A curated pack of 20 generic application-security rules with a JSON Schema contract, a Python validator, and per-rule mappings to OWASP ASVS 5.0, OWASP API Top 10, OWASP Top 10:2025, CWE, and NIST SSDF. Every rule ships a compliant and a violating example.
Scope: the validator validates and exports rules for review and CI evidence. It is not a scanner: it does not execute rules or scan source code (ADR-0001). It derives a rule index, a labelled non-runnable Semgrep scaffold, and a SARIF rule catalog. A separate, optional layer adds two tested Semgrep rules for Python/Flask; the other 18 rules have no executable detection.
Each rule has a stable ID, severity, category, targets, framework mappings, required evidence, review guidance, exceptions, and examples, validated against appsec-rule.schema.json.
Schema + semantic checks: duplicate IDs, exception-policy contradictions, malformed mapping IDs, sensitive-value detection, rule lifecycle, and --require-examples. Text or JSON output for CI.
Per rule: OWASP ASVS 5.0, OWASP API Security Top 10 (2023), OWASP Top 10:2025 (optional), CWE, and NIST SSDF. Evidence aids, not a conformance claim.
export index (JSON rule index), export semgrep (a non-runnable scaffold with placeholder patterns), and export sarif (a rule catalog with empty results). All drift-tested.
report coverage shows framework-mapping coverage per rule and in aggregate, in text or JSON, so gaps are visible instead of guessed.
Build/lint/test on Ubuntu, Windows, and Python 3.13; a security pipeline (Semgrep, CodeQL, Bandit, Trivy, KICS, pip-audit, Gitleaks); OpenSSF Scorecard, Dependabot, CODEOWNERS, and a reference policy gate that consumes the validator JSON. Fourteen required status checks on main.
The release workflow uses PyPI Trusted Publishing (OIDC), builds a CycloneDX SBOM, and attaches the baseline pack and build-provenance attestations. A signed provenance bundle supports offline artifact verification with gh attestation verify --bundle. These artifacts describe the package and its build.
An optional layer in exports/semgrep-rules/ with two tested Python/Flask detections: request data reaching sqlite3 SQL (APPSEC-INJECT-001) and Requests URLs (APPSEC-SSRF-001). Positive and negative fixtures run in CI.
examples/validation_gate.py consumes the JSON report in any CI system and passes only when the CLI exits 0 and the report says ok: true. Contributed by the community.
appsec-rules review checks a per-service record (met, not met, not applicable, excepted) against the pack: evidence for every met rule, and exceptions that the rule allows, with the required fields, unexpired and inside max_days. The gate decides what may stay open (ADR-0006).
The JSON reports carry a schema marker and stable issue codes, described by JSON Schemas shipped in the package. VERSIONING.md says what may change between releases.
A Hypothesis harness feeds the loader, validator, and review with malformed YAML, aliases, duplicate keys, raw bytes, and deep nesting, and requires a structured result every time. It runs in its own CI job.
Install from PyPI (published via Trusted Publishing / OIDC), then validate the pack and derive the exports. The validator is advisory by default and never executes rules.