Stable-Releases vom 1. September 2026¶
Alle Änderungen, die am 1. September 2026 im Stable-Kanal erschienen sind — von v2.9.27 bis v2.9.31, neueste zuerst. Installiert wird v2.9.31; die Versionen darunter sind der Weg dorthin.
Stable v2.9.31¶
- fix(waf): audit log rule-id showed the generic aggregator, not the attack rule
Stable v2.9.30¶
- docs: regenerate testing changelog index
- docs: regenerate testing changelog index
- fix(agent): unbounded chromium screenshots + frozen autoconfig vhosts
- fix(waf): audit log client_ip showed the transaction ID, not the IP
- fix(waf): log parser never matched real audit-log format; add Sites tile
Stable v2.9.29¶
- docs: regenerate testing changelog index
- docs: add WAF to the pending What's New buffer
- feat(waf): deep-link from the site toggle into the WAF settings page
- fix(waf): load per-site exclusions before global CRS to fix Detection-Only
Stable v2.9.28¶
- docs: regenerate testing changelog index
- fix(security-advisor): refresh PHP support table after a patch completes
- fix(php-patch): stop dot-sourcing agent.env, extract AGENT_TOKEN safely
- fix(waf): resolve golangci-lint findings from the testing-release gate
- docs: fix Roundcube/Catch-All staleness found by completeness audit
- docs: reflect WAF re-activation across internal + customer docs
- feat(waf): full CRUD UI (log viewer, per-site exclusions, 15 languages)
- feat(waf): controller-side model, permission gating, and API proxy
- fix(waf): create the per-site exclusion file before a WAF-enabled vhost
- feat(waf): agent-side ModSecurity/OWASP-CRS foundation (re-add, hardened)
- feat(webstats): flag scanner requests by path, independent of UA
- chore: drop Debian 12 (Bookworm) support, Debian 13 only
Stable v2.9.27¶
- feat(webstats): add Visitors/Bytes detail to the Bots table
- fix(geoip): cap decompressed GeoIP DB size against a decompression bomb
- feat(webstats): bot filtering + fix empty Countries panel + timeout fix
- fix(security-advisor): fix PHP patch button layout — button now sits inline