Skip to content

feat: register plex-hardening-plugin (9530000-9530999) - #50

Open
davidscarth wants to merge 3 commits into
coreruleset:mainfrom
davidscarth:patch-1
Open

davidscarth wants to merge 3 commits into
coreruleset:mainfrom
davidscarth:patch-1

Conversation

@davidscarth

@davidscarth davidscarth commented Sep 27, 2026 •

Copy link
Copy Markdown

what

Registers plex-hardening-plugin in the next free block, 9,530,000-9,530,999, and adds the regenerated README.md and registry.json.

why

Hardening plugin for Plex Media Server behind CRS 4.x: the rule exclusions Plex needs to run at PL1, detection rules for CVE-2026-96651/96652/96654/96655/96656 and the Zenofex Plex_Vuln_PoCs classes, and switchable owner-only endpoint denies. Tested on ModSecurity 2/3 via the shared plugin workflows and on Coraza in production.

refs

ai disclosure

tools used: Claude (Anthropic), Fable 5.1, via claude.ai.
assisted with: converting my existing production rules into the plugin file structure, drafting rule comments, tests, and diagnosing a Coraza-on-Windows transform issue in the endpoint denies.
review performed: every rule was deployed and exercised against live Plex clients (Plex Web, Windows, Android TV, Android mobile); exclusion test payloads were checked against the CRS 4.29.0 regexes; the registry entry and regenerated files were produced per the drift-check output.

Summary by CodeRabbit

  • New Features
    • Added the Plex hardening plugin to the available security rule registry, with rule IDs 9,530,000–9,530,999. Its registry listing includes a link to the project repository, tested status, an integration-test badge, CI availability, and its Apache-2.0 license, helping users review the plugin’s availability and compatibility details.

feat: register plex-hardening-plugin (9530000-9530999)
@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Advanced

Run ID: 3d1fb714-149a-4ac1-9d5b-6dc916799b28

📥 Commits

Reviewing files that changed from the base of the PR and between d2ad0fc and e5ea61c.

📒 Files selected for processing (2)
  • README.md
  • registry.json
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The registry adds plex-hardening-plugin with rule IDs 9530000–9530999 and records its repository, type, test status, CI availability, and license.

Changes

Plugin registry

Layer / File(s) Summary
Register plugin
registry.yaml, registry.json, README.md
Adds the plugin's rule ID range, repository, third-party type, tested status, CI status, and Apache-2.0 license to the registry and README table.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Feature

Suggested labels: release:ignore, :jigsaw: plugin

Merge Risk: ⚪ Minimal · up to e5ea6

The registry entry and generated files are consistent, with no identified merge blocker.

Architecture Summary

Architecture risk: 🔵 Low · up to e5ea6

The change affects 3 systems.

Changed systems: README.md, registry.json, registry.yaml

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — README.md (service) was modified; 1 changed file maps to changed impact.
  • observed — registry.json (service) was modified; 1 changed file maps to changed impact.
  • observed — registry.yaml (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in registry.yaml: Adds the plex-hardening-plugin registry entry with rule ID range 9530000–9530999, its repository, third-party type, tested status, CI enabled, and Apache-2.0 license.
  • observed — Modified behavior in README.md: The registry table now lists plex-hardening-plugin as a tested third-party plugin, with rule IDs 9,530,000–9,530,999, its repository and integration-test badge, and an Apache-2.0 license.
  • observed — Modified behavior in registry.json: The registry adds plex-hardening-plugin with its repository URL, Apache-2.0 license, CI enabled, tested status, third-party type, and rule ID range 9530000–9530999.
🚥 Pre-merge checks | ✅ 16 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Ai Contribution Disclosure ⚠️ Warning ⚠️ WARNING: The PR body omits the required lowercase ## what, ## why, and ## refs sections. The reviewed diff adds a new third-party plugin registration, so this is not an exempt typo, version b… Update the PR body to include concrete lowercase ## what, ## why, and ## refs sections. If AI tools materially assisted, add ## ai disclosure with concrete **tools used** including model and version, **assisted with** describing…
Renovate: Config Present And Valid ⚠️ Warning No Renovate configuration exists in either the PR base or head. The PR changes only README.md, registry.json, and registry.yaml, but the repository-wide absence triggers the check. Checks 1–3 therefor… Add a root renovate.json containing "$schema": "https://docs.renovatebot.com/renovate-schema.json" and an extends array that includes "github>coreruleset/renovate-config".
✅ Passed checks (16 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Regex Assembly Is The Source Of Truth ✅ Passed not applicable: the pull request changes only README.md, registry.json, and registry.yaml. It does not modify an @rx pattern in rules/*.conf or any file under regex-assembly/.
Rule Change Requires Go-Ftw Test Coverage ✅ Passed Passed: not applicable. The pull request changes only README.md, registry.json, and registry.yaml. It does not add or modify SecRule directives in rules/.conf or plugins/.conf, and it does not chang…
Redos Risk & Re2 Compatibility ✅ Passed Not applicable. The pull request changes only README.md, registry.json, and registry.yaml. It does not add or modify a pattern in rules/.conf, regex-assembly/.ra, or tooling code using regexp.MustCo…
False Positive Risk & Existing Coverage ✅ Passed Not applicable. The pull request changes only README.md, registry.yaml, and registry.json. It does not add or modify detection patterns or rules under rules/.conf, plugins/.conf, or regex-assembly/.
Crs Rule Metadata & Id Conventions ✅ Passed Passed: not applicable. The pull request changes only README.md, registry.json, and registry.yaml. It does not add or modify a SecRule in rules/.conf, plugins/.conf, or crs-setup.conf.example.
Rule & Config Breaking Changes ✅ Passed No qualifying breaking change is introduced. The diff adds only the new plugin registration to registry.yaml, registry.json, and the generated README table. It removes no existing entries, changes no …
Owasp Security (Web, Api & Llm) ✅ Passed PASS — The PR changes only registry metadata and its generated README/JSON entry. It adds no runtime web/API/LLM behavior, authorization logic, credentials, cryptography, input handling, network fetch…
Unpinned Dependencies & Actions ✅ Passed Passed — not applicable. The PR changes only README.md, registry.json, and registry.yaml. It does not change a manifest, lockfile, Dockerfile, workflow, or pipeline file covered by this check.
Secrets, Payloads & Pii In Logs ✅ Passed PASS — The pull request changes only registry metadata, a generated README table row, and registry JSON. No changed line emits logs, errors, telemetry, stack traces, request or response data, credenti…
New Dependency Scrutiny ✅ Passed PASS — The authoritative PR diff changes only README.md, registry.yaml, and registry.json. It adds a registry record for plex-hardening-plugin, not an entry in a listed dependency manifest, a new GitH…
Install & Build-Time Code Execution ✅ Passed The pull request changes only README.md, registry.yaml, and registry.json. The added content is registry metadata for plex-hardening-plugin. No installer, shell command, CI workflow, Dockerfile, packa…
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the main change: registering plex-hardening-plugin and its assigned rule ID range 9530000–9530999.
Full details: Ai Contribution Disclosure

Explanation

⚠️ WARNING: The PR body omits the required lowercase ## what, ## why, and ## refs sections. The reviewed diff adds a new third-party plugin registration, so this is not an exempt typo, version bump, or dependency update. No ## ai disclosure section is present. The three reviewed commit messages contain no Co-Authored-By or AI-tool signature line.

Resolution

Update the PR body to include concrete lowercase ## what, ## why, and ## refs sections. If AI tools materially assisted, add ## ai disclosure with concrete **tools used** including model and version, **assisted with** describing the generated work, and **review performed** describing specific verification. Remove any attribution trailer or AI-tool signature if one is added.

Full details: Renovate: Config Present And Valid

Explanation

No Renovate configuration exists in either the PR base or head. The PR changes only README.md, registry.json, and registry.yaml, but the repository-wide absence triggers the check. Checks 1–3 therefore do not pass: the required file, exact $schema value, and shared preset extension are absent.

  • Fix all pre-merge checks with AI

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

chore: regenerate registry outputs
chore: regenerate registry outputs
@davidscarth

davidscarth commented Sep 27, 2026 •

Copy link
Copy Markdown
Author

Regenerated README.md and registry.json from registry.yaml per the drift check (run 7). Workflow runs on the two follow-up commits are awaiting approval.

@davidscarth

Copy link
Copy Markdown
Author

I just saw #40 also requests 9,530,000-9,530,999 (for n8n). Happy to move to 9,531,000-9,531,999 or whatever the next free block is, just let me know. the plugin's IDs are a constant offset from the block base, so renumbering is mechanical.

@azurit

azurit commented Sep 27, 2026

Copy link
Copy Markdown
Member

I suggest to split this into two plugins:

  • exclusions
  • hardening

@davidscarth

davidscarth commented Sep 27, 2026 •

Copy link
Copy Markdown
Author

I suggest to split this into two plugins:

  • exclusions
  • hardening

Thought more about it. I also see a similar pattern for the WordPress plugin. I'm gonna go ahead and split it.

@EsadCetiner

Copy link
Copy Markdown
Member

I'd expect a hardening plugin specifically for plex would work out of the box without any false positives, or make certain hardening options configurable i.e restricting an plex admin panel to only trusted IPs or similar.

You can of course bundle both the rule-exclusions and hardening together, it is your plugin after all but in that case, I'd suggest splitting the plugin files based on rule-exclusions and hardening rules for better readability.

@davidscarth

Copy link
Copy Markdown
Author

Two people telling me to split it up is good enough for me. I have a work in progress split version running locally.

i've also added in the config conf a place to specify exception IPs for the admin endpoints, that makes sense. i plan to have an update out this week.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants