feat(apps): add SearXNG instance tracker policy and Qualys Labs SSL testing rules (#512)

* feat(apps): add SearXNG instance tracker policy

* feat(apps): add Qualys SSL Labs policy

* chore: spelling

Signed-off-by: Xe Iaso <me@xeiaso.net>

---------

Signed-off-by: Xe Iaso <me@xeiaso.net>
Co-authored-by: hyperdefined <contact@hyper.lol>
This commit is contained in:
Xe Iaso 2025-05-16 12:59:15 -04:00 committed by GitHub
parent 76849531cd
commit 3b98368aa9
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
4 changed files with 21 additions and 0 deletions

View File

@ -151,6 +151,7 @@ promauto
promhttp promhttp
pwcmd pwcmd
pwuser pwuser
qualys
qwant qwant
qwantbot qwantbot
rac rac
@ -165,6 +166,7 @@ ruleset
RUnlock RUnlock
sas sas
Scumm Scumm
searx
sebest sebest
secretplans secretplans
selfsigned selfsigned
@ -212,6 +214,7 @@ xesite
xess xess
xff xff
XForwarded XForwarded
XNG
XReal XReal
yae yae
YAMLTo YAMLTo

View File

@ -0,0 +1,7 @@
# This policy allows Qualys SSL Labs to fully work. (https://www.ssllabs.com/ssltest)
# IP ranges are taken from: https://qualys.my.site.com/discussions/s/article/000005823
- name: qualys-ssl-labs
action: ALLOW
remote_addresses:
- 64.41.200.0/24
- 2600:C02:1020:4202::/64

View File

@ -0,0 +1,9 @@
# This policy allows SearXNG's instance tracker to work. (https://searx.space)
# IPs are taken from `check.searx.space` DNS records.
# https://toolbox.googleapps.com/apps/dig/#A/check.searx.space
# https://toolbox.googleapps.com/apps/dig/#AAAA/check.searx.space
- name: searx-checker
action: ALLOW
remote_addresses:
- 167.235.158.251/32
- 2a01:4f8:1c1c:8fc2::1/128

View File

@ -21,6 +21,8 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
- Add `--target-host` flag/envvar to allow changing the value of the Host header in requests forwarded to the target service. - Add `--target-host` flag/envvar to allow changing the value of the Host header in requests forwarded to the target service.
- Bump AI-robots.txt to version 1.30 (add QualifiedBot) - Bump AI-robots.txt to version 1.30 (add QualifiedBot)
- Add `RuntimeDirectory` to systemd unit settings so native packages can listen over unix sockets - Add `RuntimeDirectory` to systemd unit settings so native packages can listen over unix sockets
- Added SearXNG instance tracker whitelist policy
- Added Qualys SSL Labs whitelist policy
## v1.18.0: Varis zos Galvus ## v1.18.0: Varis zos Galvus