Apply Open Worldwide Application Security Project (OWASP) API rules to your OpenAPI specification using vacuum. Learn more about OWASP.

The original rules were written by Ricardo Graça, based on work by Phil Sturgeon. vacuum’s native rules continue to grow with the API security guidance.


vacuum supports OWASP API rules out of the box!

Turn up the heat

Use hard mode to enable every built-in OpenAPI rule, including the OWASP rules:

vacuum lint --hard-mode my-openapi-spec.yaml

For more control, create a file such as owasp-rules.yaml that extends vacuum:owasp:

extends: [[vacuum:oas, recommended], [vacuum:owasp, all]]

This combines the Recommended Rules with the OWASP Rules.

vacuum lint -r owasp-rules.yaml my-openapi-spec.yaml

What gets checked?

The rules cover authentication declarations, transport, request limits, and error responses. For OpenAPI 3.0, 3.1, and 3.2, that includes:

These are checks of your API description. They do not prove that the running API enforces authorization, rate limits, SSRF protection, or business-flow controls. Test those behaviors too. See the OWASP API Security Top 10 for the wider picture.

Changes for existing users

Strict write-security findings now have error severity, previously info. A requirement such as security: [{auth: []}, {}] allows anonymous access and can now fail a build. Require authentication, or configure a deliberate exception below.

Inline ignores now cover the entire subtree beneath their location, for every ruleset. See Ignoring Violations for scope and examples.

Make a deliberate exception

Use the existing custom ruleset configuration to change a rule’s severity:

extends: [[vacuum:oas, recommended], [vacuum:owasp, all]]
rules:
  owasp-protection-global-unsafe-strict: warn

For a specific operation or security scheme, put x-lint-ignore on that object. The directive applies to its descendants too, including nested OAuth flows and endpoint URLs. Document why the exception is needed.

Get ready to be told about all the things you are doing wrong!

What you see may hurt, but it’s for the good of the API.