feat(controls): B1 — custom semgrep detectors for 4 CRA controls
CI / Check (push) Skipped
CI / Check (pull_request) Successful in 5m50s
CI / Detect Changes (pull_request) Skipped
CI / Deploy Agent (pull_request) Skipped
CI / Deploy Dashboard (pull_request) Skipped
CI / Deploy Docs (pull_request) Skipped
CI / Deploy MCP (pull_request) Skipped

Covers the pattern-expressible slice of the needs_tooling bucket that no
off-the-shelf ruleset digs out, keeping detection deterministic (LLM only
FP-filters downstream, never detects):

- cra-ai-1  Secure-by-Default: flask/django debug, TLS verify=False, CORS '*'
- cra-ai-7  Strong auth: password/secret hashed with md5/sha1 (metavar-gated)
- cra-ai-10 Session mgmt: Secure/HttpOnly = false cookies (py + express)
- cra-ai-14 Data at rest: ECB/DES/3DES + node createCipher

Rules ship in the binary (include_str!) and stage to a temp file at scan time,
added as a second --config alongside --config=auto (no deploy/volume change).

Wiring: control-map gains controls_for_finding (match by CWE and/or rule id);
custom controls bind by rule id with cwe:[] so a broad CWE can't over-attribute
and let the judge FP-drop a genuine finding. rule_id_matches tolerates semgrep's
path prefix on local check_ids. Triage now maps by rule id too (a custom finding
carries no LUT CWE). LUT: cra-ai-1,7,10,14 needs_tooling->covered (covered 9->13).

Validated: all 9 rules fire on positive fixtures, 0 on clean. ControlCheckSpec
gains Serialize/Deserialize (unrelated-safe; already used by the index cache).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Sharang Parnerkar
2026-07-21 14:21:34 +02:00
co-authored by Claude Fable 5
parent 0ef2cd1b23
commit 563d8afb2a
5 changed files with 338 additions and 44 deletions
+53 -12
View File
@@ -5,9 +5,21 @@
{
"control": "cra-ai-1",
"title": "Secure-by-Default-Konfiguration",
"scans": [],
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
"status": "needs_tooling"
"scans": [
{
"tool": "semgrep",
"scan_type": "sast",
"cwe": [],
"rules": [
"cra-ai-1-flask-debug-enabled",
"cra-ai-1-django-debug-true",
"cra-ai-1-tls-verify-disabled",
"cra-ai-1-cors-wildcard"
]
}
],
"note": null,
"status": "covered"
},
{
"control": "cra-ai-2",
@@ -47,9 +59,18 @@
{
"control": "cra-ai-7",
"title": "Starke Authentifizierung",
"scans": [],
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
"status": "needs_tooling"
"scans": [
{
"tool": "semgrep",
"scan_type": "sast",
"cwe": [],
"rules": [
"cra-ai-7-weak-password-hash"
]
}
],
"note": null,
"status": "covered"
},
{
"control": "cra-ai-8",
@@ -100,9 +121,19 @@
{
"control": "cra-ai-10",
"title": "Sitzungsmanagement",
"scans": [],
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
"status": "needs_tooling"
"scans": [
{
"tool": "semgrep",
"scan_type": "sast",
"cwe": [],
"rules": [
"cra-ai-10-session-cookie-insecure",
"cra-ai-10-express-cookie-insecure"
]
}
],
"note": null,
"status": "covered"
},
{
"control": "cra-ai-11",
@@ -138,9 +169,19 @@
{
"control": "cra-ai-14",
"title": "Speicher-Schutz (Data at Rest)",
"scans": [],
"note": "code-checkable but no off-the-shelf tool digs it out — author a detector (custom semgrep rule / check)",
"status": "needs_tooling"
"scans": [
{
"tool": "semgrep",
"scan_type": "sast",
"cwe": [],
"rules": [
"cra-ai-14-python-weak-cipher",
"cra-ai-14-node-weak-cipher"
]
}
],
"note": null,
"status": "covered"
},
{
"control": "cra-ai-15",
+69 -3
View File
@@ -66,6 +66,14 @@ pub struct ControlMap {
const CRA_MAP_JSON: &str = include_str!("../data/cra_control_map.json");
/// Whether an authored rule id `bound` matches a scanner's emitted rule id
/// `actual`. semgrep prefixes local-rule check_ids with a path
/// (`tmp.compliance-cra-semgrep.cra-ai-1-flask-debug-enabled`), so match the final
/// id segment rather than requiring exact equality.
fn rule_id_matches(bound: &str, actual: &str) -> bool {
actual == bound || actual.ends_with(&format!(".{bound}"))
}
impl ControlMap {
/// Load the built-in CRA control map (the embedded, authored LUT).
pub fn cra() -> Result<Self, MapError> {
@@ -80,12 +88,28 @@ impl ControlMap {
/// Controls whose bindings include the given `tool` + `cwe` — used to attach a
/// raw tool finding back to the control(s) it's evidence for.
pub fn controls_for(&self, tool: &str, cwe: &str) -> Vec<&ControlEntry> {
self.controls_for_finding(tool, Some(cwe), None)
}
/// Controls a tool finding is evidence for, matched by CWE and/or the specific
/// rule id that fired. Off-the-shelf findings bind by CWE; our custom detectors
/// bind by rule id (precise — a broad CWE would over-attribute and then the
/// grounded judge could drop a genuine finding as a control false positive).
pub fn controls_for_finding(
&self,
tool: &str,
cwe: Option<&str>,
rule_id: Option<&str>,
) -> Vec<&ControlEntry> {
self.controls
.iter()
.filter(|c| {
c.scans
.iter()
.any(|s| s.tool == tool && s.cwe.iter().any(|w| w == cwe))
c.scans.iter().any(|s| {
s.tool == tool
&& (cwe.is_some_and(|w| s.cwe.iter().any(|x| x == w))
|| rule_id
.is_some_and(|r| s.rules.iter().any(|b| rule_id_matches(b, r))))
})
})
.collect()
}
@@ -160,4 +184,46 @@ mod tests {
assert!(s.needs_tooling > 0);
assert!(s.not_code_checkable > 0);
}
#[test]
fn rule_id_matching_handles_semgrep_path_prefix() {
let bound = "cra-ai-1-flask-debug-enabled";
assert!(rule_id_matches(bound, bound)); // exact
assert!(rule_id_matches(
bound,
"tmp.compliance-cra-semgrep.cra-ai-1-flask-debug-enabled"
)); // semgrep path prefix
assert!(!rule_id_matches(
bound,
"cra-ai-1-flask-debug-enabled-extra"
)); // not a suffix segment
assert!(!rule_id_matches(
bound,
"python.lang.security.exec-detected"
)); // unrelated
}
#[test]
fn custom_rule_finding_attaches_to_control_by_rule_id() {
let map = ControlMap::cra().unwrap();
// cra-ai-1 is now tool-covered by custom rules.
assert_eq!(map.coverage("cra-ai-1").unwrap().status, Coverage::Covered);
// A prefixed check_id still maps back to cra-ai-1 by rule id.
let hits =
map.controls_for_finding("semgrep", None, Some("tmp.x.cra-ai-1-tls-verify-disabled"));
assert!(hits.iter().any(|c| c.control == "cra-ai-1"));
}
#[test]
fn custom_rule_controls_do_not_bind_by_broad_cwe() {
let map = ControlMap::cra().unwrap();
// cra-ai-1 rules emit CWE-489 in metadata, but the LUT binds by rule id
// only (cwe: []) — so a stray CWE-489 finding must NOT attach to it.
assert!(map.controls_for("semgrep", "CWE-489").is_empty());
// The CWE path for off-the-shelf findings is unchanged.
assert!(map
.controls_for("semgrep", "CWE-798")
.iter()
.any(|c| c.control == "cra-ai-8"));
}
}