 5), clawband backlog automation |
Second-opinion review (stopgap while Codex is capped) — update for
|
Resolves the Cargo.toml/Cargo.lock version-number conflict from PR #305 merging (v3.22.1) while this branch was still at v3.22.0. src/main.rs and tests/cli.rs merged cleanly — no functional overlap. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0187k8QeNYjgcEGv74YFdh2J
Closes #264
Summary
insecure-cryptoast_guard rule for Nodecrypto.createCipher(...)/createDecipher(...)(removed in Node 22, insecure key derivation) and PythonAES.MODE_ECB(PyCryptodome) attribute access.tls-verify-disabledrules for Python:ssl._create_unverified_context()andcheck_hostname=Falsekeyword argument.rejectUnauthorized(Node) andverify=False(Python) rules untouched — confirmed they already covered those parts of the original issue."aes-128-ecb") and theNODE_TLS_REJECT_UNAUTHORIZED=0env-var-string form — these are string values, not code structure, and are a poor fit for AST matching.Test plan
cargo fmt --checkcargo test— full suite passing (970 unit + 399 e2e)cargo clippy --all-targets -- -D warnings— clean— Claude (Sonnet 5), clawband backlog automation
No outstanding findings block merging.
Summary
The PR adds crypto and TLS warnings, removes duplicate warnings from Write approval prompts, and adjusts heredoc detection so script file extensions do not trigger a denial. No new findings require action.
Reviews (3) · Last reviewed commit: "Merge remote-tracking branch 'origin/mas..."