Artifact Firewall 0.7.0

Released: 2026-10-05

Added

  • New audit log fields: id, ts, kind, registry, mode, outcome, rule_system_id and ruleset_system_id.

Changed

  • Breaking: the audit log’s effective_action field is now enforced_action, and the span attribute firewall.effective_action is now firewall.enforced_action.
  • The OpenTelemetry modules are back on their current releases, with the log modules no longer held at an older one. Audit log output is unchanged.
  • A ruleset the firewall refuses to load is now reported as the ruleset, the rule and the field that failed, such as ruleset "npm-policy": rule "block-leftpad": severity: 11.0 must be between 0 and 10.
  • An api_address the firewall cannot bind now stops it at startup, with the reason in the log. It used to keep serving proxy traffic with the admin API unreachable and nothing but one line to say so.
  • /healthz and /readyz are no longer counted under the route label on the HTTP metrics.
  • A rule read back from /api/rulesets/{ruleset_id}/rules/{rule_id} now uses the same field names a ruleset uses: a selector carries version rather than version_range, the registry scope is gone, and unset fields are omitted. PATCH to that path now rejects fields it does not know, so a body captured from an older version has to drop version_range and the registry scope before it is sent back.

Fixed

  • Fixed a NuGet rule whose package name has capitals, such as pkg:nuget/Newtonsoft.Json, never matching, because the firewall lowercases the requested id. NuGet names now match in any case, in traffic and in /api/eval, whose audit entries log the NuGet purl lowercased, like traffic.
  • Fixed an action spelled in any case but lower, such as action: DENY in a rule or default_action: DENY in the config, loading without complaint and then never being enforced, so the package it was meant to block was served.
  • Fixed a ruleset with an empty entry under rules: crashing the firewall instead of being reported as invalid.
  • Fixed re-enabling a rule through the admin API failing when several rules were disabled at once, and a rule that was re-enabled coming back disabled after the next ruleset reload.

®Varnish Software, Wallingatan 12, 111 60 Stockholm, Organization nr. 556805-6203