github corazawaf/coraza v3.8.0

56 minutes ago

What's Changed

  • fix: drop -coverpkg=./... from examples/http-server test run by @fzipi in #1602
  • fix: expand rule.msg at match time and add default actions to recommended config by @fzipi with @Copilot in #1606
  • perf: replace Aho-Corasick with indexed bitmap matcher for anyRequired prefilter by @soujanyanmbri in #1597
  • perf: add minLen prefilter to @pm operator by @fzipi in #1601
  • fix(deps): update module golang.org/x/net to v0.53.0 [security] by @renovate[bot] in #1618
  • chore(deps): update module golang.org/x/net to v0.53.0 [security] by @renovate[bot] in #1619
  • tests: SecRuleRemoveBy* more coverage and better docs by @M4tteoP in #1623
  • chore(deps): update module golang.org/x/crypto to v0.52.0 [security] by @renovate[bot] in #1624
  • fix(deps): update module golang.org/x/net to v0.55.0 [security] by @renovate[bot] in #1625
  • refactor(validateUrlEncoding) by @M4tteoP in #1626
  • fix: ruleRemoveTargetById/Tag/Msg do not apply to chain children #1610 by @heaven in #1622
  • chore: remove SecDefaultAction from coraza.conf-recommended by @M4tteoP in #1630
  • ci: run enforce-all-checks on every PR by @M4tteoP in #1635
  • chore: update SECURITY.md by @M4tteoP in #1634
  • chore: update PR template by @M4tteoP in #1633
  • fix(multimatch): cmdLine and urlDecodeUni over reporting changes by @M4tteoP in #1631
  • docs: fix typos and some inaccuracies in interface docs by @M4tteoP in #1639
  • fix: reset detectionOnlyInterruption on transaction pool reuse by @flphvlck in #1641
  • fix: reset ForceResponseBodyVariable on pool reuse + guard test by @M4tteoP in #1642
  • Fill ARGS_POST variable even if body bytes were invalid JSON when JSON body processor is running by @HusseinKabbout in #1615
  • fix(deps): update module golang.org/x/net to v0.56.0 [security] by @renovate[bot] in #1646
  • chore(deps): update module golang.org/x/net to v0.56.0 [security] by @renovate[bot] in #1647
  • chore(deps): update module golang.org/x/text to v0.39.0 [security] by @renovate[bot] in #1648
  • fix: implement Unicode best-fit mapping in urlDecodeUni by @fzipi in #1649
  • fix: skip invalid bytes in base64decodeext instead of stopping by @fzipi in #1664
  • fix: decode runes in compressWhitespace instead of indexing raw bytes by @fzipi in #1659
  • fix: accept base64url alphabet in base64DecodeExt by @fzipi in #1652
  • fix: strip Windows trailing dots/spaces and ADS suffixes in normalisePathWin by @fzipi in #1660
  • fix: encode cssDecode hex escapes as UTF-8, not a truncated byte by @fzipi in #1658
  • chore(deps): update module golang.org/x/mod to v0.40.0 [security] by @renovate[bot] in #1683
  • fix: decode ES2015+ \u{...} extended unicode escapes in jsDecode by @fzipi in #1657
  • chore: tidy go modules and enable Renovate gomodTidyAll by @fzipi in #1684
  • fix: normalisePath and normalisePathWin incorrectly return changed=true when path is unmodified by @fzipi with @Copilot in #1672
  • Fix invalid gomodTidyAll postUpdateOptions value by @fzipi in #1688
  • docs(adr): add ADR directory, template and format check by @fzipi in #1690
  • docs(adr): records for the v3.0.x releases (1 of 8) by @fzipi in #1691
  • feat: register the accuracy rule action by @ChrisJr404 in #1693
  • feat: support FIPS 140-3 by @M4tteoP in #1678
  • fix: do not re-anchor glob include results to currentDir by @fzipi in #1689
  • docs: add seclang code blocks and examples for all directives by @fzipi in #1694
  • fix(deps): update all non-major dependencies in .github/workflows/tinygo.yml by @renovate[bot] in #1432
  • fix: apply SecRuleUpdateTarget to the stored rule, not a loop copy by @fzipi in #1701
  • chore: update libinjection-go to v0.3.3 by @fzipi in #1707
  • docs(readme): add link to traefik wasm plugin by @mloiseleur in #1702
  • chore: split modsecurity benchmark into its own module by @fzipi in #1708
  • docs(adr): records for the v3.1.0 release (2 of 8) by @fzipi in #1692
  • docs(adr): records for the v3.2.0 release (3 of 8) by @fzipi in #1698
  • docs(adr): records for the v3.3.x releases (4 of 8) by @fzipi in #1699
  • docs(adr): records for the v3.4.0 release, part 1 (5 of 8) by @fzipi in #1703
  • docs(adr): records for the v3.4.0 release, part 2 (6 of 8) by @fzipi in #1704
  • docs(adr): records for the v3.5.0 release (7 of 8) by @fzipi in #1705
  • docs(adr): records for v3.6.0, v3.7.0 and main (8 of 8) by @fzipi in #1706
  • docs(adr): records for accuracy action and FIPS 140-3 support by @fzipi in #1712
  • docs: make AGENTS.md the single guide for contributors and coding agents by @jptosso in #1535
  • perf: drop the RandomString mutex, use math/rand/v2 by @jptosso in #1695
  • docs(security): require AI tool/model disclosure in vulnerability reports by @fzipi in #1720
  • fix(operators): require literal adjacency to rx prefilter anchors by @fzipi in #1724

New Contributors

Full Changelog: v3.7.0...v3.8.0

Don't miss a new coraza release

NewReleases is sending notifications on new releases.