|
| 1 | +--- |
| 2 | +# We use sentence case and present imperative tone |
| 3 | +title: "Changelog" |
| 4 | +# Weights are assigned in increments of 100: determines sorting order |
| 5 | +weight: 800 |
| 6 | +# Creates a table of contents and sidebar, useful for large documents |
| 7 | +toc: true |
| 8 | +# Types have a 1:1 relationship with Hugo archetypes, so you shouldn't need to change this |
| 9 | +nd-content-type: reference |
| 10 | +# Intended for internal catalogue and search, case sensitive: |
| 11 | +# Agent, N4Azure, NIC, NIM, NGF, NAP-DOS, NAP-WAF, NGINX One, NGINX+, Solutions, Unit |
| 12 | +nd-product: NAP-WAF |
| 13 | +--- |
| 14 | + |
| 15 | +{{< call-out "warning" "Information architecture note" >}} |
| 16 | + |
| 17 | +The design intention for this page is to act as a single reference point for changes between each release. "Changelog" is the term being adopted across the entire NGINX product ecosystem. |
| 18 | + |
| 19 | +Since both versions of NGINX App Protect WAF are released at the same time, they can be stored in the same note. Change items for only one specific version are explicitly annotated when necessary. |
| 20 | + |
| 21 | +Updating the content of this page will likely be automated in the future, following some procedural changes to how tickets are managed within JIRA. |
| 22 | + |
| 23 | +{{</ call-out>}} |
| 24 | + |
| 25 | +This changelog lists all of the information for F5 NGINX App Protect WAF releases in 2025. |
| 26 | + |
| 27 | +For older releases, check the changelogs for previous years: [2024](), [2023](). |
| 28 | + |
| 29 | +## NGINX App Protect WAF 5.7 / 4.15 |
| 30 | + |
| 31 | +### New features |
| 32 | + |
| 33 | +- Added support for Rocky Linux 9 |
| 34 | +- Added support for IP Intelligence |
| 35 | +- Added support for Override rules for IP Address Lists |
| 36 | + |
| 37 | +### Important notes |
| 38 | + |
| 39 | +- Ubuntu 20.04 is no longer supported |
| 40 | +- (12447) Upgrade libk5crypto3 package |
| 41 | +- (12520) Upgrade Go compiler to 1.23.8 |
| 42 | + |
| 43 | +### Resolved issues |
| 44 | + |
| 45 | +- (12527) Remove CPAN - installed certs and source files |
| 46 | +- (11112) Remove systemd/init.d leftovers in NAP WAF v5 pkgs |
| 47 | +- (12400) Cookie attributes are not added to a TS cookie when there is more than one TS cookie |
| 48 | +- (12498) Undefined behavior when using huge XFF |
| 49 | +- (12731) Multiple clean_resp_reset internal error messages in logs when loading NAP |
| 50 | + |
| 51 | +### 5.7 packages |
| 52 | + |
| 53 | +#### NGINX Open Source |
| 54 | + |
| 55 | +| Distribution name | Package file | |
| 56 | +|--------------------------|-------------------------------------------------------------------| |
| 57 | +| Alpine 3.19 | _app-protect-module-oss-1.27.4+5.442.0-r1.apk_ | |
| 58 | +| Amazon Linux 2023 | _app-protect-module-oss-1.27.4+5.442.0-1.amzn2023.ngx.x86_64.rpm_ | |
| 59 | +| Debian 11 | _app-protect-module-oss_1.27.4+5.442.0-1\~bullseye_amd64.deb_ | |
| 60 | +| Debian 12 | _app-protect-module-oss_1.27.4+5.442.0-1\~bookworm_amd64.deb_ | |
| 61 | +| Oracle Linux 8.1 | _app-protect-module-oss-1.27.4+5.442.0-1.el8.ngx.x86_64.rpm_ | |
| 62 | +| Ubuntu 22.04 | _app-protect-module-oss_1.27.4+5.442.0-1\~jammy_amd64.deb_ | |
| 63 | +| Ubuntu 24.04 | _app-protect-module-oss_1.27.4+5.442.0-1\~noble_amd64.deb_ | |
| 64 | +| RHEL 8 and Rocky Linux 8 | _app-protect-module-oss-1.27.4+5.442.0-1.el8.ngx.x86_64.rpm_ | |
| 65 | +| RHEL 9 and Rocky Linux 9 | _app-protect-module-oss-1.27.4+5.442.0-1.el9.ngx.x86_64.rpm_ | |
| 66 | + |
| 67 | +#### NGINX Plus |
| 68 | + |
| 69 | +| Distribution name | Package file | |
| 70 | +|--------------------------|----------------------------------------------------------------| |
| 71 | +| Alpine 3.19 | _app-protect-module-plus-34+5.442.0-r1.apk_ | |
| 72 | +| Amazon Linux 2023 | _app-protect-module-plus-34+5.442.0-1.amzn2023.ngx.x86_64.rpm_ | |
| 73 | +| Debian 11 | _app-protect-module-plus_34+5.442.0-1\~bullseye_amd64.deb_ | |
| 74 | +| Debian 12 | _app-protect-module-plus_34+5.442.0-1\~bookworm_amd64.deb_ | |
| 75 | +| Oracle Linux 8.1 | _app-protect-module-plus-34+5.442.0-1.el8.ngx.x86_64.rpm_ | |
| 76 | +| Ubuntu 22.04 | _app-protect-module-plus_34+5.442.0-1\~jammy_amd64.deb_ | |
| 77 | +| Ubuntu 24.04 | _app-protect-module-plus_34+5.442.0-1\~noble_amd64.deb_ | |
| 78 | +| RHEL 8 and Rocky Linux 8 | _app-protect-module-plus-34+5.442.0-1.el8.ngx.x86_64.rpm_ | |
| 79 | +| RHEL 9 and Rocky Linux 9 | _app-protect-module-plus-34+5.442.0-1.el9.ngx.x86_64.rpm_ | |
| 80 | + |
| 81 | +### 4.15 packages |
| 82 | + |
| 83 | +| Distribution name | Package file | |
| 84 | +|--------------------------|----------------------------------------------------| |
| 85 | +| Alpine 3.19 | _app-protect-34.5.442.0-r1.apk_ | |
| 86 | +| Amazon Linux 2023 | _app-protect-34+5.442.0-1.amzn2023.ngx.x86_64.rpm_ | |
| 87 | +| Debian 11 | _app-protect_34+5.442.0-1\~bullseye_amd64.deb_ | |
| 88 | +| Debian 12 | _app-protect_34+5.442.0-1\~bookworm_amd64.deb_ | |
| 89 | +| Oracle Linux 8.1 | _app-protect-34+5.442.0-1.el8.ngx.x86_64.rpm_ | |
| 90 | +| Ubuntu 22.04 | _app-protect_34+5.442.0-1\~jammy_amd64.deb_ | |
| 91 | +| Ubuntu 24.04 | _app-protect_34+5.442.0-1\~noble_amd64.deb_ | |
| 92 | +| RHEL 8 and Rocky Linux 8 | _app-protect-34+5.442.0-1.el8.ngx.x86_64.rpm_ | |
| 93 | +| RHEL 9 and Rocky Linux 9 | _app-protect-34+5.442.0-1.el9.ngx.x86_64.rpm_ | |
| 94 | + |
| 95 | +## NGINX App Protect WAF 5.6 / 4.14 |
| 96 | + |
| 97 | +### New features |
| 98 | + |
| 99 | +- Added support for NGINX Plus R34 |
| 100 | +- **5.6 Only:** You can now [deploy NGINX App Protect WAF 5+ using a Helm chart]({{< ref "/nap-waf/v5/admin-guide/deploy-with-helm.md">}}) |
| 101 | + |
| 102 | +### Important notes |
| 103 | + |
| 104 | +- Alpine 3.17 is no longer supported |
| 105 | + |
| 106 | +### Resolved issues |
| 107 | + |
| 108 | +- Upgraded the Go compiler to 1.23.7 |
| 109 | +- (12140) Changed the maximum memory of the XML processing engine to 8GB |
| 110 | +- (12254) A modified YAML file referenced by a JSON policy file causes a reload error when running `nginx -t` |
| 111 | +- (12296) "Violation Bad Unescape" is not enabled by default |
| 112 | +- (12297) "Violation Encoding" is not enabled by default |
| 113 | + |
| 114 | +### 5.6 packages |
| 115 | + |
| 116 | +#### NGINX Open Source |
| 117 | + |
| 118 | +| Distribution name | Package file | |
| 119 | +|--------------------------|-------------------------------------------------------------------| |
| 120 | +| Alpine 3.19 | _app-protect-module-oss-1.27.4+5.342.0-r1.apk_ | |
| 121 | +| Amazon Linux 2023 | _app-protect-module-oss-1.27.4+5.342.0-1.amzn2023.ngx.x86_64.rpm_ | |
| 122 | +| Debian 11 | _app-protect-module-oss_1.27.4+5.342.0-1\~bullseye_amd64.deb_ | |
| 123 | +| Debian 12 | _app-protect-module-oss_1.27.4+5.342.0-1\~bookworm_amd64.deb_ | |
| 124 | +| Oracle Linux 8.1 | _app-protect-module-oss-1.27.4+5.342.0-1.el8.ngx.x86_64.rpm_ | |
| 125 | +| Ubuntu 20.04 | _app-protect-module-oss_1.27.4+5.342.0-1\~focal_amd64.deb_ | |
| 126 | +| Ubuntu 22.04 | _app-protect-module-oss_1.27.4+5.342.0-1\~jammy_amd64.deb_ | |
| 127 | +| Ubuntu 24.04 | _app-protect-module-oss_1.27.4+5.342.0-1\~noble_amd64.deb_ | |
| 128 | +| RHEL 8 and Rocky Linux 8 | _app-protect-module-oss-1.27.4+5.342.0-1.el8.ngx.x86_64.rpm_ | |
| 129 | +| RHEL 9 | _app-protect-module-oss-1.27.4+5.342.0-1.el9.ngx.x86_64.rpm_ | |
| 130 | + |
| 131 | +#### NGINX Plus |
| 132 | + |
| 133 | +| Distribution name | Package file | |
| 134 | +|--------------------------|----------------------------------------------------------------| |
| 135 | +| Alpine 3.19 | _app-protect-module-plus-34+5.342.0-r1.apk_ | |
| 136 | +| Amazon Linux 2023 | _app-protect-module-plus-34+5.342.0-1.amzn2023.ngx.x86_64.rpm_ | |
| 137 | +| Debian 11 | _app-protect-module-plus_34+5.342.0-1\~bullseye_amd64.deb_ | |
| 138 | +| Debian 12 | _app-protect-module-plus_34+5.342.0-1\~bookworm_amd64.deb_ | |
| 139 | +| Oracle Linux 8.1 | _app-protect-module-plus-34+5.342.0-1.el8.ngx.x86_64.rpm_ | |
| 140 | +| Ubuntu 20.04 | _app-protect-module-plus_34+5.342.0-1\~focal_amd64.deb_ | |
| 141 | +| Ubuntu 22.04 | _app-protect-module-plus_34+5.342.0-1\~jammy_amd64.deb_ | |
| 142 | +| Ubuntu 24.04 | _app-protect-module-plus_34+5.342.0-1\~noble_amd64.deb_ | |
| 143 | +| RHEL 8 and Rocky Linux 8 | _app-protect-module-plus-34+5.342.0-1.el8.ngx.x86_64.rpm_ | |
| 144 | +| RHEL 9 | _app-protect-module-plus-34+5.342.0-1.el9.ngx.x86_64.rpm_ | |
| 145 | + |
| 146 | +### 4.14 packages |
| 147 | + |
| 148 | +| Distribution name | Package file | |
| 149 | +|--------------------------|----------------------------------------------------| |
| 150 | +| Alpine 3.19 | _app-protect-34.5.342.0-r1.apk_ | |
| 151 | +| Amazon Linux 2023 | _app-protect-34+5.342.0-1.amzn2023.ngx.x86_64.rpm_ | |
| 152 | +| Debian 11 | _app-protect_34+5.342.0-1\~bullseye_amd64.deb_ | |
| 153 | +| Debian 12 | _app-protect_34+5.342.0-1\~bookworm_amd64.deb_ | |
| 154 | +| Oracle Linux 8.1 | _app-protect-34+5.342.0-1.el8.ngx.x86_64.rpm_ | |
| 155 | +| Ubuntu 20.04 | _app-protect_34+5.342.0-1\~focal_amd64.deb_ | |
| 156 | +| Ubuntu 22.04 | _app-protect_34+5.342.0-1\~jammy_amd64.deb_ | |
| 157 | +| Ubuntu 24.04 | _app-protect_34+5.342.0-1\~noble_amd64.deb_ | |
| 158 | +| RHEL 8 and Rocky Linux 8 | _app-protect-34+5.342.0-1.el8.ngx.x86_64.rpm_ | |
| 159 | +| RHEL 9 | _app-protect-34+5.342.0-1.el9.ngx.x86_64.rpm_ | |
0 commit comments