Skip to content
Draft
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
138 changes: 138 additions & 0 deletions docs/security/semgrep-triage.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,138 @@
# Triagem Semgrep — flext-sh/flext-core

Gerado do dump da plataforma Semgrep (deployment `datacosmos`, 2026-08-06).

Bead: `mro-p57t.5`

## Resumo

**6 findings** — high 1, medium 5, low 0
Confiança: high 4, medium 0, low 2

| regra | achados |
|---|---|
| `package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown` | 3 |
| `python.lang.compatibility.python37.python37-compatibility-importlib2` | 1 |
| `package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown` | 1 |
| `python.lang.security.audit.non-literal-import.non-literal-import` | 1 |

## Como usar

Cada finding traz a **mensagem completa da regra** (o Semgrep descreve o problema e frequentemente o fix), o **código real** (linha `>>>`), classe de vulnerabilidade, CWE/OWASP.
**Decisão**: `corrigir` / `falso-positivo` (`nosemgrep` ou `.semgrepignore` com justificativa) / `risco-aceito`. Priorizar high com confidence=high.

## Findings

### 1 · 🟠 HIGH · conf low · `python.lang.compatibility.python37.python37-compatibility-importlib2`
**Classe**: - · **Local**: `src/flext_core/_constants/_enforcement_data/__init__.py:9`

> Found 'importlib.resources', which is a module only available on Python 3.7+. This does not work in lower versions, and therefore is not backwards compatible. Use importlib_resources instead for older Python versions.

```python
5 """
6
7 from __future__ import annotations
8
>>> 9 import importlib.resources
10 from typing import TYPE_CHECKING, Final
11
12 from pydantic import BaseModel, Field
13
```

**Decisão**:

### 2 · 🟡 MEDIUM · conf high · `package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown`
**Classe**: Insecure Configuration · **Local**: `.github/dependabot.yml:4`

> This Dependabot configuration does not set a cooldown period. Newly published packages can be malicious or unstable. Add a `cooldown` block with `default-days: 7` to each `package-ecosystem` entry under `updates` to wait 7 days before proposing updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-option

```yaml
1 # Generated by `flext-infra codegen conform` for flext-core — DO NOT EDIT.
2 version: 2
3 updates:
>>> 4 - package-ecosystem: github-actions
5 directory: /
6 schedule:
7 interval: weekly
8 open-pull-requests-limit: 5
```

**Decisão**:

### 3 · 🟡 MEDIUM · conf high · `package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown`
**Classe**: Insecure Configuration · **Local**: `.github/dependabot.yml:11`

> This Dependabot configuration does not set a cooldown period. Newly published packages can be malicious or unstable. Add a `cooldown` block with `default-days: 7` to each `package-ecosystem` entry under `updates` to wait 7 days before proposing updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-option

```yaml
7 interval: weekly
8 open-pull-requests-limit: 5
9 labels: [dependencies, github-actions]
10
>>> 11 - package-ecosystem: devcontainers
12 directory: /
13 schedule:
14 interval: weekly
15 open-pull-requests-limit: 5
```

**Decisão**:

### 4 · 🟡 MEDIUM · conf high · `package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown`
**Classe**: Insecure Configuration · **Local**: `.github/dependabot.yml:18`

> This Dependabot configuration does not set a cooldown period. Newly published packages can be malicious or unstable. Add a `cooldown` block with `default-days: 7` to each `package-ecosystem` entry under `updates` to wait 7 days before proposing updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-option

```yaml
14 interval: weekly
15 open-pull-requests-limit: 5
16 labels: [dependencies, devcontainers]
17
>>> 18 - package-ecosystem: pip
19 directory: /
20 schedule:
21 interval: weekly
22 open-pull-requests-limit: 5
```

**Decisão**:

### 5 · 🟡 MEDIUM · conf high · `package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown`
**Classe**: Insecure Configuration · **Local**: `pyproject.toml:632`

> This pyproject.toml configures uv but does not set a dependency cooldown. Newly published packages can be malicious or unstable. Add `exclude-newer = "7 days"` under `[tool.uv]` to wait 7 days before resolving newly published package versions. Added in: 0.9.17 Reference: https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns

```toml
628 all = true
629 in_place = true
630 sort_first = ["build-system", "dependency-groups", "project", "tool"]
631
>>> 632 [tool.uv]
633 link-mode = "copy"
634
635 [[tool.uv.exclude-dependencies]]
636 dependencies = ["flext-core"]
```

**Decisão**:

### 6 · 🟡 MEDIUM · conf low · `python.lang.security.audit.non-literal-import.non-literal-import`
**Classe**: Improper Authorization · **Local**: `src/flext_core/_utilities/_beartype/_helpers_parts/helpers_part_01.py:31`

> Untrusted user input in `importlib.import_module()` function allows an attacker to load arbitrary code. Avoid dynamic values in `importlib.import_module()` or use a whitelist to prevent running untrusted code.

```python
27 """Return ``(alias, module_path, suffix)`` rows from package ``_LAZY_IMPORTS``."""
28 package = sys.modules.get(package_name)
29 if package is None:
30 try:
>>> 31 package = importlib.import_module(package_name)
32 except (ImportError, ModuleNotFoundError):
33 return ()
34 if not hasattr(package, "_LAZY_IMPORTS"):
35 return ()
```

**Decisão**:

Loading