{"repo":"fabriziosalmi/patterns","free":true,"listed":false,"github":"https://github.com/fabriziosalmi/patterns","clone":"git clone https://github.com/fabriziosalmi/patterns.git","description":"Automated OWASP CRS and Bad Bot Detection for Nginx, Apache, Traefik and HaProxy","language":"Python","stars":309,"topics":["bad-requests","caddy","caddyserver","firewall-configuration","firewall-rules","malicious-url-detection","owasp","waf","web-application-firewall","apache"],"license":"MIT","category":"workflow-automation","readme_excerpt":"Patterns Production-grade WAF rules, on autopilot. Automated OWASP Core Rule Set and bad-bot patterns, converted into native configurations for Nginx , Apache , Traefik , and HAProxy &mdash; refreshed every day. Documentation &middot; Get started &middot; Latest release --- Why Patterns The OWASP Core Rule Set (CRS) is the de-facto open-source rule base behind ModSecurity, but plugging it into anything other than Apache is non-trivial. Patterns automates the whole pipeline: 1. Pull the latest CRS rules straight from upstream. 2. Convert them into the native syntax of each web server &mdash; not a generic shim. 3. Package the output as ready-to-deploy archives, refreshed every day by GitHub Actions. You get equivalent protection across SQL injection, XSS, RCE, LFI, and bad-bot traffic, regardless of which proxy you run. Highlights --- --- OWASP CRS coverage SQLi, XSS, RCE, LFI, RFI, plus generic anomaly and protocol-violation rules. Native output Nginx map / if , Apache SecRule , Traefik middleware TOML, HAProxy ACL files. Bad-bot blocking Curated User-Agent lists from public sources, with safe defaults that do not block major search engines. Daily refresh A scheduled GitHub Actions workflow rebuilds every backend and publishes a fresh release. Pre-built archives Skip the toolchain &mdash; download nginx waf.zip , apache waf.zip , traefik waf.zip , or haproxy waf.zip . Composable Each backend is a small Python converter on top of one JSON intermediate. Adding a new platform is","default_branch":null,"files":null,"tree":[],"storefront":"/r/fabriziosalmi","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/fabriziosalmi/patterns/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}