#1036353 modsecurity-crs: also include the "plugins"

#1036353#3
Date:
2023-05-19 13:28:03 UTC
From:
To:
Hi maintainers,

so this package is packing up https://github.com/coreruleset/coreruleset

However, to properly run those rules for some website one would also
need to run so-called "plugins" of the crs.

For example, https://github.com/coreruleset/wordpress-rule-exclusions-plugin/
for wordpress (the one that interests me here for my use case, but there
are plenty of others).

I wonder what are your thoughts of bundling those up in the package,
possibly in separate binary packages, so that they can be installed only
on hosts that actually run those CMSs?  They don't seem to have actual
"releases", so at best they would need to be snapshot of whenever you
bundle them, but I think that would already be quite good.

If you would be opposed to including these, why? :)

#1036353#8
Date:
2023-07-30 10:01:50 UTC
From:
To:
Hi Mattia,

CRS plugins is a new feature and it will be available from version 4.0:

https://coreruleset.org/docs/concepts/plugins/#how-to-install-a-plugin

"CRS 4.x will come with a plugins folder next to the rules folder."

If you take a look at the existing plugins (
https://github.com/coreruleset/plugin-registry), you can see that most of
them are actually part of the current stable set (3.3.x).

The version 4.0 is coming soon (hope in this year), but the current version
(3.3.4 in stable) is not able to handle the plugins infrastructure yet.

When the 4.0 will be out, we can (must?) consider modifying the package.



Regards,

a.