Skip to content

AppSec Rules Pack - v0.3.1

Choose a tag to compare

@github-actions github-actions released this 27 Aug 15:27
v0.3.1
8d5d205

AppSec Rules Pack v0.3.1

This patch release replaces raw tracebacks with actionable errors for unreadable rule files, fixes two CLI output defects, and extends the build-provenance attestation to every release asset. The rule schema and the JSON report format are unchanged.

Install

pip install "appsec-rules-pack==0.3.1"
curl -LO https://github.com/lucashgrifoni/AppSec-Rules-Pack/releases/download/v0.3.1/appsec-baseline.yaml
appsec-rules validate appsec-baseline.yaml --require-examples --fail-on-warnings

Highlights

  • Extended the build-provenance attestation to appsec-baseline.yaml and sbom.cdx.json. The baseline pack, the file a CI gate actually runs, can now be verified with gh attestation verify.

Improvements

  • The Security CI/CD pipeline passes. SARIF-uploading jobs gained actions: read, the Gitleaks history job gained pull-requests: read, and SARIF uploads now run only on a public repository, where code scanning can store them.

Fixes

  • A rule file that is not valid UTF-8, does not parse as YAML, or nests too deeply now produces an actionable error instead of a Python traceback in every command. validate reports it as a per-file error; the export and report commands print the reason on stderr and exit 1.
  • report coverage --output now writes the text report to the named file. Before, the option was ignored without --format json.
  • The validation summary pluralizes every count (1 rule, 1 warning). Text output only; the JSON report is unchanged.

Security

  • Published through PyPI Trusted Publishing (OIDC) with a CycloneDX SBOM and a SLSA build-provenance attestation covering the wheel, sdist, SBOM, and baseline pack.

Notes

  • Patch release. No breaking changes.
  • Assets: wheel, sdist, SBOM, and baseline pack.
  • The baseline pack content did not change and keeps pack version 0.3.0.

Full Changelog: v0.3.0...v0.3.1

License: Apache-2.0.