Releases: lucashgrifoni/AppSec-Rules-Pack
Release list
AppSec Rules Pack - v0.6.0
AppSec Rules Pack v0.6.0
This minor release adds a password-storage rule, refines the configuration and secrets rules, and records why each baseline rule maps to its ASVS and SSDF entries, with corrected SSDF mappings where the old ones did not match the practice. It also documents how to gate on review records, proposes the 1.0 contract freeze, and gives the release SBOM a verified root component. The baseline grows from 19 to 20 rules.
Install
pip install "appsec-rules-pack==0.6.0"
curl -LO https://github.com/lucashgrifoni/AppSec-Rules-Pack/releases/download/v0.6.0/appsec-baseline.yaml
appsec-rules validate appsec-baseline.yaml --require-examples --fail-on-warningsHighlights
- New rule
APPSEC-PWSTORE-001: store passwords with Argon2id, scrypt, bcrypt, or PBKDF2 and a per-password salt, never a fast hash. It maps to OWASP ASVS 5.0.0 V11.4 (requirement 11.4.2), OWASP Top 10:2025 A04, CWE-916 and CWE-759, and NIST SSDF PW.5. The gap came from the first realreviewrun, against a deliberately vulnerable lab application that stored passwords as unsalted MD5. docs/mapping-rationale.mdjustifies every ASVS and SSDF mapping of the 20 rules with primary sources. SSDF mappings now follow the subject of each rule at practice level (ADR-0008). Rules that pointed at PW.7, PW.8, PW.9, or RV.1 for coding topics, such as input validation, injection, XSS, and logging, now map to PW.5 or PW.1. A test checks every ASVS ID against the ASVS 5.0.0 release tag.docs/v1-readiness.mdproposes what freezes at 1.0, the migration and deprecation policy, and the acceptance criteria. Saved v1 report fixtures make existing JSON fields and types a compatibility floor.
Improvements
APPSEC-CONFIG-001covers CORS: a fixed list of trusted origins, never the reflected Origin with credentials (ASVS V3.4, CWE-942).APPSEC-SECRETS-001rules out hard-coded default or fallback values for secrets.- The review documentation explains that the 20 baseline rules are
advisory, so a gate should usesummary.open_by_severityor a fork with raisedenforcement, and thatevidenceon anot-metresult points to the failure. - The landing page describes pack validation and review records, and a test keeps its figures in line with the repository.
Fixes
- Removed
API5:2023fromAPPSEC-AUTHZ-001, whose subject is object-level authorization (API1:2023).
Security
- The release SBOM now has a root component (
pkg:pypi/appsec-rules-pack@0.6.0) and lists only runtime dependencies, without pip, setuptools, or wheel. The build job fails before upload if the root name, version, or purl is wrong or an installer component appears. - Published through PyPI Trusted Publishing (OIDC) from a tag on
main, with hash-pinned build tools, a CycloneDX SBOM, a SLSA build-provenance attestation for the wheel, sdist, SBOM, and baseline pack, and the signed provenance bundleappsec-rules-pack-v0.6.0.intoto.jsonl.
Notes
- Minor release. No CLI, JSON report, schema, issue-code, or exit-code change. Packs that validated with v0.5.x still validate.
- The baseline pack version moves from 0.4.0 to 0.6.0 because a rule was added. A review record made against the previous baseline gets an
unreviewedentry forAPPSEC-PWSTORE-001(areview-missing-resultwarning), plus areview-pack-version-mismatchwarning if it declarespack_version: 0.4.0. - Mappings are review aids, not a claim of conformance to ASVS, SSDF, or the OWASP Top 10 lists.
- The 1.0 decision waits for feedback from external users (issue #29).
Full Changelog: v0.5.0...v0.6.0
License: Apache-2.0.
AppSec Rules Pack - v0.5.0
AppSec Rules Pack v0.5.0
This minor release gives a pack's policy its first consumer: appsec-rules review checks a per-service review record against the pack's rules and exception policy. It also versions the JSON report, opens the rule schema to custom id prefixes and x- extension keys, adds appsec-rules init, and hardens the loader and the release pipeline. The released v0.2.0 and v0.4.0 baselines still validate unchanged.
Install
pip install "appsec-rules-pack==0.5.0"
curl -LO https://github.com/lucashgrifoni/AppSec-Rules-Pack/releases/download/v0.5.0/appsec-baseline.yaml
appsec-rules validate appsec-baseline.yaml --require-examples --fail-on-warningsHighlights
appsec-rules review <pack> <record>checks a review record: for one service, each rule ismet,not-met,not-applicable, orexcepted. It reports a record that names the wrong pack, an unknown or repeated rule, ametrule without evidence, and an exception that the rule forbids, that lacks the fields the rule requires, that has expired, or that runs longer thanmax_days. Enabled rules with no result show asunreviewed. The exit code only says whether the record is valid; theappsec-rules-review/v1JSON report counts open rules by enforcement and severity for the gate to decide (ADR-0006).validate --format jsonis now a versioned contract,appsec-rules-validation/v1, described by a JSON Schema shipped in the package. Each issue carries a stablecodeand therule_idit belongs to. VERSIONING.md lists the codes and what counts as a breaking change.- The rule schema accepts any uppercase id prefix (
ACME-AUTH-001), makesowasp_api_top_10_2023optional, allowsx-keys on the pack, rules, andmappings, and lets a pack declarepack.schema_version. appsec-rules init <file>writes a starter pack that passes the strict gate.
Improvements
- A worked review of a fictional service in
examples/review/, a field reference with guidance on adapting the baseline (docs/rule-fields.md), and a downstream GitHub Actions template that verifies the pinned baseline, validates packs, checks review records, and gates on open rules, with a PowerShell version. - The reference policy gate also checks the worked review record and blocks on open blocking or critical rules.
- A property-based harness (Hypothesis) runs the loader, validator, JSON report, and
reviewagainst generated input in its own CI job, and mutation-driven tests cover checks that the earlier suite left unprotected.
Fixes
- An unquoted date that is not a real day, such as
2026-02-30, madevalidate, the exports, andreviewexit with a traceback. It is now ayaml-invaliderror with its line and column. - Pointing
-oat one of the input packs no longer overwrites the pack, and a pack value that JSON cannot represent no longer crashes the exports.
Security
- The loader rejects YAML aliases, duplicate keys, and files over 10 MiB. A 460-byte alias bomb used to take 71 s to validate, and a second
rules:key could cut a pack from 19 rules to 1 and still pass. - The dependency floors are now
typer>=0.16andclick>=8.3.3. With typer 0.12.x, every command exited 0 without validating anything; a new CI job tests the floors. - Sensitive-value detection covers mapping keys and common token formats, messages redact values that look like credentials, and tracebacks no longer print pack content.
- The release workflow verifies that the tag is on
mainand matches the package version, builds with hash-pinned tools in a job that cannot publish, and publishes from a job that installs nothing (ADR-0007). - Published through PyPI Trusted Publishing (OIDC) with a CycloneDX SBOM, a SLSA build-provenance attestation for the wheel, sdist, SBOM, and baseline pack, and the signed provenance bundle
appsec-rules-pack-v0.5.0.intoto.jsonl.
Notes
- Minor release. Packs that validated with v0.4.x still validate, unless they use YAML aliases or repeat a key (next point). Tools that parse the JSON report see new fields (
schema,code,rule_id) and should match oncode, not message text. - A pack with an alias or a duplicate key now fails validation; before, PyYAML expanded the alias or kept the last value.
reviewchecks the record against the pack. It does not inspect the reviewed code or confirm that the evidence is true.- The baseline pack keeps pack version 0.4.0 because rule content did not change.
Full Changelog: v0.4.1...v0.5.0
License: Apache-2.0.
AppSec Rules Pack - v0.4.1
AppSec Rules Pack v0.4.1
This patch release publishes the rewritten README to the PyPI project page and moves the default branch to main. The validator, the rule schema, the JSON report, and the baseline pack are unchanged.
Install
pip install "appsec-rules-pack==0.4.1"
curl -LO https://github.com/lucashgrifoni/AppSec-Rules-Pack/releases/download/v0.4.1/appsec-baseline.yaml
appsec-rules validate appsec-baseline.yaml --require-examples --fail-on-warningsHighlights
- Rewrote the README around a quick start, a scope table, a CLI reference, and release verification. Links are absolute, so the PyPI project page renders them.
- Renamed the default branch from
mastertomain. GitHub redirects old links and clones; the branch protection ruleset applies tomainunchanged.
Improvements
- Moved the landing page source to
site/and deployed it through aPagesworkflow, so the repository keeps a single branch. - The
IaC and Pipeline - TrivyandSecrets History - Gitleaksjobs now allow the hosts their tool binaries download from, so they pass without a warm cache.
Security
- Published through PyPI Trusted Publishing (OIDC) with a CycloneDX SBOM, a SLSA build-provenance attestation for the wheel, sdist, SBOM, and baseline pack, and the signed provenance bundle
appsec-rules-pack-v0.4.1.intoto.jsonl.
Notes
- Patch release. No breaking changes and no functional change.
- Assets: wheel, sdist, SBOM, baseline pack, and provenance bundle.
- The baseline pack keeps pack version 0.4.0 because rule content did not change.
- To update an existing clone:
git branch -m master main, thengit fetch originandgit branch -u origin/main main.
Full Changelog: v0.4.0...v0.4.1
License: Apache-2.0.
AppSec Rules Pack - v0.4.0
AppSec Rules Pack v0.4.0
This minor release adds an optional layer of two tested, executable Semgrep rules, a portable JSON gate example, and a signed provenance bundle attached to each release. The validator, the rule schema, and the JSON report format are unchanged.
Install
pip install "appsec-rules-pack==0.4.0"
curl -LO https://github.com/lucashgrifoni/AppSec-Rules-Pack/releases/download/v0.4.0/appsec-baseline.yaml
appsec-rules validate appsec-baseline.yaml --require-examples --fail-on-warningsHighlights
- Added
exports/semgrep-rules/, an optional, hand-maintained Semgrep layer with two tested Python/Flask detections:APPSEC-INJECT-001(request values reaching sqlite3 SQL) andAPPSEC-SSRF-001(request values reaching module-level Requests URLs). Positive and negative fixtures run in a dedicatedsemgrep --testworkflow (ADR-0005). - Attached the signed provenance bundle as
appsec-rules-pack-v0.4.0.intoto.jsonl, so any asset can be verified offline withgh attestation verify --bundle. - Added
examples/validation_gate.py, a stdlib-only gate that consumesvalidate --format jsonin any CI system. Contributed by @LEKKALAGANESH in #35. - Mapped
APPSEC-RATELIMIT-001toA10:2025, whose prevention guidance calls for rate limits and resource quotas. Optional 2025 coverage moves to 18 of 19 rules.
Improvements
- Rewrote README guidance on scope, the derived exports, mapping coverage, and release verification, with a recorded demo of a passing and a failing validation.
- Switched the downstream examples and the pull request template to the strict
--require-examples --fail-on-warningsgate, with tests that run the documented commands.CONTRIBUTING.mdnow states the automated test policy. - Replaced the Markdown issue templates with issue forms.
- Added the Python 3.13 classifier that CI already covers.
- Updated pinned GitHub Actions, including
attest-build-provenance4.2.2,gh-action-pypi-publish1.14.2,harden-runner2.21.1, and thecodeql-actiongroup 4.38.2.
Security
- The publish workflow verifies the provenance bundle against the wheel and the baseline pack before anything is published, so a bundle that fails verification never ships.
- CodeQL excludes only the two intentionally vulnerable Semgrep fixture files; no other path is excluded.
Notes
- Minor release. No breaking changes.
- Assets: wheel, sdist, SBOM, baseline pack, and provenance bundle.
- The baseline pack version moves to 0.4.0 because rule content changed; the derived exports are regenerated. The schema did not change, so its
$idstays pinned tov0.2.0. - 17 of the 19 baseline rules have no executable detection, and the two Semgrep rules cover only their documented sources and sinks. The
appsec-rulesCLI does not run Semgrep, andexport semgrepstill emits the metadata scaffold.
Full Changelog: v0.3.1...v0.4.0
License: Apache-2.0.
AppSec Rules Pack - v0.3.1
AppSec Rules Pack v0.3.1
This patch release replaces raw tracebacks with actionable errors for unreadable rule files, fixes two CLI output defects, and extends the build-provenance attestation to every release asset. The rule schema and the JSON report format are unchanged.
Install
pip install "appsec-rules-pack==0.3.1"
curl -LO https://github.com/lucashgrifoni/AppSec-Rules-Pack/releases/download/v0.3.1/appsec-baseline.yaml
appsec-rules validate appsec-baseline.yaml --require-examples --fail-on-warningsHighlights
- Extended the build-provenance attestation to
appsec-baseline.yamlandsbom.cdx.json. The baseline pack, the file a CI gate actually runs, can now be verified withgh attestation verify.
Improvements
- The
Security CI/CDpipeline passes. SARIF-uploading jobs gainedactions: read, the Gitleaks history job gainedpull-requests: read, and SARIF uploads now run only on a public repository, where code scanning can store them.
Fixes
- A rule file that is not valid UTF-8, does not parse as YAML, or nests too deeply now produces an actionable error instead of a Python traceback in every command.
validatereports it as a per-file error; the export and report commands print the reason on stderr and exit 1. report coverage --outputnow writes the text report to the named file. Before, the option was ignored without--format json.- The validation summary pluralizes every count (
1 rule,1 warning). Text output only; the JSON report is unchanged.
Security
- Published through PyPI Trusted Publishing (OIDC) with a CycloneDX SBOM and a SLSA build-provenance attestation covering the wheel, sdist, SBOM, and baseline pack.
Notes
- Patch release. No breaking changes.
- Assets: wheel, sdist, SBOM, and baseline pack.
- The baseline pack content did not change and keeps pack version 0.3.0.
Full Changelog: v0.3.0...v0.3.1
License: Apache-2.0.
AppSec Rules Pack - v0.3.0
AppSec Rules Pack v0.3.0
This minor release attaches the baseline pack to each GitHub Release, so a pipeline can pin the 19 rules without cloning the repository. It also adds Windows and Python 3.13 CI, raises the coverage gate, and makes derived artifacts byte-identical across platforms. The rule schema is unchanged.
Install
pip install "appsec-rules-pack==0.3.0"
curl -LO https://github.com/lucashgrifoni/AppSec-Rules-Pack/releases/download/v0.3.0/appsec-baseline.yaml
appsec-rules validate appsec-baseline.yaml --require-examples --fail-on-warningsHighlights
- Attached the baseline pack to the release as
appsec-baseline.yaml. The distribution ships the validator, CLI, and schema, not the rules. - Mapped
APPSEC-SSRF-001toA01:2025: the OWASP Top 10:2025 rolls SSRF into Broken Access Control. Optional 2025 coverage moves from 16 to 17 of 19 rules.
Improvements
- Documented the topic-based mapping convention in
CONTRIBUTING.md.APPSEC-FILE-001andAPPSEC-RATELIMIT-001stay unmapped on purpose. - Raised the coverage gate from 90% to 95% (130 tests at 97.46%).
- Added CI jobs on Windows and on Python 3.13.
- Made fourteen status checks required on the default branch, up from one.
Fixes
- Derived artifacts (
export index,export semgrep,export sarif,report coverage --output) were written with CRLF line endings on Windows. The same command now produces the same bytes on every platform. report coveragenow warns when a pack yields zero rules instead of printing a healthy-looking0/0. The exit code is unchanged.- Two tests failed on Windows because they decoded subprocess output with the locale encoding; they now read UTF-8.
Security
- Published through PyPI Trusted Publishing (OIDC) with a CycloneDX SBOM, a SLSA build-provenance attestation for the wheel and sdist, and a signed tag.
Notes
- Minor release. No breaking changes.
- Assets: wheel, sdist, SBOM, and baseline pack.
- The schema did not change, so its
$idstays pinned to thev0.2.0tag.
Full Changelog: v0.2.0...v0.3.0
License: Apache-2.0.
AppSec Rules Pack - v0.2.0
AppSec Rules Pack v0.2.0
This minor release publishes appsec-rules-pack to PyPI for the first time and expands the baseline from 10 to 19 rules. All schema changes are additive, so existing rule packs validate unchanged.
Install
pip install "appsec-rules-pack==0.2.0"Highlights
- Published to PyPI through Trusted Publishing (OIDC), with no long-lived API token.
- Expanded the baseline to 19 rules. The nine new rules each ship a compliant and a violating example:
APPSEC-SESSION-001(session hardening),APPSEC-XSS-001(output encoding),APPSEC-CSRF-001,APPSEC-ENUM-001(account enumeration),APPSEC-MSGAUTH-001(webhook and message authenticity),APPSEC-DATAEXPO-001(excessive data exposure),APPSEC-MASSASSIGN-001,APPSEC-REDIRECT-001(open redirect), andAPPSEC-RATELIMIT-001. - Migrated every
owasp_asvsmapping to OWASP ASVS 5.0.0, assigned by topic and checked against the official v5.0.0-to-v4.0.3 mapping. - Added derivation-only exports: a JSON rule index, a labeled non-runnable Semgrep scaffold, and a SARIF 2.1.0 rule catalog with no results (ADR-0001).
Improvements
- Added an optional
owasp_top_10_2025mapping field, populated where a 2025 category maps cleanly. - Added rule lifecycle support: a
deprecatedstatus and an optionaldeprecationblock (reason,replaced_by,since) with consistency warnings. - Extended the
categoryvocabulary withcsrf,integrity,data-exposure,open-redirect, andrate-limiting. - Added the
export index,export semgrep,export sarif, andreport coveragesubcommands; the checked-in exports are drift-tested. - Replaced the placeholder schema
$idwith a canonical, tag-versioned URL. - Added a reference
policy-gate.ymlworkflow that consumes the validator JSON (ADR-0004).
Security
- Attached a CycloneDX SBOM (
sbom.cdx.json) and a SLSA build-provenance attestation for the wheel and sdist. - The release workflow creates the GitHub Release from the signed tag.
Notes
- Minor release. No breaking changes: the 2025 mapping field, rule lifecycle, and new categories are optional and additive.
- Assets: wheel, sdist, and SBOM.
- Validation at release: 96 tests at 92.73% coverage, ruff clean, and 19 rules with 0 errors and 0 warnings.
- The Semgrep export is a non-runnable scaffold and the SARIF export has no results. Framework mappings are review aids, not a conformance claim.
Full Changelog: v0.1.0...v0.2.0
License: Apache-2.0.
AppSec Rules Pack - v0.1.0
AppSec Rules Pack v0.1.0
This initial release introduces a small, reviewable AppSec rules pack: a JSON Schema rule contract, a generic baseline of 10 rules, and a Python validator CLI. The validator is engine-agnostic: it checks rule packs and does not execute rules or scan application code.
Install
This release was not published to PyPI. Install the wheel attached to this release:
pip install https://github.com/lucashgrifoni/AppSec-Rules-Pack/releases/download/v0.1.0/appsec_rules_pack-0.1.0-py3-none-any.whlHighlights
- Added the rule contract,
appsec-rule.schema.json, covering pack and rule identity, policy attributes, framework mappings, evidence, remediation, and exceptions. - Added a baseline pack of 10 generic rules across every schema category, including authentication, logging, dependency risk, and configuration.
- Added the
appsec-rulesCLI with single-file and directory validation,--fail-on-warnings,--version, and--format jsonoutput for CI. - Added semantic checks: duplicate rule IDs within a file and across a directory, exception-window warnings, exception-policy consistency, framework mapping formats (CWE, OWASP API Top 10 2023, OWASP ASVS, NIST SSDF), and sensitive-value detection.
Improvements
- Added pass, fail, and warning fixtures for schema shape, enums, types,
additionalProperties, duplicate IDs, and exception policy. - Added 59 tests with a 90% coverage gate, ruff linting, and a packaging build check.
- Added community health files: a code of conduct, issue templates, a pull request template, and a CI integration example under
examples/.
Security
- Added a hardened CI workflow with least-privilege permissions and SHA-pinned actions.
- Added a security pipeline (Semgrep, CodeQL, Bandit, Trivy, KICS, pip-audit, Gitleaks, Dependency Review, actionlint), OpenSSF Scorecard, Dependabot, and CODEOWNERS.
- Added a
.gitleaks.tomlthat allowlists only the intentional fake-secret test fixtures, so secret scanning stays active everywhere else.
Notes
- Initial release.
- Assets: wheel and sdist. This release has no SBOM and no build-provenance attestation; both start in v0.2.0.
- The validator does not emit Semgrep, CodeQL, OPA/Rego, or SARIF, and makes no severity claims beyond the local rule content.
License: Apache-2.0.