Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature Request: GitLab Plugin #25

Open
sempervictus opened this issue Jun 23, 2024 · 5 comments
Open

Feature Request: GitLab Plugin #25

sempervictus opened this issue Jun 23, 2024 · 5 comments

Comments

@sempervictus
Copy link

Seems GitLab is fairly prone to false positives with ModSecurity and the whackamole exclusion process is a bit onerous/may exclude valid rules. Wondering if anyone's got a CRS plugin in the works for "on-prem" GitLab setups (in our case, V2+Apache).

@azurit
Copy link
Member

azurit commented Jun 23, 2024

@sempervictus Hi. Probably no but we may create one if you are willing to help - mainly providing logs and testing. What do you think?

@EsadCetiner
Copy link
Member

@sempervictus
I've been thinking about playing with GitLab and writing a plugin for it, I haven't really decided if I'll go through with it or not. Although I'm not sure who should maintain the plugins (Myself, CRS, or a 3rd party), I already maintain 3 plugins myself and I'm not sure I can maintain 4 with reasonable quality.

@azurit
Copy link
Member

azurit commented Jun 29, 2024

I'm able to maintain it but i don't use it so i can't write it only by myself - i need, at least, logs and testing.

@sempervictus
Copy link
Author

I'm not the heaviest user so won't cover all the APIs but if there's some smoke test set we could execute, it should give us a baseline. Can set up a test instance if needed in our private clouds and provide access for devs

@azurit
Copy link
Member

azurit commented Jun 29, 2024

@sempervictus No need to cover it all, we can start with your use-case. Can you provide us with logs of blocked requests?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants