The generated data (owasp_rules.json, waf_patterns/**) is derived from
third-party projects but was implicitly covered by the blanket MIT LICENSE
with no NOTICE. Add the missing attribution — additively and reversibly:
- THIRD_PARTY_NOTICES.md (new): per-source attribution
- OWASP CoreRuleSet -> Apache-2.0 (owasp_rules.json + waf_patterns/**)
- JayBizzle/Crawler-Detect -> MIT (bad-bot list)
- mitchellkrogza/...bad-bot -> MIT (bad-bot list)
- matomo/referrer-spam-... -> Public Domain (referrer spam)
- LICENSES/Apache-2.0.txt (new): canonical license copy (Apache-2.0 §4a).
- README: License section now scopes MIT to the original project code; the
generated data is redistributed under its upstream licenses. Resources now
credit the real bad-bot sources (removed the unused ai.robots.txt mention).
- Converters (owasp2json, json2nginx, json2apache, json2traefik, json2haproxy)
emit a provenance header on every generated file (Apache-2.0 §4b "state
changes"); owasp_rules.json gains a top-level _provenance key. Loaders accept
both the {_provenance, rules} object and the legacy bare-array form.
- owasp_rules.json wrapped as {_provenance, rules} (rule content unchanged).
- update_patterns.yml jq updated for the object shape.
LICENSE stays MIT (GitHub detection unaffected). Propagation of the headers to
waf_patterns/** is left to the daily update_patterns workflow.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The README claimed "Requires Python 3.11+", but the validation workflow
(test_nginx.yml) runs the converters on Python 3.9 and the code uses no
3.10+ syntax. Relax the claim to 3.9+ so the docs match what is actually
supported and tested.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Drops the self-hosted runner-02 default. With no self-hosted runner registered
on the repo, workflows now run reliably on ubuntu-latest without needing a
RUNS_ON repo variable override.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
- VitePress: custom theme (SF system fonts, glass nav, soft surfaces, pill buttons,
light/dark code blocks, refined feature cards, platform showcase + stat strip).
- Replace every emoji across docs and README with inline SVG icons.
- Verify and fix doc accuracy against actual scripts: JSON schema (category+pattern only),
env-var configuration for json2*/import_* scripts, owasp2json CLI surface.
- Add public assets (logo.svg, favicon.svg, hero-shield.svg) and Shiki haproxy alias.
- Workflows default to self-hosted runner-02 with a configurable fallback to GitHub
runners via the RUNS_ON repo variable.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>