Configuration value is passed directly to an OS command execution function without proper escaping or validation. An attacker with configuration modification privileges could inject arbitrary commands.
The community hub for quality SASTStatic Application Security Testing rules.
Search, inspect, and fetch rules ready for coding-agent workflows.
- Indexed rules
- 4,797
- Rule fetches
- 7.4M
- Verified coverage
- 100%
+1.9K · 30d
784.6K in 7d
All rules verified
Rules worth checking first
Route-bound model is updated directly from generic Request input without explicit authorization or FormRequest validation, potentially allowing IDOR or unauthorized modifications.
271 downloads
0 direct271 via packsTop 5 authors
- 1@provally1 stars · 6.2M downloads
- 2@gitlab-security-products0 stars · 1.2M downloads
Packs and collections
Common questions
Is greprules.io a scanner?
No. greprules.io is a registry and quality layer for SAST rules. Scans still run through compatible CLI, scanner, or agent workflows.
Can public rules be fetched without signing in?
Yes. Public rules are available for browse and fetch. Sign in is for starring rules, collections, feedback, and publishing reviewed submissions.
Which languages are supported?
JS/TS and Python are the focused languages today. Other languages may appear in the registry, with early support marked in the explorer filters.
How should I judge whether a rule is ready to reuse?
Check license, source/provenance, validation status, quality score, usage signals, references, and community feedback before reuse.
Is greprules open source?
Greprules is sponsored by Provally. Local tooling, public registry surfaces, schemas, manifests, and project docs are open-source oriented; hosted operations are run by Provally.