Rule-authoring structure
| Custom rule structure | Description |
|---|---|
| rules (Rules) | Rules used to identify findings |
| rule-tests (Tests) | Test files for verifying rules |
| utils | Reusable rules for authoring new rules |
Rules — rule file structure
| Field | Description |
|---|---|
| id | Unique rule identifier |
| message | Short rule title |
| description | Description of the finding |
| language | Target language |
| metadata | Additional data such as cwe, category, references, and technology |
| (metadata) severity | Severity: critical | high | medium | low | info |
| (metadata) score | Integer priority score from 0 to 100 for SAST rules. Use 70 or higher only for high-impact rules likely to identify real vulnerabilities; keep best-practice or hardening rules below 50. Not required for SCA, secrets, or internal-threat rules. |
| (metadata) fix_description | Remediation or response guidance |
| rule | The matching rule |
Rule example
This example identifies Log4j info calls. A call alone does not demonstrate a Log4j vulnerability.
yaml
id: log4j-logger-info
message: Log4j Logger info usage
description: Identify calls to Log4j Logger info.
language: Java
metadata:
category: security
severity: info
score: 35
fix_description: |-
Check whether the deployed Log4j version is affected by the security advisory.
references: https://www.cisa.gov/news-events/news/apache-log4j-vulnerability-guidance
rule:
pattern: org.apache.logging.log4j.Logger.info($$$)
Rule-tests — test file structure
| Field | Description |
|---|---|
| id | Rule identifier; not required in the web interface |
| valid | Code that should not match |
| invalid | Code that should match |
Rule test example
yaml
id: log4j-logger-info
valid:
- |
import some.other.safe.Logger;
public class VulnerableExample {
private static final Logger logger = LogManager.getLogger(VulnerableExample.class);
public void processUserInput(String userInput) {
logger.info("User input: {}", userInput);
}
}
invalid:
- |
import org.apache.logging.log4j.LogManager;
import org.apache.logging.log4j.Logger;
public class VulnerableExample {
private static final Logger logger = LogManager.getLogger(VulnerableExample.class);
public void processUserInput(String userInput) {
logger.info("User input: {}", userInput);
}
}
Utils structure
| Field | Description |
|---|---|
| id | Unique utility rule identifier |
| language | Target language |
| rule | The matching rule |
Utility example
yaml
id: detect-bad-class
language: Java
rule:
pattern: new BadClass($_N, "BadKey")
Using the utility in a rule:
yaml
id: bad-class-usage
message: BadClass construction
description: Identify object construction matched by the detect-bad-class utility.
language: Java
metadata:
severity: info
rule:
matches: detect-bad-class