Repository navigation
AppSec Rules Pack - v0.3.0
AppSec Rules Pack v0.3.0
This minor release attaches the baseline pack to each GitHub Release, so a pipeline can pin the 19 rules without cloning the repository. It also adds Windows and Python 3.13 CI, raises the coverage gate, and makes derived artifacts byte-identical across platforms. The rule schema is unchanged.
Install
pip install "appsec-rules-pack==0.3.0"
curl -LO https://github.com/lucashgrifoni/AppSec-Rules-Pack/releases/download/v0.3.0/appsec-baseline.yaml
appsec-rules validate appsec-baseline.yaml --require-examples --fail-on-warningsHighlights
- Attached the baseline pack to the release as
appsec-baseline.yaml. The distribution ships the validator, CLI, and schema, not the rules. - Mapped
APPSEC-SSRF-001toA01:2025: the OWASP Top 10:2025 rolls SSRF into Broken Access Control. Optional 2025 coverage moves from 16 to 17 of 19 rules.
Improvements
- Documented the topic-based mapping convention in
CONTRIBUTING.md.APPSEC-FILE-001andAPPSEC-RATELIMIT-001stay unmapped on purpose. - Raised the coverage gate from 90% to 95% (130 tests at 97.46%).
- Added CI jobs on Windows and on Python 3.13.
- Made fourteen status checks required on the default branch, up from one.
Fixes
- Derived artifacts (
export index,export semgrep,export sarif,report coverage --output) were written with CRLF line endings on Windows. The same command now produces the same bytes on every platform. report coveragenow warns when a pack yields zero rules instead of printing a healthy-looking0/0. The exit code is unchanged.- Two tests failed on Windows because they decoded subprocess output with the locale encoding; they now read UTF-8.
Security
- Published through PyPI Trusted Publishing (OIDC) with a CycloneDX SBOM, a SLSA build-provenance attestation for the wheel and sdist, and a signed tag.
Notes
- Minor release. No breaking changes.
- Assets: wheel, sdist, SBOM, and baseline pack.
- The schema did not change, so its
$idstays pinned to thev0.2.0tag.
Full Changelog: v0.2.0...v0.3.0
License: Apache-2.0.