Third-party notices
Clearplane includes the following third-party work. Each section names the source, what Clearplane uses, and the licence text the licence requires Clearplane to reproduce.
OWASP Core Rule Set
Clearplane's shipped WAF rulesets adapt OWASP CRS v4.29.0, commit ab3ccd5fcd691424ba3f320d4040c61417270193, for 517 of their rules and exclusions.
Source: https://github.com/coreruleset/coreruleset/tree/ab3ccd5fcd691424ba3f320d4040c61417270193. Licence: Apache-2.0.
Copyright (c) 2006–2020 Trustwave and contributors. All rights reserved. Copyright (c) 2021–2026 CRS project. All rights reserved. The candidate changes rule representation, splits some rules across stages, and records native-runtime policy adaptations and source identities in conversion provenance. Rules backed by unconfirmed GPL-derived shell lists are omitted and reported.
Each derived rule records the upstream file and line it came from, and carries Apache-2.0 as its own licence, so the attribution travels with the rule — including into an operator's custom ruleset when they copy a rule as a starting point. A draft that takes on such a rule restates its own licence to name the material it now includes.
The CRS exclusion plugins below ship adapted the same way, under the same licence:
| Plugin | Version | Commit |
|---|---|---|
wordpress-rule-exclusions-plugin |
1.2.0 | c97e42a088fbb85b3a59a2ecf686abd9752badf8 |
nextcloud-rule-exclusions-plugin |
1.7.1 | d907a20c7ca9c27d5666185c8ffab58f859d4832 |
phpmyadmin-rule-exclusions-plugin |
1.1.0 | 9769ff0f2192137c2a9d715ad60cfacee9882edc |
The complete upstream licence is available at OWASP CRS licence.
libinjection
Source: https://github.com/libinjection/libinjection, tag v4.0.0, commit 211782219663f889f471650150df12b623c5766e.
Licence: BSD-3-Clause.
Clearplane contains a C# port of libinjection's SQLi and HTML5/XSS algorithms in
Shared/Clearplane.Shared.Servers/src/Waf/Tokenizers/Libinjection/. Its keyword table, fingerprint list
and detection tables ship as WAF ruleset data rather than code. The upstream test vectors are vendored
under Tests/Unit/Clearplane.Tests.Unit.Waf/Fixtures/Libinjection/v4.0.0/. The CRS converter carries the
pinned keyword and fingerprint tables with source hashes and the upstream licence in
Tools/Clearplane.WafCrsConverter/Content/Libinjection/ to include them in generated ruleset drafts.
Copyright (c) 2012-2016, Nick Galbreath
Copyright (c) 2017-2024, libinjection Contributors
All rights reserved.
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions are
met:
1. Redistributions of source code must retain the above copyright
notice, this list of conditions and the following disclaimer.
2. Redistributions in binary form must reproduce the above copyright
notice, this list of conditions and the following disclaimer in the
documentation and/or other materials provided with the distribution.
3. Neither the name of the copyright holder nor the names of its
contributors may be used to endorse or promote products derived from
this software without specific prior written permission.
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
https://github.com/libinjection/libinjection
http://opensource.org/licenses/BSD-3-Clause
CodeMirror
Clearplane bundles CodeMirror 6 and its runtime dependencies for the custom WAF rule editor. Source: https://codemirror.net/. Licence: MIT.
Exact package versions and dependency hashes are recorded in
Clearplane.UI/codemirror/package.json and package-lock.json. Complete copyright and licence texts
for every bundled package are included with the browser asset at
Clearplane.UI/wwwroot/lib/codemirror/LICENSE.
Corvus.JsonSchema
Clearplane uses Corvus.Json.Validator and its code-generation packages, version 5.5.5.
Source: https://github.com/corvus-dotnet/Corvus.JsonSchema, commit 1a6b992ce6b77b209f4a9a6740f0e6a668e5cd15.
Copyright (c) Endjin Limited 2023. All rights reserved. Licence: Apache-2.0.
The runtime adapter uses the public generator APIs with a local-only document resolver, bounded
non-backtracking regex generation and collectible compilation assemblies. The complete licence is
in Shared/Clearplane.Shared.Servers/ThirdParty/Corvus.JsonSchema.LICENSE.txt, copied into Core and Edge publish output.
Microsoft.OpenApi
Core uses Microsoft.OpenApi and Microsoft.OpenApi.YamlReader, version 3.10.2.
Source: https://github.com/microsoft/OpenAPI.NET, commit c3e9fad2fb3191ca0cb96aa4265c65df38ebad67.
Copyright (c) Microsoft Corporation. All rights reserved. Licence: MIT.
The complete licence is in Clearplane.Core/ThirdParty/Microsoft.OpenApi.LICENSE.txt, copied into Core publish output.
OpenTelemetry
Core uses OpenTelemetry.Extensions.Hosting and OpenTelemetry.Exporter.OpenTelemetryProtocol
version 1.18.0, plus OpenTelemetry.Exporter.Prometheus.AspNetCore version 1.18.0-beta.1,
for optional WAF metrics export. Copyright The OpenTelemetry Authors. Licence: Apache-2.0.
Source: https://github.com/open-telemetry/opentelemetry-dotnet, stable commit
9db92a4e978b4ae432183c790259be48a475578f and Prometheus commit
45349c1b2e0ba8e60105e664abf0d0d0c56b6324.
The complete licence is in Clearplane.Core/ThirdParty/OpenTelemetry.LICENSE.txt,
copied into Core publish output.