Skip to content

[New Rule] SpiceDB: Reproduce A High-Severity Failure & Write a Detection Rule #60

@Lyndon-prequel

Description

@Lyndon-prequel

Description

SpiceDB powers fine-grained access control — but subtle misconfigurations or known bugs can block critical permissions.

Your task: Reproduce a high-severity failure in a recent version of SpiceDB and write a detection rule that reliably identifies the issue in production environments.

You must:

  1. Reproduce the failure scenario.
  2. Share a minimal, working reproduction (e.g., Helm, Docker Compose, etc.).
  3. Write a CRE-format detection rule for preq.

📦 Deliverables:

  • Reproduction setup and clear README
  • PR containing
    • the new CRE rule
    • example logs in test.log.
    • changes to tags and categories
  • Link to your rule in the CRE playground.
  • Provide a short demo video of your reproduction and the changes in your pull request

Note: The first viable solution for this bounty will be accepted and the bounty will be closed

/bounty $250

Rule

No response

Related issues or PRs

No response

References

No response

Redacted Example Data

No response

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions