What's Changed
- fix: drop -coverpkg=./... from examples/http-server test run by @fzipi in #1602
- fix: expand rule.msg at match time and add default actions to recommended config by @fzipi with @Copilot in #1606
- perf: replace Aho-Corasick with indexed bitmap matcher for anyRequired prefilter by @soujanyanmbri in #1597
- perf: add minLen prefilter to @pm operator by @fzipi in #1601
- fix(deps): update module golang.org/x/net to v0.53.0 [security] by @renovate[bot] in #1618
- chore(deps): update module golang.org/x/net to v0.53.0 [security] by @renovate[bot] in #1619
- tests: SecRuleRemoveBy* more coverage and better docs by @M4tteoP in #1623
- chore(deps): update module golang.org/x/crypto to v0.52.0 [security] by @renovate[bot] in #1624
- fix(deps): update module golang.org/x/net to v0.55.0 [security] by @renovate[bot] in #1625
- refactor(validateUrlEncoding) by @M4tteoP in #1626
- fix: ruleRemoveTargetById/Tag/Msg do not apply to chain children #1610 by @heaven in #1622
- chore: remove
SecDefaultActionfromcoraza.conf-recommendedby @M4tteoP in #1630 - ci: run enforce-all-checks on every PR by @M4tteoP in #1635
- chore: update SECURITY.md by @M4tteoP in #1634
- chore: update PR template by @M4tteoP in #1633
- fix(multimatch): cmdLine and urlDecodeUni over reporting changes by @M4tteoP in #1631
- docs: fix typos and some inaccuracies in interface docs by @M4tteoP in #1639
- fix: reset detectionOnlyInterruption on transaction pool reuse by @flphvlck in #1641
- fix: reset ForceResponseBodyVariable on pool reuse + guard test by @M4tteoP in #1642
- Fill ARGS_POST variable even if body bytes were invalid JSON when JSON body processor is running by @HusseinKabbout in #1615
- fix(deps): update module golang.org/x/net to v0.56.0 [security] by @renovate[bot] in #1646
- chore(deps): update module golang.org/x/net to v0.56.0 [security] by @renovate[bot] in #1647
- chore(deps): update module golang.org/x/text to v0.39.0 [security] by @renovate[bot] in #1648
- fix: implement Unicode best-fit mapping in urlDecodeUni by @fzipi in #1649
- fix: skip invalid bytes in base64decodeext instead of stopping by @fzipi in #1664
- fix: decode runes in compressWhitespace instead of indexing raw bytes by @fzipi in #1659
- fix: accept base64url alphabet in base64DecodeExt by @fzipi in #1652
- fix: strip Windows trailing dots/spaces and ADS suffixes in normalisePathWin by @fzipi in #1660
- fix: encode cssDecode hex escapes as UTF-8, not a truncated byte by @fzipi in #1658
- chore(deps): update module golang.org/x/mod to v0.40.0 [security] by @renovate[bot] in #1683
- fix: decode ES2015+ \u{...} extended unicode escapes in jsDecode by @fzipi in #1657
- chore: tidy go modules and enable Renovate gomodTidyAll by @fzipi in #1684
- fix: normalisePath and normalisePathWin incorrectly return changed=true when path is unmodified by @fzipi with @Copilot in #1672
- Fix invalid gomodTidyAll postUpdateOptions value by @fzipi in #1688
- docs(adr): add ADR directory, template and format check by @fzipi in #1690
- docs(adr): records for the v3.0.x releases (1 of 8) by @fzipi in #1691
- feat: register the accuracy rule action by @ChrisJr404 in #1693
- feat: support FIPS 140-3 by @M4tteoP in #1678
- fix: do not re-anchor glob include results to currentDir by @fzipi in #1689
- docs: add seclang code blocks and examples for all directives by @fzipi in #1694
- fix(deps): update all non-major dependencies in .github/workflows/tinygo.yml by @renovate[bot] in #1432
- fix: apply SecRuleUpdateTarget to the stored rule, not a loop copy by @fzipi in #1701
- chore: update libinjection-go to v0.3.3 by @fzipi in #1707
- docs(readme): add link to traefik wasm plugin by @mloiseleur in #1702
- chore: split modsecurity benchmark into its own module by @fzipi in #1708
- docs(adr): records for the v3.1.0 release (2 of 8) by @fzipi in #1692
- docs(adr): records for the v3.2.0 release (3 of 8) by @fzipi in #1698
- docs(adr): records for the v3.3.x releases (4 of 8) by @fzipi in #1699
- docs(adr): records for the v3.4.0 release, part 1 (5 of 8) by @fzipi in #1703
- docs(adr): records for the v3.4.0 release, part 2 (6 of 8) by @fzipi in #1704
- docs(adr): records for the v3.5.0 release (7 of 8) by @fzipi in #1705
- docs(adr): records for v3.6.0, v3.7.0 and main (8 of 8) by @fzipi in #1706
- docs(adr): records for accuracy action and FIPS 140-3 support by @fzipi in #1712
- docs: make AGENTS.md the single guide for contributors and coding agents by @jptosso in #1535
- perf: drop the RandomString mutex, use math/rand/v2 by @jptosso in #1695
- docs(security): require AI tool/model disclosure in vulnerability reports by @fzipi in #1720
- fix(operators): require literal adjacency to rx prefilter anchors by @fzipi in #1724
New Contributors
- @flphvlck made their first contribution in #1641
- @HusseinKabbout made their first contribution in #1615
- @ChrisJr404 made their first contribution in #1693
- @mloiseleur made their first contribution in #1702
Full Changelog: v3.7.0...v3.8.0