Released: 2026-10-05
id, ts, kind, registry, mode, outcome, rule_system_id and ruleset_system_id.effective_action field is now enforced_action, and the span attribute firewall.effective_action is now firewall.enforced_action.ruleset "npm-policy": rule "block-leftpad": severity: 11.0 must be between 0 and 10.api_address the firewall cannot bind now stops it at startup, with the reason in the log. It used to keep serving proxy traffic with the admin API unreachable and nothing but one line to say so./healthz and /readyz are no longer counted under the route label on the HTTP metrics./api/rulesets/{ruleset_id}/rules/{rule_id} now uses the same field names a ruleset uses: a selector carries version rather than version_range, the registry scope is gone, and unset fields are omitted. PATCH to that path now rejects fields it does not know, so a body captured from an older version has to drop version_range and the registry scope before it is sent back.pkg:nuget/Newtonsoft.Json, never matching, because the firewall lowercases the requested id. NuGet names now match in any case, in traffic and in /api/eval, whose audit entries log the NuGet purl lowercased, like traffic.action: DENY in a rule or default_action: DENY in the config, loading without complaint and then never being enforced, so the package it was meant to block was served.rules: crashing the firewall instead of being reported as invalid.