Skip to content

AppSec Rules Pack - v0.3.0

Choose a tag to compare

@github-actions github-actions released this 05 Aug 14:27
v0.3.0

AppSec Rules Pack v0.3.0

This minor release attaches the baseline pack to each GitHub Release, so a pipeline can pin the 19 rules without cloning the repository. It also adds Windows and Python 3.13 CI, raises the coverage gate, and makes derived artifacts byte-identical across platforms. The rule schema is unchanged.

Install

pip install "appsec-rules-pack==0.3.0"
curl -LO https://github.com/lucashgrifoni/AppSec-Rules-Pack/releases/download/v0.3.0/appsec-baseline.yaml
appsec-rules validate appsec-baseline.yaml --require-examples --fail-on-warnings

Highlights

  • Attached the baseline pack to the release as appsec-baseline.yaml. The distribution ships the validator, CLI, and schema, not the rules.
  • Mapped APPSEC-SSRF-001 to A01:2025: the OWASP Top 10:2025 rolls SSRF into Broken Access Control. Optional 2025 coverage moves from 16 to 17 of 19 rules.

Improvements

  • Documented the topic-based mapping convention in CONTRIBUTING.md. APPSEC-FILE-001 and APPSEC-RATELIMIT-001 stay unmapped on purpose.
  • Raised the coverage gate from 90% to 95% (130 tests at 97.46%).
  • Added CI jobs on Windows and on Python 3.13.
  • Made fourteen status checks required on the default branch, up from one.

Fixes

  • Derived artifacts (export index, export semgrep, export sarif, report coverage --output) were written with CRLF line endings on Windows. The same command now produces the same bytes on every platform.
  • report coverage now warns when a pack yields zero rules instead of printing a healthy-looking 0/0. The exit code is unchanged.
  • Two tests failed on Windows because they decoded subprocess output with the locale encoding; they now read UTF-8.

Security

  • Published through PyPI Trusted Publishing (OIDC) with a CycloneDX SBOM, a SLSA build-provenance attestation for the wheel and sdist, and a signed tag.

Notes

  • Minor release. No breaking changes.
  • Assets: wheel, sdist, SBOM, and baseline pack.
  • The schema did not change, so its $id stays pinned to the v0.2.0 tag.

Full Changelog: v0.2.0...v0.3.0

License: Apache-2.0.