Artifact Firewall Changelog
Here’s an overview of the latest Varnish Artifact Firewall releases, describing feature additions, changes, fixes and removals per version.
Artifact Firewall 0.4.0
Released: 2026-07-31
Added
- Warn when the firewall starts or reloads with no rulesets configured, since it then falls back to applying only the default action to all traffic.
- Git ruleset sources can now authenticate to GitHub with a GitHub App via
auth.github_app(a client ID and a private key by path or env). The firewall discovers the App installation from the repository URL, then mints and refreshes short-lived installation tokens automatically.api_base_urlsupports GitHub Enterprise Server. - Added Hex (Erlang/Elixir) support, including JFrog Artifactory’s Hex repository prefix. Hex’s package manifest (
/packages/<name>) is a signed protobuf payload that the client cryptographically verifies, so unlike PyPI/NuGet/Maven, denied or vulnerable versions can’t be filtered out of it (any change to the payload breaks the signature and hex_core rejects the response outright); enforcement is instead a per-tarball allow/deny check on download. - OpenTelemetry metrics exporter configured via a top-level
otel:block whose schema matches Varnish Supervisor’s, so the same config works standalone or integrated.otel.metrics.exporterselectsotlp(push) orprometheus(scrape). Standalone stands up its own OTel SDK. Integrated reuses Supervisor’s MeterProvider, where firewall metrics appear under instrumentation scopeartifact-firewall. - OpenTelemetry tracing over OTLP, configured under
otel.tracing(off until enabled with an endpoint). Per request the firewall emits an HTTP server span, afirewall.proxyspan, afirewall.transform_manifestspan, and an upstream client span. The admin/api/evalendpoint emits afirewall.evaluatespan with the rule decision. Inbound W3Ctraceparentheaders are honored and propagated upstream. Standalone stands up its own TracerProvider. Integrated reuses Supervisor’s. - Audit log export over OpenTelemetry logs. Set
audit_log_output: otelto export the audit log through the OTel logs pipeline (configured underotel.logs) instead of JSON. Each entry becomes an OTel log record under its own scopeartifact-firewall/audit(fields as attributes, severity by action), correlated with the request trace. Standalone stands up its own LoggerProvider. Integrated reuses Supervisor’s. - Process log export over OpenTelemetry logs. Set
log_output: otelto export process logs through the OTel logs pipeline under scopeartifact-firewall/log. This tees to stderr (startup logs are never lost) and also exports to OTel.log_outputis now honored generally (stdoutby default,stderr, or a file path), having previously been ignored. File-based process logs are closed on shutdown and reopened on SIGHUP for external rotation, matching the audit log.
Changed
- Metrics are now configured under
otel.metricsinstead of the top-levelmetrics_address.otel.metrics.exporterselectsotlp(default, push) orprometheus(scrape endpoint atprometheus_host:prometheus_port, defaultlocalhost:9464). In integrated mode the firewall reuses Supervisor’s metrics pipeline. - Replacing
metrics_address: ":9090"takes two settings: an endpoint orexporter: prometheus, since metrics are no longer exported by default, andprometheus_host: "0.0.0.0", since the scrape endpoint now binds loopback only. - The firewall warns at startup when a signal is enabled with nowhere to export: metrics or tracing without an endpoint, or
audit_log_output/log_outputset tootelwithoutotel.logs. - The
metrics_addressconfig field is deprecated and inert: it still parses (logging a warning) but has no effect. Configure metrics underotel.metrics.
Fixed
- Maven: a denied version no longer breaks resolution for packages that are allowed. Maven reads the
.pomof every candidate version while resolving version conflicts, including versions it then discards, so returning 403 for a denied.pomfailed the whole resolve..pomfiles (and Gradle’s.module) now stream through unchanged, and a deny is enforced on the artifact itself whatever its packaging type, so a build that pins a denied version still gets a 403. - Maven artifacts and manifests served through a JFrog Artifactory repository are now correctly identified, filtered, and rewritten.
- Fixed a race between a git ruleset fetcher rewriting its file and a reload reading it, which could intermittently fail a reload with a misleading YAML parse error.
- The environment variable named by a git ruleset’s
auth.token_envis no longer passed to git subprocesses, where the token was readable through/proc/<pid>/environand by anything git spawned (credential helpers from a system gitconfig, pagers, filters). The token still reaches the remote as an HTTP header. - A failed audit log reopen on SIGHUP no longer leaves audit logging dead until restart: the new file is opened before the old one is closed, so a failure keeps the existing file in use.
- Closing the audit log no longer races a SIGHUP arriving during shutdown, which could close one file descriptor twice and leak the other.
Artifact Firewall 0.3.6
Released: 2026-07-14
Fixed
- npm, PyPI, and Maven manifests and artifacts served through a Sonatype Nexus Repository are now correctly identified, filtered, and rewritten.
Artifact Firewall 0.3.5
Released: 2026-07-10
Fixed
- PyPI: a file that can’t be mapped to a listed version is now skipped instead of rejecting the entire package (403).
- PyPI: the PEP 503 HTML simple index is now filtered (allow/hide/deny) like the JSON index, instead of streaming through unchanged.
- PyPI: quarantine is now enforced on the HTML simple index when a publish-time source is configured (
pypi.api_url).
Artifact Firewall 0.3.4
Released: 2026-06-30
Fixed
- PyPI: fixed package downloads failing (503) in integrated mode when the upstream JSON simple index uses relative URLs (e.g. JFrog Artifactory).
- Maven: a
hideverdict no longer returns 403 for a pinned.pom/snapshot; hidden versions are dropped frommaven-metadata.xmlbut a pinned request still resolves, matching npm/PyPI/NuGet. Onlydenyhard-blocks.
Artifact Firewall 0.3.2
Released: 2026-06-13
Fixed
- Manifests and artifacts served through a JFrog Artifactory virtual repo are now correctly identified, filtered, and rewritten — in both standalone and integrated mode, with no configuration. Previously the package path was assumed to sit at the registry root, so these requests were skipped (“not a transform path”).
- npm / PyPI: the Artifactory API prefix (
.../api/<type>/<repo>/) is stripped before identification. - Maven:
maven-metadata.xmland.pomfiles are evaluated against the coordinates in the document body, not the URL path. - NuGet: V3 responses are dispatched by resource token (
registration/flatcontainer/query/index.json), which match Artifactory’s layout as well as nuget.org’s.
- npm / PyPI: the Artifactory API prefix (
- npm and PyPI manifest responses with a
Content-Typethe firewall can’t filter (an Artifactoryvnd.rtnpm variant, acharsetparameter, or a PyPI HTML simple index) now stream through unchanged instead of returning an error.
Varnish Artifact Firewall 0.3.1
Released: 2026-06-03
Fixed
- Fixed rule engine initialization issue when only git fetchers are used. Issue was introduced in 0.3.0.
Varnish Artifact Firewall 0.3.0
Released: 2026-06-02
Added
- Standalone deployment mode, now the default. The firewall sits directly in front of one or more origin registries and routes requests itself.
- Automatic detection of registry from the
Acceptheader,User-Agentprefix, and URL path pattern. Requests that can’t be classified stream through unchanged. - Per-version artifact preflight: direct downloads of tarballs (npm
.tgz), wheels/sdists (PyPI), and.nupkgfiles are blocked at 403 when a per-version deny rule applies, preventing bypass via hard-coded artifact URLs. - Added support for the Maven ecosystem: maven-metadata.xml manifest filtering (artifact-level and per-version SNAPSHOT), plus per-artifact preflight on
.jar,.pom,.war,.aar,.zip(including classifier variants). - New
api_addressconfig field. The admin API (/api/eval,/api/update,/api/mode) listens on this address only when set. - System-tests added under
system_test/(Docker-based mock origins for npm, PyPI, and NuGet plus a long-lived dotnet runtime container) covering both deployment modes. - Added
storageconfiguration section for defining the path cloned git repositories should be stored at, as well as a size limit. - API now allows rules to be disabled at run time
Changed
/api/evalresponse shape is now structured JSON:{action, rule_id, ruleset_id, reason}, plus anerrorfield on deny only (containing a human-readable message that npm-style clients display).- Admin endpoints no longer use the
/fw/prefix and are served onapi_addressonly. deployment:defaults tostandalone; the Supervisor setsintegratedexplicitly when running the firewall as a Virtual Registry add-on.
Removed
- The legacy
pkg/nuget/e2eharness and itsnuget-e2eMake target. NuGet coverage now lives in the sharedsystem_test/suite.
Varnish Artifact Firewall 0.2.2
Released: 2026-05-11
Added
- Added support for the NuGet ecosystem
- Added a
modeoption to the Artifact Firewall configuration, which can change the behavior of the firewall. Includesnormal(default),hideandreport.
Changed
- Audit log now includes an
effective_actionfield, which for modes other thannormalcan be different than theactionfield. - Changed log level for some chatty package quarantine logs to
debug.
Varnish Artifact Firewall 0.1.1
Released: 2026-04-21
Added
- Initial release.