Zarządzanie · Domyślnie przejrzyste

RFCTracker

Każda znacząca zmiana WAF++ rozpoczyna się od publicznej prośby o komentarze lub Architecture Decision Record. Ta strona śledzi każdą decyzję - od pierwszego szkicu do połączenia - więc nic nie jest ukryte.

14wdrożony 19otwarty do przeglądu 3Działania niepożądane
38
Decyzje ogółem
35
RFC
19
Otwarte do przeglądu
14
Wdrożony
3
Działania niepożądane
3
Przyjęte działania niepożądane
Propozycje

Wszystkie wnioski o uwagi

Filtruj według projektu i statusu, przeczytaj podsumowania, a następnie śledzić powiązane dyskusje i wyciągnąć wnioski.

Framework

RFCRFC-0001 Initial 7-pillar framework structure
implementedframeworkpillarsframework

Establishes the core seven-pillar model as the foundational structure of WAF++. Extended to eight pillars by RFC-0012.

Author: sascha-lewandowski Opened: 2025-12-05Decided: 2025-12-05Implemented: 2025-12-05Discussion: GitHub →PR: #1
RFCRFC-0002 Public 2026 roadmap and milestone planning
implementedgovernanceroadmapgovernance

Defines the public roadmap for 2026 covering Q1–Q4 milestones, v1.0 target, pilot programme, and foundation readiness goals.

Author: sascha-lewandowski Opened: 2025-12-06Decided: 2025-12-06Implemented: 2025-12-06Discussion: GitHub →PR: #2
RFCRFC-0003 Pillar descriptions and key questions — 7 pillars
implementedframeworkpillarsframework

Adds the initial content definition for each of the 7 pillars. Later extended to cover the 8th Agentic pillar (RFC-0012).

Author: sascha-lewandowski Opened: 2025-12-07Decided: 2025-12-07Implemented: 2025-12-07Discussion: GitHub →PR: #3
RFCRFC-0004 Documentation migration to AsciiDoc / Antora
implementeddocsdocsantoraasciidoc

Migrates all framework documentation from Markdown to AsciiDoc and establishes Antora as the documentation build system with component versioning.

Author: t1murl Opened: 2026-02-20Decided: 2026-02-26Implemented: 2026-02-26Discussion: GitHub →PR: #4
RFCRFC-0005 Contribution metadata — CONTRIBUTING, CODE_OF_CONDUCT, SECURITY
implementedgovernancegovernanceoss-health

Adds the standard open-source health files to the framework repository.

Author: sascha-lewandowski Opened: 2026-02-06Decided: 2026-02-08Implemented: 2026-02-08Discussion: GitHub →PR: #6
RFCRFC-0006 Sovereign pillar (Pillar 7) — initial controls
implementedframeworkpillarssovereigncontrols

Introduces the Sovereign pillar as the 7th pillar of WAF++ with 10 initial controls (WAF-SOV-010 through WAF-SOV-100).

Author: sascha-lewandowski Opened: 2026-02-14Decided: 2026-03-04Implemented: 2026-03-04Discussion: GitHub →
RFCRFC-0007 Governance refactor — modular best practices, case studies and navigation
implementedframeworkpillarsgovernancedocs

Restructures the Governance pillar into modular best-practice pages and adds case-study content.

Author: sascha-lewandowski Opened: 2026-02-24Decided: 2026-03-04Implemented: 2026-03-04Discussion: GitHub →PR: #10
RFCRFC-0008 Controls schema v1 — machine-readable YAML specification
implementedtoolingcontrolsschematooling

Defines a formal schema for WAF++ controls YAML files, enabling validation and tooling integration for the 83+ controls library.

Author: sascha-lewandowski Opened: 2026-03-10Decided: 2026-05-12Implemented: 2026-05-12Discussion: GitHub →
RFCRFC-0009 PASS scoring model — formal specification for v1.0
implementedframeworkscoringpassframework

Formalises the PASS scoring model as a normative specification for tier definitions, calculation rules, aggregation logic, and versioning contract.

Author: t1murl Opened: 2026-03-08Decided: 2026-05-12Implemented: 2026-05-12Discussion: GitHub →
RFCRFC-0010 Assessment tooling — CLI and scorecard approach
implementedtoolingtoolingpassclidashboard

Defines the approach for official WAF++ assessment tooling including the WAFPass CLI, server, dashboard, and web scorecard.

Author: sascha-lewandowski Opened: 2026-03-11Decided: 2026-05-12Implemented: 2026-05-12Discussion: GitHub →
RFCRFC-0011 CI/CD pipeline for framework and tooling repositories
implementedtoolingcitoolingautomation

Introduces automated checks and release workflows for framework, wafpass-core, wafpass-server, and wafpass-dashboard repositories.

Author: t1murl Opened: 2026-03-11Decided: 2026-03-22Implemented: 2026-03-22Discussion: GitHub →
RFCRFC-0012 Agentic pillar as the 8th pillar
implementedframeworkpillarsagenticcontrols

Adds the Agentic pillar as the 8th pillar of WAF++ with 10 initial controls, regulatory mappings, and bilingual documentation.

Author: sascha-lewandowski Opened: 2026-07-01Decided: 2026-07-05Implemented: 2026-07-05Discussion: GitHub →PR: #19
RFCRFC-0016 Control-level remediation playbooks
draftframeworkcontrolsremediationframework

Standardises machine- and human-readable remediation guidance for every WAF++ control so operators can act on findings directly.

Author: sascha-lewandowski Opened: 2026-07-08Discussion: GitHub →
RFCRFC-0017 Multi-cloud provider expansion beyond AWS and SINA Cloud
drafttoolingtoolingcloud-providersawsazuregcp

Defines how WAFPass detection and controls will be extended to cover Azure, GCP, and other cloud providers while keeping the framework cloud-agnostic.

Author: sascha-lewandowski Opened: 2026-07-08Discussion: GitHub →
RFCRFC-GH-framework-26 RFC: Quality Assurance
opendocsdocscilinting

CI checks for dead xrefs, unregistered nav.adoc files, and control-schema consistency between YAML, AsciiDoc, and navigation.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #26
RFCRFC-GH-framework-25 RFC: Expand Sovereign & Resources
opendocsdocssovereignresources

Expand Sovereign definitions, evidence matrix, and create real overview/glossary pages for resources and wording.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #25
RFCRFC-GH-framework-23 RFC: Complete the Agentic Pillar
opendocsdocsagenticpillars

Complete Agentic pillar maturity, evidence, glossary, and best-practice pages with examples.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #23
RFCRFC-GH-framework-22 RFC: Consolidate Navigation & Links
opendocsdocsnavigationlinks

Standardise module links, convert relative xrefs to module-prefixed xrefs, and clean Markdown links.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #22
RFCRFC-GH-framework-21 RFC: Finalize Antora Structure
opendocsdocsantorastructure

Finalise antora.yml registration, create pillar-security nav, update README/AGENTS for 8-module layout.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #21
RFCRFC-GH-framework-24 RFC: Correct and Expand the Controls Catalog
opendocsdocscontrolscatalog

Align controls to 8 pillars, add Agentic, and extend control-schema.adoc.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #24

Framework- Otwarte do przeglądu

RFCRFC-GH-framework-26 RFC: Quality Assurance
opendocsdocscilinting

CI checks for dead xrefs, unregistered nav.adoc files, and control-schema consistency between YAML, AsciiDoc, and navigation.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #26
RFCRFC-GH-framework-25 RFC: Expand Sovereign & Resources
opendocsdocssovereignresources

Expand Sovereign definitions, evidence matrix, and create real overview/glossary pages for resources and wording.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #25
RFCRFC-GH-framework-23 RFC: Complete the Agentic Pillar
opendocsdocsagenticpillars

Complete Agentic pillar maturity, evidence, glossary, and best-practice pages with examples.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #23
RFCRFC-GH-framework-22 RFC: Consolidate Navigation & Links
opendocsdocsnavigationlinks

Standardise module links, convert relative xrefs to module-prefixed xrefs, and clean Markdown links.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #22
RFCRFC-GH-framework-21 RFC: Finalize Antora Structure
opendocsdocsantorastructure

Finalise antora.yml registration, create pillar-security nav, update README/AGENTS for 8-module layout.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #21
RFCRFC-GH-framework-24 RFC: Correct and Expand the Controls Catalog
opendocsdocscontrolscatalog

Align controls to 8 pillars, add Agentic, and extend control-schema.adoc.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #24

Framework- Projekty

RFCRFC-0016 Control-level remediation playbooks
draftframeworkcontrolsremediationframework

Standardises machine- and human-readable remediation guidance for every WAF++ control so operators can act on findings directly.

Author: sascha-lewandowski Opened: 2026-07-08Discussion: GitHub →
RFCRFC-0017 Multi-cloud provider expansion beyond AWS and SINA Cloud
drafttoolingtoolingcloud-providersawsazuregcp

Defines how WAFPass detection and controls will be extended to cover Azure, GCP, and other cloud providers while keeping the framework cloud-agnostic.

Author: sascha-lewandowski Opened: 2026-07-08Discussion: GitHub →

Framework- Decyzja / realizacja

RFCRFC-0001 Initial 7-pillar framework structure
implementedframeworkpillarsframework

Establishes the core seven-pillar model as the foundational structure of WAF++. Extended to eight pillars by RFC-0012.

Author: sascha-lewandowski Opened: 2025-12-05Decided: 2025-12-05Implemented: 2025-12-05Discussion: GitHub →PR: #1
RFCRFC-0002 Public 2026 roadmap and milestone planning
implementedgovernanceroadmapgovernance

Defines the public roadmap for 2026 covering Q1–Q4 milestones, v1.0 target, pilot programme, and foundation readiness goals.

Author: sascha-lewandowski Opened: 2025-12-06Decided: 2025-12-06Implemented: 2025-12-06Discussion: GitHub →PR: #2
RFCRFC-0003 Pillar descriptions and key questions — 7 pillars
implementedframeworkpillarsframework

Adds the initial content definition for each of the 7 pillars. Later extended to cover the 8th Agentic pillar (RFC-0012).

Author: sascha-lewandowski Opened: 2025-12-07Decided: 2025-12-07Implemented: 2025-12-07Discussion: GitHub →PR: #3
RFCRFC-0004 Documentation migration to AsciiDoc / Antora
implementeddocsdocsantoraasciidoc

Migrates all framework documentation from Markdown to AsciiDoc and establishes Antora as the documentation build system with component versioning.

Author: t1murl Opened: 2026-02-20Decided: 2026-02-26Implemented: 2026-02-26Discussion: GitHub →PR: #4
RFCRFC-0005 Contribution metadata — CONTRIBUTING, CODE_OF_CONDUCT, SECURITY
implementedgovernancegovernanceoss-health

Adds the standard open-source health files to the framework repository.

Author: sascha-lewandowski Opened: 2026-02-06Decided: 2026-02-08Implemented: 2026-02-08Discussion: GitHub →PR: #6
RFCRFC-0006 Sovereign pillar (Pillar 7) — initial controls
implementedframeworkpillarssovereigncontrols

Introduces the Sovereign pillar as the 7th pillar of WAF++ with 10 initial controls (WAF-SOV-010 through WAF-SOV-100).

Author: sascha-lewandowski Opened: 2026-02-14Decided: 2026-03-04Implemented: 2026-03-04Discussion: GitHub →
RFCRFC-0007 Governance refactor — modular best practices, case studies and navigation
implementedframeworkpillarsgovernancedocs

Restructures the Governance pillar into modular best-practice pages and adds case-study content.

Author: sascha-lewandowski Opened: 2026-02-24Decided: 2026-03-04Implemented: 2026-03-04Discussion: GitHub →PR: #10
RFCRFC-0008 Controls schema v1 — machine-readable YAML specification
implementedtoolingcontrolsschematooling

Defines a formal schema for WAF++ controls YAML files, enabling validation and tooling integration for the 83+ controls library.

Author: sascha-lewandowski Opened: 2026-03-10Decided: 2026-05-12Implemented: 2026-05-12Discussion: GitHub →
RFCRFC-0009 PASS scoring model — formal specification for v1.0
implementedframeworkscoringpassframework

Formalises the PASS scoring model as a normative specification for tier definitions, calculation rules, aggregation logic, and versioning contract.

Author: t1murl Opened: 2026-03-08Decided: 2026-05-12Implemented: 2026-05-12Discussion: GitHub →
RFCRFC-0010 Assessment tooling — CLI and scorecard approach
implementedtoolingtoolingpassclidashboard

Defines the approach for official WAF++ assessment tooling including the WAFPass CLI, server, dashboard, and web scorecard.

Author: sascha-lewandowski Opened: 2026-03-11Decided: 2026-05-12Implemented: 2026-05-12Discussion: GitHub →
RFCRFC-0011 CI/CD pipeline for framework and tooling repositories
implementedtoolingcitoolingautomation

Introduces automated checks and release workflows for framework, wafpass-core, wafpass-server, and wafpass-dashboard repositories.

Author: t1murl Opened: 2026-03-11Decided: 2026-03-22Implemented: 2026-03-22Discussion: GitHub →
RFCRFC-0012 Agentic pillar as the 8th pillar
implementedframeworkpillarsagenticcontrols

Adds the Agentic pillar as the 8th pillar of WAF++ with 10 initial controls, regulatory mappings, and bilingual documentation.

Author: sascha-lewandowski Opened: 2026-07-01Decided: 2026-07-05Implemented: 2026-07-05Discussion: GitHub →PR: #19

Core

RFCRFC-0013 WAFPass support for Pillar-8 Agentic
implementedtoolingtoolingpassagentic

Extends WAFPass CLI, server, and dashboard to evaluate the Agentic pillar controls as part of a full PASS assessment.

Author: sascha-lewandowski Opened: 2026-05-20Decided: 2026-05-27Implemented: 2026-05-27Discussion: GitHub →PR: #28
RFCRFC-0014 WAFPass CLI / Server / Dashboard v1.1.0 release
implementedtoolingreleasetoolingpassserverdashboard

Releases WAFPass CLI v1.1.0, Server v1.1.0, and Dashboard v1.1.0 with Pillar-8 Agentic support, detection fixes, and SINA Cloud region detection.

Author: sascha-lewandowski Opened: 2026-06-28Decided: 2026-07-05Implemented: 2026-07-05Discussion: GitHub →PR: #31
RFCRFC-GH-wafpass-core-41 Feature Request: Comprehensive Test/Quality Coverage Implementation Plan
opentoolingtoolingtestingquality

Unify fragmented test and coverage strategy across wafpass-core, server, and dashboard.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #41
RFCRFC-GH-wafpass-core-42 Feature Request: API Versioning and Backwards-Compatibility Strategy for WAF++ PASS
opentoolingtoolingapiversioning

Define API maturity, backwards-compatibility rules, and versioning strategy for WAF++ PASS APIs.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #42
RFCRFC-GH-wafpass-core-43 Feature Request: Source Snapshots — Ingestion Contract and Reliable Upload Path
opentoolingtoolingcontractingestion

Define a reliable source-snapshot ingestion contract so dashboard preview and auto-fix work consistently.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #43
RFCRFC-GH-wafpass-core-40 Feature Request: Dashboard UX Overhaul — Guided Onboarding, Role-Based Landing, and Progressive Disclosure
opentoolingtoolingdashboardux

Reduce dashboard navigation fragmentation and add guided onboarding with role-based landing pages.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #40
RFCRFC-GH-wafpass-core-39 Feature Request: Implement Action-Oriented Notifications
opentoolingtoolingdashboardnotifications

Make dashboard notifications actionable instead of passive text displays.

Author: lewandos Opened: 2026-07-17Discussion: GitHub →Issue: #39
RFCRFC-GH-wafpass-core-38 Feature Request: Implement Control Packs Marketplace
opentoolingtoolingmarketplacecontrols

Expand the control-packs feature beyond admin-only uploads to a real marketplace with discovery and governance.

Author: lewandos Opened: 2026-07-17Discussion: GitHub →Issue: #38
RFCRFC-GH-wafpass-core-37 Feature Request: Implement Maturity-Tier Enforcement Policy Gates
opentoolingtoolingmaturitycicd

Tie maturity tiers to CI/CD policy gates so pipelines can block promotion below a target tier.

Author: lewandos Opened: 2026-07-17Discussion: GitHub →Issue: #37

Core- Otwarte do przeglądu

RFCRFC-GH-wafpass-core-41 Feature Request: Comprehensive Test/Quality Coverage Implementation Plan
opentoolingtoolingtestingquality

Unify fragmented test and coverage strategy across wafpass-core, server, and dashboard.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #41
RFCRFC-GH-wafpass-core-42 Feature Request: API Versioning and Backwards-Compatibility Strategy for WAF++ PASS
opentoolingtoolingapiversioning

Define API maturity, backwards-compatibility rules, and versioning strategy for WAF++ PASS APIs.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #42
RFCRFC-GH-wafpass-core-43 Feature Request: Source Snapshots — Ingestion Contract and Reliable Upload Path
opentoolingtoolingcontractingestion

Define a reliable source-snapshot ingestion contract so dashboard preview and auto-fix work consistently.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #43
RFCRFC-GH-wafpass-core-40 Feature Request: Dashboard UX Overhaul — Guided Onboarding, Role-Based Landing, and Progressive Disclosure
opentoolingtoolingdashboardux

Reduce dashboard navigation fragmentation and add guided onboarding with role-based landing pages.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #40
RFCRFC-GH-wafpass-core-39 Feature Request: Implement Action-Oriented Notifications
opentoolingtoolingdashboardnotifications

Make dashboard notifications actionable instead of passive text displays.

Author: lewandos Opened: 2026-07-17Discussion: GitHub →Issue: #39
RFCRFC-GH-wafpass-core-38 Feature Request: Implement Control Packs Marketplace
opentoolingtoolingmarketplacecontrols

Expand the control-packs feature beyond admin-only uploads to a real marketplace with discovery and governance.

Author: lewandos Opened: 2026-07-17Discussion: GitHub →Issue: #38
RFCRFC-GH-wafpass-core-37 Feature Request: Implement Maturity-Tier Enforcement Policy Gates
opentoolingtoolingmaturitycicd

Tie maturity tiers to CI/CD policy gates so pipelines can block promotion below a target tier.

Author: lewandos Opened: 2026-07-17Discussion: GitHub →Issue: #37
Brak projektówCore.

Core- Decyzja / realizacja

RFCRFC-0013 WAFPass support for Pillar-8 Agentic
implementedtoolingtoolingpassagentic

Extends WAFPass CLI, server, and dashboard to evaluate the Agentic pillar controls as part of a full PASS assessment.

Author: sascha-lewandowski Opened: 2026-05-20Decided: 2026-05-27Implemented: 2026-05-27Discussion: GitHub →PR: #28
RFCRFC-0014 WAFPass CLI / Server / Dashboard v1.1.0 release
implementedtoolingreleasetoolingpassserverdashboard

Releases WAFPass CLI v1.1.0, Server v1.1.0, and Dashboard v1.1.0 with Pillar-8 Agentic support, detection fixes, and SINA Cloud region detection.

Author: sascha-lewandowski Opened: 2026-06-28Decided: 2026-07-05Implemented: 2026-07-05Discussion: GitHub →PR: #31
Brak RFC dlaServer.
Brak otwartych RFC dlaServer.
Brak projektówServer.
Brak zadecydowanych lub wdrożonych RFCServer.
Brak RFC dlaDashboard.
Brak otwartych RFC dlaDashboard.
Brak projektówDashboard.
Brak zadecydowanych lub wdrożonych RFCDashboard.
Brak RFC dlaAction.
Brak otwartych RFC dlaAction.
Brak projektówAction.
Brak zadecydowanych lub wdrożonych RFCAction.

MCP

RFCRFC-GH-wafpass-mcp-7 RFC-5: Role-aware natural tool aliasing
opentoolingtoolingmcpai

Allow curated aliases for long auto-generated MCP tool names so LLMs can match them more naturally.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #7
RFCRFC-GH-wafpass-mcp-4 RFC-2: MCP resource-level read-only endpoints
opentoolingtoolingmcpapi

Add MCP Resource definitions for run://{run_id}, control://{id}, etc. to expose read-only data without multiple tool calls.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #4
RFCRFC-GH-wafpass-mcp-6 RFC-4: Multi-step remediation plans (apply with rollback)
opentoolingtoolingmcpauto-fix

Extend auto-fix/classify with an apply step that records changes and supports rollback.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #6
RFCRFC-GH-wafpass-mcp-5 RFC-3: Streaming/paginated tool results for large runs
opentoolingtoolingmcpperformance

Add cursor-based pagination helpers so large runs do not blow MCP message size limits.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #5
RFCRFC-GH-wafpass-mcp-3 RFC-1: Auto-fix default templates for WAFpass controls
opentoolingtoolingmcpcontrolsauto-fix

Add fix blocks to control YAMLs or a central provider registry so common assertions get default patches.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #3

MCP- Otwarte do przeglądu

RFCRFC-GH-wafpass-mcp-7 RFC-5: Role-aware natural tool aliasing
opentoolingtoolingmcpai

Allow curated aliases for long auto-generated MCP tool names so LLMs can match them more naturally.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #7
RFCRFC-GH-wafpass-mcp-4 RFC-2: MCP resource-level read-only endpoints
opentoolingtoolingmcpapi

Add MCP Resource definitions for run://{run_id}, control://{id}, etc. to expose read-only data without multiple tool calls.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #4
RFCRFC-GH-wafpass-mcp-6 RFC-4: Multi-step remediation plans (apply with rollback)
opentoolingtoolingmcpauto-fix

Extend auto-fix/classify with an apply step that records changes and supports rollback.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #6
RFCRFC-GH-wafpass-mcp-5 RFC-3: Streaming/paginated tool results for large runs
opentoolingtoolingmcpperformance

Add cursor-based pagination helpers so large runs do not blow MCP message size limits.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #5
RFCRFC-GH-wafpass-mcp-3 RFC-1: Auto-fix default templates for WAFpass controls
opentoolingtoolingmcpcontrolsauto-fix

Add fix blocks to control YAMLs or a central provider registry so common assertions get default patches.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #3
Brak projektówMCP.
Brak zadecydowanych lub wdrożonych RFCMCP.

Framework

RFCRFC-0001 Initial 7-pillar framework structure
implementedframeworkpillarsframework

Establishes the core seven-pillar model as the foundational structure of WAF++. Extended to eight pillars by RFC-0012.

Author: sascha-lewandowski Opened: 2025-12-05Decided: 2025-12-05Implemented: 2025-12-05Discussion: GitHub →PR: #1
RFCRFC-0002 Public 2026 roadmap and milestone planning
implementedgovernanceroadmapgovernance

Defines the public roadmap for 2026 covering Q1–Q4 milestones, v1.0 target, pilot programme, and foundation readiness goals.

Author: sascha-lewandowski Opened: 2025-12-06Decided: 2025-12-06Implemented: 2025-12-06Discussion: GitHub →PR: #2
RFCRFC-0003 Pillar descriptions and key questions — 7 pillars
implementedframeworkpillarsframework

Adds the initial content definition for each of the 7 pillars. Later extended to cover the 8th Agentic pillar (RFC-0012).

Author: sascha-lewandowski Opened: 2025-12-07Decided: 2025-12-07Implemented: 2025-12-07Discussion: GitHub →PR: #3
RFCRFC-0004 Documentation migration to AsciiDoc / Antora
implementeddocsdocsantoraasciidoc

Migrates all framework documentation from Markdown to AsciiDoc and establishes Antora as the documentation build system with component versioning.

Author: t1murl Opened: 2026-02-20Decided: 2026-02-26Implemented: 2026-02-26Discussion: GitHub →PR: #4
RFCRFC-0005 Contribution metadata — CONTRIBUTING, CODE_OF_CONDUCT, SECURITY
implementedgovernancegovernanceoss-health

Adds the standard open-source health files to the framework repository.

Author: sascha-lewandowski Opened: 2026-02-06Decided: 2026-02-08Implemented: 2026-02-08Discussion: GitHub →PR: #6
RFCRFC-0006 Sovereign pillar (Pillar 7) — initial controls
implementedframeworkpillarssovereigncontrols

Introduces the Sovereign pillar as the 7th pillar of WAF++ with 10 initial controls (WAF-SOV-010 through WAF-SOV-100).

Author: sascha-lewandowski Opened: 2026-02-14Decided: 2026-03-04Implemented: 2026-03-04Discussion: GitHub →
RFCRFC-0007 Governance refactor — modular best practices, case studies and navigation
implementedframeworkpillarsgovernancedocs

Restructures the Governance pillar into modular best-practice pages and adds case-study content.

Author: sascha-lewandowski Opened: 2026-02-24Decided: 2026-03-04Implemented: 2026-03-04Discussion: GitHub →PR: #10
RFCRFC-0008 Controls schema v1 — machine-readable YAML specification
implementedtoolingcontrolsschematooling

Defines a formal schema for WAF++ controls YAML files, enabling validation and tooling integration for the 83+ controls library.

Author: sascha-lewandowski Opened: 2026-03-10Decided: 2026-05-12Implemented: 2026-05-12Discussion: GitHub →
RFCRFC-0009 PASS scoring model — formal specification for v1.0
implementedframeworkscoringpassframework

Formalises the PASS scoring model as a normative specification for tier definitions, calculation rules, aggregation logic, and versioning contract.

Author: t1murl Opened: 2026-03-08Decided: 2026-05-12Implemented: 2026-05-12Discussion: GitHub →
RFCRFC-0010 Assessment tooling — CLI and scorecard approach
implementedtoolingtoolingpassclidashboard

Defines the approach for official WAF++ assessment tooling including the WAFPass CLI, server, dashboard, and web scorecard.

Author: sascha-lewandowski Opened: 2026-03-11Decided: 2026-05-12Implemented: 2026-05-12Discussion: GitHub →
RFCRFC-0011 CI/CD pipeline for framework and tooling repositories
implementedtoolingcitoolingautomation

Introduces automated checks and release workflows for framework, wafpass-core, wafpass-server, and wafpass-dashboard repositories.

Author: t1murl Opened: 2026-03-11Decided: 2026-03-22Implemented: 2026-03-22Discussion: GitHub →
RFCRFC-0012 Agentic pillar as the 8th pillar
implementedframeworkpillarsagenticcontrols

Adds the Agentic pillar as the 8th pillar of WAF++ with 10 initial controls, regulatory mappings, and bilingual documentation.

Author: sascha-lewandowski Opened: 2026-07-01Decided: 2026-07-05Implemented: 2026-07-05Discussion: GitHub →PR: #19
RFCRFC-0016 Control-level remediation playbooks
draftframeworkcontrolsremediationframework

Standardises machine- and human-readable remediation guidance for every WAF++ control so operators can act on findings directly.

Author: sascha-lewandowski Opened: 2026-07-08Discussion: GitHub →
RFCRFC-0017 Multi-cloud provider expansion beyond AWS and SINA Cloud
drafttoolingtoolingcloud-providersawsazuregcp

Defines how WAFPass detection and controls will be extended to cover Azure, GCP, and other cloud providers while keeping the framework cloud-agnostic.

Author: sascha-lewandowski Opened: 2026-07-08Discussion: GitHub →
RFCRFC-GH-framework-26 RFC: Quality Assurance
opendocsdocscilinting

CI checks for dead xrefs, unregistered nav.adoc files, and control-schema consistency between YAML, AsciiDoc, and navigation.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #26
RFCRFC-GH-framework-25 RFC: Expand Sovereign & Resources
opendocsdocssovereignresources

Expand Sovereign definitions, evidence matrix, and create real overview/glossary pages for resources and wording.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #25
RFCRFC-GH-framework-23 RFC: Complete the Agentic Pillar
opendocsdocsagenticpillars

Complete Agentic pillar maturity, evidence, glossary, and best-practice pages with examples.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #23
RFCRFC-GH-framework-22 RFC: Consolidate Navigation & Links
opendocsdocsnavigationlinks

Standardise module links, convert relative xrefs to module-prefixed xrefs, and clean Markdown links.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #22
RFCRFC-GH-framework-21 RFC: Finalize Antora Structure
opendocsdocsantorastructure

Finalise antora.yml registration, create pillar-security nav, update README/AGENTS for 8-module layout.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #21
RFCRFC-GH-framework-24 RFC: Correct and Expand the Controls Catalog
opendocsdocscontrolscatalog

Align controls to 8 pillars, add Agentic, and extend control-schema.adoc.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #24

Core

RFCRFC-0013 WAFPass support for Pillar-8 Agentic
implementedtoolingtoolingpassagentic

Extends WAFPass CLI, server, and dashboard to evaluate the Agentic pillar controls as part of a full PASS assessment.

Author: sascha-lewandowski Opened: 2026-05-20Decided: 2026-05-27Implemented: 2026-05-27Discussion: GitHub →PR: #28
RFCRFC-0014 WAFPass CLI / Server / Dashboard v1.1.0 release
implementedtoolingreleasetoolingpassserverdashboard

Releases WAFPass CLI v1.1.0, Server v1.1.0, and Dashboard v1.1.0 with Pillar-8 Agentic support, detection fixes, and SINA Cloud region detection.

Author: sascha-lewandowski Opened: 2026-06-28Decided: 2026-07-05Implemented: 2026-07-05Discussion: GitHub →PR: #31
RFCRFC-GH-wafpass-core-41 Feature Request: Comprehensive Test/Quality Coverage Implementation Plan
opentoolingtoolingtestingquality

Unify fragmented test and coverage strategy across wafpass-core, server, and dashboard.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #41
RFCRFC-GH-wafpass-core-42 Feature Request: API Versioning and Backwards-Compatibility Strategy for WAF++ PASS
opentoolingtoolingapiversioning

Define API maturity, backwards-compatibility rules, and versioning strategy for WAF++ PASS APIs.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #42
RFCRFC-GH-wafpass-core-43 Feature Request: Source Snapshots — Ingestion Contract and Reliable Upload Path
opentoolingtoolingcontractingestion

Define a reliable source-snapshot ingestion contract so dashboard preview and auto-fix work consistently.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #43
RFCRFC-GH-wafpass-core-40 Feature Request: Dashboard UX Overhaul — Guided Onboarding, Role-Based Landing, and Progressive Disclosure
opentoolingtoolingdashboardux

Reduce dashboard navigation fragmentation and add guided onboarding with role-based landing pages.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #40
RFCRFC-GH-wafpass-core-39 Feature Request: Implement Action-Oriented Notifications
opentoolingtoolingdashboardnotifications

Make dashboard notifications actionable instead of passive text displays.

Author: lewandos Opened: 2026-07-17Discussion: GitHub →Issue: #39
RFCRFC-GH-wafpass-core-38 Feature Request: Implement Control Packs Marketplace
opentoolingtoolingmarketplacecontrols

Expand the control-packs feature beyond admin-only uploads to a real marketplace with discovery and governance.

Author: lewandos Opened: 2026-07-17Discussion: GitHub →Issue: #38
RFCRFC-GH-wafpass-core-37 Feature Request: Implement Maturity-Tier Enforcement Policy Gates
opentoolingtoolingmaturitycicd

Tie maturity tiers to CI/CD policy gates so pipelines can block promotion below a target tier.

Author: lewandos Opened: 2026-07-17Discussion: GitHub →Issue: #37

MCP

RFCRFC-GH-wafpass-mcp-7 RFC-5: Role-aware natural tool aliasing
opentoolingtoolingmcpai

Allow curated aliases for long auto-generated MCP tool names so LLMs can match them more naturally.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #7
RFCRFC-GH-wafpass-mcp-4 RFC-2: MCP resource-level read-only endpoints
opentoolingtoolingmcpapi

Add MCP Resource definitions for run://{run_id}, control://{id}, etc. to expose read-only data without multiple tool calls.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #4
RFCRFC-GH-wafpass-mcp-6 RFC-4: Multi-step remediation plans (apply with rollback)
opentoolingtoolingmcpauto-fix

Extend auto-fix/classify with an apply step that records changes and supports rollback.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #6
RFCRFC-GH-wafpass-mcp-5 RFC-3: Streaming/paginated tool results for large runs
opentoolingtoolingmcpperformance

Add cursor-based pagination helpers so large runs do not blow MCP message size limits.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #5
RFCRFC-GH-wafpass-mcp-3 RFC-1: Auto-fix default templates for WAFpass controls
opentoolingtoolingmcpcontrolsauto-fix

Add fix blocks to control YAMLs or a central provider registry so common assertions get default patches.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #3

Framework

RFCRFC-0015 Website radical redesign — apply dark-first theme to all public pages
opendocsdocswebsitedesign

Applies the radical dark-first design system to the remaining public pages so the whole site uses one consistent visual language.

Author: sascha-lewandowski Opened: 2026-07-06Discussion: GitHub →

MCP

RFCRFC-GH-wafpass-mcp-7 RFC-5: Role-aware natural tool aliasing
opentoolingtoolingmcpai

Allow curated aliases for long auto-generated MCP tool names so LLMs can match them more naturally.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #7
RFCRFC-GH-wafpass-mcp-4 RFC-2: MCP resource-level read-only endpoints
opentoolingtoolingmcpapi

Add MCP Resource definitions for run://{run_id}, control://{id}, etc. to expose read-only data without multiple tool calls.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #4
RFCRFC-GH-wafpass-mcp-6 RFC-4: Multi-step remediation plans (apply with rollback)
opentoolingtoolingmcpauto-fix

Extend auto-fix/classify with an apply step that records changes and supports rollback.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #6
RFCRFC-GH-wafpass-mcp-5 RFC-3: Streaming/paginated tool results for large runs
opentoolingtoolingmcpperformance

Add cursor-based pagination helpers so large runs do not blow MCP message size limits.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #5
RFCRFC-GH-wafpass-mcp-3 RFC-1: Auto-fix default templates for WAFpass controls
opentoolingtoolingmcpcontrolsauto-fix

Add fix blocks to control YAMLs or a central provider registry so common assertions get default patches.

Author: lewandos Opened: 2026-08-14Discussion: GitHub →Issue: #3

Framework

RFCRFC-GH-framework-26 RFC: Quality Assurance
opendocsdocscilinting

CI checks for dead xrefs, unregistered nav.adoc files, and control-schema consistency between YAML, AsciiDoc, and navigation.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #26
RFCRFC-GH-framework-25 RFC: Expand Sovereign & Resources
opendocsdocssovereignresources

Expand Sovereign definitions, evidence matrix, and create real overview/glossary pages for resources and wording.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #25
RFCRFC-GH-framework-23 RFC: Complete the Agentic Pillar
opendocsdocsagenticpillars

Complete Agentic pillar maturity, evidence, glossary, and best-practice pages with examples.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #23
RFCRFC-GH-framework-22 RFC: Consolidate Navigation & Links
opendocsdocsnavigationlinks

Standardise module links, convert relative xrefs to module-prefixed xrefs, and clean Markdown links.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #22
RFCRFC-GH-framework-21 RFC: Finalize Antora Structure
opendocsdocsantorastructure

Finalise antora.yml registration, create pillar-security nav, update README/AGENTS for 8-module layout.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #21
RFCRFC-GH-framework-24 RFC: Correct and Expand the Controls Catalog
opendocsdocscontrolscatalog

Align controls to 8 pillars, add Agentic, and extend control-schema.adoc.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #24

Core

RFCRFC-GH-wafpass-core-41 Feature Request: Comprehensive Test/Quality Coverage Implementation Plan
opentoolingtoolingtestingquality

Unify fragmented test and coverage strategy across wafpass-core, server, and dashboard.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #41
RFCRFC-GH-wafpass-core-42 Feature Request: API Versioning and Backwards-Compatibility Strategy for WAF++ PASS
opentoolingtoolingapiversioning

Define API maturity, backwards-compatibility rules, and versioning strategy for WAF++ PASS APIs.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #42
RFCRFC-GH-wafpass-core-43 Feature Request: Source Snapshots — Ingestion Contract and Reliable Upload Path
opentoolingtoolingcontractingestion

Define a reliable source-snapshot ingestion contract so dashboard preview and auto-fix work consistently.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #43
RFCRFC-GH-wafpass-core-40 Feature Request: Dashboard UX Overhaul — Guided Onboarding, Role-Based Landing, and Progressive Disclosure
opentoolingtoolingdashboardux

Reduce dashboard navigation fragmentation and add guided onboarding with role-based landing pages.

Author: lewandos Opened: 2026-07-18Discussion: GitHub →Issue: #40
RFCRFC-GH-wafpass-core-39 Feature Request: Implement Action-Oriented Notifications
opentoolingtoolingdashboardnotifications

Make dashboard notifications actionable instead of passive text displays.

Author: lewandos Opened: 2026-07-17Discussion: GitHub →Issue: #39
RFCRFC-GH-wafpass-core-38 Feature Request: Implement Control Packs Marketplace
opentoolingtoolingmarketplacecontrols

Expand the control-packs feature beyond admin-only uploads to a real marketplace with discovery and governance.

Author: lewandos Opened: 2026-07-17Discussion: GitHub →Issue: #38
RFCRFC-GH-wafpass-core-37 Feature Request: Implement Maturity-Tier Enforcement Policy Gates
opentoolingtoolingmaturitycicd

Tie maturity tiers to CI/CD policy gates so pipelines can block promotion below a target tier.

Author: lewandos Opened: 2026-07-17Discussion: GitHub →Issue: #37

Framework

RFCRFC-0016 Control-level remediation playbooks
draftframeworkcontrolsremediationframework

Standardises machine- and human-readable remediation guidance for every WAF++ control so operators can act on findings directly.

Author: sascha-lewandowski Opened: 2026-07-08Discussion: GitHub →
RFCRFC-0017 Multi-cloud provider expansion beyond AWS and SINA Cloud
drafttoolingtoolingcloud-providersawsazuregcp

Defines how WAFPass detection and controls will be extended to cover Azure, GCP, and other cloud providers while keeping the framework cloud-agnostic.

Author: sascha-lewandowski Opened: 2026-07-08Discussion: GitHub →

Framework

RFCRFC-0001 Initial 7-pillar framework structure
implementedframeworkpillarsframework

Establishes the core seven-pillar model as the foundational structure of WAF++. Extended to eight pillars by RFC-0012.

Author: sascha-lewandowski Opened: 2025-12-05Decided: 2025-12-05Implemented: 2025-12-05Discussion: GitHub →PR: #1
RFCRFC-0002 Public 2026 roadmap and milestone planning
implementedgovernanceroadmapgovernance

Defines the public roadmap for 2026 covering Q1–Q4 milestones, v1.0 target, pilot programme, and foundation readiness goals.

Author: sascha-lewandowski Opened: 2025-12-06Decided: 2025-12-06Implemented: 2025-12-06Discussion: GitHub →PR: #2
RFCRFC-0003 Pillar descriptions and key questions — 7 pillars
implementedframeworkpillarsframework

Adds the initial content definition for each of the 7 pillars. Later extended to cover the 8th Agentic pillar (RFC-0012).

Author: sascha-lewandowski Opened: 2025-12-07Decided: 2025-12-07Implemented: 2025-12-07Discussion: GitHub →PR: #3
RFCRFC-0004 Documentation migration to AsciiDoc / Antora
implementeddocsdocsantoraasciidoc

Migrates all framework documentation from Markdown to AsciiDoc and establishes Antora as the documentation build system with component versioning.

Author: t1murl Opened: 2026-02-20Decided: 2026-02-26Implemented: 2026-02-26Discussion: GitHub →PR: #4
RFCRFC-0005 Contribution metadata — CONTRIBUTING, CODE_OF_CONDUCT, SECURITY
implementedgovernancegovernanceoss-health

Adds the standard open-source health files to the framework repository.

Author: sascha-lewandowski Opened: 2026-02-06Decided: 2026-02-08Implemented: 2026-02-08Discussion: GitHub →PR: #6
RFCRFC-0006 Sovereign pillar (Pillar 7) — initial controls
implementedframeworkpillarssovereigncontrols

Introduces the Sovereign pillar as the 7th pillar of WAF++ with 10 initial controls (WAF-SOV-010 through WAF-SOV-100).

Author: sascha-lewandowski Opened: 2026-02-14Decided: 2026-03-04Implemented: 2026-03-04Discussion: GitHub →
RFCRFC-0007 Governance refactor — modular best practices, case studies and navigation
implementedframeworkpillarsgovernancedocs

Restructures the Governance pillar into modular best-practice pages and adds case-study content.

Author: sascha-lewandowski Opened: 2026-02-24Decided: 2026-03-04Implemented: 2026-03-04Discussion: GitHub →PR: #10
RFCRFC-0008 Controls schema v1 — machine-readable YAML specification
implementedtoolingcontrolsschematooling

Defines a formal schema for WAF++ controls YAML files, enabling validation and tooling integration for the 83+ controls library.

Author: sascha-lewandowski Opened: 2026-03-10Decided: 2026-05-12Implemented: 2026-05-12Discussion: GitHub →
RFCRFC-0009 PASS scoring model — formal specification for v1.0
implementedframeworkscoringpassframework

Formalises the PASS scoring model as a normative specification for tier definitions, calculation rules, aggregation logic, and versioning contract.

Author: t1murl Opened: 2026-03-08Decided: 2026-05-12Implemented: 2026-05-12Discussion: GitHub →
RFCRFC-0010 Assessment tooling — CLI and scorecard approach
implementedtoolingtoolingpassclidashboard

Defines the approach for official WAF++ assessment tooling including the WAFPass CLI, server, dashboard, and web scorecard.

Author: sascha-lewandowski Opened: 2026-03-11Decided: 2026-05-12Implemented: 2026-05-12Discussion: GitHub →
RFCRFC-0011 CI/CD pipeline for framework and tooling repositories
implementedtoolingcitoolingautomation

Introduces automated checks and release workflows for framework, wafpass-core, wafpass-server, and wafpass-dashboard repositories.

Author: t1murl Opened: 2026-03-11Decided: 2026-03-22Implemented: 2026-03-22Discussion: GitHub →
RFCRFC-0012 Agentic pillar as the 8th pillar
implementedframeworkpillarsagenticcontrols

Adds the Agentic pillar as the 8th pillar of WAF++ with 10 initial controls, regulatory mappings, and bilingual documentation.

Author: sascha-lewandowski Opened: 2026-07-01Decided: 2026-07-05Implemented: 2026-07-05Discussion: GitHub →PR: #19

Core

RFCRFC-0013 WAFPass support for Pillar-8 Agentic
implementedtoolingtoolingpassagentic

Extends WAFPass CLI, server, and dashboard to evaluate the Agentic pillar controls as part of a full PASS assessment.

Author: sascha-lewandowski Opened: 2026-05-20Decided: 2026-05-27Implemented: 2026-05-27Discussion: GitHub →PR: #28
RFCRFC-0014 WAFPass CLI / Server / Dashboard v1.1.0 release
implementedtoolingreleasetoolingpassserverdashboard

Releases WAFPass CLI v1.1.0, Server v1.1.0, and Dashboard v1.1.0 with Pillar-8 Agentic support, detection fixes, and SINA Cloud region detection.

Author: sascha-lewandowski Opened: 2026-06-28Decided: 2026-07-05Implemented: 2026-07-05Discussion: GitHub →PR: #31

Chcesz zaproponować zmianę?

Otwórz dyskusję o GitHub używając szablonu RFC. Społeczność to ocenia, opiekunowie decydują - wszystko jest udokumentowane i identyfikowalne.

Architektura

Architektura Decision Records

Działania niepożądane uwzględniają decyzje strukturalne i przekrojowe, które kształtują ekosystem WAF++, repozytoria i kontrakty.

ADRADR-000 WAF++ Federated Repository Architecture & Onboarding Overview
acceptedarchitectureonboardingumbrella

Master onboarding document explaining the WAF++ ecosystem, repository layout, two-branch documentation model, and central wafpass-result.json contract.

Author: sascha-lewandowski Date: 2026-09-17Record: GitHub →Repos: framework, waf2p.github.io, wafpass-core, wafpass-server, wafpass-dashboard, wafpass-mcp, wafpass-action
ADRADR-001 The wafpass-result.json Contract
acceptedcontractwafpass-corewafpass-serverdashboard

Defines the single JSON schema that all WAF++ components use to exchange scan results, findings, waivers, risks, and metadata.

Author: sascha-lewandowski Date: 2026-09-17Record: GitHub →Repos: wafpass-core, wafpass-server, wafpass-dashboard
ADRADR-002 Two Long-Lived Branches for German and English Framework Documentation
accepteddocsframeworklocalizationi18n

Uses main-de and main-en branches (checked out as framework/ and framework-en/) so German and English Antora component releases can evolve independently.

Author: sascha-lewandowski Date: 2026-09-17Record: GitHub →Repos: framework
Brak proponowanych działań niepożądanych.
ADRADR-000 WAF++ Federated Repository Architecture & Onboarding Overview
acceptedarchitectureonboardingumbrella

Master onboarding document explaining the WAF++ ecosystem, repository layout, two-branch documentation model, and central wafpass-result.json contract.

Author: sascha-lewandowski Date: 2026-09-17Record: GitHub →Repos: framework, waf2p.github.io, wafpass-core, wafpass-server, wafpass-dashboard, wafpass-mcp, wafpass-action
ADRADR-001 The wafpass-result.json Contract
acceptedcontractwafpass-corewafpass-serverdashboard

Defines the single JSON schema that all WAF++ components use to exchange scan results, findings, waivers, risks, and metadata.

Author: sascha-lewandowski Date: 2026-09-17Record: GitHub →Repos: wafpass-core, wafpass-server, wafpass-dashboard
ADRADR-002 Two Long-Lived Branches for German and English Framework Documentation
accepteddocsframeworklocalizationi18n

Uses main-de and main-en branches (checked out as framework/ and framework-en/) so German and English Antora component releases can evolve independently.

Author: sascha-lewandowski Date: 2026-09-17Record: GitHub →Repos: framework
Brak działań niepożądanych.
Brak zastępczych działań niepożądanych.

Rejestr decyzji do odczytu maszynowego

Wszystkie RFC i ADR są również dostępne jako pojedynczy plik YAML, który narzędzia, skrypty i konsumenci niższego szczebla mogą analizować. Rejestr zawiera statusy, kategorie, repozytoria, znaczniki i bezpośrednie linki do każdego rekordu.

Pobierz rejestry.yml →
Proces

Co kwalifikuje się jako RFC?

Nie każda zmiana wymaga RFC - tylko znaczące. Użyj poniższej tabeli, aby zdecydować.

Typ zmiany RFC potrzebowało? Proces
Nowy filar lub usunięcie filaru Tak. RFC → TSC głosuje → PR
Zmiany modelu punktowego (poziomy PASS, wagi) Tak. RFC → TSC głosuje → PR
Przerwanie zmiany schematów kontroli lub identyfikatorów Tak. RFC → TSC głosuje → PR
Nowy wniosek grupy roboczej Tak. RFC → leniwy konsensus → karta opublikowana
Zmiany w zarządzaniu lub roli Tak. RFC → superwiększość TSC
Nowa kontrola (nieniszcząca, dodatek) Zalecane PR z linkiem dyskusyjnym · leniwy konsensus
Teksty dokumentów, poprawki literackie, tłumaczenia Nie. Tylko PR
Zawartość stron internetowych, blogi Nie. Tylko PR
Cykl życia

Przepływ stanu RFC

Każdy RFC podąża tą samą udokumentowaną ścieżką - od pierwszego projektu do decyzji zamkniętej.

projekt
Autor pisze propozycję w GitHub Dyskusje
otwarte
Minimum 5 dni roboczych otwarte dla Community Comment
przyjęte
Głosowanie TSC lub leniwy konsensus - udokumentowane publicznie
wdrożony
PR połączone, wpis changelog dodany, RFC zamknięte
Alternatywne wyniki: odrzucono(nieakceptowane po przeglądzie)   ·   wycofane(ciągnięty przez autora). Oba są udokumentowane z powodów.
Pisanie RFC

Jak napisać dobry RFC

Trzy rzeczy, które czynią różnicę między RFC, który porusza się szybko i jeden, który zatrzymuje.

Podaj problem, a nie rozwiązanie

Zacznij od tego, co jest zepsute lub brakujące - nie od tego, co chcesz zbudować. Recenzenci muszą się zgodzić, że problem jest prawdziwy, zanim będą mogli ocenić proponowane rozwiązanie. Wrabiaj "dlaczego" przed "co".

Pokaż oferty handlowe i alternatywy

Silny RFC wyjaśnia, co jeszcze zostało rozważone i dlaczego zostało odrzucone. To oszczędza cykle przeglądów i daje kontekst przyszłych opiekunów, gdy oryginalny autor przeniósł się dalej.

Określić wpływ

Kto ucierpiał? Które repozytoria, pliki czy zamówienia publiczne się zmieniają? Im jaśniejszy zakres, tym szybciej społeczność może udzielić przydatnych informacji zwrotnych, a opiekun może podjąć decyzję.

Gotowy na kształt WAF++?

Każda decyzja zaczyna się od rozmowy.

Wybierz otwarty RFC, podziel się perspektywą lub otwórz nowy. Ramy są budowane publicznie i każdy głos się liczy.