Repository navigation
AppSec Rules Pack - v0.4.0
AppSec Rules Pack v0.4.0
This minor release adds an optional layer of two tested, executable Semgrep rules, a portable JSON gate example, and a signed provenance bundle attached to each release. The validator, the rule schema, and the JSON report format are unchanged.
Install
pip install "appsec-rules-pack==0.4.0"
curl -LO https://github.com/lucashgrifoni/AppSec-Rules-Pack/releases/download/v0.4.0/appsec-baseline.yaml
appsec-rules validate appsec-baseline.yaml --require-examples --fail-on-warningsHighlights
- Added
exports/semgrep-rules/, an optional, hand-maintained Semgrep layer with two tested Python/Flask detections:APPSEC-INJECT-001(request values reaching sqlite3 SQL) andAPPSEC-SSRF-001(request values reaching module-level Requests URLs). Positive and negative fixtures run in a dedicatedsemgrep --testworkflow (ADR-0005). - Attached the signed provenance bundle as
appsec-rules-pack-v0.4.0.intoto.jsonl, so any asset can be verified offline withgh attestation verify --bundle. - Added
examples/validation_gate.py, a stdlib-only gate that consumesvalidate --format jsonin any CI system. Contributed by @LEKKALAGANESH in #35. - Mapped
APPSEC-RATELIMIT-001toA10:2025, whose prevention guidance calls for rate limits and resource quotas. Optional 2025 coverage moves to 18 of 19 rules.
Improvements
- Rewrote README guidance on scope, the derived exports, mapping coverage, and release verification, with a recorded demo of a passing and a failing validation.
- Switched the downstream examples and the pull request template to the strict
--require-examples --fail-on-warningsgate, with tests that run the documented commands.CONTRIBUTING.mdnow states the automated test policy. - Replaced the Markdown issue templates with issue forms.
- Added the Python 3.13 classifier that CI already covers.
- Updated pinned GitHub Actions, including
attest-build-provenance4.2.2,gh-action-pypi-publish1.14.2,harden-runner2.21.1, and thecodeql-actiongroup 4.38.2.
Security
- The publish workflow verifies the provenance bundle against the wheel and the baseline pack before anything is published, so a bundle that fails verification never ships.
- CodeQL excludes only the two intentionally vulnerable Semgrep fixture files; no other path is excluded.
Notes
- Minor release. No breaking changes.
- Assets: wheel, sdist, SBOM, baseline pack, and provenance bundle.
- The baseline pack version moves to 0.4.0 because rule content changed; the derived exports are regenerated. The schema did not change, so its
$idstays pinned tov0.2.0. - 17 of the 19 baseline rules have no executable detection, and the two Semgrep rules cover only their documented sources and sinks. The
appsec-rulesCLI does not run Semgrep, andexport semgrepstill emits the metadata scaffold.
Full Changelog: v0.3.1...v0.4.0
License: Apache-2.0.