diff --git a/docs/security/semgrep-triage.md b/docs/security/semgrep-triage.md new file mode 100644 index 000000000..eb8e706f0 --- /dev/null +++ b/docs/security/semgrep-triage.md @@ -0,0 +1,138 @@ +# Triagem Semgrep — flext-sh/flext-core + +Gerado do dump da plataforma Semgrep (deployment `datacosmos`, 2026-08-06). + +Bead: `mro-p57t.5` + +## Resumo + +**6 findings** — high 1, medium 5, low 0 +Confiança: high 4, medium 0, low 2 + +| regra | achados | +|---|---| +| `package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown` | 3 | +| `python.lang.compatibility.python37.python37-compatibility-importlib2` | 1 | +| `package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown` | 1 | +| `python.lang.security.audit.non-literal-import.non-literal-import` | 1 | + +## Como usar + +Cada finding traz a **mensagem completa da regra** (o Semgrep descreve o problema e frequentemente o fix), o **código real** (linha `>>>`), classe de vulnerabilidade, CWE/OWASP. +**Decisão**: `corrigir` / `falso-positivo` (`nosemgrep` ou `.semgrepignore` com justificativa) / `risco-aceito`. Priorizar high com confidence=high. + +## Findings + +### 1 · 🟠 HIGH · conf low · `python.lang.compatibility.python37.python37-compatibility-importlib2` +**Classe**: - · **Local**: `src/flext_core/_constants/_enforcement_data/__init__.py:9` + +> Found 'importlib.resources', which is a module only available on Python 3.7+. This does not work in lower versions, and therefore is not backwards compatible. Use importlib_resources instead for older Python versions. + +```python + 5 """ + 6 + 7 from __future__ import annotations + 8 +>>> 9 import importlib.resources + 10 from typing import TYPE_CHECKING, Final + 11 + 12 from pydantic import BaseModel, Field + 13 +``` + +**Decisão**: + +### 2 · 🟡 MEDIUM · conf high · `package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown` +**Classe**: Insecure Configuration · **Local**: `.github/dependabot.yml:4` + +> This Dependabot configuration does not set a cooldown period. Newly published packages can be malicious or unstable. Add a `cooldown` block with `default-days: 7` to each `package-ecosystem` entry under `updates` to wait 7 days before proposing updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-option + +```yaml + 1 # Generated by `flext-infra codegen conform` for flext-core — DO NOT EDIT. + 2 version: 2 + 3 updates: +>>> 4 - package-ecosystem: github-actions + 5 directory: / + 6 schedule: + 7 interval: weekly + 8 open-pull-requests-limit: 5 +``` + +**Decisão**: + +### 3 · 🟡 MEDIUM · conf high · `package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown` +**Classe**: Insecure Configuration · **Local**: `.github/dependabot.yml:11` + +> This Dependabot configuration does not set a cooldown period. Newly published packages can be malicious or unstable. Add a `cooldown` block with `default-days: 7` to each `package-ecosystem` entry under `updates` to wait 7 days before proposing updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-option + +```yaml + 7 interval: weekly + 8 open-pull-requests-limit: 5 + 9 labels: [dependencies, github-actions] + 10 +>>> 11 - package-ecosystem: devcontainers + 12 directory: / + 13 schedule: + 14 interval: weekly + 15 open-pull-requests-limit: 5 +``` + +**Decisão**: + +### 4 · 🟡 MEDIUM · conf high · `package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown` +**Classe**: Insecure Configuration · **Local**: `.github/dependabot.yml:18` + +> This Dependabot configuration does not set a cooldown period. Newly published packages can be malicious or unstable. Add a `cooldown` block with `default-days: 7` to each `package-ecosystem` entry under `updates` to wait 7 days before proposing updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-option + +```yaml + 14 interval: weekly + 15 open-pull-requests-limit: 5 + 16 labels: [dependencies, devcontainers] + 17 +>>> 18 - package-ecosystem: pip + 19 directory: / + 20 schedule: + 21 interval: weekly + 22 open-pull-requests-limit: 5 +``` + +**Decisão**: + +### 5 · 🟡 MEDIUM · conf high · `package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown` +**Classe**: Insecure Configuration · **Local**: `pyproject.toml:632` + +> This pyproject.toml configures uv but does not set a dependency cooldown. Newly published packages can be malicious or unstable. Add `exclude-newer = "7 days"` under `[tool.uv]` to wait 7 days before resolving newly published package versions. Added in: 0.9.17 Reference: https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns + +```toml + 628 all = true + 629 in_place = true + 630 sort_first = ["build-system", "dependency-groups", "project", "tool"] + 631 +>>> 632 [tool.uv] + 633 link-mode = "copy" + 634 + 635 [[tool.uv.exclude-dependencies]] + 636 dependencies = ["flext-core"] +``` + +**Decisão**: + +### 6 · 🟡 MEDIUM · conf low · `python.lang.security.audit.non-literal-import.non-literal-import` +**Classe**: Improper Authorization · **Local**: `src/flext_core/_utilities/_beartype/_helpers_parts/helpers_part_01.py:31` + +> Untrusted user input in `importlib.import_module()` function allows an attacker to load arbitrary code. Avoid dynamic values in `importlib.import_module()` or use a whitelist to prevent running untrusted code. + +```python + 27 """Return ``(alias, module_path, suffix)`` rows from package ``_LAZY_IMPORTS``.""" + 28 package = sys.modules.get(package_name) + 29 if package is None: + 30 try: +>>> 31 package = importlib.import_module(package_name) + 32 except (ImportError, ModuleNotFoundError): + 33 return () + 34 if not hasattr(package, "_LAZY_IMPORTS"): + 35 return () +``` + +**Decisão**: +