86 Commits

Author SHA1 Message Date
Zoey
842b7d9a72 do not build images for PRs
Signed-off-by: Zoey <zoey@z0ey.de>
2026-03-01 11:25:23 +01:00
Zoey
951062a6b9 switch to aws-lc/add patches for zlib-ng and brotli cert compression 2026-02-20 17:41:02 +01:00
Zoey
ae13514410 fix ga-IE langname in selection/update and pin dep
Signed-off-by: Zoey <zoey@z0ey.de>
2026-02-19 18:33:40 +01:00
Zoey
93522c0879 merge upstream/dep updates 2026-01-27 23:24:17 +01:00
Zoey
2acf184bd1 Merge remote-tracking branch 'upstream/develop' into develop 2026-01-27 11:56:58 +01:00
dependabot[bot]
69f9031447 Bump actions/stale from 9 to 10
Bumps [actions/stale](https://github.com/actions/stale) from 9 to 10.
- [Release notes](https://github.com/actions/stale/releases)
- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/stale/compare/v9...v10)

---
updated-dependencies:
- dependency-name: actions/stale
  dependency-version: '10'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-01-25 12:30:04 +00:00
renovate[bot]
f292ef71a6 dep updates/also lint PRs
Signed-off-by: Zoey <zoey@z0ey.de>
2026-01-20 22:08:22 +01:00
Zoey
135b2c7162 try to fix zstd with disabled proxy buffering and add unzstd module
Signed-off-by: Zoey <zoey@z0ey.de>
2026-01-20 22:08:21 +01:00
Lokowitz
50cf275328 split directories 2026-01-18 07:00:46 +00:00
Lokowitz
7bcc34dea9 add dependabot config 2026-01-18 06:52:30 +00:00
Zoey
6053d73a3b readd njs
Signed-off-by: Zoey <zoey@z0ey.de>
2026-01-17 22:42:43 +01:00
renovate[bot]
505bc73f52 dep updates/ignor elint push errors
Signed-off-by: Zoey <zoey@z0ey.de>
2026-01-13 12:34:26 +01:00
Zoey
e41c804904 add compatibility to authentiks broken OIDC and add OIDC_REQUIRE_VERIFIED_EMAIL env 2025-12-29 21:26:12 +01:00
Zoey
d6907df75b add workflow to support betas 2025-12-28 02:09:03 +01:00
Zoey
664b0507e0 remove crowdsec build step
Signed-off-by: Zoey <zoey@z0ey.de>
2025-12-27 23:38:58 +01:00
Zoey
0ee6985568 don't push singel develop arch images to docker hub
Signed-off-by: Zoey <zoey@z0ey.de>
2025-12-23 21:42:12 +01:00
Zoey
65e366a647 switch to pnpm/dep updates
Signed-off-by: Zoey <zoey@z0ey.de>
2025-12-23 21:42:12 +01:00
Zoey
1a77cb4e94 also push single arch to docker hub
Signed-off-by: Zoey <zoey@z0ey.de>
2025-12-17 09:34:14 +01:00
renovate[bot]
b3591ba720 dep updates
Signed-off-by: Zoey <zoey@z0ey.de>
2025-12-17 09:34:14 +01:00
Zoey
dcf4d62850 merge nginx-quic Dockerfile/repo into NPMplus Dockerfile/repo
Signed-off-by: Zoey <zoey@z0ey.de>
2025-12-09 20:43:17 +01:00
Zoey
325cbe241a fix #2352/remove modsec/opentelemetry/njs module/slim build
Signed-off-by: Zoey <zoey@z0ey.de>
2025-12-05 19:36:32 +01:00
Zoey
bf46ddc5cb use native aarch64 runner
Signed-off-by: Zoey <zoey@z0ey.de>
2025-12-02 12:11:37 +01:00
Zoey
59dfce954f dep updates/small cipher fix/move security.txt
Signed-off-by: Zoey <zoey@z0ey.de>
2025-12-02 12:10:59 +01:00
Zoey
c906f2814d Update nginx.conf
Signed-off-by: Zoey <zoey@z0ey.de>
2025-11-26 15:27:21 +01:00
renovate[bot]
95f87a875c Update actions/checkout action to v6 2025-11-21 11:15:47 +01:00
Zoey
d3440e1b04 merge upstream
Signed-off-by: Zoey <zoey@z0ey.de>
2025-11-18 12:32:42 +01:00
Zoey
afe06158ec move frontend to frontend-old 2025-11-11 12:13:38 +01:00
Zoey
aed8c7e0f4 add zstd and unbrotli
Signed-off-by: Zoey <zoey@z0ey.de>

close #2244

Lock file maintenance

update cs-nginx-bouncer version to v1.1.5

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

Update dependency sass to v1.94.0

close #2252

Signed-off-by: Zoey <zoey@z0ey.de>
2025-11-11 12:13:38 +01:00
renovate[bot]
7e2fe30944 require x86-64-v2
Signed-off-by: Zoey <zoey@z0ey.de>
2025-10-25 17:15:25 +02:00
Zoey
8b1529758a small improvements
Signed-off-by: Zoey <zoey@z0ey.de>
2025-10-25 17:14:42 +02:00
renovate[bot]
1b00303506 dep updates
Signed-off-by: Zoey <zoey@z0ey.de>
2025-09-13 11:11:12 +02:00
renovate[bot]
ba776511e4 improve default buffer sizes/set SKIP_IP_RANGES to true by defaultdep updates/blacklist X-XSS-Protection header
Signed-off-by: Zoey <zoey@z0ey.de>
2025-08-12 12:57:54 +02:00
Daeho Ro
d7bb9859bb Add Korean translation (#1967)
Co-authored-by: Daeho Ro <40587651+daeho-ro@users.noreply.github.com>
Co-authored-by: OpenAI <noreply-mt-openai@weblate.org>
Co-authored-by: Weblate Admin <email@daeho.ro>
2025-07-05 15:48:07 +02:00
renovate[bot]
cf55e340d9 see commit body
dep updates
rename NGINX_HSTS_SUBDMAINS env to NGINX_HSTS_SUBDOMAINS (reported and partly fixed by @dormancygrace)
fix usage of $server_port as forwarding port in streams by @joshf67
impove/unify version naming a bit (still not perfect)
also thanks to @shedowe19 for testing
add anubis example to readme and improve some config examples
enable early hints by default (now supported because of nginx update to v1.29)

Signed-off-by: Zoey <zoey@z0ey.de>
2025-06-24 21:38:26 +02:00
renovate[bot]
8b2bc2845e see commit body
zh-lang by @ZhWn
update alpine to 3.22 (includes openssl 3.5)
remove liboqs/oqs-provider sinc eopenssl 3.5 now has mlkem support
dep updates
run internal APIs in unix sockets instead of tcp ports
improve templates (not done yeet)

Signed-off-by: Zoey <zoey@z0ey.de>
2025-06-14 14:00:39 +02:00
renovate[bot]
00b042a98c see commit body
Signed-off-by: Zoey <zoey@z0ey.de>

drop armv7 support again
make some modules dynamic, can be loaded using env
add ENABLE_PRERUN env, if not set to true, then prerun scripts wont run
dep updates
trust localhost ips
add reuseport to udp stream
fix hosts with new certs go offline
block deletion of used certs, when not in use
also delete certificates on disk when deleted in ui
used certs function now also works for redirection hosts (streams still todo)
error log is now also written to disk, which means that you don't need to mount the docker socket into the crowdsec container anymore
use random default initial password
2025-03-11 15:10:22 +01:00
Zoey
089a358126 add grpc usptream support/dep updates/merge upstream/armv7 support
Signed-off-by: Zoey <zoey@z0ey.de>
2025-02-24 18:41:29 +01:00
Zoey
a0673283a1 disable brotli when using openappsec/use X-Forwarded-For/add more headers/improve authelia+uthentik example/add HTTP3_ALT_SVC_PORT env/dep updates/upstream support for custom locations/sub path support/add lockfiles
Signed-off-by: Zoey <zoey@z0ey.de>
2025-02-02 21:25:11 +01:00
Andrea Macaro
a245da05fc add it-lang/add missing translation fields
Signed-off-by: Andrea Macaro <andreamac2000@gmail.com>
Signed-off-by: Zoey <zoey@z0ey.de>
2025-01-26 12:02:43 +01:00
renovate[bot]
fd869f0668 dep updates/add openappsec env/add worker_processes env/support ocsp stapling for custom certs/allow empty port/fix #1405/document Load Balancing/allow all forward hostnames again
Signed-off-by: Zoey <zoey@z0ey.de>
2025-01-26 12:02:43 +01:00
Zoey
aff410c2e3 prepare final release/small fixes/allow watchtower
Signed-off-by: Zoey <zoey@z0ey.de>
2025-01-10 18:40:41 +01:00
renovate[bot]
14b3cc77c1 alpine&dep updates/changing must-staple&acme server now also effect renewals/change default mime types to download
Signed-off-by: Zoey <zoey@z0ey.de>
2024-12-14 19:20:50 +01:00
Zoey
a9b9269f11 add de-lang 2024-10-29 12:12:33 +01:00
renovate[bot]
bb09562f89 fixes/dep updates/improved tls
Signed-off-by: Zoey <zoey@z0ey.de>
2024-10-02 23:17:42 +02:00
Zoey
22fa2f04ab dep updates/alpine 3.20.1
Signed-off-by: Zoey <zoey@z0ey.de>
2024-06-22 00:55:42 +02:00
renovate[bot]
132623891a dep updates/see description
little php design preview (dead host/default page/fancyindex)
improved "exploit blocking"
fancyindex now default off
block access to .git folders/files
change NGINX_404_REDIRECT default to false
2024-06-09 15:20:13 +02:00
Zoey
906d7ce04a update nginx/dep updates/fix eslint/change line endings
Signed-off-by: Zoey <zoey@z0ey.de>
2024-04-19 11:42:01 +02:00
Zoey
a779df8d1b dep updates
Signed-off-by: Zoey <zoey@z0ey.de>
2024-01-31 20:56:20 +01:00
Zoey
740d4c74aa fix healthcheck again 2024-01-26 23:30:14 +01:00
Zoey
aeebd0841e merge upstream 2024-01-20 14:42:28 +01:00