{"repo":"sefinek/Cloudflare-WAF-Expressions","free":true,"listed":false,"github":"https://github.com/sefinek/Cloudflare-WAF-Expressions","clone":"git clone https://github.com/sefinek/Cloudflare-WAF-Expressions.git","description":"Cloudflare WAF (Web Application Firewall) rules + a script for their automatic updates. Block unwanted and malicious requests to enhance the security of your origin server!","language":"JavaScript","stars":211,"topics":["cloudflare","cloudflare-waf","expression","expressions","cloudflare-expressions","cloudflare-firewall","cloudflare-firewall-rules","cloudflare-expression","cloudflare-waf-expression","cloudflare-waf-expressions"],"license":"GPL-3.0","category":"databases-storage","readme_excerpt":"☁️ Cloudflare Web Application Firewall Rules By using these WAF expressions, you can effectively block most unnecessary and potentially malicious requests targeting your origin server, thereby enhancing its security. No Pro account or higher plan is required - everything works fine on the free Cloudflare plan. If you find this repository useful, I would greatly appreciate it if you could give it a star ⭐. Thank you! [!TIP] - Use a dedicated script to automatically update rules for each zone. - Want to report Cloudflare WAF events to a public abuse database? See Cloudflare-WAF-To-SniffCat. - Join my Discord server if you need help or want to receive notifications about important updates. 🛑 SniffCat and AbuseIPDB integrations The script supports two external services that provide dynamic lists of known malicious IP addresses: SniffCat and AbuseIPDB. When you set SNIFFCAT API TOKEN and/or ABUSEIPDB API KEY , the script fetches IP addresses from the APIs on every sync and merges them with the static rules/ip-blocklist.txt before uploading to Cloudflare Lists. This significantly extends the IP blocklist without any manual effort. Both integrations work independently of each other - you can enable one, both, or neither. Cloudflare allows up to 10,000 entries per list. Each integration can be configured via two optional environment variables: SniffCat: - SNIFFCAT CONFIDENCE MIN - minimum confidence level (0-100) required to include an IP address. Default: 80 . - SNIFFCAT LIMIT - ma","default_branch":null,"files":null,"tree":[],"storefront":"/r/sefinek","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/sefinek/Cloudflare-WAF-Expressions/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}