- Add organizing rules (language/domain structure, naming, metadata) - Require all rules to fail CI (severity: ERROR, no warn-only) - Move unbounded-memory.yml to python/reliability/ per structure - Enhance unbounded-memory rule metadata (tags, confidence, source)
14 lines
508 B
YAML
14 lines
508 B
YAML
# Unbounded memory growth – data structures without a clear max limit
|
||
# Can lead to OOM under load.
|
||
|
||
rules:
|
||
- id: unbounded-asyncio-queue
|
||
message: asyncio.Queue() with no maxsize can grow unbounded. Use asyncio.Queue(maxsize=N) for integrations (e.g. log queues).
|
||
severity: ERROR
|
||
languages: [python]
|
||
pattern-either:
|
||
- pattern: asyncio.Queue()
|
||
- pattern: asyncio.Queue(maxsize=0)
|
||
metadata:
|
||
category: correctness
|
||
cwe: "CWE-400: Uncontrolled Resource Consumption" |