From 5a254c727265f7a151157c4dd981aee7b6326df4 Mon Sep 17 00:00:00 2001 From: Felipe Zipitria Date: Sun, 13 Sep 2026 09:29:42 -0700 Subject: [PATCH 1/2] Add plugin.yaml descriptor Adds the machine-readable plugin descriptor defined in coreruleset/plugin-registry#37, per the rollout plan in coreruleset/plugin-registry#21. Co-Authored-By: Claude Sonnet 5 --- plugin.yaml | 47 +++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 47 insertions(+) create mode 100644 plugin.yaml diff --git a/plugin.yaml b/plugin.yaml new file mode 100644 index 0000000..c337fce --- /dev/null +++ b/plugin.yaml @@ -0,0 +1,47 @@ +# OWASP CRS Plugin Descriptor +# See https://github.com/coreruleset/plugin-registry for the schema definition. + +schema_version: 1 + +plugin: + name: "template-plugin" + description: "Reference template plugin illustrating the OWASP CRS plugin mechanism." + long_description: | + The reference implementation of the OWASP CRS plugin structure. It is meant + to be copied and adapted as the starting point for new plugins, and it + documents the plugin file layout (-config.conf, -before.conf, -after.conf), + the mandatory enable/disable control rule, and the include order plugins + run in relative to the core rule set. + type: "official" + category: "utility" + status: "tested" + license: "Apache-2.0" + authors: + - name: "OWASP CRS Team" + url: "https://coreruleset.org" + repository: "https://github.com/coreruleset/template-plugin" + keywords: + - "template" + - "example" + - "starter" + - "reference" + +rule_id_range: + start: 9500000 + end: 9500999 + +compatibility: + crs_version: ">=4.0.0" + engines: + - "modsecurity2" + - "modsecurity3" + - "coraza" + +configuration: + file: "plugins/template-config.conf" + variables: + - name: "tx.template-plugin_enabled" + type: "boolean" + default: 1 + description: "Enables or disables the template plugin (0 to disable)." + required: false From eeba2985b80ab6b09d899cd81173d751ae3dac62 Mon Sep 17 00:00:00 2001 From: Felipe Zipitria Date: Sun, 13 Sep 2026 09:59:10 -0700 Subject: [PATCH 2/2] Explain why the template plugin spells out compatibility.engines Other plugin.yaml PRs in this rollout omit engines when every engine is supported, since the schema treats an absent field as "all". This file intentionally keeps the explicit list as a showcase for authors copying it, so a comment now says so instead of leaving it looking like an oversight. Co-Authored-By: Claude Sonnet 5 --- plugin.yaml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/plugin.yaml b/plugin.yaml index c337fce..006bbb1 100644 --- a/plugin.yaml +++ b/plugin.yaml @@ -32,6 +32,10 @@ rule_id_range: compatibility: crs_version: ">=4.0.0" + # engines is spelled out here, even though the template supports all three, + # to showcase the field for authors copying this file. A real plugin that + # truly supports every engine should omit `engines` instead: per + # docs/plugin-descriptor-schema.md, an omitted field already means "all". engines: - "modsecurity2" - "modsecurity3"