Repository navigation
AppSec Rules Pack - v0.2.0
AppSec Rules Pack v0.2.0
This minor release publishes appsec-rules-pack to PyPI for the first time and expands the baseline from 10 to 19 rules. All schema changes are additive, so existing rule packs validate unchanged.
Install
pip install "appsec-rules-pack==0.2.0"Highlights
- Published to PyPI through Trusted Publishing (OIDC), with no long-lived API token.
- Expanded the baseline to 19 rules. The nine new rules each ship a compliant and a violating example:
APPSEC-SESSION-001(session hardening),APPSEC-XSS-001(output encoding),APPSEC-CSRF-001,APPSEC-ENUM-001(account enumeration),APPSEC-MSGAUTH-001(webhook and message authenticity),APPSEC-DATAEXPO-001(excessive data exposure),APPSEC-MASSASSIGN-001,APPSEC-REDIRECT-001(open redirect), andAPPSEC-RATELIMIT-001. - Migrated every
owasp_asvsmapping to OWASP ASVS 5.0.0, assigned by topic and checked against the official v5.0.0-to-v4.0.3 mapping. - Added derivation-only exports: a JSON rule index, a labeled non-runnable Semgrep scaffold, and a SARIF 2.1.0 rule catalog with no results (ADR-0001).
Improvements
- Added an optional
owasp_top_10_2025mapping field, populated where a 2025 category maps cleanly. - Added rule lifecycle support: a
deprecatedstatus and an optionaldeprecationblock (reason,replaced_by,since) with consistency warnings. - Extended the
categoryvocabulary withcsrf,integrity,data-exposure,open-redirect, andrate-limiting. - Added the
export index,export semgrep,export sarif, andreport coveragesubcommands; the checked-in exports are drift-tested. - Replaced the placeholder schema
$idwith a canonical, tag-versioned URL. - Added a reference
policy-gate.ymlworkflow that consumes the validator JSON (ADR-0004).
Security
- Attached a CycloneDX SBOM (
sbom.cdx.json) and a SLSA build-provenance attestation for the wheel and sdist. - The release workflow creates the GitHub Release from the signed tag.
Notes
- Minor release. No breaking changes: the 2025 mapping field, rule lifecycle, and new categories are optional and additive.
- Assets: wheel, sdist, and SBOM.
- Validation at release: 96 tests at 92.73% coverage, ruff clean, and 19 rules with 0 errors and 0 warnings.
- The Semgrep export is a non-runnable scaffold and the SARIF export has no results. Framework mappings are review aids, not a conformance claim.
Full Changelog: v0.1.0...v0.2.0
License: Apache-2.0.