0.22.0 (2026-10-07)
Bug Fixes
- finalise phase 4 before the headers when the body will not be inspected (#142) (e40152a)
- finalize delayed-header responses instead of returning a bare status (#122) (4c85346)
- guard body filter error pages and header filter loc conf (#123) (ae515a5)
- intervention poll consistency in the pre-access handler (#124) (61e8c14)
- reject premature response file EOF (#120) (57ac5da)
- reject ruleless Coraza enablement (#118) (ced32f6)
- reject SecRemoteRules at nginx -t instead of in every worker (#141) (045f8b4)
- stop double-submitting proxied headers; free the WAF error string (#125) (4872414)
- submit the request body to Coraza exactly once (#126) (cd2a70c)
Performance Improvements
- bound file-backed response inspection (#119) (1706b75)
- deduplicate WAFs by ordered rule content (#135) (1f0b73e)
- read request tempfiles in 64 KiB chunks (#115) (6efa914)
- skip inaccessible request body buffering (#113) (7d268d4)
- trim request hot-path overhead (#134) (80bff01)