Skip to content

AppSec Rules Pack - v0.4.0

Choose a tag to compare

@github-actions github-actions released this 05 Oct 12:08
v0.4.0
fe05966

AppSec Rules Pack v0.4.0

This minor release adds an optional layer of two tested, executable Semgrep rules, a portable JSON gate example, and a signed provenance bundle attached to each release. The validator, the rule schema, and the JSON report format are unchanged.

Install

pip install "appsec-rules-pack==0.4.0"
curl -LO https://github.com/lucashgrifoni/AppSec-Rules-Pack/releases/download/v0.4.0/appsec-baseline.yaml
appsec-rules validate appsec-baseline.yaml --require-examples --fail-on-warnings

Highlights

  • Added exports/semgrep-rules/, an optional, hand-maintained Semgrep layer with two tested Python/Flask detections: APPSEC-INJECT-001 (request values reaching sqlite3 SQL) and APPSEC-SSRF-001 (request values reaching module-level Requests URLs). Positive and negative fixtures run in a dedicated semgrep --test workflow (ADR-0005).
  • Attached the signed provenance bundle as appsec-rules-pack-v0.4.0.intoto.jsonl, so any asset can be verified offline with gh attestation verify --bundle.
  • Added examples/validation_gate.py, a stdlib-only gate that consumes validate --format json in any CI system. Contributed by @LEKKALAGANESH in #35.
  • Mapped APPSEC-RATELIMIT-001 to A10:2025, whose prevention guidance calls for rate limits and resource quotas. Optional 2025 coverage moves to 18 of 19 rules.

Improvements

  • Rewrote README guidance on scope, the derived exports, mapping coverage, and release verification, with a recorded demo of a passing and a failing validation.
  • Switched the downstream examples and the pull request template to the strict --require-examples --fail-on-warnings gate, with tests that run the documented commands. CONTRIBUTING.md now states the automated test policy.
  • Replaced the Markdown issue templates with issue forms.
  • Added the Python 3.13 classifier that CI already covers.
  • Updated pinned GitHub Actions, including attest-build-provenance 4.2.2, gh-action-pypi-publish 1.14.2, harden-runner 2.21.1, and the codeql-action group 4.38.2.

Security

  • The publish workflow verifies the provenance bundle against the wheel and the baseline pack before anything is published, so a bundle that fails verification never ships.
  • CodeQL excludes only the two intentionally vulnerable Semgrep fixture files; no other path is excluded.

Notes

  • Minor release. No breaking changes.
  • Assets: wheel, sdist, SBOM, baseline pack, and provenance bundle.
  • The baseline pack version moves to 0.4.0 because rule content changed; the derived exports are regenerated. The schema did not change, so its $id stays pinned to v0.2.0.
  • 17 of the 19 baseline rules have no executable detection, and the two Semgrep rules cover only their documented sources and sinks. The appsec-rules CLI does not run Semgrep, and export semgrep still emits the metadata scaffold.

Full Changelog: v0.3.1...v0.4.0

License: Apache-2.0.