Skip to content

chore(deps): update dependency coreruleset/coreruleset to v4.23.0 in config/_default/config.toml#266

Merged
fzipi merged 1 commit intomainfrom
renovate/all-minor-patch
Feb 5, 2026
Merged

chore(deps): update dependency coreruleset/coreruleset to v4.23.0 in config/_default/config.toml#266
fzipi merged 1 commit intomainfrom
renovate/all-minor-patch

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Feb 5, 2026

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Update Change OpenSSF
coreruleset/coreruleset minor 4.0.04.23.0 OpenSSF Scorecard

Release Notes

coreruleset/coreruleset (coreruleset/coreruleset)

v4.23.0

Compare Source

What's Changed

⭐ Important changes
  • feat(920640): add rule to enforce content-type if there is body by @​fzipi in #​4406
🆕 New features and detections 🎉
🧰 Other Changes

New Contributors

Full Changelog: coreruleset/coreruleset@v4.22.0...v4.23.0

v4.22.0

Compare Source

What's Changed
CRITICAL
  • fix for 9AJ-260102
🧰 Other Changes

Special thanks to @​daytriftnewgen for responsible reporting 9AJ-260102

Full Changelog: coreruleset/coreruleset@v4.21.0...v4.22.0

v4.21.0

Compare Source

What's Changed
🆕 New features and detections 🎉
🧰 Other Changes

Full Changelog: coreruleset/coreruleset@v4.20.0...v4.21.0

v4.20.0

Compare Source

What's Changed

🆕 New features and detections 🎉
🧰 Other Changes

Full Changelog: coreruleset/coreruleset@v4.19.0...v4.20.0

v4.19.0

Compare Source

What's Changed

⭐ Important changes
🆕 New features and detections 🎉
🧰 Other Changes

New Contributors

Full Changelog: coreruleset/coreruleset@v4.18.0...v4.19.0

v4.18.0

Compare Source

What's Changed

🆕 New features and detections 🎉
🧰 Other Changes

Full Changelog: coreruleset/coreruleset@v4.17.1...v4.18.0

v4.17.1

Compare Source

What's Changed

⭐ Important changes
🧰 Other Changes

Full Changelog: coreruleset/coreruleset@v4.17.0...v4.17.1

v4.17.0

Compare Source

[!IMPORTANT]
This release contains a new rule to detect LaTeX injections which was not supposed to be released as it is too prone to false positives in it's current state. Please use v4.17.1 instead.

What's Changed

⭐ Important changes
🆕 New features and detections 🎉
🧰 Other Changes

New Contributors

Full Changelog: coreruleset/coreruleset@v4.16.0...v4.17.0

v4.16.0

Compare Source

What's Changed

🆕 New features and detections 🎉
🧰 Other Changes

New Contributors

Full Changelog: coreruleset/coreruleset@v4.15.0...v4.16.0

v4.15.0

Compare Source

What's Changed

🆕 New features and detections 🎉
🧰 Other Changes

Full Changelog: coreruleset/coreruleset@v4.14.0...v4.15.0

v4.14.0

Compare Source

What's Changed

🆕 New features and detections 🎉
🧰 Other Changes

Full Changelog: coreruleset/coreruleset@v4.13.0...v4.14.0

v4.13.0

Compare Source

What's Changed

⭐ Important changes
🆕 New features and detections 🎉
🪦 Rule removals
  • feat: remove rule 952100 for detecting Java Source Code Leakage by @​S0obi in #​4052
🧰 Other Changes
  • fix(934130): extend prototype pollution payload by @​Xhoenix in #​4036
  • fix: rule 930110 is not supposed to match bare '..' without (back)slashes by @​azurit in #​4050
  • fix: use boundary to fix false positive with email firstname.dockery@host.tld by @​EsadCetiner in #​4045
  • feat: refresh restricted-upload.data by @​S0obi in #​4046
  • fix: tag inconsistency per file by @​Xhoenix in #​4031
  • fix: added pre-check of unset TX variable by @​airween in #​4066
  • fix: false positive found in quantitative testing round 2 for unix rce rules (932230 PL-1, 932235 PL-1, 932250 PL-1, 932260 PL-1, 932231 PL-2, 932220 PL-2, 932236 PL-2, 932239 PL-2, 932232 PL-3, 932238 PL-3) by @​EsadCetiner in #​4019

New Contributors

Full Changelog: coreruleset/coreruleset@v4.12.0...v4.13.0

v4.12.0

Compare Source

What's Changed

🆕 New features and detections 🎉
🧰 Other Changes
  • fix: multipart header tag consistency by @​Xhoenix in #​3992
  • fix: prevent invalid commands matches on 5 characters or less (932220 PL-2, 932230 PL-1, 932232 PL-3, 932235 PL-1, 932236 PL-2, 932237 PL-3, 932238 PL-3, 932239 PL-2, 932250 PL-1, 932260 PL-1) by @​EsadCetiner in #​3735
  • docs: add warning about default charsets modification by @​fzipi in #​4003
  • fix: response splitting rules and tests by @​theseion in #​4009
  • fix(933160): use better regex by @​fzipi in #​4010
  • fix: move fopen to 933160 to resolve fp with RootAndLeafOpenCamera.jpg (933150 PL-1, 933160 PL-1) by @​EsadCetiner in #​4016
  • fix(941210): update log message to reflect rule javascript word detection by @​fzipi in #​4023
  • fix: remove .env from lfi-os-files.data by @​theseion in #​4024

New Contributors

Full Changelog: coreruleset/coreruleset@v4.11.0...v4.12.0

v4.11.0

Compare Source

What's Changed

🪦 Rule removals
  • feat: Remove rules for lack of viable attack scenario (920220 PL1, 920221 PL1) by @​dune73 in #​3969
🧰 Other Changes

Full Changelog: coreruleset/coreruleset@v4.10.0...v4.11.0

v4.10.0

Compare Source

What's Changed

🆕 New features and detections 🎉
🧰 Other Changes

Full Changelog: coreruleset/coreruleset@v4.9.0...v4.10.0

v4.9.0

Compare Source

What's Changed

⭐ Important changes
🆕 New features and detections 🎉
🧰 Other Changes

New Contributors

Full Changelog: coreruleset/coreruleset@v4.8.0...v4.9.0

v4.8.0

Compare Source

What's Changed

⭐ Important changes
🆕 New features and detections 🎉
🧰 Other Changes

New Contributors

Full Changelog: coreruleset/coreruleset@v4.7.0...v4.8.0

v4.7.0

Compare Source

What's Changed

🆕 New features and detections 🎉
🧰 Other Changes

New Contributors

Full Changelog: coreruleset/coreruleset@v4.6.0...v4.7.0

v4.6.0

Compare Source

What's Changed

⭐ Important changes

Big thanks tu @​luelueking for reporting us these two ☝️ .

🧰 Other Changes

New Contributors

Full Changelog: coreruleset/coreruleset@v4.5.0...v4.6.0

v4.5.0

Compare Source

What's Changed

🆕 New features and detections 🎉
🧰 Other Changes

New Contributors

Full Changelog: coreruleset/coreruleset@v4.4.0...v4.5.0

v4.4.0

Compare Source

What's Changed

🆕 New features and detections 🎉
🧰 Other Changes
  • fix(934140): update regex by @​fzipi in #​3731
  • fix: replacing t:UrlDecode with t:UrlDecodeUni (921240 PL1, 932170 PL1, 932171 PL1, 932190 PL3, 932190 PL1, 933211 PL3, 941310 PL1, 941350 PL1) by @​azurit in #​3713

Full Changelog: coreruleset/coreruleset@v4.3.0...v4.4.0

v4.3.0

Compare Source

What's Changed

🆕 New features and detections 🎉
🧰 Other Changes

Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM ( * 0-3 * * * ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@cloudflare-workers-and-pages
Copy link

Deploying crs-documentation with  Cloudflare Pages  Cloudflare Pages

Latest commit: 8f26284
Status:🚫  Build failed.

View logs

@fzipi fzipi merged commit e89576f into main Feb 5, 2026
1 of 2 checks passed
@fzipi fzipi deleted the renovate/all-minor-patch branch February 5, 2026 23:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant