Rules
KAEV reports stable rule IDs with a category, severity, confidence, source location, rationale, and recommendation. Rule basis is Official for directly documented UI5 guidance, Derived for a static interpretation of documented behavior, and Heuristic for a KAEV risk pattern requiring project context. A heuristic finding is not proof of a vulnerability.
Project and configuration
Section titled “Project and configuration”| Rule | Severity / basis | Trigger and boundary |
|---|---|---|
KAEV-PROJ-001 |
Info / Heuristic | Insufficient evidence to identify a UI5 project. Scores are unavailable; run from an individual UI5 root. |
KAEV-CONFIG-001 |
High / Derived | A project manifest cannot be parsed or read. Fix it before trusting dependent checks. |
KAEV-CONFIG-002 |
Medium / Derived | Expected ui5.yaml is missing or malformed for a tooling project. Manifest-less legacy projects without UI5 CLI evidence are not forced to provide it. |
KAEV-CONFIG-003 |
Medium / Official | UI5 configuration lacks a specification/type or uses an inconsistent component specification. This is a partial check, not full UI5 CLI schema validation. |
| Rule | Severity / basis | Trigger and boundary |
|---|---|---|
KAEV-UI5-001 |
Medium / Official | Selected sap.m interactive controls lack IDs in a flexibility-enabled freestyle application. Other controls and template semantics may require review. |
KAEV-I18N-001 |
Low / Heuristic | Static text on selected sap.m controls in XML views/fragments. Bindings, empty text, numbers, and icon URIs are excluded. |
KAEV-UI5-002 |
Low / Official | Direct sap.ui.getCore() call. This is conservatively scored modernization guidance; prefer scoped APIs or imported modules where appropriate. |
The localization rule ignores bindings, empty values, numbers, and icon URIs. Global Core access is a modernization signal, not a claim that every use is deprecated or defective.
OData, architecture, and performance
Section titled “OData, architecture, and performance”| Rule | Severity / basis | Trigger and boundary |
|---|---|---|
KAEV-ODATA-001 |
Medium / Derived | JavaScript .filter() on a locally traced OData V2/V4 collection. Small intentional local datasets are valid exceptions; binding-level filters are not reported. |
KAEV-ODATA-002 |
Medium / Derived | JavaScript .sort() on a locally traced OData V2/V4 collection. Binding sorters are not reported. |
KAEV-ODATA-003 |
Medium / Heuristic | A proven OData model receives a literal setSizeLimit above 10,000. This does not itself prove that all data is fetched. |
KAEV-ARCH-001 |
Medium / Derived | fetch, jQuery AJAX, or XHR directly targets a configured or recognizable OData URL. Intentional low-level networking may be legitimate. |
KAEV-ARCH-002 |
Low / Heuristic | innerHTML/outerHTML assignment in controller or component source. Custom rendering can be intentional; stronger security findings take precedence at the same location. |
KAEV-PERF-001 |
Medium / Heuristic | A proven OData model is refreshed inside a syntactic loop. Indirect loop helpers are outside the local analysis. |
KAEV-SEC-010 |
High / Derived | $.ajax/jQuery.ajax with async: false, XHR open(..., false), or proven legacy/V2 OData read(..., {async:false}). Unrelated same-name APIs are excluded. |
KAEV-LEAK-001 |
Medium / Derived | EventBus/router subscription in onInit lacks a matching receiver, event, handler, and context cleanup in onExit, or uses an unstable bound handler. Indirect/base-class cleanup is not traced. |
KAEV-LEAK-002 |
Medium / Derived | A controller stores setInterval on this without clearing the same property in onExit. Self-terminating timeouts are intentionally not reported. |
Lifecycle rules compare the receiver, handler, and arguments that can be resolved locally. Cleanup performed indirectly or by a base class may require manual review. Timer analysis intentionally focuses on repeating intervals rather than treating every timeout as a leak.
Security
Section titled “Security”| Rule | Severity / basis | Trigger and boundary |
|---|---|---|
KAEV-SEC-001 |
Critical / Heuristic | Credential-shaped literal assigned to a sensitive name, bearer token, private-key marker, or structured JSON credential. Placeholders and names alone do not suffice; evidence is redacted. |
KAEV-SEC-002 |
High / Heuristic | Sensitive key written to localStorage or sessionStorage. Ordinary preferences are excluded. |
KAEV-SEC-003 |
High / Heuristic | Dynamic DOM HTML assignment or UI5 HTML content without explicit sanitization. Trusted or previously sanitized data can be a valid exception. |
KAEV-SEC-004 |
High / Derived | eval or new Function dynamic execution. Replace code strings with explicit functions or data parsing. |
KAEV-SEC-005 |
High / Heuristic | Non-loopback HTTP backend endpoint in source or structured configuration. Local development endpoints are excluded. |
KAEV-SEC-006 |
High / Heuristic | Sensitive identifier passed to supported console/UI5 logging APIs. This is local identifier analysis, not full taint tracking. |
KAEV-SEC-007 |
High / Heuristic | Role/permission logic controls UI5 visibility or enablement. Verify backend authorization independently; frontend evidence cannot prove it is missing. |
KAEV-SEC-008 |
High / Derived | Direct POST/PUT/PATCH/DELETE to a recognizable OData endpoint. Review CSRF lifecycle and backend authorization; this is not a confirmed exploit. |
Official UI5 Linter
Section titled “Official UI5 Linter”UI5-LINTER represents findings returned by the bundled official analyzer. Individual IDs are emitted as UI5LINT/<original-rule-id>, classified as modernization, and scored conservatively. The adapter runs only for applicable application roots with a manifest; legacy manifest-less projects remain analyzable with native KAEV rules. It runs in an isolated, read-only child process with filesystem permissions and offline guards. Use --no-ui5-lint only when partial coverage is intentional.
Run kaev explain <rule-id> for the metadata and recommendation shipped with the installed KAEV version.
Applicability and finding precedence
Section titled “Applicability and finding precedence”Rules can be limited by framework, project type, app type, language, OData version, backend, deployment, UI5 version, UI5 specification, and flexibility evidence. A rule that does not apply is reported as N/A, not as a pass. Requested category filtering produces SKIPPED; an analyzer that cannot complete safely produces UNAVAILABLE.
KAEV deduplicates identical findings and suppresses weaker architecture findings when a stronger security finding establishes the same location. Results are sorted deterministically by severity, category, file, line, rule ID, and column.