Skip to content

v1.3.20

Choose a tag to compare

@github-actions github-actions released this 28 May 01:57
97a9b70

🚀 SamWaf v1.3.20 Release Notes

Release Date: 2026-02-24
Version: v1.3.20


✨ Added

  • 🌐 Open Platform

  • 📊 Comprehensive website query statistics

  • 🧩 Custom static service response headers

  • 🔐 Tunnel SSL support for intranet penetration, cross-network secure communication, and zero-trust architecture scenarios

  • ⚡ Site gzip / br compression support to reduce transfer size and improve performance

  • 🪪 Enhanced certificate application capability

    • Automatic retry mechanism
    • Support for skipping local DNS validation
    • Improved success rate in complex network environments
  • 🛡️ Secure entry

  • 🗃️ Database table information display

  • 📦 Zstd compression support

  • 🧹 Data cleanup disabled by default with new cleanup policy controls

  • 🎯 Custom response rules

  • 📜 Task log feature for tracking execution status

  • 🔔 Notification title prefix support for distinguishing multiple SamWaf instances

  • 🚫 Skip global CC feature

  • 🗜️ Static website compression support

  • 📚 Deep integrated OWASP rule set management

  • 🔒 Request protection enhancements

  • 🌍 Custom IP header retrieval on management side

  • 🗑️ Bulk deletion of risk logs

  • 🚀 HTTP/3 BBR support for improved transmission efficiency

  • ⏪ Version rollback feature

  • 🧾 Custom request header deletion

    • Defining an empty string for a request header means it will not be forwarded to the backend
  • 🏷️ Tag select all / deselect all

  • 🗄️ Database support for SQLite & MySQL

  • ⚡ Redis cache support

  • 🛣️ Path routing support


🐛 Fixed

  • 🌐 Global IP judgment logic anomaly causing inaccurate policy matching
  • 🛡️ XSS false positive issues to improve rule accuracy
  • ➕ Issue where IP extraction mode could not be correctly selected when adding a new site
  • 📦 WASM resource handling issue
  • 📖 monitor/system_info API documentation error
  • 🌍 Multiple ports and multiple domains not taking effect correctly
  • 🌙 Dark mode display issue in IP database management interface
  • 🔥 Firewall permission prompt issue
  • 🔗 Open API URL issue
  • 🌐 In non-strict source mode, multiple domains and ports binding issue
  • 🧩 Sensitive word null value issue causing crashes
  • 📡 Null value errors during IP management
  • 📊 Statistics calculation inaccuracies
  • 🧪 Open API test case errors
  • ⏰ CC notification sending time issue
  • ❤️ Health check bug
  • 🔑 Account password reset bug
  • ⚙️ OWASP variable setting bug

⚙️ Optimized

  • 🖥️ Website list display

  • 📦 gzip compression for management-side static resources

  • 🧩 Configuration system consistency to avoid duplicate parameter definitions

  • 🔑 Password reset workflow

  • 📉 Default compression priority order:

    • Zstd → Brotli → Gzip
  • 🚀 Request context cancellation mechanism for improved stability and response speed

  • 🏷️ Removed static labels and optimized configuration management

  • 🧠 Reduced heap allocation during header string concatenation in modifyResponse and errorResponse

  • 🧪 Improved test case stability


❤️ Contributors

Thanks to all contributors for helping improve SamWaf (in no particular order):

@blue991989, @boxker, @Cycloctane, @echs-top, @EvianTian, @f0Xj1MnNy, @Firfr, @FoxZzz, @fudiwei, @hamgua, @hashwing, @heruiguo, @hjpc, @lifetin, @liujiangniao, @Lvshujun0918, @MadeLuckyBoy, @MetaCubeX, @Omoinemie, @raychan239, @raychan2394, @rzorzo, @SONGjiemo, @systemctl529, @Tea-NT, @wangpenga999, @yinyutao, @恒嘉电脑-张波, @四维, @孙工