RFC Tracker
Every significant change to WAF++ starts with a public Request for Comments. This page tracks every RFC — from first draft to merge — so every decision stays traceable.
All Requests for Comments
Filter by status, read the summaries, and follow the linked discussions and pull requests.
Establishes the core seven-pillar model as the foundational structure of WAF++, covering Security, Reliability, Performance Efficiency, Cost Optimisation, Operational Excellence, Sustainability, and Developer Experience. Extended to eight pillars by RFC-0012.
Defines the public roadmap for 2026 covering Q1–Q4 milestones, including v1.0 target, pilot programme, and foundation readiness goals.
Adds the initial content definition for each of the 7 pillars: scope, rationale, and key assessment questions. Serves as the baseline for the controls library and was later extended to cover the 8th Agentic pillar (RFC-0012).
Migrates all framework documentation from Markdown to AsciiDoc and establishes Antora as the documentation build system with component versioning (v1.0).
Adds the standard open-source health files to the framework repository: contribution guidelines, code of conduct (based on Contributor Covenant v2.1), and security policy.
Introduces the Sovereign pillar as the 7th pillar of WAF++, covering data sovereignty, compliance, and jurisdictional control. Ships with 10 initial controls (WAF-SOV-010 through WAF-SOV-100).
Restructures the Governance pillar (Pillar 7) into modular best-practice pages, adds case-study content, and updates the Antora navigation to improve discoverability and readability.
Defines a formal schema for WAF++ controls YAML files, enabling consistent validation, tooling integration, and third-party consumption of the 83+ controls library. Shipped as part of the v1.0 release.
Formalises the PASS scoring model as a normative specification: tier definitions, calculation rules, aggregation logic, and versioning contract. Required for and shipped with the WAFPass CLI / Server v1.0.0 release.
Defines the approach for official WAF++ assessment tooling: the WAFPass CLI, server, dashboard, and web scorecard that consume the controls library and produce a PASS score report. Shipped with WAFPass v1.0.0 and extended in v1.1.0.
Introduces automated checks and release workflows for the framework, pass, wafpass-server, and wafpass-dashboard repositories: Antora build validation, controls YAML linting, release automation, and link checking on every pull request.
Adds the Agentic pillar (WAF-AGN) as the 8th pillar of WAF++, covering autonomous AI agent governance. Ships with 10 initial controls (WAF-AGN-010 through WAF-AGN-100), regulatory mappings, and English and German documentation. Brings the framework to 8 pillars and 83+ controls.
Extends WAFPass CLI, server, and dashboard to evaluate the Agentic pillar controls (WAF-AGN-*) as part of a full PASS assessment. Merged ahead of the WAFPass v1.1.0 release.
Releases WAFPass CLI v1.1.0, WAFPass Server v1.1.0, and WAFPass Dashboard v1.1.0 with Pillar-8 Agentic support, detection fixes, and SINA Cloud region detection. Aligned with framework v1.1 and the 83+ controls library.
Applies the radical dark-first design system to the remaining public pages (RFC tracker, team, roles, about, press, install) so the whole site uses one consistent visual language and accessibility patterns.
Standardises machine- and human-readable remediation guidance for every WAF++ control so operators can act on findings directly from a PASS report or dashboard.
Defines how WAFPass detection and controls will be extended to cover Azure, GCP, and other cloud providers while keeping the framework cloud-agnostic.
Applies the radical dark-first design system to the remaining public pages (RFC tracker, team, roles, about, press, install) so the whole site uses one consistent visual language and accessibility patterns.
Standardises machine- and human-readable remediation guidance for every WAF++ control so operators can act on findings directly from a PASS report or dashboard.
Defines how WAFPass detection and controls will be extended to cover Azure, GCP, and other cloud providers while keeping the framework cloud-agnostic.
Establishes the core seven-pillar model as the foundational structure of WAF++, covering Security, Reliability, Performance Efficiency, Cost Optimisation, Operational Excellence, Sustainability, and Developer Experience. Extended to eight pillars by RFC-0012.
Defines the public roadmap for 2026 covering Q1–Q4 milestones, including v1.0 target, pilot programme, and foundation readiness goals.
Adds the initial content definition for each of the 7 pillars: scope, rationale, and key assessment questions. Serves as the baseline for the controls library and was later extended to cover the 8th Agentic pillar (RFC-0012).
Migrates all framework documentation from Markdown to AsciiDoc and establishes Antora as the documentation build system with component versioning (v1.0).
Adds the standard open-source health files to the framework repository: contribution guidelines, code of conduct (based on Contributor Covenant v2.1), and security policy.
Introduces the Sovereign pillar as the 7th pillar of WAF++, covering data sovereignty, compliance, and jurisdictional control. Ships with 10 initial controls (WAF-SOV-010 through WAF-SOV-100).
Restructures the Governance pillar (Pillar 7) into modular best-practice pages, adds case-study content, and updates the Antora navigation to improve discoverability and readability.
Defines a formal schema for WAF++ controls YAML files, enabling consistent validation, tooling integration, and third-party consumption of the 83+ controls library. Shipped as part of the v1.0 release.
Formalises the PASS scoring model as a normative specification: tier definitions, calculation rules, aggregation logic, and versioning contract. Required for and shipped with the WAFPass CLI / Server v1.0.0 release.
Defines the approach for official WAF++ assessment tooling: the WAFPass CLI, server, dashboard, and web scorecard that consume the controls library and produce a PASS score report. Shipped with WAFPass v1.0.0 and extended in v1.1.0.
Introduces automated checks and release workflows for the framework, pass, wafpass-server, and wafpass-dashboard repositories: Antora build validation, controls YAML linting, release automation, and link checking on every pull request.
Adds the Agentic pillar (WAF-AGN) as the 8th pillar of WAF++, covering autonomous AI agent governance. Ships with 10 initial controls (WAF-AGN-010 through WAF-AGN-100), regulatory mappings, and English and German documentation. Brings the framework to 8 pillars and 83+ controls.
Extends WAFPass CLI, server, and dashboard to evaluate the Agentic pillar controls (WAF-AGN-*) as part of a full PASS assessment. Merged ahead of the WAFPass v1.1.0 release.
Releases WAFPass CLI v1.1.0, WAFPass Server v1.1.0, and WAFPass Dashboard v1.1.0 with Pillar-8 Agentic support, detection fixes, and SINA Cloud region detection. Aligned with framework v1.1 and the 83+ controls library.
Want to propose a change?
Open a GitHub Discussion using the RFC template. The community reviews it, maintainers decide — everything is documented and traceable.
What qualifies as an RFC?
Not every change needs an RFC — only significant ones. Use the table below to decide.
| Change type | RFC needed? | Process |
|---|---|---|
| New pillar or removal of a pillar | Yes | RFC → TSC vote → PR |
| Scoring model changes (PASS tiers, weights) | Yes | RFC → TSC vote → PR |
| Breaking change to controls schema or IDs | Yes | RFC → TSC vote → PR |
| New Working Group proposal | Yes | RFC → lazy consensus → charter published |
| Governance or role changes | Yes | RFC → TSC supermajority |
| New control (non-breaking, additive) | Recommended | PR with discussion link · lazy consensus |
| Docs wording, typo fixes, translations | No | PR only |
| Website content, blog posts | No | PR only |
RFC status flow
Every RFC follows the same documented path — from first draft to closed decision.
How to write a good RFC
Three things that make the difference between an RFC that moves fast and one that stalls.
State the problem, not the solution
Start with what is broken or missing — not with what you want to build. Reviewers need to agree that the problem is real before they can evaluate your proposed solution. Frame the "why" before the "what".
Document trade-offs explicitly
Every decision has costs. Name them. What gets worse? What are the alternatives you considered? An RFC that acknowledges trade-offs earns trust faster than one that only sells the upside.
Link to evidence
Point to real examples — issues, incidents, prior discussions, or production patterns. Evidence turns opinions into traceable facts and dramatically shortens the review cycle.
Start an RFC today.
Open a discussion on GitHub, follow the template, and let the process do the rest. No prior approval needed — just a clear problem statement.