Skip to content

AppSec Rules Pack - v0.2.0

Choose a tag to compare

@github-actions github-actions released this 03 Jun 14:22
v0.2.0
0373226

AppSec Rules Pack v0.2.0

This minor release publishes appsec-rules-pack to PyPI for the first time and expands the baseline from 10 to 19 rules. All schema changes are additive, so existing rule packs validate unchanged.

Install

pip install "appsec-rules-pack==0.2.0"

Highlights

  • Published to PyPI through Trusted Publishing (OIDC), with no long-lived API token.
  • Expanded the baseline to 19 rules. The nine new rules each ship a compliant and a violating example: APPSEC-SESSION-001 (session hardening), APPSEC-XSS-001 (output encoding), APPSEC-CSRF-001, APPSEC-ENUM-001 (account enumeration), APPSEC-MSGAUTH-001 (webhook and message authenticity), APPSEC-DATAEXPO-001 (excessive data exposure), APPSEC-MASSASSIGN-001, APPSEC-REDIRECT-001 (open redirect), and APPSEC-RATELIMIT-001.
  • Migrated every owasp_asvs mapping to OWASP ASVS 5.0.0, assigned by topic and checked against the official v5.0.0-to-v4.0.3 mapping.
  • Added derivation-only exports: a JSON rule index, a labeled non-runnable Semgrep scaffold, and a SARIF 2.1.0 rule catalog with no results (ADR-0001).

Improvements

  • Added an optional owasp_top_10_2025 mapping field, populated where a 2025 category maps cleanly.
  • Added rule lifecycle support: a deprecated status and an optional deprecation block (reason, replaced_by, since) with consistency warnings.
  • Extended the category vocabulary with csrf, integrity, data-exposure, open-redirect, and rate-limiting.
  • Added the export index, export semgrep, export sarif, and report coverage subcommands; the checked-in exports are drift-tested.
  • Replaced the placeholder schema $id with a canonical, tag-versioned URL.
  • Added a reference policy-gate.yml workflow that consumes the validator JSON (ADR-0004).

Security

  • Attached a CycloneDX SBOM (sbom.cdx.json) and a SLSA build-provenance attestation for the wheel and sdist.
  • The release workflow creates the GitHub Release from the signed tag.

Notes

  • Minor release. No breaking changes: the 2025 mapping field, rule lifecycle, and new categories are optional and additive.
  • Assets: wheel, sdist, and SBOM.
  • Validation at release: 96 tests at 92.73% coverage, ruff clean, and 19 rules with 0 errors and 0 warnings.
  • The Semgrep export is a non-runnable scaffold and the SARIF export has no results. Framework mappings are review aids, not a conformance claim.

Full Changelog: v0.1.0...v0.2.0

License: Apache-2.0.