Update Coraza and x/net, score requests CRS could not inspect, add .ojoignore #10
Loading…
Reference in a new issue
No description provided.
Delete branch "dependency-fixes"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Clears the 12 open findings from the OJO CI scan. Three commits.
1. Update Coraza to 3.8.1 and golang.org/x/net to 0.60.0
x/net is an indirect dependency and the binary links only its html packages. go mod tidy also moved x/sync to 0.23.0 and x/text to 0.42.0.
2. Score requests CRS could not inspect in full
Updating Coraza does not close CVE-2026-41510 for Centinela. Upstream's fix sets a limit-reached flag and relies on deny rules 200004 and 200005 in its recommended configuration. Centinela runs detection-only and reads the CRS anomaly score, so a deny never acts and those rules add no score.
Measured on 3.8.0 and 3.8.1 alike, at paranoia 3:
Evaluate now reads the engine's own flags and adds one critical finding (5) for each of:
Each appears in the rules field of the decision log and counts toward the grey gate, so the request reaches the model.
Still open: the request is scored, not refused. A padded request lands around 7 to 10, under any sensible hard block, and for a form body the model sees only the first CENTINELA_MAX_BODY bytes. Refusing requests over the argument limit outright is a separate decision.
3. Add .ojoignore
One entry: dockerfile-no-healthcheck on Dockerfile. The runtime image is distroless static nonroot, with no shell or HTTP client for a HEALTHCHECK to run; liveness and readiness are Kubernetes HTTP probes on /healthz.
Before merging: the entry's reason says the risk is accepted in Balam. That record had not been created when this was written. Create it first, or drop this commit.
Verification
Merging to main runs build-and-push, which tags and publishes the next patch version.
🔎 ojo scan results
No findings.