{"object":"code_ruleset","ruleset_version":"2026.07.16","updated":"2026-07-16","object_scanned":"application source code / unified git-diff (CWE Top-25 logic bugs)","cwe_catalog":{"CWE-89":"SQL Injection","CWE-78":"OS Command Injection","CWE-94":"Code Injection (eval/exec)","CWE-1336":"Server-Side Template Injection","CWE-79":"Cross-Site Scripting (XSS)","CWE-918":"Server-Side Request Forgery (SSRF)","CWE-22":"Path Traversal","CWE-502":"Insecure Deserialization","CWE-327":"Weak / Broken Cryptography","CWE-330":"Insecure Randomness","CWE-601":"Open Redirect","CWE-611":"XML External Entity (XXE)"},"cwe_total":12,"dimensions":["injection","xss","ssrf","path_traversal","insecure_deserialization","weak_crypto","insecure_random","open_redirect","xxe"],"signals_total":12,"rules_total":73,"rules_by_dimension":{"injection":31,"xss":7,"ssrf":5,"path_traversal":5,"insecure_deserialization":8,"weak_crypto":7,"insecure_random":4,"open_redirect":3,"xxe":3},"rules_by_language":{"python":26,"javascript":18,"java":11,"go":5,"php":8,"ruby":5},"languages":["python","javascript","java","go","php","ruby"],"verdicts":["pass","caution","block"],"verdict_thresholds":{"block":"any critical/high finding","caution":"any medium finding","pass":"no findings above low"},"fp_suppression":{"test_fixture_downgrade":true,"inline_suppression_markers":["nosec","noqa: s","noqa:s","codeql[","codeql-ignore","semgrep-ignore","nosemgrep","sast-ignore","security-ignore"],"parameterized_query_recognition":true,"security_context_gate":["insecure_random"]},"output_modes":["diff","files","inspect"],"limits":{"max_files":100,"max_text_bytes":262144,"max_findings":500,"max_line_len":2000},"provenance":"Our own clean-room detectors informed by PUBLIC taxonomies (MITRE CWE Top-25, OWASP Top-10 / cheat-sheets). No third-party rule file (Semgrep, CodeQL, Bandit) is imported or vendored; every regex is authored here. Lightweight stdlib re — no Semgrep/CodeQL binary, no subprocess, no network.","disclaimer":"Automated static security indicators, NOT a guarantee. Deterministic pattern analysis of the code YOU supply; it does NOT execute or dataflow-trace the code, so it can miss real bugs (false negatives) and flag safe code (false positives). A clean verdict is not proof the code is secure — always review before relying on it.","note":"Freshness = a data update of the pattern registry (no live daemon). The paid /code/scan and /code/inspect routes match against this ruleset."}