PluginBench
Rule
Always applies

security devsecops ssdls appsec

via PatrickJS/awesome-cursorrules

Secure coding, secret handling, dependency hygiene, and compliance for DevSecOps and SSDLC.

What is security devsecops ssdls appsec?

This rule enforces secure development practices across multiple languages, covering secret management, input validation, dependency security, authentication, and compliance. Use it to embed security guardrails into your coding workflow and reduce vulnerabilities before deployment.

  • Prohibit hardcoded secrets and enforce environment variables or secure vaults for sensitive data
  • Require parameterized queries and ORM patterns to prevent SQL injection
  • Enforce strong password hashing (Argon2, bcrypt) and Role-Based Access Control (RBAC)
  • Mandate SAST, SCA, and secret scanning in CI/CD pipelines
  • Validate and sanitize all user input; block unsafe functions like eval and exec
  • Require least-privilege database and API access policies with regular review

Applies to

Always applied, in addition to these file patterns.

["**/*.py"
**/*.js
**/*.ts
**/*.go
**/*.java
**/*.rb
**/*.php
**/*.cs
"**/*.sh"]
Rule definition (reference)

Source of truth, from the repository.

DevSecOps + SSDLC + AppSec Cursor Rule

General Security Principles

  • Never hardcode secrets, credentials, or API keys. Use environment variables or secure vaults for sensitive data.
  • Prohibit the inclusion of .env, secret config files, or unknown tokens in source control.
  • Never log sensitive data, secrets, or session tokens in application logs.
  • Validate and sanitize all user input. Escape output in HTML, JS, and SQL contexts.
  • Avoid unsafe functions such as exec, eval, or similar dynamic code execution.

Database Security

  • Use parameterized queries or ORM for all database access. Do not use string concatenation for query building.
  • Ensure database users have the least privilege required for their tasks.
  • Regularly review and update database access policies.

Dependency Management

  • Only use packages from verified sources.
  • Do not add new dependencies without explicit approval and security review.
  • Regularly update dependencies and scan for known vulnerabilities (SCA).

Authentication & Authorization

  • Use secure authentication frameworks; never implement custom authentication.
  • Store passwords using strong, salted hashes (e.g., Argon2, bcrypt).
  • Implement Role-Based Access Control (RBAC) for sensitive operations.
  • Enforce the principle of least privilege for APIs and UI actions.

Secure SDLC Practices

  • Integrate Static Application Security Testing (SAST) and Software Composition Analysis (SCA) into the CI pipeline.
  • Scan all code for secrets before merging (Secret Scanning).
  • Use Infrastructure as Code (IaC) scanning for all infrastructure code.
  • Integrate Dynamic Application Security Testing (DAST) in the CD pipeline for deployed applications.
  • Enforce Policy as Code (PaC) for automated, version-controlled security policies.

Monitoring & Feedback

  • Enable continuous vulnerability monitoring and alerting.
  • Integrate Runtime Application Self-Protection (RASP) and Web Application Firewall (WAF) as appropriate.
  • Encourage regular vulnerability assessments and penetration testing.
  • Maintain a feedback loop to update rules and prompts based on recurring vulnerabilities.

Compliance & Documentation

  • Align with industry standards (e.g., OWASP Top 10, NIST, ISO 27001).
  • Document all security controls and decisions for auditability.

Related rules

30+ chart types for React with AI-assisted generation, real-time streaming, and geographic visualization.

**/*
41k
via PatrickJS/awesome-cursorrules

Best practices for Shopify Liquid theme development with structured project organization, performance optimization, and accessibility.

["**/*.liquid" +5
41k
via PatrickJS/awesome-cursorrules

SQL-callable AI functions and hybrid vector+keyword search for RAG within Snowflake.

**/*
41k
via PatrickJS/awesome-cursorrules

Expert guidance for Snowflake SQL, data pipelines, semi-structured data, and cost optimization.

**/*
41k
via PatrickJS/awesome-cursorrules

Expert guidance for Snowpark Python and dbt with Snowflake adapter.

**/*
41k
via PatrickJS/awesome-cursorrules

Secure Solana wallet architecture with MEV defense, signer isolation, and transaction safety checks.

**/*.{ts +5
41k
via PatrickJS/awesome-cursorrules