Skip to content

Rules

KAEV reports stable rule IDs with a category, severity, confidence, source location, rationale, and recommendation. Rule basis is Official for directly documented UI5 guidance, Derived for a static interpretation of documented behavior, and Heuristic for a KAEV risk pattern requiring project context. A heuristic finding is not proof of a vulnerability.

Rule Severity / basis Trigger and boundary
KAEV-PROJ-001 Info / Heuristic Insufficient evidence to identify a UI5 project. Scores are unavailable; run from an individual UI5 root.
KAEV-CONFIG-001 High / Derived A project manifest cannot be parsed or read. Fix it before trusting dependent checks.
KAEV-CONFIG-002 Medium / Derived Expected ui5.yaml is missing or malformed for a tooling project. Manifest-less legacy projects without UI5 CLI evidence are not forced to provide it.
KAEV-CONFIG-003 Medium / Official UI5 configuration lacks a specification/type or uses an inconsistent component specification. This is a partial check, not full UI5 CLI schema validation.
Rule Severity / basis Trigger and boundary
KAEV-UI5-001 Medium / Official Selected sap.m interactive controls lack IDs in a flexibility-enabled freestyle application. Other controls and template semantics may require review.
KAEV-I18N-001 Low / Heuristic Static text on selected sap.m controls in XML views/fragments. Bindings, empty text, numbers, and icon URIs are excluded.
KAEV-UI5-002 Low / Official Direct sap.ui.getCore() call. This is conservatively scored modernization guidance; prefer scoped APIs or imported modules where appropriate.

The localization rule ignores bindings, empty values, numbers, and icon URIs. Global Core access is a modernization signal, not a claim that every use is deprecated or defective.

Rule Severity / basis Trigger and boundary
KAEV-ODATA-001 Medium / Derived JavaScript .filter() on a locally traced OData V2/V4 collection. Small intentional local datasets are valid exceptions; binding-level filters are not reported.
KAEV-ODATA-002 Medium / Derived JavaScript .sort() on a locally traced OData V2/V4 collection. Binding sorters are not reported.
KAEV-ODATA-003 Medium / Heuristic A proven OData model receives a literal setSizeLimit above 10,000. This does not itself prove that all data is fetched.
KAEV-ARCH-001 Medium / Derived fetch, jQuery AJAX, or XHR directly targets a configured or recognizable OData URL. Intentional low-level networking may be legitimate.
KAEV-ARCH-002 Low / Heuristic innerHTML/outerHTML assignment in controller or component source. Custom rendering can be intentional; stronger security findings take precedence at the same location.
KAEV-PERF-001 Medium / Heuristic A proven OData model is refreshed inside a syntactic loop. Indirect loop helpers are outside the local analysis.
KAEV-SEC-010 High / Derived $.ajax/jQuery.ajax with async: false, XHR open(..., false), or proven legacy/V2 OData read(..., {async:false}). Unrelated same-name APIs are excluded.
KAEV-LEAK-001 Medium / Derived EventBus/router subscription in onInit lacks a matching receiver, event, handler, and context cleanup in onExit, or uses an unstable bound handler. Indirect/base-class cleanup is not traced.
KAEV-LEAK-002 Medium / Derived A controller stores setInterval on this without clearing the same property in onExit. Self-terminating timeouts are intentionally not reported.

Lifecycle rules compare the receiver, handler, and arguments that can be resolved locally. Cleanup performed indirectly or by a base class may require manual review. Timer analysis intentionally focuses on repeating intervals rather than treating every timeout as a leak.

Rule Severity / basis Trigger and boundary
KAEV-SEC-001 Critical / Heuristic Credential-shaped literal assigned to a sensitive name, bearer token, private-key marker, or structured JSON credential. Placeholders and names alone do not suffice; evidence is redacted.
KAEV-SEC-002 High / Heuristic Sensitive key written to localStorage or sessionStorage. Ordinary preferences are excluded.
KAEV-SEC-003 High / Heuristic Dynamic DOM HTML assignment or UI5 HTML content without explicit sanitization. Trusted or previously sanitized data can be a valid exception.
KAEV-SEC-004 High / Derived eval or new Function dynamic execution. Replace code strings with explicit functions or data parsing.
KAEV-SEC-005 High / Heuristic Non-loopback HTTP backend endpoint in source or structured configuration. Local development endpoints are excluded.
KAEV-SEC-006 High / Heuristic Sensitive identifier passed to supported console/UI5 logging APIs. This is local identifier analysis, not full taint tracking.
KAEV-SEC-007 High / Heuristic Role/permission logic controls UI5 visibility or enablement. Verify backend authorization independently; frontend evidence cannot prove it is missing.
KAEV-SEC-008 High / Derived Direct POST/PUT/PATCH/DELETE to a recognizable OData endpoint. Review CSRF lifecycle and backend authorization; this is not a confirmed exploit.

UI5-LINTER represents findings returned by the bundled official analyzer. Individual IDs are emitted as UI5LINT/<original-rule-id>, classified as modernization, and scored conservatively. The adapter runs only for applicable application roots with a manifest; legacy manifest-less projects remain analyzable with native KAEV rules. It runs in an isolated, read-only child process with filesystem permissions and offline guards. Use --no-ui5-lint only when partial coverage is intentional.

Run kaev explain <rule-id> for the metadata and recommendation shipped with the installed KAEV version.

Rules can be limited by framework, project type, app type, language, OData version, backend, deployment, UI5 version, UI5 specification, and flexibility evidence. A rule that does not apply is reported as N/A, not as a pass. Requested category filtering produces SKIPPED; an analyzer that cannot complete safely produces UNAVAILABLE.

KAEV deduplicates identical findings and suppresses weaker architecture findings when a stronger security finding establishes the same location. Results are sorted deterministically by severity, category, file, line, rule ID, and column.