RFCTracker
Ogni cambiamento significativo a WAF++ inizia con una richiesta pubblica per i commenti o il record di decisione di architettura. Questa pagina traccia ogni decisione — dalla prima bozza alla fusione — quindi nulla è nascosto.
Tutte le richieste di commenti
Filtra per progetto e stato, leggere i riassunti, e seguire le discussioni collegate e tirare richieste.
Framework
Establishes the core seven-pillar model as the foundational structure of WAF++. Extended to eight pillars by RFC-0012.
Defines the public roadmap for 2026 covering Q1–Q4 milestones, v1.0 target, pilot programme, and foundation readiness goals.
Adds the initial content definition for each of the 7 pillars. Later extended to cover the 8th Agentic pillar (RFC-0012).
Migrates all framework documentation from Markdown to AsciiDoc and establishes Antora as the documentation build system with component versioning.
Adds the standard open-source health files to the framework repository.
Introduces the Sovereign pillar as the 7th pillar of WAF++ with 10 initial controls (WAF-SOV-010 through WAF-SOV-100).
Restructures the Governance pillar into modular best-practice pages and adds case-study content.
Defines a formal schema for WAF++ controls YAML files, enabling validation and tooling integration for the 83+ controls library.
Formalises the PASS scoring model as a normative specification for tier definitions, calculation rules, aggregation logic, and versioning contract.
Defines the approach for official WAF++ assessment tooling including the WAFPass CLI, server, dashboard, and web scorecard.
Introduces automated checks and release workflows for framework, wafpass-core, wafpass-server, and wafpass-dashboard repositories.
Adds the Agentic pillar as the 8th pillar of WAF++ with 10 initial controls, regulatory mappings, and bilingual documentation.
Standardises machine- and human-readable remediation guidance for every WAF++ control so operators can act on findings directly.
Defines how WAFPass detection and controls will be extended to cover Azure, GCP, and other cloud providers while keeping the framework cloud-agnostic.
CI checks for dead xrefs, unregistered nav.adoc files, and control-schema consistency between YAML, AsciiDoc, and navigation.
Expand Sovereign definitions, evidence matrix, and create real overview/glossary pages for resources and wording.
Complete Agentic pillar maturity, evidence, glossary, and best-practice pages with examples.
Standardise module links, convert relative xrefs to module-prefixed xrefs, and clean Markdown links.
Finalise antora.yml registration, create pillar-security nav, update README/AGENTS for 8-module layout.
Align controls to 8 pillars, add Agentic, and extend control-schema.adoc.
Framework— Aperto per la revisione
CI checks for dead xrefs, unregistered nav.adoc files, and control-schema consistency between YAML, AsciiDoc, and navigation.
Expand Sovereign definitions, evidence matrix, and create real overview/glossary pages for resources and wording.
Complete Agentic pillar maturity, evidence, glossary, and best-practice pages with examples.
Standardise module links, convert relative xrefs to module-prefixed xrefs, and clean Markdown links.
Finalise antora.yml registration, create pillar-security nav, update README/AGENTS for 8-module layout.
Align controls to 8 pillars, add Agentic, and extend control-schema.adoc.
Framework— Progetti
Standardises machine- and human-readable remediation guidance for every WAF++ control so operators can act on findings directly.
Defines how WAFPass detection and controls will be extended to cover Azure, GCP, and other cloud providers while keeping the framework cloud-agnostic.
Framework— Deciso / implementato
Establishes the core seven-pillar model as the foundational structure of WAF++. Extended to eight pillars by RFC-0012.
Defines the public roadmap for 2026 covering Q1–Q4 milestones, v1.0 target, pilot programme, and foundation readiness goals.
Adds the initial content definition for each of the 7 pillars. Later extended to cover the 8th Agentic pillar (RFC-0012).
Migrates all framework documentation from Markdown to AsciiDoc and establishes Antora as the documentation build system with component versioning.
Adds the standard open-source health files to the framework repository.
Introduces the Sovereign pillar as the 7th pillar of WAF++ with 10 initial controls (WAF-SOV-010 through WAF-SOV-100).
Restructures the Governance pillar into modular best-practice pages and adds case-study content.
Defines a formal schema for WAF++ controls YAML files, enabling validation and tooling integration for the 83+ controls library.
Formalises the PASS scoring model as a normative specification for tier definitions, calculation rules, aggregation logic, and versioning contract.
Defines the approach for official WAF++ assessment tooling including the WAFPass CLI, server, dashboard, and web scorecard.
Introduces automated checks and release workflows for framework, wafpass-core, wafpass-server, and wafpass-dashboard repositories.
Adds the Agentic pillar as the 8th pillar of WAF++ with 10 initial controls, regulatory mappings, and bilingual documentation.
Core
Extends WAFPass CLI, server, and dashboard to evaluate the Agentic pillar controls as part of a full PASS assessment.
Releases WAFPass CLI v1.1.0, Server v1.1.0, and Dashboard v1.1.0 with Pillar-8 Agentic support, detection fixes, and SINA Cloud region detection.
Unify fragmented test and coverage strategy across wafpass-core, server, and dashboard.
Define API maturity, backwards-compatibility rules, and versioning strategy for WAF++ PASS APIs.
Define a reliable source-snapshot ingestion contract so dashboard preview and auto-fix work consistently.
Reduce dashboard navigation fragmentation and add guided onboarding with role-based landing pages.
Make dashboard notifications actionable instead of passive text displays.
Expand the control-packs feature beyond admin-only uploads to a real marketplace with discovery and governance.
Tie maturity tiers to CI/CD policy gates so pipelines can block promotion below a target tier.
Core— Aperto per la revisione
Unify fragmented test and coverage strategy across wafpass-core, server, and dashboard.
Define API maturity, backwards-compatibility rules, and versioning strategy for WAF++ PASS APIs.
Define a reliable source-snapshot ingestion contract so dashboard preview and auto-fix work consistently.
Reduce dashboard navigation fragmentation and add guided onboarding with role-based landing pages.
Make dashboard notifications actionable instead of passive text displays.
Expand the control-packs feature beyond admin-only uploads to a real marketplace with discovery and governance.
Tie maturity tiers to CI/CD policy gates so pipelines can block promotion below a target tier.
Core— Deciso / implementato
Extends WAFPass CLI, server, and dashboard to evaluate the Agentic pillar controls as part of a full PASS assessment.
Releases WAFPass CLI v1.1.0, Server v1.1.0, and Dashboard v1.1.0 with Pillar-8 Agentic support, detection fixes, and SINA Cloud region detection.
MCP
Allow curated aliases for long auto-generated MCP tool names so LLMs can match them more naturally.
Add MCP Resource definitions for run://{run_id}, control://{id}, etc. to expose read-only data without multiple tool calls.
Extend auto-fix/classify with an apply step that records changes and supports rollback.
Add cursor-based pagination helpers so large runs do not blow MCP message size limits.
Add fix blocks to control YAMLs or a central provider registry so common assertions get default patches.
MCP— Aperto per la revisione
Allow curated aliases for long auto-generated MCP tool names so LLMs can match them more naturally.
Add MCP Resource definitions for run://{run_id}, control://{id}, etc. to expose read-only data without multiple tool calls.
Extend auto-fix/classify with an apply step that records changes and supports rollback.
Add cursor-based pagination helpers so large runs do not blow MCP message size limits.
Add fix blocks to control YAMLs or a central provider registry so common assertions get default patches.
Framework
Establishes the core seven-pillar model as the foundational structure of WAF++. Extended to eight pillars by RFC-0012.
Defines the public roadmap for 2026 covering Q1–Q4 milestones, v1.0 target, pilot programme, and foundation readiness goals.
Adds the initial content definition for each of the 7 pillars. Later extended to cover the 8th Agentic pillar (RFC-0012).
Migrates all framework documentation from Markdown to AsciiDoc and establishes Antora as the documentation build system with component versioning.
Adds the standard open-source health files to the framework repository.
Introduces the Sovereign pillar as the 7th pillar of WAF++ with 10 initial controls (WAF-SOV-010 through WAF-SOV-100).
Restructures the Governance pillar into modular best-practice pages and adds case-study content.
Defines a formal schema for WAF++ controls YAML files, enabling validation and tooling integration for the 83+ controls library.
Formalises the PASS scoring model as a normative specification for tier definitions, calculation rules, aggregation logic, and versioning contract.
Defines the approach for official WAF++ assessment tooling including the WAFPass CLI, server, dashboard, and web scorecard.
Introduces automated checks and release workflows for framework, wafpass-core, wafpass-server, and wafpass-dashboard repositories.
Adds the Agentic pillar as the 8th pillar of WAF++ with 10 initial controls, regulatory mappings, and bilingual documentation.
Standardises machine- and human-readable remediation guidance for every WAF++ control so operators can act on findings directly.
Defines how WAFPass detection and controls will be extended to cover Azure, GCP, and other cloud providers while keeping the framework cloud-agnostic.
CI checks for dead xrefs, unregistered nav.adoc files, and control-schema consistency between YAML, AsciiDoc, and navigation.
Expand Sovereign definitions, evidence matrix, and create real overview/glossary pages for resources and wording.
Complete Agentic pillar maturity, evidence, glossary, and best-practice pages with examples.
Standardise module links, convert relative xrefs to module-prefixed xrefs, and clean Markdown links.
Finalise antora.yml registration, create pillar-security nav, update README/AGENTS for 8-module layout.
Align controls to 8 pillars, add Agentic, and extend control-schema.adoc.
Core
Extends WAFPass CLI, server, and dashboard to evaluate the Agentic pillar controls as part of a full PASS assessment.
Releases WAFPass CLI v1.1.0, Server v1.1.0, and Dashboard v1.1.0 with Pillar-8 Agentic support, detection fixes, and SINA Cloud region detection.
Unify fragmented test and coverage strategy across wafpass-core, server, and dashboard.
Define API maturity, backwards-compatibility rules, and versioning strategy for WAF++ PASS APIs.
Define a reliable source-snapshot ingestion contract so dashboard preview and auto-fix work consistently.
Reduce dashboard navigation fragmentation and add guided onboarding with role-based landing pages.
Make dashboard notifications actionable instead of passive text displays.
Expand the control-packs feature beyond admin-only uploads to a real marketplace with discovery and governance.
Tie maturity tiers to CI/CD policy gates so pipelines can block promotion below a target tier.
MCP
Allow curated aliases for long auto-generated MCP tool names so LLMs can match them more naturally.
Add MCP Resource definitions for run://{run_id}, control://{id}, etc. to expose read-only data without multiple tool calls.
Extend auto-fix/classify with an apply step that records changes and supports rollback.
Add cursor-based pagination helpers so large runs do not blow MCP message size limits.
Add fix blocks to control YAMLs or a central provider registry so common assertions get default patches.
Framework
Applies the radical dark-first design system to the remaining public pages so the whole site uses one consistent visual language.
MCP
Allow curated aliases for long auto-generated MCP tool names so LLMs can match them more naturally.
Add MCP Resource definitions for run://{run_id}, control://{id}, etc. to expose read-only data without multiple tool calls.
Extend auto-fix/classify with an apply step that records changes and supports rollback.
Add cursor-based pagination helpers so large runs do not blow MCP message size limits.
Add fix blocks to control YAMLs or a central provider registry so common assertions get default patches.
Framework
CI checks for dead xrefs, unregistered nav.adoc files, and control-schema consistency between YAML, AsciiDoc, and navigation.
Expand Sovereign definitions, evidence matrix, and create real overview/glossary pages for resources and wording.
Complete Agentic pillar maturity, evidence, glossary, and best-practice pages with examples.
Standardise module links, convert relative xrefs to module-prefixed xrefs, and clean Markdown links.
Finalise antora.yml registration, create pillar-security nav, update README/AGENTS for 8-module layout.
Align controls to 8 pillars, add Agentic, and extend control-schema.adoc.
Core
Unify fragmented test and coverage strategy across wafpass-core, server, and dashboard.
Define API maturity, backwards-compatibility rules, and versioning strategy for WAF++ PASS APIs.
Define a reliable source-snapshot ingestion contract so dashboard preview and auto-fix work consistently.
Reduce dashboard navigation fragmentation and add guided onboarding with role-based landing pages.
Make dashboard notifications actionable instead of passive text displays.
Expand the control-packs feature beyond admin-only uploads to a real marketplace with discovery and governance.
Tie maturity tiers to CI/CD policy gates so pipelines can block promotion below a target tier.
Framework
Standardises machine- and human-readable remediation guidance for every WAF++ control so operators can act on findings directly.
Defines how WAFPass detection and controls will be extended to cover Azure, GCP, and other cloud providers while keeping the framework cloud-agnostic.
Framework
Establishes the core seven-pillar model as the foundational structure of WAF++. Extended to eight pillars by RFC-0012.
Defines the public roadmap for 2026 covering Q1–Q4 milestones, v1.0 target, pilot programme, and foundation readiness goals.
Adds the initial content definition for each of the 7 pillars. Later extended to cover the 8th Agentic pillar (RFC-0012).
Migrates all framework documentation from Markdown to AsciiDoc and establishes Antora as the documentation build system with component versioning.
Adds the standard open-source health files to the framework repository.
Introduces the Sovereign pillar as the 7th pillar of WAF++ with 10 initial controls (WAF-SOV-010 through WAF-SOV-100).
Restructures the Governance pillar into modular best-practice pages and adds case-study content.
Defines a formal schema for WAF++ controls YAML files, enabling validation and tooling integration for the 83+ controls library.
Formalises the PASS scoring model as a normative specification for tier definitions, calculation rules, aggregation logic, and versioning contract.
Defines the approach for official WAF++ assessment tooling including the WAFPass CLI, server, dashboard, and web scorecard.
Introduces automated checks and release workflows for framework, wafpass-core, wafpass-server, and wafpass-dashboard repositories.
Adds the Agentic pillar as the 8th pillar of WAF++ with 10 initial controls, regulatory mappings, and bilingual documentation.
Core
Extends WAFPass CLI, server, and dashboard to evaluate the Agentic pillar controls as part of a full PASS assessment.
Releases WAFPass CLI v1.1.0, Server v1.1.0, and Dashboard v1.1.0 with Pillar-8 Agentic support, detection fixes, and SINA Cloud region detection.
Vuoi proporre un cambiamento?
Aprire una discussione GitHub utilizzando il modello RFC. La comunità lo esamina, i manutentori decidono — tutto è documentato e tracciabile.
Architettura Decision Records
Gli ADR catturano le decisioni strutturali e cross-cutting che modellano l'ecosistema WAF++, i repository e i contratti.
Master onboarding document explaining the WAF++ ecosystem, repository layout, two-branch documentation model, and central wafpass-result.json contract.
Defines the single JSON schema that all WAF++ components use to exchange scan results, findings, waivers, risks, and metadata.
Uses main-de and main-en branches (checked out as framework/ and framework-en/) so German and English Antora component releases can evolve independently.
Master onboarding document explaining the WAF++ ecosystem, repository layout, two-branch documentation model, and central wafpass-result.json contract.
Defines the single JSON schema that all WAF++ components use to exchange scan results, findings, waivers, risks, and metadata.
Uses main-de and main-en branches (checked out as framework/ and framework-en/) so German and English Antora component releases can evolve independently.
Registro delle decisioni leggibili in macchina
Tutti gli RFC e gli ADR sono disponibili anche come un unico file YAML che gli strumenti, gli script e i consumatori a valle possono parse. Il registro include stati, categorie, repository, tag e link diretti ad ogni record.
Cosa si qualifica come RFC?
Non ogni cambiamento ha bisogno di un RFC — solo quelli significativi. Utilizzare la tabella qui sotto per decidere.
| Tipo di cambiamento | RFC necessario? | Processo |
|---|---|---|
| Nuovo pilastro o rimozione di un pilastro | Sì. | RFC → TSC vota &rr; PR |
| Cambiamenti del modello di punteggio (PASS tiers, pesi) | Sì. | RFC → TSC vota &rr; PR |
| Cambiamento di rottura a schemi di controllo o ID | Sì. | RFC → TSC vota &rr; PR |
| Proposta del gruppo di lavoro | Sì. | RFC → lazy consenso → charter pubblicato |
| Governance o cambiamenti di ruolo | Sì. | RFC → supermajority TSC |
| Nuovo controllo (non rotante, additivo) | Consigliato | PR con link di discussione · consenso pigro |
| Docs wording, typo fixs, traduzioni | No. | PR solo |
| Contenuto del sito web, post del blog | No. | PR solo |
Flusso di stato RFC
Ogni RFC segue lo stesso percorso documentato — dal primo progetto alla decisione chiusa.
Come scrivere una buona RFC
Tre cose che fanno la differenza tra un RFC che si muove velocemente e uno che si blocca.
Dichiarare il problema, non la soluzione
Inizia con ciò che è rotto o mancante — non con quello che vuoi costruire. I recensori devono concordare che il problema è reale prima che possano valutare la soluzione proposta. Incorniciare il "perché" prima del "cosa".
Mostra trade-off e alternative
Una forte RFC spiega cos'altro è stato considerato e perché è stato respinto. Questo salva i cicli di revisione e dà il contesto futuro dei manutentori quando l'autore originale ha acceso.
Essere specifici per l'impatto
Chi è interessato? Quali repository, file o contratti pubblici cambiano? Più chiara la portata, più veloce la comunità può dare feedback utili e un manutentore può prendere una decisione.
Ogni decisione inizia con una conversazione.
Scegli un RFC aperto, condividi la tua prospettiva, o apri una nuova. Il quadro è costruito in pubblico e ogni voce conta.