v0.6.0 · Apache-2.0 · engine-agnostic

An AppSec rules pack
for documented reviews.

A curated pack of 20 generic application-security rules with a JSON Schema contract, a Python validator, and per-rule mappings to OWASP ASVS 5.0, OWASP API Top 10, OWASP Top 10:2025, CWE, and NIST SSDF. Every rule ships a compliant and a violating example.

Scope: the validator validates and exports rules for review and CI evidence. It is not a scanner: it does not execute rules or scan source code (ADR-0001). It derives a rule index, a labelled non-runnable Semgrep scaffold, and a SARIF rule catalog. A separate, optional layer adds two tested Semgrep rules for Python/Flask; the other 18 rules have no executable detection.

Get the pack → Install from PyPI See the CLI

OpenSSF Best Practices: passing

20
baseline rules
5
framework maps
3
export formats
15
rule categories
// what it is

Rule contracts, pack validation, and exports.

F.01

JSON Schema contract

Each rule has a stable ID, severity, category, targets, framework mappings, required evidence, review guidance, exceptions, and examples, validated against appsec-rule.schema.json.

F.02

Python validator (CLI)

Schema + semantic checks: duplicate IDs, exception-policy contradictions, malformed mapping IDs, sensitive-value detection, rule lifecycle, and --require-examples. Text or JSON output for CI.

F.03

Framework mappings

Per rule: OWASP ASVS 5.0, OWASP API Security Top 10 (2023), OWASP Top 10:2025 (optional), CWE, and NIST SSDF. Evidence aids, not a conformance claim.

F.04

Derivation-only exports

export index (JSON rule index), export semgrep (a non-runnable scaffold with placeholder patterns), and export sarif (a rule catalog with empty results). All drift-tested.

F.05

Coverage report

report coverage shows framework-mapping coverage per rule and in aggregate, in text or JSON, so gaps are visible instead of guessed.

F.06

Repository CI checks

Build/lint/test on Ubuntu, Windows, and Python 3.13; a security pipeline (Semgrep, CodeQL, Bandit, Trivy, KICS, pip-audit, Gitleaks); OpenSSF Scorecard, Dependabot, CODEOWNERS, and a reference policy gate that consumes the validator JSON. Fourteen required status checks on main.

F.07

Release artifacts and provenance

The release workflow uses PyPI Trusted Publishing (OIDC), builds a CycloneDX SBOM, and attaches the baseline pack and build-provenance attestations. A signed provenance bundle supports offline artifact verification with gh attestation verify --bundle. These artifacts describe the package and its build.

F.08

Executable Semgrep rules

An optional layer in exports/semgrep-rules/ with two tested Python/Flask detections: request data reaching sqlite3 SQL (APPSEC-INJECT-001) and Requests URLs (APPSEC-SSRF-001). Positive and negative fixtures run in CI.

F.09

Portable CI gate

examples/validation_gate.py consumes the JSON report in any CI system and passes only when the CLI exits 0 and the report says ok: true. Contributed by the community.

F.10

Review records

appsec-rules review checks a per-service record (met, not met, not applicable, excepted) against the pack: evidence for every met rule, and exceptions that the rule allows, with the required fields, unexpired and inside max_days. The gate decides what may stay open (ADR-0006).

F.11

Versioned report contract

The JSON reports carry a schema marker and stable issue codes, described by JSON Schemas shipped in the package. VERSIONING.md says what may change between releases.

F.12

Property-based tests

A Hypothesis harness feeds the loader, validator, and review with malformed YAML, aliases, duplicate keys, raw bytes, and deep nesting, and requires a structured result every time. It runs in its own CI job.

// use it

Validate packs and review records.

Install from PyPI (published via Trusted Publishing / OIDC), then validate the pack and derive the exports. The validator is advisory by default and never executes rules.

# install the validator from PyPI $ pip install "appsec-rules-pack==0.6.0" # the distribution ships the validator, not the rules: grab the pack $ mkdir -p rules && curl -fsSL -o rules/appsec-baseline.yaml \ https://github.com/lucashgrifoni/AppSec-Rules-Pack/releases/download/v0.6.0/appsec-baseline.yaml $ appsec-rules validate rules --require-examples --fail-on-warnings Validation passed: 1 file, 20 rules, 0 errors, 0 warnings. # start your own pack, and check a service's review record against the baseline $ appsec-rules init rules/my-pack.yaml $ appsec-rules review rules/appsec-baseline.yaml reviews/payments-api.yaml $ appsec-rules report coverage rules # reports mapping coverage and unmapped rules for each framework $ appsec-rules export index rules/appsec-baseline.yaml -o exports/index.json # derivation only: no rule execution, no scanning # verify the pack came from the release workflow $ gh attestation verify rules/appsec-baseline.yaml --repo lucashgrifoni/AppSec-Rules-Pack
// coverage

Rule categories and framework mappings.

› authentication
› authorization (IDOR/BOLA)
› input-validation
› injection / XSS
› ssrf
› secrets
› file-handling
› logging
› dependency-risk
› configuration
› csrf
› integrity (webhook auth)
› data-exposure
› open-redirect
› rate-limiting