mirror of
https://github.com/TecharoHQ/anubis.git
synced 2025-08-03 17:59:24 -04:00
feat(apps): add SearXNG instance tracker policy and Qualys Labs SSL testing rules (#512)
* feat(apps): add SearXNG instance tracker policy * feat(apps): add Qualys SSL Labs policy * chore: spelling Signed-off-by: Xe Iaso <me@xeiaso.net> --------- Signed-off-by: Xe Iaso <me@xeiaso.net> Co-authored-by: hyperdefined <contact@hyper.lol>
This commit is contained in:
parent
76849531cd
commit
3b98368aa9
3
.github/actions/spelling/expect.txt
vendored
3
.github/actions/spelling/expect.txt
vendored
@ -151,6 +151,7 @@ promauto
|
|||||||
promhttp
|
promhttp
|
||||||
pwcmd
|
pwcmd
|
||||||
pwuser
|
pwuser
|
||||||
|
qualys
|
||||||
qwant
|
qwant
|
||||||
qwantbot
|
qwantbot
|
||||||
rac
|
rac
|
||||||
@ -165,6 +166,7 @@ ruleset
|
|||||||
RUnlock
|
RUnlock
|
||||||
sas
|
sas
|
||||||
Scumm
|
Scumm
|
||||||
|
searx
|
||||||
sebest
|
sebest
|
||||||
secretplans
|
secretplans
|
||||||
selfsigned
|
selfsigned
|
||||||
@ -212,6 +214,7 @@ xesite
|
|||||||
xess
|
xess
|
||||||
xff
|
xff
|
||||||
XForwarded
|
XForwarded
|
||||||
|
XNG
|
||||||
XReal
|
XReal
|
||||||
yae
|
yae
|
||||||
YAMLTo
|
YAMLTo
|
||||||
|
7
data/apps/qualys-ssl-labs.yml
Normal file
7
data/apps/qualys-ssl-labs.yml
Normal file
@ -0,0 +1,7 @@
|
|||||||
|
# This policy allows Qualys SSL Labs to fully work. (https://www.ssllabs.com/ssltest)
|
||||||
|
# IP ranges are taken from: https://qualys.my.site.com/discussions/s/article/000005823
|
||||||
|
- name: qualys-ssl-labs
|
||||||
|
action: ALLOW
|
||||||
|
remote_addresses:
|
||||||
|
- 64.41.200.0/24
|
||||||
|
- 2600:C02:1020:4202::/64
|
9
data/apps/searx-checker.yml
Normal file
9
data/apps/searx-checker.yml
Normal file
@ -0,0 +1,9 @@
|
|||||||
|
# This policy allows SearXNG's instance tracker to work. (https://searx.space)
|
||||||
|
# IPs are taken from `check.searx.space` DNS records.
|
||||||
|
# https://toolbox.googleapps.com/apps/dig/#A/check.searx.space
|
||||||
|
# https://toolbox.googleapps.com/apps/dig/#AAAA/check.searx.space
|
||||||
|
- name: searx-checker
|
||||||
|
action: ALLOW
|
||||||
|
remote_addresses:
|
||||||
|
- 167.235.158.251/32
|
||||||
|
- 2a01:4f8:1c1c:8fc2::1/128
|
@ -21,6 +21,8 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
|||||||
- Add `--target-host` flag/envvar to allow changing the value of the Host header in requests forwarded to the target service.
|
- Add `--target-host` flag/envvar to allow changing the value of the Host header in requests forwarded to the target service.
|
||||||
- Bump AI-robots.txt to version 1.30 (add QualifiedBot)
|
- Bump AI-robots.txt to version 1.30 (add QualifiedBot)
|
||||||
- Add `RuntimeDirectory` to systemd unit settings so native packages can listen over unix sockets
|
- Add `RuntimeDirectory` to systemd unit settings so native packages can listen over unix sockets
|
||||||
|
- Added SearXNG instance tracker whitelist policy
|
||||||
|
- Added Qualys SSL Labs whitelist policy
|
||||||
|
|
||||||
## v1.18.0: Varis zos Galvus
|
## v1.18.0: Varis zos Galvus
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user