Governance · Transparent by Default

RFC Tracker

Jede wesentliche Änderung an WAF++ beginnt mit einem öffentlichen Request for Comments. Diese Seite verfolgt jeden RFC — vom ersten Entwurf bis zum Merge — damit jede Entscheidung nachvollziehbar bleibt.

14 umgesetzt 19 offen zur Prüfung 2 Entwürfe
35
RFCs gesamt
19
Offen zur Prüfung
2
Entwürfe
14
Umgesetzt
0
Akzeptiert
0
Abgelehnt
Vorschläge

Alle Requests for Comments

Nach Status filtern, Zusammenfassungen lesen und den verlinkten Diskussionen sowie Pull Requests folgen.

WAF++ Framework

RFC-0001 Initiale 7-Säulen-Framework-Struktur
implemented framework

Legt das grundlegende Sieben-Säulen-Modell als Basis von WAF++ fest: Sicherheit, Zuverlässigkeit, Performance-Effizienz, Kostenoptimierung, Operationelle Exzellenz, Nachhaltigkeit und Developer Experience. Durch RFC-0012 auf acht Säulen erweitert.

Autor:sascha-lewandowski Eröffnet: 2025-12-05Entschieden: 2025-12-05Umgesetzt: 2025-12-05PR: #1
RFC-0002 Öffentliche Roadmap 2026 und Meilensteinplanung
implemented governance

Definiert die öffentliche Roadmap für 2026 mit Q1–Q4-Meilensteinen, v1.0-Ziel, Pilotprogramm und Foundation-Readiness-Zielen.

Autor:sascha-lewandowski Eröffnet: 2025-12-06Entschieden: 2025-12-06Umgesetzt: 2025-12-06PR: #2
RFC-0003 Pillar-Beschreibungen und Kernfragen — 7 Säulen
implemented framework

Fügt die initiale Inhaltsdefinition für jede der 7 Säulen hinzu: Scope, Begründung und Kernbewertungsfragen. Bildet die Basis für die Controls Library und wurde später um die 8. Säule Agentic erweitert (RFC-0012).

Autor:sascha-lewandowski Eröffnet: 2025-12-07Entschieden: 2025-12-07Umgesetzt: 2025-12-07PR: #3
RFC-0004 Dokumentationsmigration zu AsciiDoc / Antora
implemented docs

Migriert die gesamte Framework-Dokumentation von Markdown nach AsciiDoc und etabliert Antora als Dokumentations-Build-System mit Komponenten-Versionierung (v1.0).

Autor:t1murl Eröffnet: 2026-02-20Entschieden: 2026-02-26Umgesetzt: 2026-02-26PR: #4
RFC-0005 Contribution-Metadaten: CONTRIBUTING, CODE_OF_CONDUCT, SECURITY
implemented governance

Fügt dem Framework-Repository die Standard-Open-Source-Health-Dateien hinzu: Beitragsrichtlinien, Verhaltenskodex (basierend auf Contributor Covenant v2.1) und Sicherheitsrichtlinie.

Autor:sascha-lewandowski Eröffnet: 2026-02-06Entschieden: 2026-02-08Umgesetzt: 2026-02-08PR: #6
RFC-0006 Sovereign-Pillar (Säule 7) — initiale Controls
implemented framework

Führt den Sovereign-Pillar als 7. Säule von WAF++ ein — Datensouveränität, Compliance und jurisdiktionale Kontrolle. Liefert 10 initiale Controls (WAF-SOV-010 bis WAF-SOV-100).

Autor:sascha-lewandowski Eröffnet: 2026-02-14Entschieden: 2026-03-04Umgesetzt: 2026-03-04
RFC-0007 Governance-Refactor: modulare Best Practices, Fallstudien und Navigation
implemented framework

Strukturiert den Governance-Pillar (Säule 7) in modulare Best-Practice-Seiten um, ergänzt Fallstudien-Inhalte und aktualisiert die Antora-Navigation für bessere Auffindbarkeit und Lesbarkeit.

Autor:sascha-lewandowski Eröffnet: 2026-02-24Entschieden: 2026-03-04Umgesetzt: 2026-03-04PR: #10
RFC-0008 Controls-Schema v1 — maschinenlesbare YAML-Spezifikation
implemented tooling

Definiert ein formales Schema für WAF++-Controls-YAML-Dateien, das konsistente Validierung, Tool-Integration und die Nutzung der 83+ Controls Library durch Dritte ermöglicht. Mit der v1.0-Release ausgeliefert.

Autor:sascha-lewandowski Eröffnet: 2026-03-10Entschieden: 2026-05-12Umgesetzt: 2026-05-12
RFC-0009 PASS-Scoring-Modell — formale Spezifikation für v1.0
implemented framework

Formalisiert das PASS-Scoring-Modell als normative Spezifikation: Tier-Definitionen, Berechnungsregeln, Aggregationslogik und Versionierungsvertrag. Voraussetzung für und ausgeliefert mit WAFPass CLI / Server v1.0.0.

Autor:t1murl Eröffnet: 2026-03-08Entschieden: 2026-05-12Umgesetzt: 2026-05-12
RFC-0010 Assessment-Tooling — CLI und Scorecard-Ansatz
implemented tooling

Definiert den Ansatz für das offizielle WAF++-Assessment-Tooling: WAFPass CLI, Server, Dashboard und Web-Scorecard, die die Controls Library nutzen und einen PASS-Score-Bericht erzeugen. Mit WAFPass v1.0.0 ausgeliefert und in v1.1.0 erweitert.

Autor:sascha-lewandowski Eröffnet: 2026-03-11Entschieden: 2026-05-12Umgesetzt: 2026-05-12
RFC-0011 CI/CD-Pipeline für Framework- und Tooling-Repositories
implemented tooling

Führt automatisierte Checks und Release-Workflows für die Repositories framework, pass, wafpass-server und wafpass-dashboard ein: Antora-Build-Validierung, Controls-YAML-Linting, Release-Automatisierung und Link-Prüfung bei jedem Pull Request.

Autor:t1murl Eröffnet: 2026-03-11Entschieden: 2026-03-22Umgesetzt: 2026-03-22
RFC-0012 Agentic-Pillar als 8. Säule
implemented framework

Fügt den Agentic-Pillar (WAF-AGN) als 8. Säule von WAF++ hinzu — Governance autonomer KI-Agenten. Liefert 10 initiale Controls (WAF-AGN-010 bis WAF-AGN-100), regulatorische Mappings sowie englische und deutsche Dokumentation. Erweitert das Framework auf 8 Säulen und 83+ Controls.

Autor:sascha-lewandowski Eröffnet: 2026-07-01Entschieden: 2026-07-05Umgesetzt: 2026-07-05PR: #19
RFC-0015 Website-Radical-Redesign — dunkles Theme auf alle öffentlichen Seiten ausrollen
open docs

Rollt das radical dunkle Design-System auf die verbleibenden öffentlichen Seiten (RFC-Tracker, Team, Rollen, About, Press, Install) aus, sodass die gesamte Website eine konsistente visuelle Sprache und Barrierefreiheitsmuster verwendet.

Autor:sascha-lewandowski Eröffnet: 2026-07-06Diskussion: GitHub →
RFC-0016 Remediation-Playbooks auf Control-Ebene
draft framework

Standardisiert maschinen- und menschenlesbare Remediation-Anleitungen für jeden WAF++-Control, damit Betriebsteams direkt aus einem PASS-Bericht oder Dashboard handeln können.

Autor:sascha-lewandowski Eröffnet: 2026-07-08
RFC-0017 Multi-Cloud-Provider-Erweiterung über AWS und SINA Cloud hinaus
draft tooling

Definiert, wie WAFPass-Erkennung und Controls um Azure, GCP und weitere Cloud-Provider erweitert werden, während das Framework cloud-agnostic bleibt.

Autor:sascha-lewandowski Eröffnet: 2026-07-08
GH-framework-26 RFC: Qualitätssicherung
open docs

- CI-Check für tote xrefs - CI-Check für unregistrierte nav.adoc - Linter für Control-Schema-Konsistenz (YAML ↔ .adoc ↔ Nav)

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-25 RFC: Sovereign & Resources ausbauen
open docs

- Sovereign-Definition/Scope/Principles auf Peer-Level erweitern - Sovereign-Evidence-Matrix - resources/index.adoc und wording/index.adoc als echte Übersicht/Glossar

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-23 RFC: Agentic-Säule vollenden
open docs

- maturity.adoc anlegen - evidence.adoc auf Security-Vorbild erweitern - glossary.adoc vervollständigen - alle agent-design/* und best-practices/* mit Beispielen ausschreiben

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-22 RFC: Navigation & Links konsolidieren
open docs

WIP - Homepage + pillars/index.adoc auf einheitliche Modul-Links umstellen - 64 relative ../-xrefs in modulpräfix-xrefs wandeln - Markdown-Links in bp-runbooks.adoc bereinigen

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-21 RFC: Antora-Struktur finalisieren
open docs

WIP - antora.yml: alle 10 Nav-Dateien registrieren, start_page setzen - pillar-security/nav.adoc anlegen - README.md + AGENTS.md auf 8-Modul-Layout aktualisieren - Entscheidung: efficiancy umbenennen ja/nein

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-24 RFC: Controls-Katalog korrigieren und erweitern
open docs

- 8 Säulen, korrekte Nummerierung - Agentic aufnehmen - WAF-COST-001 entweder in 010 umbenennen oder offiziell als “Pre-010” etablieren - control-schema.adoc auf AGN erweitern

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →

WAF++ Framework — Offen zur Prüfung

RFC-0015 Website-Radical-Redesign — dunkles Theme auf alle öffentlichen Seiten ausrollen
open docs

Rollt das radical dunkle Design-System auf die verbleibenden öffentlichen Seiten (RFC-Tracker, Team, Rollen, About, Press, Install) aus, sodass die gesamte Website eine konsistente visuelle Sprache und Barrierefreiheitsmuster verwendet.

Autor:sascha-lewandowski Eröffnet: 2026-07-06Diskussion: GitHub →
GH-framework-26 RFC: Qualitätssicherung
open docs

- CI-Check für tote xrefs - CI-Check für unregistrierte nav.adoc - Linter für Control-Schema-Konsistenz (YAML ↔ .adoc ↔ Nav)

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-25 RFC: Sovereign & Resources ausbauen
open docs

- Sovereign-Definition/Scope/Principles auf Peer-Level erweitern - Sovereign-Evidence-Matrix - resources/index.adoc und wording/index.adoc als echte Übersicht/Glossar

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-23 RFC: Agentic-Säule vollenden
open docs

- maturity.adoc anlegen - evidence.adoc auf Security-Vorbild erweitern - glossary.adoc vervollständigen - alle agent-design/* und best-practices/* mit Beispielen ausschreiben

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-22 RFC: Navigation & Links konsolidieren
open docs

WIP - Homepage + pillars/index.adoc auf einheitliche Modul-Links umstellen - 64 relative ../-xrefs in modulpräfix-xrefs wandeln - Markdown-Links in bp-runbooks.adoc bereinigen

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-21 RFC: Antora-Struktur finalisieren
open docs

WIP - antora.yml: alle 10 Nav-Dateien registrieren, start_page setzen - pillar-security/nav.adoc anlegen - README.md + AGENTS.md auf 8-Modul-Layout aktualisieren - Entscheidung: efficiancy umbenennen ja/nein

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-24 RFC: Controls-Katalog korrigieren und erweitern
open docs

- 8 Säulen, korrekte Nummerierung - Agentic aufnehmen - WAF-COST-001 entweder in 010 umbenennen oder offiziell als “Pre-010” etablieren - control-schema.adoc auf AGN erweitern

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →

WAF++ Framework — Entwürfe

RFC-0016 Remediation-Playbooks auf Control-Ebene
draft framework

Standardisiert maschinen- und menschenlesbare Remediation-Anleitungen für jeden WAF++-Control, damit Betriebsteams direkt aus einem PASS-Bericht oder Dashboard handeln können.

Autor:sascha-lewandowski Eröffnet: 2026-07-08
RFC-0017 Multi-Cloud-Provider-Erweiterung über AWS und SINA Cloud hinaus
draft tooling

Definiert, wie WAFPass-Erkennung und Controls um Azure, GCP und weitere Cloud-Provider erweitert werden, während das Framework cloud-agnostic bleibt.

Autor:sascha-lewandowski Eröffnet: 2026-07-08

WAF++ Framework — Entschieden / umgesetzt

RFC-0001 Initiale 7-Säulen-Framework-Struktur
implemented framework

Legt das grundlegende Sieben-Säulen-Modell als Basis von WAF++ fest: Sicherheit, Zuverlässigkeit, Performance-Effizienz, Kostenoptimierung, Operationelle Exzellenz, Nachhaltigkeit und Developer Experience. Durch RFC-0012 auf acht Säulen erweitert.

Autor:sascha-lewandowski Eröffnet: 2025-12-05Entschieden: 2025-12-05Umgesetzt: 2025-12-05PR: #1
RFC-0002 Öffentliche Roadmap 2026 und Meilensteinplanung
implemented governance

Definiert die öffentliche Roadmap für 2026 mit Q1–Q4-Meilensteinen, v1.0-Ziel, Pilotprogramm und Foundation-Readiness-Zielen.

Autor:sascha-lewandowski Eröffnet: 2025-12-06Entschieden: 2025-12-06Umgesetzt: 2025-12-06PR: #2
RFC-0003 Pillar-Beschreibungen und Kernfragen — 7 Säulen
implemented framework

Fügt die initiale Inhaltsdefinition für jede der 7 Säulen hinzu: Scope, Begründung und Kernbewertungsfragen. Bildet die Basis für die Controls Library und wurde später um die 8. Säule Agentic erweitert (RFC-0012).

Autor:sascha-lewandowski Eröffnet: 2025-12-07Entschieden: 2025-12-07Umgesetzt: 2025-12-07PR: #3
RFC-0004 Dokumentationsmigration zu AsciiDoc / Antora
implemented docs

Migriert die gesamte Framework-Dokumentation von Markdown nach AsciiDoc und etabliert Antora als Dokumentations-Build-System mit Komponenten-Versionierung (v1.0).

Autor:t1murl Eröffnet: 2026-02-20Entschieden: 2026-02-26Umgesetzt: 2026-02-26PR: #4
RFC-0005 Contribution-Metadaten: CONTRIBUTING, CODE_OF_CONDUCT, SECURITY
implemented governance

Fügt dem Framework-Repository die Standard-Open-Source-Health-Dateien hinzu: Beitragsrichtlinien, Verhaltenskodex (basierend auf Contributor Covenant v2.1) und Sicherheitsrichtlinie.

Autor:sascha-lewandowski Eröffnet: 2026-02-06Entschieden: 2026-02-08Umgesetzt: 2026-02-08PR: #6
RFC-0006 Sovereign-Pillar (Säule 7) — initiale Controls
implemented framework

Führt den Sovereign-Pillar als 7. Säule von WAF++ ein — Datensouveränität, Compliance und jurisdiktionale Kontrolle. Liefert 10 initiale Controls (WAF-SOV-010 bis WAF-SOV-100).

Autor:sascha-lewandowski Eröffnet: 2026-02-14Entschieden: 2026-03-04Umgesetzt: 2026-03-04
RFC-0007 Governance-Refactor: modulare Best Practices, Fallstudien und Navigation
implemented framework

Strukturiert den Governance-Pillar (Säule 7) in modulare Best-Practice-Seiten um, ergänzt Fallstudien-Inhalte und aktualisiert die Antora-Navigation für bessere Auffindbarkeit und Lesbarkeit.

Autor:sascha-lewandowski Eröffnet: 2026-02-24Entschieden: 2026-03-04Umgesetzt: 2026-03-04PR: #10
RFC-0008 Controls-Schema v1 — maschinenlesbare YAML-Spezifikation
implemented tooling

Definiert ein formales Schema für WAF++-Controls-YAML-Dateien, das konsistente Validierung, Tool-Integration und die Nutzung der 83+ Controls Library durch Dritte ermöglicht. Mit der v1.0-Release ausgeliefert.

Autor:sascha-lewandowski Eröffnet: 2026-03-10Entschieden: 2026-05-12Umgesetzt: 2026-05-12
RFC-0009 PASS-Scoring-Modell — formale Spezifikation für v1.0
implemented framework

Formalisiert das PASS-Scoring-Modell als normative Spezifikation: Tier-Definitionen, Berechnungsregeln, Aggregationslogik und Versionierungsvertrag. Voraussetzung für und ausgeliefert mit WAFPass CLI / Server v1.0.0.

Autor:t1murl Eröffnet: 2026-03-08Entschieden: 2026-05-12Umgesetzt: 2026-05-12
RFC-0010 Assessment-Tooling — CLI und Scorecard-Ansatz
implemented tooling

Definiert den Ansatz für das offizielle WAF++-Assessment-Tooling: WAFPass CLI, Server, Dashboard und Web-Scorecard, die die Controls Library nutzen und einen PASS-Score-Bericht erzeugen. Mit WAFPass v1.0.0 ausgeliefert und in v1.1.0 erweitert.

Autor:sascha-lewandowski Eröffnet: 2026-03-11Entschieden: 2026-05-12Umgesetzt: 2026-05-12
RFC-0011 CI/CD-Pipeline für Framework- und Tooling-Repositories
implemented tooling

Führt automatisierte Checks und Release-Workflows für die Repositories framework, pass, wafpass-server und wafpass-dashboard ein: Antora-Build-Validierung, Controls-YAML-Linting, Release-Automatisierung und Link-Prüfung bei jedem Pull Request.

Autor:t1murl Eröffnet: 2026-03-11Entschieden: 2026-03-22Umgesetzt: 2026-03-22
RFC-0012 Agentic-Pillar als 8. Säule
implemented framework

Fügt den Agentic-Pillar (WAF-AGN) als 8. Säule von WAF++ hinzu — Governance autonomer KI-Agenten. Liefert 10 initiale Controls (WAF-AGN-010 bis WAF-AGN-100), regulatorische Mappings sowie englische und deutsche Dokumentation. Erweitert das Framework auf 8 Säulen und 83+ Controls.

Autor:sascha-lewandowski Eröffnet: 2026-07-01Entschieden: 2026-07-05Umgesetzt: 2026-07-05PR: #19

WAFPass

RFC-0013 WAFPass-Unterstützung für Säule-8 Agentic
implemented tooling

Erweitert WAFPass CLI, Server und Dashboard, um die Agentic-Pillar-Controls (WAF-AGN-*) im Rahmen einer vollständigen PASS-Bewertung auszuwerten. Vor der WAFPass-v1.1.0-Release gemergt.

Autor:sascha-lewandowski Eröffnet: 2026-05-20Entschieden: 2026-05-27Umgesetzt: 2026-05-27PR: #28
RFC-0014 WAFPass CLI / Server / Dashboard v1.1.0-Release
implemented tooling

Veröffentlicht WAFPass CLI v1.1.0, WAFPass Server v1.1.0 und WAFPass Dashboard v1.1.0 mit Unterstützung für Säule-8 Agentic, Korrekturen bei der Erkennung und SINA-Cloud-Region-Erkennung. Abgestimmt auf Framework v1.1 und die 83+ Controls Library.

Autor:sascha-lewandowski Eröffnet: 2026-06-28Entschieden: 2026-07-05Umgesetzt: 2026-07-05PR: #31
GH-pass-41 Feature Request: Comprehensive Test/Quality Coverage Implementation Plan
open tooling

📋 Context & Problem Statement The WAF++ PASS platform code and test coverage are highly fragmented across three distinct repositories: * pass (Python CLI / pytest): Contains ~150 unit tests, localized auto-fix tests, and a single golden-file E2E fixture, but…

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-pass-42 Feature Request: API Versioning and Backwards-Compatibility Strategy for WAF++ PASS
open tooling

Context and Goals The WAF++ PASS product is moving through an API maturity push. Several parallel efforts already exist or are planned: * Maturity enforcement: Achievements, leaderboard, project passports, and tier rules. * Action-oriented notifications:…

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub → Kommentare: lewandos
GH-pass-43 Feature Request: Source Snapshots — Ingestion Contract and Reliable Upload Path
open tooling

Context Dashboard local preview and auto-fix features rely on Run.source_snapshot, a JSONB map of relative IaC file paths to raw file contents. Today, this snapshot is only captured when the CLI is explicitly invoked with both --output json, --upload-source,…

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-pass-40 Feature Request: Dashboard UX Overhaul — Guided Onboarding, Role-Based Landing, and Progressive Disclosure
open tooling

📋 Context & Problem Statement The dashboard currently exposes 46 pages through a bloated, 700px-wide mega-menu in TopNavigation.tsx. The navigation model is highly fragmented; buildNavSections() is duplicated across Sidebar.tsx and MobileMenu.tsx, leading to…

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-pass-39 Feature Request: Implement Action-Oriented Notifications
open tooling

📋 Context & Problem Statement The dashboard currently features a NotificationBell and a dedicated NotificationsPage, but notifications are entirely passive—they only display text titles, messages, and categories with no trailing interactive…

Autor: lewandos lewandos Eröffnet: 2026-07-17Diskussion: GitHub →
GH-pass-38 Feature Request: Implement Control Packs Marketplace
open tooling

📋 Context & Problem Statement The dashboard currently features a ControlsPacksPage and the server exposes /control-packs endpoints, but functionality is restricted to admin-only uploads and basic catalogue syncs[cite: 1]. Auditors have highlighted that the…

Autor: lewandos lewandos Eröffnet: 2026-07-17Diskussion: GitHub → Kommentare: lewandos
GH-pass-37 Feature Request: Implement Maturity-Tier Enforcement Policy Gates
open tooling

📋 Context & Problem Statement Currently, the maturity journey is purely a dashboard visualization and local settings concept. Auditors have flagged a critical gap: there are no policy gates tying maturity tiers to CI/CD pipeline behavior (e.g., preventing a…

Autor: lewandos lewandos Eröffnet: 2026-07-17Diskussion: GitHub →

WAFPass — Offen zur Prüfung

GH-pass-41 Feature Request: Comprehensive Test/Quality Coverage Implementation Plan
open tooling

📋 Context & Problem Statement The WAF++ PASS platform code and test coverage are highly fragmented across three distinct repositories: * pass (Python CLI / pytest): Contains ~150 unit tests, localized auto-fix tests, and a single golden-file E2E fixture, but…

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-pass-42 Feature Request: API Versioning and Backwards-Compatibility Strategy for WAF++ PASS
open tooling

Context and Goals The WAF++ PASS product is moving through an API maturity push. Several parallel efforts already exist or are planned: * Maturity enforcement: Achievements, leaderboard, project passports, and tier rules. * Action-oriented notifications:…

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub → Kommentare: lewandos
GH-pass-43 Feature Request: Source Snapshots — Ingestion Contract and Reliable Upload Path
open tooling

Context Dashboard local preview and auto-fix features rely on Run.source_snapshot, a JSONB map of relative IaC file paths to raw file contents. Today, this snapshot is only captured when the CLI is explicitly invoked with both --output json, --upload-source,…

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-pass-40 Feature Request: Dashboard UX Overhaul — Guided Onboarding, Role-Based Landing, and Progressive Disclosure
open tooling

📋 Context & Problem Statement The dashboard currently exposes 46 pages through a bloated, 700px-wide mega-menu in TopNavigation.tsx. The navigation model is highly fragmented; buildNavSections() is duplicated across Sidebar.tsx and MobileMenu.tsx, leading to…

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-pass-39 Feature Request: Implement Action-Oriented Notifications
open tooling

📋 Context & Problem Statement The dashboard currently features a NotificationBell and a dedicated NotificationsPage, but notifications are entirely passive—they only display text titles, messages, and categories with no trailing interactive…

Autor: lewandos lewandos Eröffnet: 2026-07-17Diskussion: GitHub →
GH-pass-38 Feature Request: Implement Control Packs Marketplace
open tooling

📋 Context & Problem Statement The dashboard currently features a ControlsPacksPage and the server exposes /control-packs endpoints, but functionality is restricted to admin-only uploads and basic catalogue syncs[cite: 1]. Auditors have highlighted that the…

Autor: lewandos lewandos Eröffnet: 2026-07-17Diskussion: GitHub → Kommentare: lewandos
GH-pass-37 Feature Request: Implement Maturity-Tier Enforcement Policy Gates
open tooling

📋 Context & Problem Statement Currently, the maturity journey is purely a dashboard visualization and local settings concept. Auditors have flagged a critical gap: there are no policy gates tying maturity tiers to CI/CD pipeline behavior (e.g., preventing a…

Autor: lewandos lewandos Eröffnet: 2026-07-17Diskussion: GitHub →
Keine Entwürfe für WAFPass.

WAFPass — Entschieden / umgesetzt

RFC-0013 WAFPass-Unterstützung für Säule-8 Agentic
implemented tooling

Erweitert WAFPass CLI, Server und Dashboard, um die Agentic-Pillar-Controls (WAF-AGN-*) im Rahmen einer vollständigen PASS-Bewertung auszuwerten. Vor der WAFPass-v1.1.0-Release gemergt.

Autor:sascha-lewandowski Eröffnet: 2026-05-20Entschieden: 2026-05-27Umgesetzt: 2026-05-27PR: #28
RFC-0014 WAFPass CLI / Server / Dashboard v1.1.0-Release
implemented tooling

Veröffentlicht WAFPass CLI v1.1.0, WAFPass Server v1.1.0 und WAFPass Dashboard v1.1.0 mit Unterstützung für Säule-8 Agentic, Korrekturen bei der Erkennung und SINA-Cloud-Region-Erkennung. Abgestimmt auf Framework v1.1 und die 83+ Controls Library.

Autor:sascha-lewandowski Eröffnet: 2026-06-28Entschieden: 2026-07-05Umgesetzt: 2026-07-05PR: #31
Keine RFCs für WAFPass Action.
Keine offenen RFCs für WAFPass Action.
Keine Entwürfe für WAFPass Action.
Keine entschiedenen oder umgesetzten RFCs für WAFPass Action.

WAFPass MCP

GH-wafpass-mcp-7 RFC-5: Role-aware natural tool aliasing
open tooling

Problem: Tool names are long and auto-generated (api_auto_fix_classify_api_v1_auto_fix_classify_post). The LLM has to match long operation IDs, and the descriptions are now long because they embed role/category. Proposal: Allow curated aliases for the…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →
GH-wafpass-mcp-4 RFC-2: MCP resource-level read-only endpoints
open tooling

Problem: The MCP only exposes tools. Users cannot ask "what controls failed in this run?" or "show me the source snapshot" without making multiple tool calls and stitching the JSON together. Proposal: Add MCP Resource definitions for run://{run_id},…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →
GH-wafpass-mcp-6 RFC-4: Multi-step remediation plans (apply with rollback)
open tooling

Problem: Users can classify and preview patches, but applying them requires a separate auto-fix call with a filesystem path. There is no safe "apply this classify result to this run and record what changed." Proposal: Extend /api/v1/auto-fix/classify with an…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →
GH-wafpass-mcp-5 RFC-3: Streaming/paginated tool results for large runs
open tooling

Problem: Runs with thousands of findings return huge JSON blobs. The current proxy loads everything into one TextContent block, which is slow and can hit MCP message size limits. Proposal: Add cursor-based pagination helpers to the bridge: - For list…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →
GH-wafpass-mcp-3 RFC-1: Auto-fix default templates for WAFpass controls
open tooling

Problem: auto-fix/classify returns zero active patches for many controls because assertions like not_empty, attribute_exists, is_true have no registered default value. Proposal: Add a fix block to control YAMLs (or a central provider registry) that declares:…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →

WAFPass MCP — Offen zur Prüfung

GH-wafpass-mcp-7 RFC-5: Role-aware natural tool aliasing
open tooling

Problem: Tool names are long and auto-generated (api_auto_fix_classify_api_v1_auto_fix_classify_post). The LLM has to match long operation IDs, and the descriptions are now long because they embed role/category. Proposal: Allow curated aliases for the…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →
GH-wafpass-mcp-4 RFC-2: MCP resource-level read-only endpoints
open tooling

Problem: The MCP only exposes tools. Users cannot ask "what controls failed in this run?" or "show me the source snapshot" without making multiple tool calls and stitching the JSON together. Proposal: Add MCP Resource definitions for run://{run_id},…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →
GH-wafpass-mcp-6 RFC-4: Multi-step remediation plans (apply with rollback)
open tooling

Problem: Users can classify and preview patches, but applying them requires a separate auto-fix call with a filesystem path. There is no safe "apply this classify result to this run and record what changed." Proposal: Extend /api/v1/auto-fix/classify with an…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →
GH-wafpass-mcp-5 RFC-3: Streaming/paginated tool results for large runs
open tooling

Problem: Runs with thousands of findings return huge JSON blobs. The current proxy loads everything into one TextContent block, which is slow and can hit MCP message size limits. Proposal: Add cursor-based pagination helpers to the bridge: - For list…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →
GH-wafpass-mcp-3 RFC-1: Auto-fix default templates for WAFpass controls
open tooling

Problem: auto-fix/classify returns zero active patches for many controls because assertions like not_empty, attribute_exists, is_true have no registered default value. Proposal: Add a fix block to control YAMLs (or a central provider registry) that declares:…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →
Keine Entwürfe für WAFPass MCP.
Keine entschiedenen oder umgesetzten RFCs für WAFPass MCP.

WAF++ Framework

RFC-0001 Initiale 7-Säulen-Framework-Struktur
implemented framework

Legt das grundlegende Sieben-Säulen-Modell als Basis von WAF++ fest: Sicherheit, Zuverlässigkeit, Performance-Effizienz, Kostenoptimierung, Operationelle Exzellenz, Nachhaltigkeit und Developer Experience. Durch RFC-0012 auf acht Säulen erweitert.

Autor:sascha-lewandowski Eröffnet: 2025-12-05Entschieden: 2025-12-05Umgesetzt: 2025-12-05PR: #1
RFC-0002 Öffentliche Roadmap 2026 und Meilensteinplanung
implemented governance

Definiert die öffentliche Roadmap für 2026 mit Q1–Q4-Meilensteinen, v1.0-Ziel, Pilotprogramm und Foundation-Readiness-Zielen.

Autor:sascha-lewandowski Eröffnet: 2025-12-06Entschieden: 2025-12-06Umgesetzt: 2025-12-06PR: #2
RFC-0003 Pillar-Beschreibungen und Kernfragen — 7 Säulen
implemented framework

Fügt die initiale Inhaltsdefinition für jede der 7 Säulen hinzu: Scope, Begründung und Kernbewertungsfragen. Bildet die Basis für die Controls Library und wurde später um die 8. Säule Agentic erweitert (RFC-0012).

Autor:sascha-lewandowski Eröffnet: 2025-12-07Entschieden: 2025-12-07Umgesetzt: 2025-12-07PR: #3
RFC-0004 Dokumentationsmigration zu AsciiDoc / Antora
implemented docs

Migriert die gesamte Framework-Dokumentation von Markdown nach AsciiDoc und etabliert Antora als Dokumentations-Build-System mit Komponenten-Versionierung (v1.0).

Autor:t1murl Eröffnet: 2026-02-20Entschieden: 2026-02-26Umgesetzt: 2026-02-26PR: #4
RFC-0005 Contribution-Metadaten: CONTRIBUTING, CODE_OF_CONDUCT, SECURITY
implemented governance

Fügt dem Framework-Repository die Standard-Open-Source-Health-Dateien hinzu: Beitragsrichtlinien, Verhaltenskodex (basierend auf Contributor Covenant v2.1) und Sicherheitsrichtlinie.

Autor:sascha-lewandowski Eröffnet: 2026-02-06Entschieden: 2026-02-08Umgesetzt: 2026-02-08PR: #6
RFC-0006 Sovereign-Pillar (Säule 7) — initiale Controls
implemented framework

Führt den Sovereign-Pillar als 7. Säule von WAF++ ein — Datensouveränität, Compliance und jurisdiktionale Kontrolle. Liefert 10 initiale Controls (WAF-SOV-010 bis WAF-SOV-100).

Autor:sascha-lewandowski Eröffnet: 2026-02-14Entschieden: 2026-03-04Umgesetzt: 2026-03-04
RFC-0007 Governance-Refactor: modulare Best Practices, Fallstudien und Navigation
implemented framework

Strukturiert den Governance-Pillar (Säule 7) in modulare Best-Practice-Seiten um, ergänzt Fallstudien-Inhalte und aktualisiert die Antora-Navigation für bessere Auffindbarkeit und Lesbarkeit.

Autor:sascha-lewandowski Eröffnet: 2026-02-24Entschieden: 2026-03-04Umgesetzt: 2026-03-04PR: #10
RFC-0008 Controls-Schema v1 — maschinenlesbare YAML-Spezifikation
implemented tooling

Definiert ein formales Schema für WAF++-Controls-YAML-Dateien, das konsistente Validierung, Tool-Integration und die Nutzung der 83+ Controls Library durch Dritte ermöglicht. Mit der v1.0-Release ausgeliefert.

Autor:sascha-lewandowski Eröffnet: 2026-03-10Entschieden: 2026-05-12Umgesetzt: 2026-05-12
RFC-0009 PASS-Scoring-Modell — formale Spezifikation für v1.0
implemented framework

Formalisiert das PASS-Scoring-Modell als normative Spezifikation: Tier-Definitionen, Berechnungsregeln, Aggregationslogik und Versionierungsvertrag. Voraussetzung für und ausgeliefert mit WAFPass CLI / Server v1.0.0.

Autor:t1murl Eröffnet: 2026-03-08Entschieden: 2026-05-12Umgesetzt: 2026-05-12
RFC-0010 Assessment-Tooling — CLI und Scorecard-Ansatz
implemented tooling

Definiert den Ansatz für das offizielle WAF++-Assessment-Tooling: WAFPass CLI, Server, Dashboard und Web-Scorecard, die die Controls Library nutzen und einen PASS-Score-Bericht erzeugen. Mit WAFPass v1.0.0 ausgeliefert und in v1.1.0 erweitert.

Autor:sascha-lewandowski Eröffnet: 2026-03-11Entschieden: 2026-05-12Umgesetzt: 2026-05-12
RFC-0011 CI/CD-Pipeline für Framework- und Tooling-Repositories
implemented tooling

Führt automatisierte Checks und Release-Workflows für die Repositories framework, pass, wafpass-server und wafpass-dashboard ein: Antora-Build-Validierung, Controls-YAML-Linting, Release-Automatisierung und Link-Prüfung bei jedem Pull Request.

Autor:t1murl Eröffnet: 2026-03-11Entschieden: 2026-03-22Umgesetzt: 2026-03-22
RFC-0012 Agentic-Pillar als 8. Säule
implemented framework

Fügt den Agentic-Pillar (WAF-AGN) als 8. Säule von WAF++ hinzu — Governance autonomer KI-Agenten. Liefert 10 initiale Controls (WAF-AGN-010 bis WAF-AGN-100), regulatorische Mappings sowie englische und deutsche Dokumentation. Erweitert das Framework auf 8 Säulen und 83+ Controls.

Autor:sascha-lewandowski Eröffnet: 2026-07-01Entschieden: 2026-07-05Umgesetzt: 2026-07-05PR: #19
RFC-0015 Website-Radical-Redesign — dunkles Theme auf alle öffentlichen Seiten ausrollen
open docs

Rollt das radical dunkle Design-System auf die verbleibenden öffentlichen Seiten (RFC-Tracker, Team, Rollen, About, Press, Install) aus, sodass die gesamte Website eine konsistente visuelle Sprache und Barrierefreiheitsmuster verwendet.

Autor:sascha-lewandowski Eröffnet: 2026-07-06Diskussion: GitHub →
RFC-0016 Remediation-Playbooks auf Control-Ebene
draft framework

Standardisiert maschinen- und menschenlesbare Remediation-Anleitungen für jeden WAF++-Control, damit Betriebsteams direkt aus einem PASS-Bericht oder Dashboard handeln können.

Autor:sascha-lewandowski Eröffnet: 2026-07-08
RFC-0017 Multi-Cloud-Provider-Erweiterung über AWS und SINA Cloud hinaus
draft tooling

Definiert, wie WAFPass-Erkennung und Controls um Azure, GCP und weitere Cloud-Provider erweitert werden, während das Framework cloud-agnostic bleibt.

Autor:sascha-lewandowski Eröffnet: 2026-07-08
GH-framework-26 RFC: Qualitätssicherung
open docs

- CI-Check für tote xrefs - CI-Check für unregistrierte nav.adoc - Linter für Control-Schema-Konsistenz (YAML ↔ .adoc ↔ Nav)

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-25 RFC: Sovereign & Resources ausbauen
open docs

- Sovereign-Definition/Scope/Principles auf Peer-Level erweitern - Sovereign-Evidence-Matrix - resources/index.adoc und wording/index.adoc als echte Übersicht/Glossar

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-23 RFC: Agentic-Säule vollenden
open docs

- maturity.adoc anlegen - evidence.adoc auf Security-Vorbild erweitern - glossary.adoc vervollständigen - alle agent-design/* und best-practices/* mit Beispielen ausschreiben

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-22 RFC: Navigation & Links konsolidieren
open docs

WIP - Homepage + pillars/index.adoc auf einheitliche Modul-Links umstellen - 64 relative ../-xrefs in modulpräfix-xrefs wandeln - Markdown-Links in bp-runbooks.adoc bereinigen

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-21 RFC: Antora-Struktur finalisieren
open docs

WIP - antora.yml: alle 10 Nav-Dateien registrieren, start_page setzen - pillar-security/nav.adoc anlegen - README.md + AGENTS.md auf 8-Modul-Layout aktualisieren - Entscheidung: efficiancy umbenennen ja/nein

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-24 RFC: Controls-Katalog korrigieren und erweitern
open docs

- 8 Säulen, korrekte Nummerierung - Agentic aufnehmen - WAF-COST-001 entweder in 010 umbenennen oder offiziell als “Pre-010” etablieren - control-schema.adoc auf AGN erweitern

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →

WAFPass

RFC-0013 WAFPass-Unterstützung für Säule-8 Agentic
implemented tooling

Erweitert WAFPass CLI, Server und Dashboard, um die Agentic-Pillar-Controls (WAF-AGN-*) im Rahmen einer vollständigen PASS-Bewertung auszuwerten. Vor der WAFPass-v1.1.0-Release gemergt.

Autor:sascha-lewandowski Eröffnet: 2026-05-20Entschieden: 2026-05-27Umgesetzt: 2026-05-27PR: #28
RFC-0014 WAFPass CLI / Server / Dashboard v1.1.0-Release
implemented tooling

Veröffentlicht WAFPass CLI v1.1.0, WAFPass Server v1.1.0 und WAFPass Dashboard v1.1.0 mit Unterstützung für Säule-8 Agentic, Korrekturen bei der Erkennung und SINA-Cloud-Region-Erkennung. Abgestimmt auf Framework v1.1 und die 83+ Controls Library.

Autor:sascha-lewandowski Eröffnet: 2026-06-28Entschieden: 2026-07-05Umgesetzt: 2026-07-05PR: #31
GH-pass-41 Feature Request: Comprehensive Test/Quality Coverage Implementation Plan
open tooling

📋 Context & Problem Statement The WAF++ PASS platform code and test coverage are highly fragmented across three distinct repositories: * pass (Python CLI / pytest): Contains ~150 unit tests, localized auto-fix tests, and a single golden-file E2E fixture, but…

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-pass-42 Feature Request: API Versioning and Backwards-Compatibility Strategy for WAF++ PASS
open tooling

Context and Goals The WAF++ PASS product is moving through an API maturity push. Several parallel efforts already exist or are planned: * Maturity enforcement: Achievements, leaderboard, project passports, and tier rules. * Action-oriented notifications:…

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub → Kommentare: lewandos
GH-pass-43 Feature Request: Source Snapshots — Ingestion Contract and Reliable Upload Path
open tooling

Context Dashboard local preview and auto-fix features rely on Run.source_snapshot, a JSONB map of relative IaC file paths to raw file contents. Today, this snapshot is only captured when the CLI is explicitly invoked with both --output json, --upload-source,…

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-pass-40 Feature Request: Dashboard UX Overhaul — Guided Onboarding, Role-Based Landing, and Progressive Disclosure
open tooling

📋 Context & Problem Statement The dashboard currently exposes 46 pages through a bloated, 700px-wide mega-menu in TopNavigation.tsx. The navigation model is highly fragmented; buildNavSections() is duplicated across Sidebar.tsx and MobileMenu.tsx, leading to…

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-pass-39 Feature Request: Implement Action-Oriented Notifications
open tooling

📋 Context & Problem Statement The dashboard currently features a NotificationBell and a dedicated NotificationsPage, but notifications are entirely passive—they only display text titles, messages, and categories with no trailing interactive…

Autor: lewandos lewandos Eröffnet: 2026-07-17Diskussion: GitHub →
GH-pass-38 Feature Request: Implement Control Packs Marketplace
open tooling

📋 Context & Problem Statement The dashboard currently features a ControlsPacksPage and the server exposes /control-packs endpoints, but functionality is restricted to admin-only uploads and basic catalogue syncs[cite: 1]. Auditors have highlighted that the…

Autor: lewandos lewandos Eröffnet: 2026-07-17Diskussion: GitHub → Kommentare: lewandos
GH-pass-37 Feature Request: Implement Maturity-Tier Enforcement Policy Gates
open tooling

📋 Context & Problem Statement Currently, the maturity journey is purely a dashboard visualization and local settings concept. Auditors have flagged a critical gap: there are no policy gates tying maturity tiers to CI/CD pipeline behavior (e.g., preventing a…

Autor: lewandos lewandos Eröffnet: 2026-07-17Diskussion: GitHub →

WAFPass Action

WAFPass MCP

GH-wafpass-mcp-7 RFC-5: Role-aware natural tool aliasing
open tooling

Problem: Tool names are long and auto-generated (api_auto_fix_classify_api_v1_auto_fix_classify_post). The LLM has to match long operation IDs, and the descriptions are now long because they embed role/category. Proposal: Allow curated aliases for the…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →
GH-wafpass-mcp-4 RFC-2: MCP resource-level read-only endpoints
open tooling

Problem: The MCP only exposes tools. Users cannot ask "what controls failed in this run?" or "show me the source snapshot" without making multiple tool calls and stitching the JSON together. Proposal: Add MCP Resource definitions for run://{run_id},…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →
GH-wafpass-mcp-6 RFC-4: Multi-step remediation plans (apply with rollback)
open tooling

Problem: Users can classify and preview patches, but applying them requires a separate auto-fix call with a filesystem path. There is no safe "apply this classify result to this run and record what changed." Proposal: Extend /api/v1/auto-fix/classify with an…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →
GH-wafpass-mcp-5 RFC-3: Streaming/paginated tool results for large runs
open tooling

Problem: Runs with thousands of findings return huge JSON blobs. The current proxy loads everything into one TextContent block, which is slow and can hit MCP message size limits. Proposal: Add cursor-based pagination helpers to the bridge: - For list…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →
GH-wafpass-mcp-3 RFC-1: Auto-fix default templates for WAFpass controls
open tooling

Problem: auto-fix/classify returns zero active patches for many controls because assertions like not_empty, attribute_exists, is_true have no registered default value. Proposal: Add a fix block to control YAMLs (or a central provider registry) that declares:…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →

WAF++ Framework

RFC-0015 Website-Radical-Redesign — dunkles Theme auf alle öffentlichen Seiten ausrollen
open docs

Rollt das radical dunkle Design-System auf die verbleibenden öffentlichen Seiten (RFC-Tracker, Team, Rollen, About, Press, Install) aus, sodass die gesamte Website eine konsistente visuelle Sprache und Barrierefreiheitsmuster verwendet.

Autor:sascha-lewandowski Eröffnet: 2026-07-06Diskussion: GitHub →
GH-framework-26 RFC: Qualitätssicherung
open docs

- CI-Check für tote xrefs - CI-Check für unregistrierte nav.adoc - Linter für Control-Schema-Konsistenz (YAML ↔ .adoc ↔ Nav)

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-25 RFC: Sovereign & Resources ausbauen
open docs

- Sovereign-Definition/Scope/Principles auf Peer-Level erweitern - Sovereign-Evidence-Matrix - resources/index.adoc und wording/index.adoc als echte Übersicht/Glossar

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-23 RFC: Agentic-Säule vollenden
open docs

- maturity.adoc anlegen - evidence.adoc auf Security-Vorbild erweitern - glossary.adoc vervollständigen - alle agent-design/* und best-practices/* mit Beispielen ausschreiben

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-22 RFC: Navigation & Links konsolidieren
open docs

WIP - Homepage + pillars/index.adoc auf einheitliche Modul-Links umstellen - 64 relative ../-xrefs in modulpräfix-xrefs wandeln - Markdown-Links in bp-runbooks.adoc bereinigen

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-21 RFC: Antora-Struktur finalisieren
open docs

WIP - antora.yml: alle 10 Nav-Dateien registrieren, start_page setzen - pillar-security/nav.adoc anlegen - README.md + AGENTS.md auf 8-Modul-Layout aktualisieren - Entscheidung: efficiancy umbenennen ja/nein

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-framework-24 RFC: Controls-Katalog korrigieren und erweitern
open docs

- 8 Säulen, korrekte Nummerierung - Agentic aufnehmen - WAF-COST-001 entweder in 010 umbenennen oder offiziell als “Pre-010” etablieren - control-schema.adoc auf AGN erweitern

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →

WAFPass MCP

GH-wafpass-mcp-7 RFC-5: Role-aware natural tool aliasing
open tooling

Problem: Tool names are long and auto-generated (api_auto_fix_classify_api_v1_auto_fix_classify_post). The LLM has to match long operation IDs, and the descriptions are now long because they embed role/category. Proposal: Allow curated aliases for the…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →
GH-wafpass-mcp-4 RFC-2: MCP resource-level read-only endpoints
open tooling

Problem: The MCP only exposes tools. Users cannot ask "what controls failed in this run?" or "show me the source snapshot" without making multiple tool calls and stitching the JSON together. Proposal: Add MCP Resource definitions for run://{run_id},…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →
GH-wafpass-mcp-6 RFC-4: Multi-step remediation plans (apply with rollback)
open tooling

Problem: Users can classify and preview patches, but applying them requires a separate auto-fix call with a filesystem path. There is no safe "apply this classify result to this run and record what changed." Proposal: Extend /api/v1/auto-fix/classify with an…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →
GH-wafpass-mcp-5 RFC-3: Streaming/paginated tool results for large runs
open tooling

Problem: Runs with thousands of findings return huge JSON blobs. The current proxy loads everything into one TextContent block, which is slow and can hit MCP message size limits. Proposal: Add cursor-based pagination helpers to the bridge: - For list…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →
GH-wafpass-mcp-3 RFC-1: Auto-fix default templates for WAFpass controls
open tooling

Problem: auto-fix/classify returns zero active patches for many controls because assertions like not_empty, attribute_exists, is_true have no registered default value. Proposal: Add a fix block to control YAMLs (or a central provider registry) that declares:…

Autor: lewandos lewandos Eröffnet: 2026-08-14Diskussion: GitHub →

WAFPass

GH-pass-41 Feature Request: Comprehensive Test/Quality Coverage Implementation Plan
open tooling

📋 Context & Problem Statement The WAF++ PASS platform code and test coverage are highly fragmented across three distinct repositories: * pass (Python CLI / pytest): Contains ~150 unit tests, localized auto-fix tests, and a single golden-file E2E fixture, but…

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-pass-42 Feature Request: API Versioning and Backwards-Compatibility Strategy for WAF++ PASS
open tooling

Context and Goals The WAF++ PASS product is moving through an API maturity push. Several parallel efforts already exist or are planned: * Maturity enforcement: Achievements, leaderboard, project passports, and tier rules. * Action-oriented notifications:…

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub → Kommentare: lewandos
GH-pass-43 Feature Request: Source Snapshots — Ingestion Contract and Reliable Upload Path
open tooling

Context Dashboard local preview and auto-fix features rely on Run.source_snapshot, a JSONB map of relative IaC file paths to raw file contents. Today, this snapshot is only captured when the CLI is explicitly invoked with both --output json, --upload-source,…

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-pass-40 Feature Request: Dashboard UX Overhaul — Guided Onboarding, Role-Based Landing, and Progressive Disclosure
open tooling

📋 Context & Problem Statement The dashboard currently exposes 46 pages through a bloated, 700px-wide mega-menu in TopNavigation.tsx. The navigation model is highly fragmented; buildNavSections() is duplicated across Sidebar.tsx and MobileMenu.tsx, leading to…

Autor: lewandos lewandos Eröffnet: 2026-07-18Diskussion: GitHub →
GH-pass-39 Feature Request: Implement Action-Oriented Notifications
open tooling

📋 Context & Problem Statement The dashboard currently features a NotificationBell and a dedicated NotificationsPage, but notifications are entirely passive—they only display text titles, messages, and categories with no trailing interactive…

Autor: lewandos lewandos Eröffnet: 2026-07-17Diskussion: GitHub →
GH-pass-38 Feature Request: Implement Control Packs Marketplace
open tooling

📋 Context & Problem Statement The dashboard currently features a ControlsPacksPage and the server exposes /control-packs endpoints, but functionality is restricted to admin-only uploads and basic catalogue syncs[cite: 1]. Auditors have highlighted that the…

Autor: lewandos lewandos Eröffnet: 2026-07-17Diskussion: GitHub → Kommentare: lewandos
GH-pass-37 Feature Request: Implement Maturity-Tier Enforcement Policy Gates
open tooling

📋 Context & Problem Statement Currently, the maturity journey is purely a dashboard visualization and local settings concept. Auditors have flagged a critical gap: there are no policy gates tying maturity tiers to CI/CD pipeline behavior (e.g., preventing a…

Autor: lewandos lewandos Eröffnet: 2026-07-17Diskussion: GitHub →

WAF++ Framework

RFC-0016 Remediation-Playbooks auf Control-Ebene
draft framework

Standardisiert maschinen- und menschenlesbare Remediation-Anleitungen für jeden WAF++-Control, damit Betriebsteams direkt aus einem PASS-Bericht oder Dashboard handeln können.

Autor:sascha-lewandowski Eröffnet: 2026-07-08
RFC-0017 Multi-Cloud-Provider-Erweiterung über AWS und SINA Cloud hinaus
draft tooling

Definiert, wie WAFPass-Erkennung und Controls um Azure, GCP und weitere Cloud-Provider erweitert werden, während das Framework cloud-agnostic bleibt.

Autor:sascha-lewandowski Eröffnet: 2026-07-08

WAF++ Framework

RFC-0001 Initiale 7-Säulen-Framework-Struktur
implemented framework

Legt das grundlegende Sieben-Säulen-Modell als Basis von WAF++ fest: Sicherheit, Zuverlässigkeit, Performance-Effizienz, Kostenoptimierung, Operationelle Exzellenz, Nachhaltigkeit und Developer Experience. Durch RFC-0012 auf acht Säulen erweitert.

Autor:sascha-lewandowski Eröffnet: 2025-12-05Entschieden: 2025-12-05Umgesetzt: 2025-12-05PR: #1
RFC-0002 Öffentliche Roadmap 2026 und Meilensteinplanung
implemented governance

Definiert die öffentliche Roadmap für 2026 mit Q1–Q4-Meilensteinen, v1.0-Ziel, Pilotprogramm und Foundation-Readiness-Zielen.

Autor:sascha-lewandowski Eröffnet: 2025-12-06Entschieden: 2025-12-06Umgesetzt: 2025-12-06PR: #2
RFC-0003 Pillar-Beschreibungen und Kernfragen — 7 Säulen
implemented framework

Fügt die initiale Inhaltsdefinition für jede der 7 Säulen hinzu: Scope, Begründung und Kernbewertungsfragen. Bildet die Basis für die Controls Library und wurde später um die 8. Säule Agentic erweitert (RFC-0012).

Autor:sascha-lewandowski Eröffnet: 2025-12-07Entschieden: 2025-12-07Umgesetzt: 2025-12-07PR: #3
RFC-0004 Dokumentationsmigration zu AsciiDoc / Antora
implemented docs

Migriert die gesamte Framework-Dokumentation von Markdown nach AsciiDoc und etabliert Antora als Dokumentations-Build-System mit Komponenten-Versionierung (v1.0).

Autor:t1murl Eröffnet: 2026-02-20Entschieden: 2026-02-26Umgesetzt: 2026-02-26PR: #4
RFC-0005 Contribution-Metadaten: CONTRIBUTING, CODE_OF_CONDUCT, SECURITY
implemented governance

Fügt dem Framework-Repository die Standard-Open-Source-Health-Dateien hinzu: Beitragsrichtlinien, Verhaltenskodex (basierend auf Contributor Covenant v2.1) und Sicherheitsrichtlinie.

Autor:sascha-lewandowski Eröffnet: 2026-02-06Entschieden: 2026-02-08Umgesetzt: 2026-02-08PR: #6
RFC-0006 Sovereign-Pillar (Säule 7) — initiale Controls
implemented framework

Führt den Sovereign-Pillar als 7. Säule von WAF++ ein — Datensouveränität, Compliance und jurisdiktionale Kontrolle. Liefert 10 initiale Controls (WAF-SOV-010 bis WAF-SOV-100).

Autor:sascha-lewandowski Eröffnet: 2026-02-14Entschieden: 2026-03-04Umgesetzt: 2026-03-04
RFC-0007 Governance-Refactor: modulare Best Practices, Fallstudien und Navigation
implemented framework

Strukturiert den Governance-Pillar (Säule 7) in modulare Best-Practice-Seiten um, ergänzt Fallstudien-Inhalte und aktualisiert die Antora-Navigation für bessere Auffindbarkeit und Lesbarkeit.

Autor:sascha-lewandowski Eröffnet: 2026-02-24Entschieden: 2026-03-04Umgesetzt: 2026-03-04PR: #10
RFC-0008 Controls-Schema v1 — maschinenlesbare YAML-Spezifikation
implemented tooling

Definiert ein formales Schema für WAF++-Controls-YAML-Dateien, das konsistente Validierung, Tool-Integration und die Nutzung der 83+ Controls Library durch Dritte ermöglicht. Mit der v1.0-Release ausgeliefert.

Autor:sascha-lewandowski Eröffnet: 2026-03-10Entschieden: 2026-05-12Umgesetzt: 2026-05-12
RFC-0009 PASS-Scoring-Modell — formale Spezifikation für v1.0
implemented framework

Formalisiert das PASS-Scoring-Modell als normative Spezifikation: Tier-Definitionen, Berechnungsregeln, Aggregationslogik und Versionierungsvertrag. Voraussetzung für und ausgeliefert mit WAFPass CLI / Server v1.0.0.

Autor:t1murl Eröffnet: 2026-03-08Entschieden: 2026-05-12Umgesetzt: 2026-05-12
RFC-0010 Assessment-Tooling — CLI und Scorecard-Ansatz
implemented tooling

Definiert den Ansatz für das offizielle WAF++-Assessment-Tooling: WAFPass CLI, Server, Dashboard und Web-Scorecard, die die Controls Library nutzen und einen PASS-Score-Bericht erzeugen. Mit WAFPass v1.0.0 ausgeliefert und in v1.1.0 erweitert.

Autor:sascha-lewandowski Eröffnet: 2026-03-11Entschieden: 2026-05-12Umgesetzt: 2026-05-12
RFC-0011 CI/CD-Pipeline für Framework- und Tooling-Repositories
implemented tooling

Führt automatisierte Checks und Release-Workflows für die Repositories framework, pass, wafpass-server und wafpass-dashboard ein: Antora-Build-Validierung, Controls-YAML-Linting, Release-Automatisierung und Link-Prüfung bei jedem Pull Request.

Autor:t1murl Eröffnet: 2026-03-11Entschieden: 2026-03-22Umgesetzt: 2026-03-22
RFC-0012 Agentic-Pillar als 8. Säule
implemented framework

Fügt den Agentic-Pillar (WAF-AGN) als 8. Säule von WAF++ hinzu — Governance autonomer KI-Agenten. Liefert 10 initiale Controls (WAF-AGN-010 bis WAF-AGN-100), regulatorische Mappings sowie englische und deutsche Dokumentation. Erweitert das Framework auf 8 Säulen und 83+ Controls.

Autor:sascha-lewandowski Eröffnet: 2026-07-01Entschieden: 2026-07-05Umgesetzt: 2026-07-05PR: #19

WAFPass

RFC-0013 WAFPass-Unterstützung für Säule-8 Agentic
implemented tooling

Erweitert WAFPass CLI, Server und Dashboard, um die Agentic-Pillar-Controls (WAF-AGN-*) im Rahmen einer vollständigen PASS-Bewertung auszuwerten. Vor der WAFPass-v1.1.0-Release gemergt.

Autor:sascha-lewandowski Eröffnet: 2026-05-20Entschieden: 2026-05-27Umgesetzt: 2026-05-27PR: #28
RFC-0014 WAFPass CLI / Server / Dashboard v1.1.0-Release
implemented tooling

Veröffentlicht WAFPass CLI v1.1.0, WAFPass Server v1.1.0 und WAFPass Dashboard v1.1.0 mit Unterstützung für Säule-8 Agentic, Korrekturen bei der Erkennung und SINA-Cloud-Region-Erkennung. Abgestimmt auf Framework v1.1 und die 83+ Controls Library.

Autor:sascha-lewandowski Eröffnet: 2026-06-28Entschieden: 2026-07-05Umgesetzt: 2026-07-05PR: #31

Eine Änderung vorschlagen?

Eine GitHub Discussion mit dem RFC-Template eröffnen. Die Community prüft es, Maintainer entscheiden — alles ist dokumentiert und nachvollziehbar.

Prozess

Was qualifiziert sich als RFC?

Nicht jede Änderung braucht einen RFC — nur wesentliche. Die folgende Tabelle hilft bei der Entscheidung.

Änderungstyp RFC erforderlich? Prozess
Neue Säule oder Entfernung einer Säule Ja RFC → TSC-Abstimmung → PR
Änderungen am Scoring-Modell (PASS-Tiers, Gewichtungen) Ja RFC → TSC-Abstimmung → PR
Breaking Changes am Controls-Schema oder IDs Ja RFC → TSC-Abstimmung → PR
Neuer Working-Group-Vorschlag Ja RFC → Lazy Consensus → Charter veröffentlicht
Governance- oder Rollenänderungen Ja RFC → TSC-Supermehrheit
Neuer Control (nicht-breaking, additiv) Empfohlen PR mit Diskussionslink · Lazy Consensus
Docs-Wording, Tippfehler, Übersetzungen Nein Nur PR
Website-Inhalte, Blog-Beiträge Nein Nur PR
Lebenszyklus

RFC-Status-Ablauf

Jeder RFC folgt demselben dokumentierten Pfad — vom ersten Entwurf bis zur geschlossenen Entscheidung.

draft
Autor verfasst den Vorschlag in GitHub Discussions
open
Mindestens 5 Werktage offen für Community-Kommentare
accepted
TSC-Abstimmung oder Lazy Consensus — öffentlich dokumentiert
implemented
PR gemergt, Changelog-Eintrag hinzugefügt, RFC geschlossen
Alternative Ausgänge: rejected (nach Review nicht akzeptiert)  ·  withdrawn (vom Autor zurückgezogen). Beide werden mit Begründung dokumentiert.
RFC schreiben

Was einen guten RFC ausmacht

Drei Dinge, die den Unterschied machen zwischen einem RFC, der schnell vorankommt, und einem, der stagniert.

Problem beschreiben, nicht die Lösung

Beginne damit, was fehlt oder nicht funktioniert — nicht damit, was du bauen willst. Reviewer müssen zuerst dem Problem zustimmen, bevor sie eine Lösung beurteilen können. Das „Warum“ kommt vor dem „Was“.

Trade-offs explizit benennen

Jede Entscheidung hat Kosten. Benenne sie. Was wird schlechter? Welche Alternativen hast du erwogen? Ein RFC, der Trade-offs anerkennt, gewinnt Vertrauen schneller als einer, der nur Vorteile verkauft.

Auf Evidenz verweisen

Verweise auf echte Beispiele — Issues, Vorfälle, frühere Diskussionen oder Produktionsmuster. Evidenz verwandelt Meinungen in nachvollziehbare Fakten und verkürzt den Review-Zyklus erheblich.

Bereit beizutragen?

Starte heute einen RFC.

Eröffne eine Diskussion auf GitHub, folge dem Template und lass den Prozess den Rest erledigen. Keine vorherige Genehmigung nötig — nur eine klare Problembeschreibung.