feat/wazuh5-rules-migration #7

Merged
steve merged 2 commits from feat/wazuh5-rules-migration into main 2026-09-07 04:13:18 +00:00
Owner
No description provided.
- Add missing Trivy detection rules (trivy-100301, trivy-100302, trivy-100304, trivy-100305) to roles/wazuh_agent/files/engine/rules.json to achieve full parity with 4.x rules
- Delete obsolete 4.x XML rule templates (platform-security-rules.xml.j2 and trivy-rules.xml.j2)
- Update roles/trivy task name to reflect engine content publishing
- Expand roles/verify assertions to require all Trivy Sigma rule IDs
- Update tests/render.yml to validate Wazuh 5 Sigma rules and assert legacy XML templates are absent
- Add exclusions on git host for user content parameters (content, title, commit_message, commit_summary, text, patch, q) from attack tags (attack-sqli, attack-xss, attack-rce, attack-lfi, attack-generic, attack-injection-php, attack-injection-java, OWASP_CRS)
- Add explicit ruleRemoveTargetById for all PL1 SQLi rules (942100-942550) on user content parameters, fixing false positive 403 blocks on PRs, issues, and comments containing text such as '- Delete obsolete' (rule 942360)
- Add assertions in tests/render.yml to prevent regressions
steve merged commit 21440ef141 into main 2026-09-07 04:13:18 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
steve/debian13-secure-platform!7
No description provided.