Releases: corazawaf/coraza
Release v2 beta 5 🦄
This is (not anymore) the final beta release (or not?), it contains:
- New macro engine
- 25%+ performance improvements
- 99,7% crs compatibility
- Minor low level api changes
v2.0 release's codename is wild pony 🦄
Next beta release will be 100% CRS compatibility and then the last low level API normalization, I will remove some pointers, change some names and unexport some stuff
v2.0.0-beta.4
There are not many changes but I fixed a huge bug with multipart, now it's working fine.
v2.0.0-beta.3 (api breaking)
This is the first API change to break some implementations, but keep in mind there are only small changes, like function names.
- Plugins API rework, operators.RegisterOperator was redundant and changed to operators.RegisterPlugin
- All the API is compliant against golint
- A lot of audit logging fixes
v2.0.0-beta.2
- A lot of fixes
- 99% CRS compatibility
- Variable system rework and optimization
- Lot of lint fixes
- 90% coverage
- A few low level api changes
v2.0.0-beta.1
- Complete testing engine rework
- 96%+ crs compatibility
- Lots of bug fixes
- A lot of linter fixes
v2.0.0-alpha.1
- Most external APIs removed
- Types were moved to the types package
- Variables were moved to the variables package
- Now the plugin engine is native and part of the core design
- New audit log plugins for writers and formatters
- New body processor plugins system
v1.2.0
v1.1.0
- Added JSON support using XPATH in replacement of JQ (yes, XPATH for JSON)
- Added Plugins, see https://coraza.io/docs/reference/extending/
First stable release v1
First stable release 🎉
Welcome to the first stable release of Coraza Web Application Firewall. This version is highly stable and production ready. Fully compatible with OWASP CRS.
What is working
- Rules
- Directives
- Actions
- Operators
- Transformations
- Variables
- Interruptions
- Audit Logging
What is not working
- JSON body processor
- Persistent Collections
Important considerations
Most features require CGO enabled, libpcre and libinjection, if none of these are available, you won't have @detectXSS, @detectSQLi nor PCRE expressions (OWASP CRS compatibility)
v1.0.0-beta.7 (Final RC)
This is the final release candidate, OWASP CRS compatibility is at 96,4%
We are almost there :D
v1.0 won't contain many changes, we are production ready.