CrowdSec

Developer ToolsWindowsLinux

A collaborative intrusion-prevention system that detects attacks and shares blocklists across its user network.

Latest v1.7.8 · · Windows · Linuxby CrowdSecWebsitecrowdsecurity/crowdsec

Release activity

Release activity — 10 releases across 10 days since Dec 3, 2025. Each cell is one day; darker means more releases that day. Nothing is recorded before Dec 3, 2025. Older weeks are hidden at this screen width.
MayJunJulAug
SundayNo releases on May 3, 2026No releases on May 10, 2026No releases on May 17, 2026No releases on May 24, 2026No releases on May 31, 2026No releases on Jun 7, 2026No releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026No releases on Aug 9, 2026No releases on Aug 16, 2026
MondayNo releases on May 4, 20261 release on May 11, 2026No releases on May 18, 2026No releases on May 25, 2026No releases on Jun 1, 2026No releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 20261 release on Jul 27, 2026No releases on Aug 3, 2026No releases on Aug 10, 2026
Tuesday1 release on May 5, 2026No releases on May 12, 2026No releases on May 19, 2026No releases on May 26, 2026No releases on Jun 2, 2026No releases on Jun 9, 2026No releases on Jun 16, 2026No releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 2026No releases on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026No releases on Aug 11, 2026
WednesdayNo releases on May 6, 2026No releases on May 13, 2026No releases on May 20, 2026No releases on May 27, 2026No releases on Jun 3, 2026No releases on Jun 10, 2026No releases on Jun 17, 2026No releases on Jun 24, 2026No releases on Jul 1, 2026No releases on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 2026No releases on Aug 5, 2026No releases on Aug 12, 2026
ThursdayNo releases on May 7, 2026No releases on May 14, 2026No releases on May 21, 2026No releases on May 28, 2026No releases on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026No releases on Aug 13, 2026
FridayNo releases on May 8, 2026No releases on May 15, 2026No releases on May 22, 2026No releases on May 29, 2026No releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 2026No releases on Jun 26, 2026No releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026No releases on Aug 14, 2026
SaturdayNo releases on May 9, 2026No releases on May 16, 2026No releases on May 23, 2026No releases on May 30, 2026No releases on Jun 6, 2026No releases on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026No releases on Aug 8, 2026No releases on Aug 15, 2026

10 releases since Dec 3, 2025

Changelog

v1.8.0-rc1

Pre-release
Added 4
  • Bot detection feature for CrowdSec WAF that serves a challenge and fingerprinting page to clients, evaluating legitimacy based on challenge response and fingerprint rules
  • Kubernetes log acquisition datasource to fetch logs directly from the Kubernetes API server
  • HTTP helpers for the expression language to query external services from parsers and scenarios
  • cs_machines_heartbeat_seconds metric
Changed 1
  • Improve cscli hub list functionality
Fixed 13
  • Allow spaces in ENROLL_INSTANCE_NAME environment variable in Docker
  • Return nil response from API client if unable to connect to LAPI
  • Remove error when running cscli lapi register if the credentials file does not exist
  • Avoid panic on colliding nested crowdsec labels in Docker
  • Prevent closing the shared acquisition output channel in syslog
  • Track id/name pairs for all subrules in WAF
Bot detection with CrowdSec WAF

This release brings a major change to the CrowdSec WAF: a bot detection feature.

If enabled, clients will be served a challenge + fingerprinting page before accessing the website. CrowdSec will evaluate the challenge and check the fingerprint against pre-configured rules to decide whether the client looks legitimate or not.

You can find more information about this new feature in the documentation.

Other notable changes include:

  • a dedicated kubernetes datasource: crowdsec will fetch logs directly from the k8s apiserver
  • new HTTP helpers for the expression language, to query external services from parsers and scenarios
New Features
  • k8s log acquisition datasource (#4221) @sabban
  • Waf challenge mode (#4268) @blotus
Improvements
  • Add cs_machines_heartbeat_seconds metric (#4569) @kushiemoon-dev
  • Cscli hub list improvements (#4567) @buixor
  • expr: add HTTP helpers (#4533) @blotus
Bug Fixes
  • fix(docker): allow spaces in ENROLL_INSTANCE_NAME (#4582) @sahilnyk
  • apiclient: return nil response if we couldnt connect to LAPI (#4573) @blotus
  • cscli lapi register: no error if the credentials file does not exist (#4570) @lopster568
  • fix(docker): avoid panic on colliding nested crowdsec labels (#4555) @arpitjain099
  • fix(syslog): don't close the shared acquisition output channel (#4553) @alxrxs
  • waf: track id/name pairs for all subrules (#4505) @blotus
  • apiserver: prevent from fetching JWT token from query string (#4554) @blotus
  • fix(leakybucket): emit overflow before pouring the next event (#4547) @blotus
  • loki: prevent duplicate log ingestion and improve timestamp handling (#4498) @Anulo2
  • db: use proper mutex when checking if flush can happen (#4528) @blotus
  • db: do not flush alerts with active decisions (#4527) @blotus
  • Fix Distinct() panic on []string and other non-[]any slices (#4543) @Synvoya
  • fix(docker): bouncer name strips wrong field from Docker secrets path (#4490) @tejgokani
Chore / Deps
  • ci(bats): fix scenarios badge color variable name (#4551) @blotus
  • ci(docker): inherit secrets so the docker environment secrets resolve (#4550) @blotus
  • build: use version based on latest for dev builds (#4583) @blotus
  • build(deps): bump the gomod group with 19 updates (#4581) @dependabot[bot]
  • build(deps): bump github.com/quic-go/quic-go from 0.57.0 to 0.59.1 (#4499) @dependabot[bot]
  • build(deps): bump cryptography from 46.0.6 to 48.0.1 in /build/docker/test (#4522) @dependabot[bot]
  • build(deps-dev): bump ruff from 0.15.20 to 0.15.22 in /build/docker/test in the uv group across 1 directory (#4559) @dependabot[bot]
  • WAF: update coraza (#4572) @blotus
  • build(deps): bump the github-actions group across 1 directory with 3 updates (#4558) @dependabot[bot]
  • build(deps): bump the gomod group across 1 directory with 21 updates (#4566) @dependabot[bot]
  • bump fpscanner to v1.0.7 (#4557) @blotus
  • update go-re2 to 1.11.0 (#4478) @blotus
  • Unify sqlite build flag (#4525) @zc-devs
  • fix TestCryptoObfuscationDefaultPoolSize (#4565) @buixor
  • build(deps): bump the gomod group across 1 directory with 30 updates (#4542) @dependabot[bot]
  • chore: delete publiccode.yml to comply with the process (#4552) @mazzma12
  • build(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 (#4549) @dependabot[bot]
  • CI hardening (#4546) @blotus
  • fix(docs): set pubblicode.yml to correct version (#4548) @mazzma12
  • build(deps): bump cloudflare/wrangler-action from 3.15.0 to 4.0.0 (#4541) @dependabot[bot]
  • build(deps): bump codecov/codecov-action from 6.0.0 to 7.0.0 (#4540) @dependabot[bot]
  • build(deps-dev): bump the uv group in /build/docker/test with 2 updates (#4537) @dependabot[bot]
  • build(deps): bump the github-actions group with 7 updates (#4538) @dependabot[bot]
  • build(deps): bump actions/checkout from 6.0.2 to 7.0.0 (#4539) @dependabot[bot]
  • build(deps): bump golang.org/x/net from 0.53.0 to 0.55.0 (#4544) @dependabot[bot]
  • build(deps): bump the github-actions group across 1 directory with 11 updates (#4524) @dependabot[bot]
  • build(deps): bump the uv group across 1 directory with 3 updates (#4519) @dependabot[bot]
  • build(deps): bump alpine from 3.23 to 3.24 in /build/docker in the docker group across 1 directory (#4513) @dependabot[bot]
Geolite2 notice

This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.

Installation

Take a look at the installation instructions.

View originalPermalink
How v1.8.0-rc1 went

v1.7.8

Latest
Added 2
  • WAF: OpenAPI schema validation
  • cscli: add `--quick` flag to enroll command
Changed 4
  • WAF: enforce body size limitation
  • Decision stream: move to chunked transfer by default
  • Propose an alternative, cleaner configuration for appsec-config
  • db: add some missing indexes
Fixed 4
  • cscli metrics: don't attempt to create a DB client if there's no DB config
  • papi: don't spam logs if chan is closed
  • alerts: use single transaction when creating alert and all related items
  • LAPI: enforce maximum body size for decompression
New Features
  • WAF: OpenAPI schema validation (#4097) @blotus
Improvements
  • WAF: enforce body size limitation (#4355) @blotus
  • Decision stream: move to chunked transfer by default (#4413) @blotus
  • cscli: add --quick flag to enroll command (#4350) @blotus
  • propose an alternative, cleaner configuration for appsec-config (#4397) @buixor
Bug Fixes
  • cscli metrics: don't attempt to create a DB client if there's no DB config (#4451) @blotus
  • papi: don't spam logs if chan is closed (#4439) @blotus
  • alerts: use single transaction when creating alert and all related items (#4438) @blotus
  • LAPI: enforce maximum body size for decompression
Chore / Deps
  • build(deps): bump the gomod group across 1 directory with 34 updates (#4453) @dependabot[bot]
  • build(deps): bump the github-actions group with 2 updates (#4447) @dependabot[bot]
  • build(deps): bump alpine from 3.21 to 3.23 in /build/docker in the docker group across 1 directory (#4441) @dependabot[bot]
  • build(deps): bump the github-actions group with 7 updates (#4443) @dependabot[bot]
  • build(deps): bump the uv group in /build/docker/test with 3 updates (#4442) @dependabot[bot]
  • db: add some missing indexes (#4435) @blotus
  • Dependencies update (#4412) @blotus
  • add PAPI metrics (#4411) @blotus
  • build(deps): bump github.com/aws/aws-lambda-go from 1.47.0 to 1.54.0 (#4402) @dependabot[bot]
  • build(deps): bump docker/login-action from 4.0.0 to 4.1.0 (#4403) @dependabot[bot]
  • build(deps): bump github.com/google/go-querystring from 1.1.0 to 1.2.0 (#4400) @dependabot[bot]
  • build(deps): bump actions/setup-go from 6.3.0 to 6.4.0 (#4404) @dependabot[bot]
  • build(deps): bump github.com/aws/aws-sdk-go-v2/service/sqs from 1.42.3 to 1.42.25 (#4405) @dependabot[bot]
  • build(deps): bump release-drafter/release-drafter from 6.4.0 to 7.1.1 (#4381) @dependabot[bot]
  • build(deps): bump codecov/codecov-action from 5.5.2 to 6.0.0 (#4388) @dependabot[bot]
  • build(deps): bump schneegans/dynamic-badges-action from 1.7.0 to 1.8.0 (#4393) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.6.0 to 8.0.0 (#4394) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.33.0 to 4.35.1 (#4395) @dependabot[bot]
  • update dependabot config (#4440) @blotus
  • build(deps): bump requests from 2.32.5 to 2.33.0 in /build/docker/test (#4389) @dependabot[bot]
  • build(deps): bump cryptography from 46.0.5 to 46.0.6 in /build/docker/test (#4391) @dependabot[bot]
  • build(deps): bump pygments from 2.19.2 to 2.20.0 in /build/docker/test (#4396) @dependabot[bot]
Geolite2 notice

This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.

Installation

Take a look at the installation instructions.

View originalPermalink
How v1.7.8 went

v1.7.8-rc1

Pre-release
Added 2
  • WAF: OpenAPI schema validation
  • cscli: add `--quick` flag to enroll command
Changed 4
  • WAF: enforce body size limitation
  • Decision stream: move to chunked transfer by default
  • Propose an alternative, cleaner configuration for appsec-config
  • db: add some missing indexes
Fixed 3
  • cscli metrics: don't attempt to create a DB client if there's no DB config
  • papi: don't spam logs if chan is closed
  • alerts: use single transaction when creating alert and all related items
New Features
  • WAF: OpenAPI schema validation (#4097) @blotus
Improvements
  • WAF: enforce body size limitation (#4355) @blotus
  • Decision stream: move to chunked transfer by default (#4413) @blotus
  • cscli: add --quick flag to enroll command (#4350) @blotus
  • propose an alternative, cleaner configuration for appsec-config (#4397) @buixor
Bug Fixes
  • cscli metrics: don't attempt to create a DB client if there's no DB config (#4451) @blotus
  • papi: don't spam logs if chan is closed (#4439) @blotus
  • alerts: use single transaction when creating alert and all related items (#4438) @blotus
Chore / Deps
  • build(deps): bump the gomod group across 1 directory with 34 updates (#4453) @dependabot[bot]
  • build(deps): bump the github-actions group with 2 updates (#4447) @dependabot[bot]
  • build(deps): bump alpine from 3.21 to 3.23 in /build/docker in the docker group across 1 directory (#4441) @dependabot[bot]
  • build(deps): bump the github-actions group with 7 updates (#4443) @dependabot[bot]
  • build(deps): bump the uv group in /build/docker/test with 3 updates (#4442) @dependabot[bot]
  • db: add some missing indexes (#4435) @blotus
  • Dependencies update (#4412) @blotus
  • add PAPI metrics (#4411) @blotus
  • build(deps): bump github.com/aws/aws-lambda-go from 1.47.0 to 1.54.0 (#4402) @dependabot[bot]
  • build(deps): bump docker/login-action from 4.0.0 to 4.1.0 (#4403) @dependabot[bot]
  • build(deps): bump github.com/google/go-querystring from 1.1.0 to 1.2.0 (#4400) @dependabot[bot]
  • build(deps): bump actions/setup-go from 6.3.0 to 6.4.0 (#4404) @dependabot[bot]
  • build(deps): bump github.com/aws/aws-sdk-go-v2/service/sqs from 1.42.3 to 1.42.25 (#4405) @dependabot[bot]
  • build(deps): bump release-drafter/release-drafter from 6.4.0 to 7.1.1 (#4381) @dependabot[bot]
  • build(deps): bump codecov/codecov-action from 5.5.2 to 6.0.0 (#4388) @dependabot[bot]
  • build(deps): bump schneegans/dynamic-badges-action from 1.7.0 to 1.8.0 (#4393) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.6.0 to 8.0.0 (#4394) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.33.0 to 4.35.1 (#4395) @dependabot[bot]
  • update dependabot config (#4440) @blotus
  • build(deps): bump requests from 2.32.5 to 2.33.0 in /build/docker/test (#4389) @dependabot[bot]
  • build(deps): bump cryptography from 46.0.5 to 46.0.6 in /build/docker/test (#4391) @dependabot[bot]
  • build(deps): bump pygments from 2.19.2 to 2.20.0 in /build/docker/test (#4396) @dependabot[bot]
Geolite2 notice

This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.

Installation

Take a look at the installation instructions.

View originalPermalink
How v1.7.8-rc1 went

v1.7.7

Added 4
  • WAF rules can now contain a mix of AND/OR conditions without limits
  • Add new kind alert attribute to identify its source
  • Add cscli allowlist import command
  • Add LookupFile and FileMap expr helpers
Changed 4
  • RE2 is now used by default for evaluating regexp in parsers on Linux
  • Support for the HTTP_PROXY environment variable in the notification-http plugin
  • WAF exposes more transformations from coraza
  • Support waf- alias in cscli
Fixed 9
  • Fix resource leak under high load
  • Apply allowlist items to existing decisions in batch
  • Fix WAF tests for modsec rules generation
  • Add file notification plugin in MSI package on Windows
  • Fix leakroutine by calling cancel after leakroutine returns
  • Lowercase x-ms-date header in notification-sentinel for correct HMAC

CrowdSec 1.7.7 brings 2 major changes:

  • On linux, RE2 is now used by default for evaluating regexp in parsers
  • WAF rules can now contain a mix of AND/OR conditions without any limits, giving much greater flexibility when writing new rules
RE2 by default on linux

CrowdsSec has supported for a long time using RE2 as the regexp engine, and with this release we make it the default.

CrowdSec has always used the builtin Go regexp package, which is a Go reimplementation of the RE2 library, but with known performance limitations.

The switch to RE2 will bring significantly increased regexp performance (one of the most critical part of CrowdSec) at the cost of slightly longer regexp compilation and higher baseline memory usage.

[!IMPORTANT] If you encounter any issues with the new regexp engine, you can fallback to the previous Go implementation by setting the feature flag re2_disable_grok_support (see the documentation).

Other changes

Other notable changes include:

  • a new kind attribute for alerts used to identify its source (a scenario, a WAF rule, a manual decision creation, ...)
  • a new cscli allowlist import command
  • support for the HTTP_PROXY environment variable in the notification-http plugin
  • A resource leak under high load was fixed

Full changelog

New Features
  • add LookupFile and FileMap expr helpers (#4372) @buixor
  • waf rules: allow arbitrary mix of AND and OR conditions (#4358) @blotus
Improvements
  • enable RE2 support by default on linux (#4386) @blotus
  • cscli allowlists: add import command (#4378) @blotus
  • WAF: expose more transformations from coraza (#4140) @blotus
  • Add new kind alert attribute (#4351) @blotus
  • Use environment proxy settings for notification-http (#4364) @op3
Bug Fixes
  • allowlists: apply items to existing decisions in batch (#4095) @blotus
  • waf: fix tests for modsec rules generation (#4385) @blotus
  • windows: add file notification plugin in MSI package (#4367) @blotus
  • leakroutine: call cancel after leakroutine returns (#4369) @blotus
  • notification-sentinel: lower-case x-ms-date header for correct HMAC (#4288) @ebirn
  • tests: remove temporary sqlite/plugin files from /tmp/ (#4332) @mmetc
  • pkg/apiserver: fix scenario count in debug log (#4333) @mmetc
  • pkg/csplugin: prevent race condition, deadlock (#4294) @mmetc
  • pkg/acquisitioncontext: minimal fix for data race in tests (#4327) @mmetc
  • acquisition/file: minimal fix for data race in tests (#4326) @mmetc
  • fix lint fsutil/freebsd: unnecessary conversion (#4324) @mmetc
  • cscli: consistent status and usage message for unknown subcommands (#4320) @mmetc
  • cscli detect: set log type for caddy unit to "syslog" (#4321) @mmetc
  • CI: add published_at to version.crowdsec.net/latest (#4291) @blotus
  • cmd/crowdsec: assign overflow after parsing (#4226) @mmetc
  • waf: format as CRS match only if anomaly score is not 0 (#4230) @blotus
Changes
  • build(deps): bump cryptography from 46.0.3 to 46.0.5 in /build/docker/test (#4298) @dependabot[bot]
  • support for waf- alias in cscli (#4347) @buixor
  • refact pkg/dumps: reduce complexity (#4209) @mmetc
  • lint: refact pkg/dumps for nilaway (#4208) @mmetc
  • refact pkg/parser: redundant indirection (#4344) @mmetc
  • refact pkg/parser: extract+embed NodeConfig in Node struct (#4343) @mmetc
  • move calls to trace.ReportPanic() on top of goroutines (#4338) @mmetc
  • pkg/csplugin: simplify notification loop; noop with empty queue (#4328) @mmetc
  • pkg/parsers: light refact, remove redundant code (#4213) @mmetc
  • refact cmd/crowdsec: encapsulate cache into alertBuffer (#4300) @mmetc
  • cmd/notification-*: don't provide the same context twice for request (#4316) @mmetc
  • don't flush 127.0.0.1 (#4315) @sabban
  • clipapi: replace tomb with errgroup (#4207) @mmetc
  • refact cmd/crowdsec: remove redundant global variable (#4299) @mmetc
  • refact: remove unused code in crowdsec-cli, apiserver, acquisition, database (#4304) @mmetc
  • refact pkg/leakybucket: trim down redundant Leaky struct fields (#4290) @mmetc
  • pkg/leakybucket: remove global bucketStore, unused parameters + tags (#4286) @mmetc
  • pkg/leakybucket: remove Simulated field from Leaky, keep it in config (#4285) @mmetc
  • pkg/leakybucket: extract BucketSpec from BucketFactory (#4284) @mmetc
  • refact pkg/leakybucket: extract methods from LoadBucket() part 2 (#4282) @mmetc
  • pkg/leakybucket: refact test loop, more explicit failures in testFile() (#4281) @mmetc
  • refact pkg/leakybucket: extract methods from LoadBucket() (#4279) @mmetc
  • pkg/leakybucket: replace Signal chan with explicit read/done chans (#4277) @mmetc
  • pkg/leakybucket: replace waitgroups with single rwlock (#4276) @mmetc
  • pkg/leakybucket: garbage collect: compare float with epsilon (#4275) @mmetc
  • pkg/leakybucket: refactor tests (#4272) @mmetc
  • pkg/leakybucket: replace sycn.Map with map + mutex (#4271) @mmetc
  • pkg/leakybucket: replace global counter with call to bucket store (#4273) @mmetc
  • pkg/leakybucket: review README.md (#4274) @mmetc
  • pkg/leakybucket: encapsulate store map + add methods (#4253) @mmetc
  • pkg/leakybucket: remove redundant bool var (#4252) @mmetc
  • fix hub console side (#4266) @sabban
  • version workflow fix (#4262) @sabban
  • rename the prod branch to main (#4261) @sabban
  • add version workflow (#4210) @sabban
  • pkg/leakybucket: remove unused global (#4251) @mmetc
  • pkg/leakybucket: pass bucket factories by pointer (#4250) @mmetc
  • pkt/leakybucket: compileScopeFilter() -> ScopeType.CompileFilter() (#4247) @mmetc
  • pkg/leakybucket: rename OverflowFilter -> OverflowProcessor (#4248) @mmetc
  • pkg/leakybucket: rename Buckets -> BucketStore (#4246) @mmetc
  • refact leaky bayesian: method to function, unlock w/defer (#4242) @mmetc
  • pkg/leakybucket: early return (#4244) @mmetc
  • pkg/leakybucket: variable shorthand (#4245) @mmetc
  • pkg/leakybucket: move LeakRoutine to method, rename parameters (#4243) @mmetc
  • pkg/leakybucket: review bucket validation and tests (#4241) @mmetc
  • refact: remove unnecessary pointers to map, string, mutex (#4212) @mmetc
  • pkg/leakybucket: function to method BucketFactory.LoadBucket() (#4229) @mmetc
  • pkg/leakybucket: BucketType interface, method BucketFactory.Validate() (#4228) @mmetc
Chore / Deps
  • build(deps): bump github.com/buger/jsonparser from 1.1.1 to 1.1.2 (#4382) @dependabot[bot]
  • CI: use windows-2025 image (#4379) @blotus
  • build(deps): bump github/codeql-action from 4.32.6 to 4.33.0 (#4371) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.5.0 to 7.6.0 (#4373) @dependabot[bot]
  • build(deps): bump google.golang.org/grpc from 1.74.2 to 1.79.3 (#4376) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.3.1 to 7.5.0 (#4366) @dependabot[bot]
  • build(deps): bump filippo.io/edwards25519 from 1.1.0 to 1.1.1 (#4319) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.32.5 to 4.32.6 (#4360) @dependabot[bot]
  • build(deps): bump docker/build-push-action from 6.19.2 to 7.0.0 (#4361) @dependabot[bot]
  • build(deps): bump release-drafter/release-drafter from 6.2.0 to 6.4.0 (#4362) @dependabot[bot]
  • build(deps): bump docker/setup-buildx-action from 3.12.0 to 4.0.0 (#4356) @dependabot[bot]
  • build(deps): bump docker/setup-qemu-action from 3.7.0 to 4.0.0 (#4353) @dependabot[bot]
  • build(deps): bump actions/setup-node from 6.2.0 to 6.3.0 (#4352) @dependabot[bot]
  • build(deps): bump docker/login-action from 3.7.0 to 4.0.0 (#4354) @dependabot[bot]
  • deps: update actions and golangci-lint (#4348) @mmetc
  • build(deps): bump github/codeql-action from 4.32.4 to 4.32.5 (#4345) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.3.0 to 7.3.1 (#4346) @dependabot[bot]
  • build(deps): bump actions/setup-go from 6.2.0 to 6.3.0 (#4339) @dependabot[bot]
  • build(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 (#4342) @dependabot[bot]
  • replace trace.CatchPanic(...) with trace.ReportPanic() (#4336) @mmetc
  • build(deps): bump github/codeql-action from 4.32.3 to 4.32.4 (#4322) @dependabot[bot]
  • deps: update gocron v1 -> v2 (#4317) @mmetc
  • build(deps): bump docker/build-push-action from 6.19.0 to 6.19.2 (#4306) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.32.2 to 4.32.3 (#4312) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.32.1 to 4.32.2 (#4292) @dependabot[bot]
  • update golangci-lint 2.9 (#4302) @mmetc
  • build(deps): bump astral-sh/setup-uv from 7.2.1 to 7.3.0 (#4296) @dependabot[bot]
  • build(deps): bump docker/build-push-action from 6.18.0 to 6.19.0 (#4303) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.32.0 to 4.32.1 (#4278) @dependabot[bot]
  • build(deps): bump actions/setup-node from 4.4.0 to 6.2.0 (#4264) @dependabot[bot]
  • CI: update python and dependencies (#4249) @mmetc
  • build(deps): bump actions/checkout from 6.0.1 to 6.0.2 (#4263) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.2.0 to 7.2.1 (#4265) @dependabot[bot]
  • build(deps): bump docker/login-action from 3.6.0 to 3.7.0 (#4257) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.31.11 to 4.32.0 (#4254) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.31.10 to 4.31.11 (#4233) @dependabot[bot]
  • build(deps): bump actions/checkout from 6.0.1 to 6.0.2 (#4234) @dependabot[bot]
  • build(deps): bump release-drafter/release-drafter from 6.1.0 to 6.2.0 (#4222) @dependabot[bot]
  • build(deps): bump actions/setup-python from 6.1.0 to 6.2.0 (#4223) @dependabot[bot]
Geolite2 notice

This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.

Installation

Take a look at the installation instructions.

View originalPermalink
How v1.7.7 went

v1.7.7-rc1

Pre-release
Added 5
  • Add LookupFile and FileMap expr helpers
  • Add LookupFile and FileMap expr helpers
  • Allow arbitrary mix of AND and OR conditions in WAF rules
  • Add new kind alert attribute
  • Add cscli allowlists import command
Changed 4
  • Enable RE2 support by default on Linux
  • Expose more transformations from coraza in WAF
  • Use environment proxy settings for notification-http
  • Add support for waf- alias in cscli
Fixed 11
  • Apply allowlist items to existing decisions in batch
  • Fix tests for modsec rules generation
  • Add file notification plugin in MSI package for Windows
  • Call cancel after leakroutine returns
  • Lower-case x-ms-date header in notification-sentinel for correct HMAC
  • Remove temporary sqlite and plugin files from /tmp/ in tests
New Features
  • add LookupFile and FileMap expr helpers (#4372) @buixor
  • waf rules: allow arbitrary mix of AND and OR conditions (#4358) @blotus
Improvements
  • enable RE2 support by default on linux (#4386) @blotus
  • cscli allowlists: add import command (#4378) @blotus
  • WAF: expose more transformations from coraza (#4140) @blotus
  • Add new kind alert attribute (#4351) @blotus
  • Use environment proxy settings for notification-http (#4364) @op3
Bug Fixes
  • allowlists: apply items to existing decisions in batch (#4095) @blotus
  • waf: fix tests for modsec rules generation (#4385) @blotus
  • windows: add file notification plugin in MSI package (#4367) @blotus
  • leakroutine: call cancel after leakroutine returns (#4369) @blotus
  • notification-sentinel: lower-case x-ms-date header for correct HMAC (#4288) @ebirn
  • tests: remove temporary sqlite/plugin files from /tmp/ (#4332) @mmetc
  • pkg/apiserver: fix scenario count in debug log (#4333) @mmetc
  • pkg/csplugin: prevent race condition, deadlock (#4294) @mmetc
  • pkg/acquisitioncontext: minimal fix for data race in tests (#4327) @mmetc
  • acquisition/file: minimal fix for data race in tests (#4326) @mmetc
  • fix lint fsutil/freebsd: unnecessary conversion (#4324) @mmetc
  • cscli: consistent status and usage message for unknown subcommands (#4320) @mmetc
  • cscli detect: set log type for caddy unit to "syslog" (#4321) @mmetc
  • CI: add published_at to version.crowdsec.net/latest (#4291) @blotus
  • cmd/crowdsec: assign overflow after parsing (#4226) @mmetc
  • waf: format as CRS match only if anomaly score is not 0 (#4230) @blotus
Changes
  • build(deps): bump cryptography from 46.0.3 to 46.0.5 in /build/docker/test (#4298) @dependabot[bot]
  • support for waf- alias in cscli (#4347) @buixor
  • refact pkg/dumps: reduce complexity (#4209) @mmetc
  • lint: refact pkg/dumps for nilaway (#4208) @mmetc
  • refact pkg/parser: redundant indirection (#4344) @mmetc
  • refact pkg/parser: extract+embed NodeConfig in Node struct (#4343) @mmetc
  • move calls to trace.ReportPanic() on top of goroutines (#4338) @mmetc
  • pkg/csplugin: simplify notification loop; noop with empty queue (#4328) @mmetc
  • pkg/parsers: light refact, remove redundant code (#4213) @mmetc
  • refact cmd/crowdsec: encapsulate cache into alertBuffer (#4300) @mmetc
  • cmd/notification-*: don't provide the same context twice for request (#4316) @mmetc
  • don't flush 127.0.0.1 (#4315) @sabban
  • clipapi: replace tomb with errgroup (#4207) @mmetc
  • refact cmd/crowdsec: remove redundant global variable (#4299) @mmetc
  • refact: remove unused code in crowdsec-cli, apiserver, acquisition, database (#4304) @mmetc
  • refact pkg/leakybucket: trim down redundant Leaky struct fields (#4290) @mmetc
  • pkg/leakybucket: remove global bucketStore, unused parameters + tags (#4286) @mmetc
  • pkg/leakybucket: remove Simulated field from Leaky, keep it in config (#4285) @mmetc
  • pkg/leakybucket: extract BucketSpec from BucketFactory (#4284) @mmetc
  • refact pkg/leakybucket: extract methods from LoadBucket() part 2 (#4282) @mmetc
  • pkg/leakybucket: refact test loop, more explicit failures in testFile() (#4281) @mmetc
  • refact pkg/leakybucket: extract methods from LoadBucket() (#4279) @mmetc
  • pkg/leakybucket: replace Signal chan with explicit read/done chans (#4277) @mmetc
  • pkg/leakybucket: replace waitgroups with single rwlock (#4276) @mmetc
  • pkg/leakybucket: garbage collect: compare float with epsilon (#4275) @mmetc
  • pkg/leakybucket: refactor tests (#4272) @mmetc
  • pkg/leakybucket: replace sycn.Map with map + mutex (#4271) @mmetc
  • pkg/leakybucket: replace global counter with call to bucket store (#4273) @mmetc
  • pkg/leakybucket: review README.md (#4274) @mmetc
  • pkg/leakybucket: encapsulate store map + add methods (#4253) @mmetc
  • pkg/leakybucket: remove redundant bool var (#4252) @mmetc
  • fix hub console side (#4266) @sabban
  • version workflow fix (#4262) @sabban
  • rename the prod branch to main (#4261) @sabban
  • add version workflow (#4210) @sabban
  • pkg/leakybucket: remove unused global (#4251) @mmetc
  • pkg/leakybucket: pass bucket factories by pointer (#4250) @mmetc
  • pkt/leakybucket: compileScopeFilter() -> ScopeType.CompileFilter() (#4247) @mmetc
  • pkg/leakybucket: rename OverflowFilter -> OverflowProcessor (#4248) @mmetc
  • pkg/leakybucket: rename Buckets -> BucketStore (#4246) @mmetc
  • refact leaky bayesian: method to function, unlock w/defer (#4242) @mmetc
  • pkg/leakybucket: early return (#4244) @mmetc
  • pkg/leakybucket: variable shorthand (#4245) @mmetc
  • pkg/leakybucket: move LeakRoutine to method, rename parameters (#4243) @mmetc
  • pkg/leakybucket: review bucket validation and tests (#4241) @mmetc
  • refact: remove unnecessary pointers to map, string, mutex (#4212) @mmetc
  • pkg/leakybucket: function to method BucketFactory.LoadBucket() (#4229) @mmetc
  • pkg/leakybucket: BucketType interface, method BucketFactory.Validate() (#4228) @mmetc
Chore / Deps
  • build(deps): bump github.com/buger/jsonparser from 1.1.1 to 1.1.2 (#4382) @dependabot[bot]
  • CI: use windows-2025 image (#4379) @blotus
  • build(deps): bump github/codeql-action from 4.32.6 to 4.33.0 (#4371) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.5.0 to 7.6.0 (#4373) @dependabot[bot]
  • build(deps): bump google.golang.org/grpc from 1.74.2 to 1.79.3 (#4376) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.3.1 to 7.5.0 (#4366) @dependabot[bot]
  • build(deps): bump filippo.io/edwards25519 from 1.1.0 to 1.1.1 (#4319) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.32.5 to 4.32.6 (#4360) @dependabot[bot]
  • build(deps): bump docker/build-push-action from 6.19.2 to 7.0.0 (#4361) @dependabot[bot]
  • build(deps): bump release-drafter/release-drafter from 6.2.0 to 6.4.0 (#4362) @dependabot[bot]
  • build(deps): bump docker/setup-buildx-action from 3.12.0 to 4.0.0 (#4356) @dependabot[bot]
  • build(deps): bump docker/setup-qemu-action from 3.7.0 to 4.0.0 (#4353) @dependabot[bot]
  • build(deps): bump actions/setup-node from 6.2.0 to 6.3.0 (#4352) @dependabot[bot]
  • build(deps): bump docker/login-action from 3.7.0 to 4.0.0 (#4354) @dependabot[bot]
  • deps: update actions and golangci-lint (#4348) @mmetc
  • build(deps): bump github/codeql-action from 4.32.4 to 4.32.5 (#4345) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.3.0 to 7.3.1 (#4346) @dependabot[bot]
  • build(deps): bump actions/setup-go from 6.2.0 to 6.3.0 (#4339) @dependabot[bot]
  • build(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 (#4342) @dependabot[bot]
  • replace trace.CatchPanic(...) with trace.ReportPanic() (#4336) @mmetc
  • build(deps): bump github/codeql-action from 4.32.3 to 4.32.4 (#4322) @dependabot[bot]
  • deps: update gocron v1 -> v2 (#4317) @mmetc
  • build(deps): bump docker/build-push-action from 6.19.0 to 6.19.2 (#4306) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.32.2 to 4.32.3 (#4312) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.32.1 to 4.32.2 (#4292) @dependabot[bot]
  • update golangci-lint 2.9 (#4302) @mmetc
  • build(deps): bump astral-sh/setup-uv from 7.2.1 to 7.3.0 (#4296) @dependabot[bot]
  • build(deps): bump docker/build-push-action from 6.18.0 to 6.19.0 (#4303) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.32.0 to 4.32.1 (#4278) @dependabot[bot]
  • build(deps): bump actions/setup-node from 4.4.0 to 6.2.0 (#4264) @dependabot[bot]
  • CI: update python and dependencies (#4249) @mmetc
  • build(deps): bump actions/checkout from 6.0.1 to 6.0.2 (#4263) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.2.0 to 7.2.1 (#4265) @dependabot[bot]
  • build(deps): bump docker/login-action from 3.6.0 to 3.7.0 (#4257) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.31.11 to 4.32.0 (#4254) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.31.10 to 4.31.11 (#4233) @dependabot[bot]
  • build(deps): bump actions/checkout from 6.0.1 to 6.0.2 (#4234) @dependabot[bot]
  • build(deps): bump release-drafter/release-drafter from 6.1.0 to 6.2.0 (#4222) @dependabot[bot]
  • build(deps): bump actions/setup-python from 6.1.0 to 6.2.0 (#4223) @dependabot[bot]
Geolite2 notice

This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.

Installation

Take a look at the installation instructions.

View originalPermalink
How v1.7.7-rc1 went

v1.7.6

Fixed 1
  • Fix assign overflow after parsing in cmd/crowdsec
Changes
Bug Fixes
  • cmd/crowdsec: assign overflow after parsing (#4225) @mmetc
Geolite2 notice

This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.

Installation

Take a look at the installation instructions.

View originalPermalink
How v1.7.6 went

v1.7.5

Added 2
  • Add ParseKVLax for flexible key-value parsing
  • Support transaction id header for request tracing in appsec
Changed 12
  • Replace syscall with unix/windows packages where possible
  • Replace errors.Wrapf with fmt.Errorf and remove dependency on github.com/pkg/errors
  • Update golangci-lint to 2.8
  • Refactor acquisition configuration validation and tests
  • Replace global variables with injected StateDumper in pkg/leakybucket
  • Refactor notification plugins for readability and remove unnecessary pointers
Fixed 6
  • Check if decision is allowlisted before adding it in papi
  • Always reuse the stored token in CAPI
  • Prevent duplicate send in case of transform error in pkg/acquisition
  • Do not prepare the hub in lapi-only containers
  • Fix build issue on freebsd and add cross platform CI build and lint target
  • Prevent data race in appsec tests
Changes
  • replace syscall with unix/windows packages where possible (#3032) @mmetc
  • pkg/acquisition: refact configuration validation and tests (#4187) @mmetc
  • pkg/acquisition: remove/restore mock datasources after usage (#4190) @mmetc
  • pkg/leakybucket: replace global variables with injected StateDumper (#4197) @mmetc
  • pkg/acquisition: method docs, deduplicate module names (#4192) @mmetc
  • errors.Wrapf -> fmt.Errorf, remove dependency on github.com/pkg/errors (#4198) @mmetc
  • update golangci-lint 2.8 (#4194) @mmetc
  • notification plugins: readability / dry refact, unnecessary pointers (#4166) @mmetc
  • refact acquisition/appsec: happy path (#4183) @mmetc
  • pkg/acquisition/registry, move datasource registration to avoid dependency (#4189) @mmetc
  • gin middleware: drop closures (#4186) @mmetc
  • acquisition/journalctl: test cleanup (#4182) @mmetc
  • cscli hubtest: extract method finalizeRun() (#4181) @mmetc
  • refact cmd/crowdsec: remove globals ParseDump, BucketPourTrack (#4184) @mmetc
  • refact pkg/apiserver: happy path; nil guard (#4180) @mmetc
  • refact pkg/leakybucket: drop closures (#4178) @mmetc
  • cmd/crowdsec: rename pipeline channels (#4175) @mmetc
  • move dir debian, rpm to /build/ (#4174) @mmetc
  • refact cmd/crowdsec: remove globals, lint, etc (#4163) @mmetc
  • lint: modernize - enable slicessort, stringsseq (#4162) @mmetc
  • appsec: inject dependencies, avoid globals (#4148) @mmetc
  • CI: move windows build scripts to ./build/windows (#4145) @mmetc
  • remove obsolete readme (replaced by go generate) (#4164) @mmetc
  • cmd/crowdsec: refact dump.go, loops (#4158) @mmetc
  • cmd/crowdsec: refact output.go, pour.go, parse.go (#4157) @mmetc
  • refact: drop parserTomb, lpMetricsTomb (#4138) @mmetc
  • drop unused method Client.IsMachineRegistered() (#4121) @mmetc
  • CI: build with the tag "nomsgpack" to reduce binary size (#4151) @mmetc
  • move ./docker to ./build/docker (#4130) @mmetc
  • acquisition refact: context-aware OneShot(), for file + journalctl + wineventlog (#4125) @mmetc
  • lint: forbidigo (no print or printf in production, prefer fprint) (#4141) @mmetc
  • CI: avoid using nolint with revive (#4144) @mmetc
  • Lint: add explicit per-linter settings (#4134) @mmetc
  • refact pkg/acquisition: split docker.go (#4065) @mmetc
  • get rid of tombs in leakybucket package (#4127) @sabban
  • refact pkg/acquisition: cloudwatch configuration (#4058) @mmetc
  • refact pkg/acquisition: kinesis configuration (#4059) @mmetc
  • refact pkg/acquisition: k8saudit configuration (#4060) @mmetc
  • refact pkg/acquisition: http configuration (#4061) @mmetc
  • refact heartbeat: context-aware method (#4126) @mmetc
  • pkg/leakybucket refact: unexport, unused, explicit field names (#4123) @mmetc
  • docker build: run builds on large runner (#4120) @blotus
Improvements
  • docker datasource schema (#4206) @mmetc
  • lint: enable bodyclose (ensure response bodies are closed to avoid leaks) (#4200) @mmetc
  • feat: Add ParseKVLax for Flexible Key-Value Parsing (#4007) @LaurenceJJones
  • pkg/parser: avoid calling spew unless trace (#4156) @mmetc
  • leakybucket: reduce error verbosity, test for misconfiguration (#4087) @mmetc
  • feat(appsec): support transaction id header for request tracing (#4124) @LaurenceJJones
Bug Fixes
  • update functional tests with time-based-bf (#4217) @mmetc
  • papi: check if decision is allowlisted before adding it (#4196) @blotus
  • pkg/acquisition: register mock datasource for YAML tests (#4205) @mmetc
  • pkg/acquisition: prevent duplicate send in case of transform error (#4191) @mmetc
  • CI fix - exit lapi during hub tests; pass container struct reference instead of slice (#4202) @mmetc
  • CAPI: always reuse the stored token (#4201) @blotus
  • fix #4066: don't prepare the hub in lapi-only containers (#4169) @mmetc
  • fix #3991 - Acquisition config formatting in bug template (#4170) @mmetc
  • fix typos in function name, comments and user-facing docs (#4154) @mmetc
  • refact appsec tests: prevent data race (#3902) @mmetc
  • fix build issue on freebsd, add cross platform CI build and lint target (#4109) @mmetc
Chore / Deps
  • build(deps): bump actions/setup-go from 6.1.0 to 6.2.0 (#4195) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.31.9 to 4.31.10 (#4193) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.1.6 to 7.2.0 (#4185) @dependabot[bot]
  • CI/tests: update bats-*, remove bats-mock (#4172) @mmetc
  • deps: update modernc.org/sqlite (#4177) @mmetc
  • CI, docker: update yq to v4.50.1 (#4179) @mmetc
  • build(deps): bump docker/setup-buildx-action from 3.11.1 to 3.12.0 (#4167) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.31.8 to 4.31.9 (#4153) @dependabot[bot]
  • update expr to 1.17.7 (#4150) @blotus
  • build(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 (#4146) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.1.5 to 7.1.6 (#4147) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.31.7 to 4.31.8 (#4135) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.31.6 to 4.31.7 (#4116) @dependabot[bot]
  • CI: update and/or pin actions with tag comments (#4108) @mmetc
  • CI: update golangci-lint to 2.7 (#4110) @mmetc
  • make: move ./mk to ./build/mk, update gmsl (#4111) @mmetc
Geolite2 notice

This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.

Installation

Take a look at the installation instructions.

View originalPermalink
How v1.7.5 went

v1.7.5-rc1

Pre-release
Added 2
  • Add ParseKVLax for flexible key-value parsing
  • Support transaction id header for request tracing in appsec
Changed 14
  • Replace syscall with unix/windows packages where possible
  • Replace errors.Wrapf with fmt.Errorf and remove dependency on github.com/pkg/errors
  • Update golangci-lint to 2.8
  • Replace global variables with injected StateDumper in pkg/leakybucket
  • Move debian and rpm directories to /build/
  • Move docker directory to /build/docker
Fixed 4
  • Check if decision is allowlisted before adding it in papi
  • Prevent duplicate send in case of transform error in pkg/acquisition
  • Always reuse the stored token in CAPI
  • Fix FreeBSD build issue and add cross platform CI build and lint target
Changes
  • replace syscall with unix/windows packages where possible (#3032) @mmetc
  • pkg/acquisition: refact configuration validation and tests (#4187) @mmetc
  • pkg/acquisition: remove/restore mock datasources after usage (#4190) @mmetc
  • pkg/leakybucket: replace global variables with injected StateDumper (#4197) @mmetc
  • pkg/acquisition: method docs, deduplicate module names (#4192) @mmetc
  • errors.Wrapf -> fmt.Errorf, remove dependency on github.com/pkg/errors (#4198) @mmetc
  • update golangci-lint 2.8 (#4194) @mmetc
  • notification plugins: readability / dry refact, unnecessary pointers (#4166) @mmetc
  • refact acquisition/appsec: happy path (#4183) @mmetc
  • pkg/acquisition/registry, move datasource registration to avoid dependency (#4189) @mmetc
  • gin middleware: drop closures (#4186) @mmetc
  • acquisition/journalctl: test cleanup (#4182) @mmetc
  • cscli hubtest: extract method finalizeRun() (#4181) @mmetc
  • refact cmd/crowdsec: remove globals ParseDump, BucketPourTrack (#4184) @mmetc
  • refact pkg/apiserver: happy path; nil guard (#4180) @mmetc
  • refact pkg/leakybucket: drop closures (#4178) @mmetc
  • cmd/crowdsec: rename pipeline channels (#4175) @mmetc
  • move dir debian, rpm to /build/ (#4174) @mmetc
  • refact cmd/crowdsec: remove globals, lint, etc (#4163) @mmetc
  • lint: modernize - enable slicessort, stringsseq (#4162) @mmetc
  • appsec: inject dependencies, avoid globals (#4148) @mmetc
  • CI: move windows build scripts to ./build/windows (#4145) @mmetc
  • remove obsolete readme (replaced by go generate) (#4164) @mmetc
  • cmd/crowdsec: refact dump.go, loops (#4158) @mmetc
  • cmd/crowdsec: refact output.go, pour.go, parse.go (#4157) @mmetc
  • refact: drop parserTomb, lpMetricsTomb (#4138) @mmetc
  • drop unused method Client.IsMachineRegistered() (#4121) @mmetc
  • CI: build with the tag "nomsgpack" to reduce binary size (#4151) @mmetc
  • move ./docker to ./build/docker (#4130) @mmetc
  • acquisition refact: context-aware OneShot(), for file + journalctl + wineventlog (#4125) @mmetc
  • lint: forbidigo (no print or printf in production, prefer fprint) (#4141) @mmetc
  • CI: avoid using nolint with revive (#4144) @mmetc
  • Lint: add explicit per-linter settings (#4134) @mmetc
  • refact pkg/acquisition: split docker.go (#4065) @mmetc
  • get rid of tombs in leakybucket package (#4127) @sabban
  • refact pkg/acquisition: cloudwatch configuration (#4058) @mmetc
  • refact pkg/acquisition: kinesis configuration (#4059) @mmetc
  • refact pkg/acquisition: k8saudit configuration (#4060) @mmetc
  • refact pkg/acquisition: http configuration (#4061) @mmetc
  • refact heartbeat: context-aware method (#4126) @mmetc
  • pkg/leakybucket refact: unexport, unused, explicit field names (#4123) @mmetc
  • docker build: run builds on large runner (#4120) @blotus
Improvements
  • docker datasource schema (#4206) @mmetc
  • lint: enable bodyclose (ensure response bodies are closed to avoid leaks) (#4200) @mmetc
  • feat: Add ParseKVLax for Flexible Key-Value Parsing (#4007) @LaurenceJJones
  • pkg/parser: avoid calling spew unless trace (#4156) @mmetc
  • leakybucket: reduce error verbosity, test for misconfiguration (#4087) @mmetc
  • feat(appsec): support transaction id header for request tracing (#4124) @LaurenceJJones
Bug Fixes
  • papi: check if decision is allowlisted before adding it (#4196) @blotus
  • pkg/acquisition: register mock datasource for YAML tests (#4205) @mmetc
  • pkg/acquisition: prevent duplicate send in case of transform error (#4191) @mmetc
  • CI fix - exit lapi during hub tests; pass container struct reference instead of slice (#4202) @mmetc
  • CAPI: always reuse the stored token (#4201) @blotus
  • fix #4066: don't prepare the hub in lapi-only containers (#4169) @mmetc
  • fix #3991 - Acquisition config formatting in bug template (#4170) @mmetc
  • fix typos in function name, comments and user-facing docs (#4154) @mmetc
  • refact appsec tests: prevent data race (#3902) @mmetc
  • fix build issue on freebsd, add cross platform CI build and lint target (#4109) @mmetc
Chore / Deps
  • build(deps): bump actions/setup-go from 6.1.0 to 6.2.0 (#4195) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.31.9 to 4.31.10 (#4193) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.1.6 to 7.2.0 (#4185) @dependabot[bot]
  • CI/tests: update bats-*, remove bats-mock (#4172) @mmetc
  • deps: update modernc.org/sqlite (#4177) @mmetc
  • CI, docker: update yq to v4.50.1 (#4179) @mmetc
  • build(deps): bump docker/setup-buildx-action from 3.11.1 to 3.12.0 (#4167) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.31.8 to 4.31.9 (#4153) @dependabot[bot]
  • update expr to 1.17.7 (#4150) @blotus
  • build(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 (#4146) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.1.5 to 7.1.6 (#4147) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.31.7 to 4.31.8 (#4135) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.31.6 to 4.31.7 (#4116) @dependabot[bot]
  • CI: update and/or pin actions with tag comments (#4108) @mmetc
  • CI: update golangci-lint to 2.7 (#4110) @mmetc
  • make: move ./mk to ./build/mk, update gmsl (#4111) @mmetc
Geolite2 notice

This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.

Installation

Take a look at the installation instructions.

View originalPermalink
How v1.7.5-rc1 went

v1.7.4

Added 1
  • WAF: Add DropRequest helper to block request in hooks
Changed 11
  • Remove CROWDSEC_CONTAINER_ENV from docker
  • Update syslog to RestartableStreamer
  • Add log_media="syslog" option to logging configuration
  • Use backoff package to retry notifications in pkg/csplugin
  • Replace prom2json with native Prometheus parser and context-aware scraping in CLI metrics
  • Update go-re2 to 1.10.0
Fixed 7
  • LAPI metrics: don't use empty path as label for LAPI hits metrics
  • Fix accessLogger setup to separate file
  • Docker acquisition: prevent data races
  • Fix avoidable prometheus metrics cardinality
  • Loki acquisition: remove forgotten debug print
  • Show certificate path in "lapi status"
  • DecisionStream: only select required fields from the DB
Changes
  • docker: remove CROWDSEC_CONTAINER_ENV (#4085) @mmetc
  • refact cscli: define csconfig.Getter once (#4091) @mmetc
  • refact load/save apic token: dependencies and sentinel errors (#4081) @mmetc
  • pkg/csplugin: use backoff package to retry notifications (#3944) @mmetc
  • refact pkg/database batching (#3906) @mmetc
  • refact pkg/acquisition: split appsec.go (#4043) @mmetc
  • refact pkg/acquisition: journalctl configuration (#4057) @mmetc
  • lint revive: lower complexity threshold (#4056) @mmetc
  • lint: unused parameters / 2 (#4055) @mmetc
  • lint: unused parameters (#4049) @mmetc
  • refact pkg/acquisition: split loki.go (#4034) @mmetc
  • refact pkg/acquisition: split victorialogs.go (#4037) @mmetc
  • refact pkg/acquisition: split wineventlog.go (#4036) @mmetc
  • refact pkg/acquisition: split s3.go (#4035) @mmetc
  • refact pkg/acquisition: split k8s_audit.go (#4033) @mmetc
  • refact pkg/acquisition: split kinesis.go (#4032) @mmetc
  • refact pkg/acquisition: split kafka.go (#4031) @mmetc
  • refact pkg/acquisition: split cloudwatch.go (#4029) @mmetc
  • refact pkg/acquisition: split http.go (#4030) @mmetc
  • refactg pkg/acquisition: split file.go (#4038) @mmetc
  • refact pkg/acquisition: split syslog.go (#4028) @mmetc
  • papi: explicit context (#3973) @mmetc
  • pkg/csplugin: remove unused function (#4019) @mmetc
  • pkg/types -> new imports pt 4 (#4012) @mmetc
  • pkg/types -> new imports pt 3 (#4014) @mmetc
  • pkg/types -> new imports pt 2 (#4013) @mmetc
  • pkg/types -> new imports pt 1 (#4011) @mmetc
  • pkg/types -> pkg/{pipeline,fsutil,enrichment,logging...} (#4006) @mmetc
  • CI: enable linter "protogetter" (#3995) @mmetc
  • enable linters: unnecessary-format, unused-receiver (#4001) @mmetc
  • refact: remove unused struct fields and params / 3; enable linter "unused" (#3334) @mmetc
New Features
  • WAF: Add DropRequest helper to block request in hooks (#4016) @blotus
Improvements
  • pkg/acquisition: update syslog to RestartableStreamer (#4040) @mmetc
  • refact logging configuration; add log_media="syslog" (#4045) @mmetc
  • cscli hubtest: better report docker/nuclei errors (#4052) @mmetc
  • build: check make version before running Makefile (#4054) @mmetc
  • pkg/acquisition: refact journalctl datasource and unified retry loop (#4023) @mmetc
  • option api.server.disable_usage_metrics_export (#4021) @mmetc
  • build: optional pure-go sqlite driver (#3908) @mmetc
Bug Fixes
  • LAPI metrics: don't use empty path as label for LAPI hits metrics (#4106) @blotus
  • fix accessLogger setup to separate file (#4103) @mmetc
  • docker acquisition: prevent data races (#3956) @mmetc
  • Fix avoidable prometheus metrics cardinality (#4080) @g00g1
  • loki acquisition: remove forgotten debug print (#4062) @mmetc
  • fix 2808: show certificate path in "lapi status" (#4053) @mmetc
  • decisionStream: only select required fields from the DB (#4024) @blotus
Documentation
  • docs: add public roadmap section to README.md (#4039) @mazzma12
Chore / Deps
  • build(deps): bump github/codeql-action from 4.31.4 to 4.31.6 (#4101) @dependabot[bot]
  • build(deps): bump golangci/golangci-lint-action from 9.0.0 to 9.1.0 (#4083) @dependabot[bot]
  • Update go-re2 to 1.10.0 (#4020) @blotus
  • waf: remove custom raw body processor and use the upstream one (#4092) @blotus
  • build(deps): bump actions/setup-python from 6.0.0 to 6.1.0 (#4089) @dependabot[bot]
  • update go-cs-lib (#4084) @mmetc
  • update coraza (#4047) @blotus
  • build(deps): bump actions/checkout from 5.0.1 to 6.0.0 (#4077) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.1.3 to 7.1.4 (#4078) @dependabot[bot]
  • replace prom2json with native Prometheus parser and context-aware scraping in CLI metrics (#3932) @mmetc
  • build(deps): bump actions/setup-go from 6.0.0 to 6.1.0 (#4073) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.31.3 to 4.31.4 (#4069) @dependabot[bot]
  • build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4064) @dependabot[bot]
  • update docker/docker to moby/moby (version docker-v29.0.0) (#4048) @mmetc
  • build(deps): bump github/codeql-action from 4.31.0 to 4.31.3 (#4051) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.1.2 to 7.1.3 (#4042) @dependabot[bot]
  • build(deps): bump golangci/golangci-lint-action from 8.0.0 to 9.0.0 (#4041) @dependabot[bot]
  • build(deps): bump docker/setup-qemu-action from 3.6.0 to 3.7.0 (#4025) @dependabot[bot]
  • CI: update golangci-lint to 2.6.1 (#4026) @mmetc
  • waf: extract temp state from AppsecRuntimeConfig (#3952) @blotus
  • build(deps): bump astral-sh/setup-uv from 7.1.1 to 7.1.2 (#4009) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.30.9 to 4.31.0 (#4008) @dependabot[bot]
  • build(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 (#4010) @dependabot[bot]
Geolite2 notice

This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.

Installation

Take a look at the installation instructions.

View originalPermalink
How v1.7.4 went

v1.7.4-rc2

Pre-release
Added 2
  • Add DropRequest helper to block request in hooks in WAF
  • Add option api.server.disable_usage_metrics_export
Changed 13
  • Update syslog to RestartableStreamer in pkg/acquisition
  • Refactor logging configuration and add log_media="syslog" option
  • Use backoff package to retry notifications in pkg/csplugin
  • Replace prom2json with native Prometheus parser and context-aware scraping in CLI metrics
  • Remove CROWDSEC_CONTAINER_ENV in docker
  • Update go-re2 to 1.10.0
Fixed 6
  • Fix accessLogger setup to separate file
  • Prevent data races in docker acquisition
  • Fix avoidable prometheus metrics cardinality
  • Remove forgotten debug print in loki acquisition
  • Show certificate path in lapi status command
  • Make decisionStream only select required fields from the DB
Changes
  • docker: remove CROWDSEC_CONTAINER_ENV (#4085) @mmetc
  • refact cscli: define csconfig.Getter once (#4091) @mmetc
  • refact load/save apic token: dependencies and sentinel errors (#4081) @mmetc
  • pkg/csplugin: use backoff package to retry notifications (#3944) @mmetc
  • refact pkg/database batching (#3906) @mmetc
  • refact pkg/acquisition: split appsec.go (#4043) @mmetc
  • refact pkg/acquisition: journalctl configuration (#4057) @mmetc
  • lint revive: lower complexity threshold (#4056) @mmetc
  • lint: unused parameters / 2 (#4055) @mmetc
  • lint: unused parameters (#4049) @mmetc
  • refact pkg/acquisition: split loki.go (#4034) @mmetc
  • refact pkg/acquisition: split victorialogs.go (#4037) @mmetc
  • refact pkg/acquisition: split wineventlog.go (#4036) @mmetc
  • refact pkg/acquisition: split s3.go (#4035) @mmetc
  • refact pkg/acquisition: split k8s_audit.go (#4033) @mmetc
  • refact pkg/acquisition: split kinesis.go (#4032) @mmetc
  • refact pkg/acquisition: split kafka.go (#4031) @mmetc
  • refact pkg/acquisition: split cloudwatch.go (#4029) @mmetc
  • refact pkg/acquisition: split http.go (#4030) @mmetc
  • refactg pkg/acquisition: split file.go (#4038) @mmetc
  • refact pkg/acquisition: split syslog.go (#4028) @mmetc
  • papi: explicit context (#3973) @mmetc
  • pkg/csplugin: remove unused function (#4019) @mmetc
  • pkg/types -> new imports pt 4 (#4012) @mmetc
  • pkg/types -> new imports pt 3 (#4014) @mmetc
  • pkg/types -> new imports pt 2 (#4013) @mmetc
  • pkg/types -> new imports pt 1 (#4011) @mmetc
  • pkg/types -> pkg/{pipeline,fsutil,enrichment,logging...} (#4006) @mmetc
  • CI: enable linter "protogetter" (#3995) @mmetc
  • enable linters: unnecessary-format, unused-receiver (#4001) @mmetc
  • refact: remove unused struct fields and params / 3; enable linter "unused" (#3334) @mmetc
New Features
  • WAF: Add DropRequest helper to block request in hooks (#4016) @blotus
Improvements
  • pkg/acquisition: update syslog to RestartableStreamer (#4040) @mmetc
  • refact logging configuration; add log_media="syslog" (#4045) @mmetc
  • cscli hubtest: better report docker/nuclei errors (#4052) @mmetc
  • build: check make version before running Makefile (#4054) @mmetc
  • pkg/acquisition: refact journalctl datasource and unified retry loop (#4023) @mmetc
  • option api.server.disable_usage_metrics_export (#4021) @mmetc
  • build: optional pure-go sqlite driver (#3908) @mmetc
Bug Fixes
  • fix accessLogger setup to separate file (#4103) @mmetc
  • docker acquisition: prevent data races (#3956) @mmetc
  • Fix avoidable prometheus metrics cardinality (#4080) @g00g1
  • loki acquisition: remove forgotten debug print (#4062) @mmetc
  • fix 2808: show certificate path in "lapi status" (#4053) @mmetc
  • decisionStream: only select required fields from the DB (#4024) @blotus
Documentation
  • docs: add public roadmap section to README.md (#4039) @mazzma12
Chore / Deps
  • build(deps): bump github/codeql-action from 4.31.4 to 4.31.6 (#4101) @dependabot[bot]
  • build(deps): bump golangci/golangci-lint-action from 9.0.0 to 9.1.0 (#4083) @dependabot[bot]
  • Update go-re2 to 1.10.0 (#4020) @blotus
  • waf: remove custom raw body processor and use the upstream one (#4092) @blotus
  • build(deps): bump actions/setup-python from 6.0.0 to 6.1.0 (#4089) @dependabot[bot]
  • update go-cs-lib (#4084) @mmetc
  • update coraza (#4047) @blotus
  • build(deps): bump actions/checkout from 5.0.1 to 6.0.0 (#4077) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.1.3 to 7.1.4 (#4078) @dependabot[bot]
  • replace prom2json with native Prometheus parser and context-aware scraping in CLI metrics (#3932) @mmetc
  • build(deps): bump actions/setup-go from 6.0.0 to 6.1.0 (#4073) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.31.3 to 4.31.4 (#4069) @dependabot[bot]
  • build(deps): bump actions/checkout from 5.0.0 to 5.0.1 (#4064) @dependabot[bot]
  • update docker/docker to moby/moby (version docker-v29.0.0) (#4048) @mmetc
  • build(deps): bump github/codeql-action from 4.31.0 to 4.31.3 (#4051) @dependabot[bot]
  • build(deps): bump astral-sh/setup-uv from 7.1.2 to 7.1.3 (#4042) @dependabot[bot]
  • build(deps): bump golangci/golangci-lint-action from 8.0.0 to 9.0.0 (#4041) @dependabot[bot]
  • build(deps): bump docker/setup-qemu-action from 3.6.0 to 3.7.0 (#4025) @dependabot[bot]
  • CI: update golangci-lint to 2.6.1 (#4026) @mmetc
  • waf: extract temp state from AppsecRuntimeConfig (#3952) @blotus
  • build(deps): bump astral-sh/setup-uv from 7.1.1 to 7.1.2 (#4009) @dependabot[bot]
  • build(deps): bump github/codeql-action from 4.30.9 to 4.31.0 (#4008) @dependabot[bot]
  • build(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 (#4010) @dependabot[bot]
Geolite2 notice

This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.

Installation

Take a look at the installation instructions.

View originalPermalink
How v1.7.4-rc2 went
View all

Discussion

If you publish CrowdSec, you can claim this product by proving you administer its repository.