# CrowdSec v1.7.4-rc2 - Product: CrowdSec (https://whatsnew.fyi/product/crowdsec) - Vendor: CrowdSec - Date: 2025-12-03 - Version: v1.7.4-rc2 - Original notes: https://github.com/crowdsecurity/crowdsec/releases/tag/v1.7.4-rc2 - Permalink: https://whatsnew.fyi/product/crowdsec/releases/v1.7.4-rc2 - Labels: Pre-release; Platforms: Windows, Linux What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **added** — Add DropRequest helper to block request in hooks in WAF - **changed** — Update syslog to RestartableStreamer in pkg/acquisition - **changed** — Refactor logging configuration and add log_media="syslog" option - **changed** — Use backoff package to retry notifications in pkg/csplugin - **changed** — Replace prom2json with native Prometheus parser and context-aware scraping in CLI metrics - **changed** — Remove CROWDSEC_CONTAINER_ENV in docker - **changed** — Update go-re2 to 1.10.0 - **changed** — Update coraza - **changed** — Update docker/docker to moby/moby version docker-v29.0.0 - **changed** — Update go-cs-lib - **changed** — Remove custom raw body processor and use the upstream one in WAF - **fixed** — Fix accessLogger setup to separate file - **fixed** — Prevent data races in docker acquisition - **fixed** — Fix avoidable prometheus metrics cardinality - **fixed** — Remove forgotten debug print in loki acquisition - **fixed** — Show certificate path in lapi status command - **fixed** — Make decisionStream only select required fields from the DB - **added** — Add option api.server.disable_usage_metrics_export - **changed** — Improve cscli hubtest to better report docker and nuclei errors - **changed** — Check make version before running Makefile in build - **changed** — Add optional pure-go sqlite driver in build ##### Changes * docker: remove CROWDSEC_CONTAINER_ENV (#4085) @mmetc * refact cscli: define csconfig.Getter once (#4091) @mmetc * refact load/save apic token: dependencies and sentinel errors (#4081) @mmetc * pkg/csplugin: use backoff package to retry notifications (#3944) @mmetc * refact pkg/database batching (#3906) @mmetc * refact pkg/acquisition: split appsec.go (#4043) @mmetc * refact pkg/acquisition: journalctl configuration (#4057) @mmetc * lint revive: lower complexity threshold (#4056) @mmetc * lint: unused parameters / 2 (#4055) @mmetc * lint: unused parameters (#4049) @mmetc * refact pkg/acquisition: split loki.go (#4034) @mmetc * refact pkg/acquisition: split victorialogs.go (#4037) @mmetc * refact pkg/acquisition: split wineventlog.go (#4036) @mmetc * refact pkg/acquisition: split s3.go (#4035) @mmetc * refact pkg/acquisition: split k8s_audit.go (#4033) @mmetc * refact pkg/acquisition: split kinesis.go (#4032) @mmetc * refact pkg/acquisition: split kafka.go (#4031) @mmetc * refact pkg/acquisition: split cloudwatch.go (#4029) @mmetc * refact pkg/acquisition: split http.go (#4030) @mmetc * refactg pkg/acquisition: split file.go (#4038) @mmetc * refact pkg/acquisition: split syslog.go (#4028) @mmetc * papi: explicit context (#3973) @mmetc * pkg/csplugin: remove unused function (#4019) @mmetc * pkg/types -> new imports pt 4 (#4012) @mmetc * pkg/types -> new imports pt 3 (#4014) @mmetc * pkg/types -> new imports pt 2 (#4013) @mmetc * pkg/types -> new imports pt 1 (#4011) @mmetc * pkg/types -> pkg/{pipeline,fsutil,enrichment,logging...} (#4006) @mmetc * CI: enable linter "protogetter" (#3995) @mmetc * enable linters: unnecessary-format, unused-receiver (#4001) @mmetc * refact: remove unused struct fields and params / 3; enable linter "unused" (#3334) @mmetc ##### New Features * WAF: Add `DropRequest` helper to block request in hooks (#4016) @blotus ##### Improvements * pkg/acquisition: update syslog to RestartableStreamer (#4040) @mmetc * refact logging configuration; add log_media="syslog" (#4045) @mmetc * cscli hubtest: better report docker/nuclei errors (#4052) @mmetc * build: check make version before running Makefile (#4054) @mmetc * pkg/acquisition: refact journalctl datasource and unified retry loop (#4023) @mmetc * option api.server.disable_usage_metrics_export (#4021) @mmetc * build: optional pure-go sqlite driver (#3908) @mmetc ##### Bug Fixes * fix accessLogger setup to separate file (#4103) @mmetc * docker acquisition: prevent data races (#3956) @mmetc * Fix avoidable prometheus metrics cardinality (#4080) @g00g1 * loki acquisition: remove forgotten debug print (#4062) @mmetc * fix 2808: show certificate path in "lapi status" (#4053) @mmetc * decisionStream: only select required fields from the DB (#4024) @blotus ##### Documentation * docs: add public roadmap section to README.md (#4039) @mazzma12 ##### Chore / Deps * build(deps): bump github/codeql-action from 4.31.4 to 4.31.6 (#4101) @[dependabot[bot]](https://github.com/apps/dependabot) * build(deps): bump golangci/golangci-lint-action from 9.0.0 to 9.1.0 (#4083) @[dependabot[bot]](https://github.com/apps/dependabot) * Update go-re2 to 1.10.0 (#4020) @blotus * waf: remove custom raw body processor and use the upstream one (#4092) @blotus * build(deps): bump actions/setup-python from 6.0.0 to 6.1.0 (#4089) @[dependabot[bot]](https://github.com/apps/dependabot) * update go-cs-lib (#4084) @mmetc * update coraza (#4047) @blotus * build(deps): bump actions/checkout from 5.0.1 to 6.0.0 (#4077) @[dependabot[bot]](https://github.com/apps/dependabot) * build(deps): bump astral-sh/setup-uv from 7.1.3 to 7.1.4 (#4078) @[dependabot[bot]](https://github.com/apps/dependabot) * replace prom2json with native Prometheus parser and context-aware scraping in CLI metrics (#3932) @mmetc * build(deps): bump actions/setup-go from 6.0.0 to 6.1.0 (#4073) @[dependabot[bot]](https://github.com/apps _[Truncated at 4000 characters — full notes: https://github.com/crowdsecurity/crowdsec/releases/tag/v1.7.4-rc2]_