RFC Tracker
Jede wesentliche Änderung an WAF++ beginnt mit einem öffentlichen Request for Comments. Diese Seite verfolgt jeden RFC — vom ersten Entwurf bis zum Merge — damit jede Entscheidung nachvollziehbar bleibt.
Alle Requests for Comments
Nach Status filtern, Zusammenfassungen lesen und den verlinkten Diskussionen sowie Pull Requests folgen.
WAF++ Framework
Legt das grundlegende Sieben-Säulen-Modell als Basis von WAF++ fest: Sicherheit, Zuverlässigkeit, Performance-Effizienz, Kostenoptimierung, Operationelle Exzellenz, Nachhaltigkeit und Developer Experience. Durch RFC-0012 auf acht Säulen erweitert.
Definiert die öffentliche Roadmap für 2026 mit Q1–Q4-Meilensteinen, v1.0-Ziel, Pilotprogramm und Foundation-Readiness-Zielen.
Fügt die initiale Inhaltsdefinition für jede der 7 Säulen hinzu: Scope, Begründung und Kernbewertungsfragen. Bildet die Basis für die Controls Library und wurde später um die 8. Säule Agentic erweitert (RFC-0012).
Migriert die gesamte Framework-Dokumentation von Markdown nach AsciiDoc und etabliert Antora als Dokumentations-Build-System mit Komponenten-Versionierung (v1.0).
Fügt dem Framework-Repository die Standard-Open-Source-Health-Dateien hinzu: Beitragsrichtlinien, Verhaltenskodex (basierend auf Contributor Covenant v2.1) und Sicherheitsrichtlinie.
Führt den Sovereign-Pillar als 7. Säule von WAF++ ein — Datensouveränität, Compliance und jurisdiktionale Kontrolle. Liefert 10 initiale Controls (WAF-SOV-010 bis WAF-SOV-100).
Strukturiert den Governance-Pillar (Säule 7) in modulare Best-Practice-Seiten um, ergänzt Fallstudien-Inhalte und aktualisiert die Antora-Navigation für bessere Auffindbarkeit und Lesbarkeit.
Definiert ein formales Schema für WAF++-Controls-YAML-Dateien, das konsistente Validierung, Tool-Integration und die Nutzung der 83+ Controls Library durch Dritte ermöglicht. Mit der v1.0-Release ausgeliefert.
Formalisiert das PASS-Scoring-Modell als normative Spezifikation: Tier-Definitionen, Berechnungsregeln, Aggregationslogik und Versionierungsvertrag. Voraussetzung für und ausgeliefert mit WAFPass CLI / Server v1.0.0.
Definiert den Ansatz für das offizielle WAF++-Assessment-Tooling: WAFPass CLI, Server, Dashboard und Web-Scorecard, die die Controls Library nutzen und einen PASS-Score-Bericht erzeugen. Mit WAFPass v1.0.0 ausgeliefert und in v1.1.0 erweitert.
Führt automatisierte Checks und Release-Workflows für die Repositories framework, pass, wafpass-server und wafpass-dashboard ein: Antora-Build-Validierung, Controls-YAML-Linting, Release-Automatisierung und Link-Prüfung bei jedem Pull Request.
Fügt den Agentic-Pillar (WAF-AGN) als 8. Säule von WAF++ hinzu — Governance autonomer KI-Agenten. Liefert 10 initiale Controls (WAF-AGN-010 bis WAF-AGN-100), regulatorische Mappings sowie englische und deutsche Dokumentation. Erweitert das Framework auf 8 Säulen und 83+ Controls.
Rollt das radical dunkle Design-System auf die verbleibenden öffentlichen Seiten (RFC-Tracker, Team, Rollen, About, Press, Install) aus, sodass die gesamte Website eine konsistente visuelle Sprache und Barrierefreiheitsmuster verwendet.
Standardisiert maschinen- und menschenlesbare Remediation-Anleitungen für jeden WAF++-Control, damit Betriebsteams direkt aus einem PASS-Bericht oder Dashboard handeln können.
Definiert, wie WAFPass-Erkennung und Controls um Azure, GCP und weitere Cloud-Provider erweitert werden, während das Framework cloud-agnostic bleibt.
- CI-Check für tote xrefs - CI-Check für unregistrierte nav.adoc - Linter für Control-Schema-Konsistenz (YAML ↔ .adoc ↔ Nav)
- Sovereign-Definition/Scope/Principles auf Peer-Level erweitern - Sovereign-Evidence-Matrix - resources/index.adoc und wording/index.adoc als echte Übersicht/Glossar
- maturity.adoc anlegen - evidence.adoc auf Security-Vorbild erweitern - glossary.adoc vervollständigen - alle agent-design/* und best-practices/* mit Beispielen ausschreiben
WIP - Homepage + pillars/index.adoc auf einheitliche Modul-Links umstellen - 64 relative ../-xrefs in modulpräfix-xrefs wandeln - Markdown-Links in bp-runbooks.adoc bereinigen
WIP - antora.yml: alle 10 Nav-Dateien registrieren, start_page setzen - pillar-security/nav.adoc anlegen - README.md + AGENTS.md auf 8-Modul-Layout aktualisieren - Entscheidung: efficiancy umbenennen ja/nein
- 8 Säulen, korrekte Nummerierung - Agentic aufnehmen - WAF-COST-001 entweder in 010 umbenennen oder offiziell als “Pre-010” etablieren - control-schema.adoc auf AGN erweitern
WAF++ Framework — Offen zur Prüfung
Rollt das radical dunkle Design-System auf die verbleibenden öffentlichen Seiten (RFC-Tracker, Team, Rollen, About, Press, Install) aus, sodass die gesamte Website eine konsistente visuelle Sprache und Barrierefreiheitsmuster verwendet.
- CI-Check für tote xrefs - CI-Check für unregistrierte nav.adoc - Linter für Control-Schema-Konsistenz (YAML ↔ .adoc ↔ Nav)
- Sovereign-Definition/Scope/Principles auf Peer-Level erweitern - Sovereign-Evidence-Matrix - resources/index.adoc und wording/index.adoc als echte Übersicht/Glossar
- maturity.adoc anlegen - evidence.adoc auf Security-Vorbild erweitern - glossary.adoc vervollständigen - alle agent-design/* und best-practices/* mit Beispielen ausschreiben
WIP - Homepage + pillars/index.adoc auf einheitliche Modul-Links umstellen - 64 relative ../-xrefs in modulpräfix-xrefs wandeln - Markdown-Links in bp-runbooks.adoc bereinigen
WIP - antora.yml: alle 10 Nav-Dateien registrieren, start_page setzen - pillar-security/nav.adoc anlegen - README.md + AGENTS.md auf 8-Modul-Layout aktualisieren - Entscheidung: efficiancy umbenennen ja/nein
- 8 Säulen, korrekte Nummerierung - Agentic aufnehmen - WAF-COST-001 entweder in 010 umbenennen oder offiziell als “Pre-010” etablieren - control-schema.adoc auf AGN erweitern
WAF++ Framework — Entwürfe
Standardisiert maschinen- und menschenlesbare Remediation-Anleitungen für jeden WAF++-Control, damit Betriebsteams direkt aus einem PASS-Bericht oder Dashboard handeln können.
Definiert, wie WAFPass-Erkennung und Controls um Azure, GCP und weitere Cloud-Provider erweitert werden, während das Framework cloud-agnostic bleibt.
WAF++ Framework — Entschieden / umgesetzt
Legt das grundlegende Sieben-Säulen-Modell als Basis von WAF++ fest: Sicherheit, Zuverlässigkeit, Performance-Effizienz, Kostenoptimierung, Operationelle Exzellenz, Nachhaltigkeit und Developer Experience. Durch RFC-0012 auf acht Säulen erweitert.
Definiert die öffentliche Roadmap für 2026 mit Q1–Q4-Meilensteinen, v1.0-Ziel, Pilotprogramm und Foundation-Readiness-Zielen.
Fügt die initiale Inhaltsdefinition für jede der 7 Säulen hinzu: Scope, Begründung und Kernbewertungsfragen. Bildet die Basis für die Controls Library und wurde später um die 8. Säule Agentic erweitert (RFC-0012).
Migriert die gesamte Framework-Dokumentation von Markdown nach AsciiDoc und etabliert Antora als Dokumentations-Build-System mit Komponenten-Versionierung (v1.0).
Fügt dem Framework-Repository die Standard-Open-Source-Health-Dateien hinzu: Beitragsrichtlinien, Verhaltenskodex (basierend auf Contributor Covenant v2.1) und Sicherheitsrichtlinie.
Führt den Sovereign-Pillar als 7. Säule von WAF++ ein — Datensouveränität, Compliance und jurisdiktionale Kontrolle. Liefert 10 initiale Controls (WAF-SOV-010 bis WAF-SOV-100).
Strukturiert den Governance-Pillar (Säule 7) in modulare Best-Practice-Seiten um, ergänzt Fallstudien-Inhalte und aktualisiert die Antora-Navigation für bessere Auffindbarkeit und Lesbarkeit.
Definiert ein formales Schema für WAF++-Controls-YAML-Dateien, das konsistente Validierung, Tool-Integration und die Nutzung der 83+ Controls Library durch Dritte ermöglicht. Mit der v1.0-Release ausgeliefert.
Formalisiert das PASS-Scoring-Modell als normative Spezifikation: Tier-Definitionen, Berechnungsregeln, Aggregationslogik und Versionierungsvertrag. Voraussetzung für und ausgeliefert mit WAFPass CLI / Server v1.0.0.
Definiert den Ansatz für das offizielle WAF++-Assessment-Tooling: WAFPass CLI, Server, Dashboard und Web-Scorecard, die die Controls Library nutzen und einen PASS-Score-Bericht erzeugen. Mit WAFPass v1.0.0 ausgeliefert und in v1.1.0 erweitert.
Führt automatisierte Checks und Release-Workflows für die Repositories framework, pass, wafpass-server und wafpass-dashboard ein: Antora-Build-Validierung, Controls-YAML-Linting, Release-Automatisierung und Link-Prüfung bei jedem Pull Request.
Fügt den Agentic-Pillar (WAF-AGN) als 8. Säule von WAF++ hinzu — Governance autonomer KI-Agenten. Liefert 10 initiale Controls (WAF-AGN-010 bis WAF-AGN-100), regulatorische Mappings sowie englische und deutsche Dokumentation. Erweitert das Framework auf 8 Säulen und 83+ Controls.
WAFPass
Erweitert WAFPass CLI, Server und Dashboard, um die Agentic-Pillar-Controls (WAF-AGN-*) im Rahmen einer vollständigen PASS-Bewertung auszuwerten. Vor der WAFPass-v1.1.0-Release gemergt.
Veröffentlicht WAFPass CLI v1.1.0, WAFPass Server v1.1.0 und WAFPass Dashboard v1.1.0 mit Unterstützung für Säule-8 Agentic, Korrekturen bei der Erkennung und SINA-Cloud-Region-Erkennung. Abgestimmt auf Framework v1.1 und die 83+ Controls Library.
📋 Context & Problem Statement The WAF++ PASS platform code and test coverage are highly fragmented across three distinct repositories: * pass (Python CLI / pytest): Contains ~150 unit tests, localized auto-fix tests, and a single golden-file E2E fixture, but…
Context and Goals The WAF++ PASS product is moving through an API maturity push. Several parallel efforts already exist or are planned: * Maturity enforcement: Achievements, leaderboard, project passports, and tier rules. * Action-oriented notifications:…
Context Dashboard local preview and auto-fix features rely on Run.source_snapshot, a JSONB map of relative IaC file paths to raw file contents. Today, this snapshot is only captured when the CLI is explicitly invoked with both --output json, --upload-source,…
📋 Context & Problem Statement The dashboard currently exposes 46 pages through a bloated, 700px-wide mega-menu in TopNavigation.tsx. The navigation model is highly fragmented; buildNavSections() is duplicated across Sidebar.tsx and MobileMenu.tsx, leading to…
📋 Context & Problem Statement The dashboard currently features a NotificationBell and a dedicated NotificationsPage, but notifications are entirely passive—they only display text titles, messages, and categories with no trailing interactive…
📋 Context & Problem Statement The dashboard currently features a ControlsPacksPage and the server exposes /control-packs endpoints, but functionality is restricted to admin-only uploads and basic catalogue syncs[cite: 1]. Auditors have highlighted that the…
📋 Context & Problem Statement Currently, the maturity journey is purely a dashboard visualization and local settings concept. Auditors have flagged a critical gap: there are no policy gates tying maturity tiers to CI/CD pipeline behavior (e.g., preventing a…
WAFPass — Offen zur Prüfung
📋 Context & Problem Statement The WAF++ PASS platform code and test coverage are highly fragmented across three distinct repositories: * pass (Python CLI / pytest): Contains ~150 unit tests, localized auto-fix tests, and a single golden-file E2E fixture, but…
Context and Goals The WAF++ PASS product is moving through an API maturity push. Several parallel efforts already exist or are planned: * Maturity enforcement: Achievements, leaderboard, project passports, and tier rules. * Action-oriented notifications:…
Context Dashboard local preview and auto-fix features rely on Run.source_snapshot, a JSONB map of relative IaC file paths to raw file contents. Today, this snapshot is only captured when the CLI is explicitly invoked with both --output json, --upload-source,…
📋 Context & Problem Statement The dashboard currently exposes 46 pages through a bloated, 700px-wide mega-menu in TopNavigation.tsx. The navigation model is highly fragmented; buildNavSections() is duplicated across Sidebar.tsx and MobileMenu.tsx, leading to…
📋 Context & Problem Statement The dashboard currently features a NotificationBell and a dedicated NotificationsPage, but notifications are entirely passive—they only display text titles, messages, and categories with no trailing interactive…
📋 Context & Problem Statement The dashboard currently features a ControlsPacksPage and the server exposes /control-packs endpoints, but functionality is restricted to admin-only uploads and basic catalogue syncs[cite: 1]. Auditors have highlighted that the…
📋 Context & Problem Statement Currently, the maturity journey is purely a dashboard visualization and local settings concept. Auditors have flagged a critical gap: there are no policy gates tying maturity tiers to CI/CD pipeline behavior (e.g., preventing a…
WAFPass — Entschieden / umgesetzt
Erweitert WAFPass CLI, Server und Dashboard, um die Agentic-Pillar-Controls (WAF-AGN-*) im Rahmen einer vollständigen PASS-Bewertung auszuwerten. Vor der WAFPass-v1.1.0-Release gemergt.
Veröffentlicht WAFPass CLI v1.1.0, WAFPass Server v1.1.0 und WAFPass Dashboard v1.1.0 mit Unterstützung für Säule-8 Agentic, Korrekturen bei der Erkennung und SINA-Cloud-Region-Erkennung. Abgestimmt auf Framework v1.1 und die 83+ Controls Library.
WAFPass MCP
Problem: Tool names are long and auto-generated (api_auto_fix_classify_api_v1_auto_fix_classify_post). The LLM has to match long operation IDs, and the descriptions are now long because they embed role/category. Proposal: Allow curated aliases for the…
Problem: The MCP only exposes tools. Users cannot ask "what controls failed in this run?" or "show me the source snapshot" without making multiple tool calls and stitching the JSON together. Proposal: Add MCP Resource definitions for run://{run_id},…
Problem: Users can classify and preview patches, but applying them requires a separate auto-fix call with a filesystem path. There is no safe "apply this classify result to this run and record what changed." Proposal: Extend /api/v1/auto-fix/classify with an…
Problem: Runs with thousands of findings return huge JSON blobs. The current proxy loads everything into one TextContent block, which is slow and can hit MCP message size limits. Proposal: Add cursor-based pagination helpers to the bridge: - For list…
Problem: auto-fix/classify returns zero active patches for many controls because assertions like not_empty, attribute_exists, is_true have no registered default value. Proposal: Add a fix block to control YAMLs (or a central provider registry) that declares:…
WAFPass MCP — Offen zur Prüfung
Problem: Tool names are long and auto-generated (api_auto_fix_classify_api_v1_auto_fix_classify_post). The LLM has to match long operation IDs, and the descriptions are now long because they embed role/category. Proposal: Allow curated aliases for the…
Problem: The MCP only exposes tools. Users cannot ask "what controls failed in this run?" or "show me the source snapshot" without making multiple tool calls and stitching the JSON together. Proposal: Add MCP Resource definitions for run://{run_id},…
Problem: Users can classify and preview patches, but applying them requires a separate auto-fix call with a filesystem path. There is no safe "apply this classify result to this run and record what changed." Proposal: Extend /api/v1/auto-fix/classify with an…
Problem: Runs with thousands of findings return huge JSON blobs. The current proxy loads everything into one TextContent block, which is slow and can hit MCP message size limits. Proposal: Add cursor-based pagination helpers to the bridge: - For list…
Problem: auto-fix/classify returns zero active patches for many controls because assertions like not_empty, attribute_exists, is_true have no registered default value. Proposal: Add a fix block to control YAMLs (or a central provider registry) that declares:…
WAF++ Framework
Legt das grundlegende Sieben-Säulen-Modell als Basis von WAF++ fest: Sicherheit, Zuverlässigkeit, Performance-Effizienz, Kostenoptimierung, Operationelle Exzellenz, Nachhaltigkeit und Developer Experience. Durch RFC-0012 auf acht Säulen erweitert.
Definiert die öffentliche Roadmap für 2026 mit Q1–Q4-Meilensteinen, v1.0-Ziel, Pilotprogramm und Foundation-Readiness-Zielen.
Fügt die initiale Inhaltsdefinition für jede der 7 Säulen hinzu: Scope, Begründung und Kernbewertungsfragen. Bildet die Basis für die Controls Library und wurde später um die 8. Säule Agentic erweitert (RFC-0012).
Migriert die gesamte Framework-Dokumentation von Markdown nach AsciiDoc und etabliert Antora als Dokumentations-Build-System mit Komponenten-Versionierung (v1.0).
Fügt dem Framework-Repository die Standard-Open-Source-Health-Dateien hinzu: Beitragsrichtlinien, Verhaltenskodex (basierend auf Contributor Covenant v2.1) und Sicherheitsrichtlinie.
Führt den Sovereign-Pillar als 7. Säule von WAF++ ein — Datensouveränität, Compliance und jurisdiktionale Kontrolle. Liefert 10 initiale Controls (WAF-SOV-010 bis WAF-SOV-100).
Strukturiert den Governance-Pillar (Säule 7) in modulare Best-Practice-Seiten um, ergänzt Fallstudien-Inhalte und aktualisiert die Antora-Navigation für bessere Auffindbarkeit und Lesbarkeit.
Definiert ein formales Schema für WAF++-Controls-YAML-Dateien, das konsistente Validierung, Tool-Integration und die Nutzung der 83+ Controls Library durch Dritte ermöglicht. Mit der v1.0-Release ausgeliefert.
Formalisiert das PASS-Scoring-Modell als normative Spezifikation: Tier-Definitionen, Berechnungsregeln, Aggregationslogik und Versionierungsvertrag. Voraussetzung für und ausgeliefert mit WAFPass CLI / Server v1.0.0.
Definiert den Ansatz für das offizielle WAF++-Assessment-Tooling: WAFPass CLI, Server, Dashboard und Web-Scorecard, die die Controls Library nutzen und einen PASS-Score-Bericht erzeugen. Mit WAFPass v1.0.0 ausgeliefert und in v1.1.0 erweitert.
Führt automatisierte Checks und Release-Workflows für die Repositories framework, pass, wafpass-server und wafpass-dashboard ein: Antora-Build-Validierung, Controls-YAML-Linting, Release-Automatisierung und Link-Prüfung bei jedem Pull Request.
Fügt den Agentic-Pillar (WAF-AGN) als 8. Säule von WAF++ hinzu — Governance autonomer KI-Agenten. Liefert 10 initiale Controls (WAF-AGN-010 bis WAF-AGN-100), regulatorische Mappings sowie englische und deutsche Dokumentation. Erweitert das Framework auf 8 Säulen und 83+ Controls.
Rollt das radical dunkle Design-System auf die verbleibenden öffentlichen Seiten (RFC-Tracker, Team, Rollen, About, Press, Install) aus, sodass die gesamte Website eine konsistente visuelle Sprache und Barrierefreiheitsmuster verwendet.
Standardisiert maschinen- und menschenlesbare Remediation-Anleitungen für jeden WAF++-Control, damit Betriebsteams direkt aus einem PASS-Bericht oder Dashboard handeln können.
Definiert, wie WAFPass-Erkennung und Controls um Azure, GCP und weitere Cloud-Provider erweitert werden, während das Framework cloud-agnostic bleibt.
- CI-Check für tote xrefs - CI-Check für unregistrierte nav.adoc - Linter für Control-Schema-Konsistenz (YAML ↔ .adoc ↔ Nav)
- Sovereign-Definition/Scope/Principles auf Peer-Level erweitern - Sovereign-Evidence-Matrix - resources/index.adoc und wording/index.adoc als echte Übersicht/Glossar
- maturity.adoc anlegen - evidence.adoc auf Security-Vorbild erweitern - glossary.adoc vervollständigen - alle agent-design/* und best-practices/* mit Beispielen ausschreiben
WIP - Homepage + pillars/index.adoc auf einheitliche Modul-Links umstellen - 64 relative ../-xrefs in modulpräfix-xrefs wandeln - Markdown-Links in bp-runbooks.adoc bereinigen
WIP - antora.yml: alle 10 Nav-Dateien registrieren, start_page setzen - pillar-security/nav.adoc anlegen - README.md + AGENTS.md auf 8-Modul-Layout aktualisieren - Entscheidung: efficiancy umbenennen ja/nein
- 8 Säulen, korrekte Nummerierung - Agentic aufnehmen - WAF-COST-001 entweder in 010 umbenennen oder offiziell als “Pre-010” etablieren - control-schema.adoc auf AGN erweitern
WAFPass
Erweitert WAFPass CLI, Server und Dashboard, um die Agentic-Pillar-Controls (WAF-AGN-*) im Rahmen einer vollständigen PASS-Bewertung auszuwerten. Vor der WAFPass-v1.1.0-Release gemergt.
Veröffentlicht WAFPass CLI v1.1.0, WAFPass Server v1.1.0 und WAFPass Dashboard v1.1.0 mit Unterstützung für Säule-8 Agentic, Korrekturen bei der Erkennung und SINA-Cloud-Region-Erkennung. Abgestimmt auf Framework v1.1 und die 83+ Controls Library.
📋 Context & Problem Statement The WAF++ PASS platform code and test coverage are highly fragmented across three distinct repositories: * pass (Python CLI / pytest): Contains ~150 unit tests, localized auto-fix tests, and a single golden-file E2E fixture, but…
Context and Goals The WAF++ PASS product is moving through an API maturity push. Several parallel efforts already exist or are planned: * Maturity enforcement: Achievements, leaderboard, project passports, and tier rules. * Action-oriented notifications:…
Context Dashboard local preview and auto-fix features rely on Run.source_snapshot, a JSONB map of relative IaC file paths to raw file contents. Today, this snapshot is only captured when the CLI is explicitly invoked with both --output json, --upload-source,…
📋 Context & Problem Statement The dashboard currently exposes 46 pages through a bloated, 700px-wide mega-menu in TopNavigation.tsx. The navigation model is highly fragmented; buildNavSections() is duplicated across Sidebar.tsx and MobileMenu.tsx, leading to…
📋 Context & Problem Statement The dashboard currently features a NotificationBell and a dedicated NotificationsPage, but notifications are entirely passive—they only display text titles, messages, and categories with no trailing interactive…
📋 Context & Problem Statement The dashboard currently features a ControlsPacksPage and the server exposes /control-packs endpoints, but functionality is restricted to admin-only uploads and basic catalogue syncs[cite: 1]. Auditors have highlighted that the…
📋 Context & Problem Statement Currently, the maturity journey is purely a dashboard visualization and local settings concept. Auditors have flagged a critical gap: there are no policy gates tying maturity tiers to CI/CD pipeline behavior (e.g., preventing a…
WAFPass Action
WAFPass MCP
Problem: Tool names are long and auto-generated (api_auto_fix_classify_api_v1_auto_fix_classify_post). The LLM has to match long operation IDs, and the descriptions are now long because they embed role/category. Proposal: Allow curated aliases for the…
Problem: The MCP only exposes tools. Users cannot ask "what controls failed in this run?" or "show me the source snapshot" without making multiple tool calls and stitching the JSON together. Proposal: Add MCP Resource definitions for run://{run_id},…
Problem: Users can classify and preview patches, but applying them requires a separate auto-fix call with a filesystem path. There is no safe "apply this classify result to this run and record what changed." Proposal: Extend /api/v1/auto-fix/classify with an…
Problem: Runs with thousands of findings return huge JSON blobs. The current proxy loads everything into one TextContent block, which is slow and can hit MCP message size limits. Proposal: Add cursor-based pagination helpers to the bridge: - For list…
Problem: auto-fix/classify returns zero active patches for many controls because assertions like not_empty, attribute_exists, is_true have no registered default value. Proposal: Add a fix block to control YAMLs (or a central provider registry) that declares:…
WAF++ Framework
Rollt das radical dunkle Design-System auf die verbleibenden öffentlichen Seiten (RFC-Tracker, Team, Rollen, About, Press, Install) aus, sodass die gesamte Website eine konsistente visuelle Sprache und Barrierefreiheitsmuster verwendet.
- CI-Check für tote xrefs - CI-Check für unregistrierte nav.adoc - Linter für Control-Schema-Konsistenz (YAML ↔ .adoc ↔ Nav)
- Sovereign-Definition/Scope/Principles auf Peer-Level erweitern - Sovereign-Evidence-Matrix - resources/index.adoc und wording/index.adoc als echte Übersicht/Glossar
- maturity.adoc anlegen - evidence.adoc auf Security-Vorbild erweitern - glossary.adoc vervollständigen - alle agent-design/* und best-practices/* mit Beispielen ausschreiben
WIP - Homepage + pillars/index.adoc auf einheitliche Modul-Links umstellen - 64 relative ../-xrefs in modulpräfix-xrefs wandeln - Markdown-Links in bp-runbooks.adoc bereinigen
WIP - antora.yml: alle 10 Nav-Dateien registrieren, start_page setzen - pillar-security/nav.adoc anlegen - README.md + AGENTS.md auf 8-Modul-Layout aktualisieren - Entscheidung: efficiancy umbenennen ja/nein
- 8 Säulen, korrekte Nummerierung - Agentic aufnehmen - WAF-COST-001 entweder in 010 umbenennen oder offiziell als “Pre-010” etablieren - control-schema.adoc auf AGN erweitern
WAFPass MCP
Problem: Tool names are long and auto-generated (api_auto_fix_classify_api_v1_auto_fix_classify_post). The LLM has to match long operation IDs, and the descriptions are now long because they embed role/category. Proposal: Allow curated aliases for the…
Problem: The MCP only exposes tools. Users cannot ask "what controls failed in this run?" or "show me the source snapshot" without making multiple tool calls and stitching the JSON together. Proposal: Add MCP Resource definitions for run://{run_id},…
Problem: Users can classify and preview patches, but applying them requires a separate auto-fix call with a filesystem path. There is no safe "apply this classify result to this run and record what changed." Proposal: Extend /api/v1/auto-fix/classify with an…
Problem: Runs with thousands of findings return huge JSON blobs. The current proxy loads everything into one TextContent block, which is slow and can hit MCP message size limits. Proposal: Add cursor-based pagination helpers to the bridge: - For list…
Problem: auto-fix/classify returns zero active patches for many controls because assertions like not_empty, attribute_exists, is_true have no registered default value. Proposal: Add a fix block to control YAMLs (or a central provider registry) that declares:…
WAFPass
📋 Context & Problem Statement The WAF++ PASS platform code and test coverage are highly fragmented across three distinct repositories: * pass (Python CLI / pytest): Contains ~150 unit tests, localized auto-fix tests, and a single golden-file E2E fixture, but…
Context and Goals The WAF++ PASS product is moving through an API maturity push. Several parallel efforts already exist or are planned: * Maturity enforcement: Achievements, leaderboard, project passports, and tier rules. * Action-oriented notifications:…
Context Dashboard local preview and auto-fix features rely on Run.source_snapshot, a JSONB map of relative IaC file paths to raw file contents. Today, this snapshot is only captured when the CLI is explicitly invoked with both --output json, --upload-source,…
📋 Context & Problem Statement The dashboard currently exposes 46 pages through a bloated, 700px-wide mega-menu in TopNavigation.tsx. The navigation model is highly fragmented; buildNavSections() is duplicated across Sidebar.tsx and MobileMenu.tsx, leading to…
📋 Context & Problem Statement The dashboard currently features a NotificationBell and a dedicated NotificationsPage, but notifications are entirely passive—they only display text titles, messages, and categories with no trailing interactive…
📋 Context & Problem Statement The dashboard currently features a ControlsPacksPage and the server exposes /control-packs endpoints, but functionality is restricted to admin-only uploads and basic catalogue syncs[cite: 1]. Auditors have highlighted that the…
📋 Context & Problem Statement Currently, the maturity journey is purely a dashboard visualization and local settings concept. Auditors have flagged a critical gap: there are no policy gates tying maturity tiers to CI/CD pipeline behavior (e.g., preventing a…
WAF++ Framework
Standardisiert maschinen- und menschenlesbare Remediation-Anleitungen für jeden WAF++-Control, damit Betriebsteams direkt aus einem PASS-Bericht oder Dashboard handeln können.
Definiert, wie WAFPass-Erkennung und Controls um Azure, GCP und weitere Cloud-Provider erweitert werden, während das Framework cloud-agnostic bleibt.
WAF++ Framework
Legt das grundlegende Sieben-Säulen-Modell als Basis von WAF++ fest: Sicherheit, Zuverlässigkeit, Performance-Effizienz, Kostenoptimierung, Operationelle Exzellenz, Nachhaltigkeit und Developer Experience. Durch RFC-0012 auf acht Säulen erweitert.
Definiert die öffentliche Roadmap für 2026 mit Q1–Q4-Meilensteinen, v1.0-Ziel, Pilotprogramm und Foundation-Readiness-Zielen.
Fügt die initiale Inhaltsdefinition für jede der 7 Säulen hinzu: Scope, Begründung und Kernbewertungsfragen. Bildet die Basis für die Controls Library und wurde später um die 8. Säule Agentic erweitert (RFC-0012).
Migriert die gesamte Framework-Dokumentation von Markdown nach AsciiDoc und etabliert Antora als Dokumentations-Build-System mit Komponenten-Versionierung (v1.0).
Fügt dem Framework-Repository die Standard-Open-Source-Health-Dateien hinzu: Beitragsrichtlinien, Verhaltenskodex (basierend auf Contributor Covenant v2.1) und Sicherheitsrichtlinie.
Führt den Sovereign-Pillar als 7. Säule von WAF++ ein — Datensouveränität, Compliance und jurisdiktionale Kontrolle. Liefert 10 initiale Controls (WAF-SOV-010 bis WAF-SOV-100).
Strukturiert den Governance-Pillar (Säule 7) in modulare Best-Practice-Seiten um, ergänzt Fallstudien-Inhalte und aktualisiert die Antora-Navigation für bessere Auffindbarkeit und Lesbarkeit.
Definiert ein formales Schema für WAF++-Controls-YAML-Dateien, das konsistente Validierung, Tool-Integration und die Nutzung der 83+ Controls Library durch Dritte ermöglicht. Mit der v1.0-Release ausgeliefert.
Formalisiert das PASS-Scoring-Modell als normative Spezifikation: Tier-Definitionen, Berechnungsregeln, Aggregationslogik und Versionierungsvertrag. Voraussetzung für und ausgeliefert mit WAFPass CLI / Server v1.0.0.
Definiert den Ansatz für das offizielle WAF++-Assessment-Tooling: WAFPass CLI, Server, Dashboard und Web-Scorecard, die die Controls Library nutzen und einen PASS-Score-Bericht erzeugen. Mit WAFPass v1.0.0 ausgeliefert und in v1.1.0 erweitert.
Führt automatisierte Checks und Release-Workflows für die Repositories framework, pass, wafpass-server und wafpass-dashboard ein: Antora-Build-Validierung, Controls-YAML-Linting, Release-Automatisierung und Link-Prüfung bei jedem Pull Request.
Fügt den Agentic-Pillar (WAF-AGN) als 8. Säule von WAF++ hinzu — Governance autonomer KI-Agenten. Liefert 10 initiale Controls (WAF-AGN-010 bis WAF-AGN-100), regulatorische Mappings sowie englische und deutsche Dokumentation. Erweitert das Framework auf 8 Säulen und 83+ Controls.
WAFPass
Erweitert WAFPass CLI, Server und Dashboard, um die Agentic-Pillar-Controls (WAF-AGN-*) im Rahmen einer vollständigen PASS-Bewertung auszuwerten. Vor der WAFPass-v1.1.0-Release gemergt.
Veröffentlicht WAFPass CLI v1.1.0, WAFPass Server v1.1.0 und WAFPass Dashboard v1.1.0 mit Unterstützung für Säule-8 Agentic, Korrekturen bei der Erkennung und SINA-Cloud-Region-Erkennung. Abgestimmt auf Framework v1.1 und die 83+ Controls Library.
Eine Änderung vorschlagen?
Eine GitHub Discussion mit dem RFC-Template eröffnen. Die Community prüft es, Maintainer entscheiden — alles ist dokumentiert und nachvollziehbar.
Was qualifiziert sich als RFC?
Nicht jede Änderung braucht einen RFC — nur wesentliche. Die folgende Tabelle hilft bei der Entscheidung.
| Änderungstyp | RFC erforderlich? | Prozess |
|---|---|---|
| Neue Säule oder Entfernung einer Säule | Ja | RFC → TSC-Abstimmung → PR |
| Änderungen am Scoring-Modell (PASS-Tiers, Gewichtungen) | Ja | RFC → TSC-Abstimmung → PR |
| Breaking Changes am Controls-Schema oder IDs | Ja | RFC → TSC-Abstimmung → PR |
| Neuer Working-Group-Vorschlag | Ja | RFC → Lazy Consensus → Charter veröffentlicht |
| Governance- oder Rollenänderungen | Ja | RFC → TSC-Supermehrheit |
| Neuer Control (nicht-breaking, additiv) | Empfohlen | PR mit Diskussionslink · Lazy Consensus |
| Docs-Wording, Tippfehler, Übersetzungen | Nein | Nur PR |
| Website-Inhalte, Blog-Beiträge | Nein | Nur PR |
RFC-Status-Ablauf
Jeder RFC folgt demselben dokumentierten Pfad — vom ersten Entwurf bis zur geschlossenen Entscheidung.
Was einen guten RFC ausmacht
Drei Dinge, die den Unterschied machen zwischen einem RFC, der schnell vorankommt, und einem, der stagniert.
Problem beschreiben, nicht die Lösung
Beginne damit, was fehlt oder nicht funktioniert — nicht damit, was du bauen willst. Reviewer müssen zuerst dem Problem zustimmen, bevor sie eine Lösung beurteilen können. Das „Warum“ kommt vor dem „Was“.
Trade-offs explizit benennen
Jede Entscheidung hat Kosten. Benenne sie. Was wird schlechter? Welche Alternativen hast du erwogen? Ein RFC, der Trade-offs anerkennt, gewinnt Vertrauen schneller als einer, der nur Vorteile verkauft.
Auf Evidenz verweisen
Verweise auf echte Beispiele — Issues, Vorfälle, frühere Diskussionen oder Produktionsmuster. Evidenz verwandelt Meinungen in nachvollziehbare Fakten und verkürzt den Review-Zyklus erheblich.
Starte heute einen RFC.
Eröffne eine Diskussion auf GitHub, folge dem Template und lass den Prozess den Rest erledigen. Keine vorherige Genehmigung nötig — nur eine klare Problembeschreibung.