corazawaf / coraza

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library
https://www.coraza.io
Apache License 2.0
1.99k stars 201 forks source link

Invitation for Contributors: Seeking NGINX Module Engineer for Building OWASP Coraza WAF Connector #803

Open jptosso opened 1 year ago

jptosso commented 1 year ago

Hello everyone,

We have an exciting project on the table, and we're looking to engage the collective brilliance of this community. We're seeking contributions from individual engineers, open-source enthusiasts, or even companies interested in helping fortify web application security.

Objective

We aim to build a robust OWASP Coraza Web Application Firewall (WAF) connector that integrates seamlessly with NGINX. This connector will act as a vital link between the NGINX server and the Coraza WAF, effectively enhancing the security capabilities of web applications.

Requirements

The connector should be primarily written in C and interact with libcoraza, the C wrapper for Coraza coded in Go. However, we're also open to building the connector using Rust, given its reputation for memory safety and performance, while maintaining the connection to libcoraza.

Desired Skills

Technical Details

The implementation of the connector should meet the following requirements:

Support

We are committed to actively support throughout the project, especially in understanding and integrating with libcoraza. Our team is equipped to provide clarifications, technical insights, and testing support to ensure the project's success.

Open Invitation

This call is open to everyone - from individual open-source enthusiasts to larger organizations that can contribute. If you are interested in participating in this project, please comment here.

This is a great chance to contribute to an essential security feature for our WAF, work with advanced technologies, and be a part of the effort to create a safer web environment.

We eagerly anticipate your innovative ideas and valuable contributions.

Thanks & Best Regards, Juan Pablo Tosso & the Coraza Team

References:

dune73 commented 1 year ago

Chiming in from the OWASP ModSecurity Core Rule Set team: We are 100% behind this and we have also set aside some funds for this. It's not much, but it's enough to get you going.

jptosso commented 1 year ago

Thank you very much, @dune73. CRS participation is very much appreciated and essential for the success of this project.

swzaaaaaaa commented 8 months ago

Please,how is it going?

jptosso commented 8 months ago

Please,how is it going?

No updates

pvalin commented 3 months ago

Hi,

And today? Some news?