secubox-cve-triage (1.1.0-1~bookworm1) bookworm; urgency=medium * WAF product-absent rule generator (closes #875). Turns vendored Nuclei templates into detect-mode WAF rules fingerprinting scanners that probe for products this box does not run (F5/PAN-OS/Ivanti). Zero false positives by construction: appliance-family allowlist AND absence from the presence union (dpkg + WAF-routed vhosts + secubox modules), fail-safe present-in-doubt. * CLI secubox-cvectl waf-rules generate (dry-run by default, --apply writes). * Panel tab + JWT routes GET /waf-rules (preview) and POST /waf-rules/generate. * Ships a vendored Nuclei subset (MIT) and an offline curation script. * Depends: python3-yaml. -- Gerald KERMA Fri, 18 Jul 2026 08:00:00 +0200 secubox-cve-triage (1.0.1-1~bookworm2) bookworm; urgency=medium * webui: hybrid-dark cyan reskin (WebUI Panel Guidelines) baked into the package. -- Gerald KERMA Thu, 10 Jul 2026 10:00:00 +0200 secubox-cve-triage (1.0.1-1~bookworm1) bookworm; urgency=low * Rewrite Description to identify this as the CVE vulnerability triage workflow and disambiguate from the other six threats-cluster packages (closes #383, part of dns/threats naming-clarity pass) * Maintainer corrected to Gerald KERMA -- Gerald KERMA Wed, 27 May 2026 12:00:00 +0000 secubox-cve-triage (1.0.0-1~bookworm1) bookworm; urgency=medium * Initial release -- SecuBox Fri, 27 Mar 2026 08:57:14 +0100