Gixy-Next has been introduced, a fork of Gixy-ng, stripped of AI-generated changes.

The first release of the Gixy-Next project has been presented, developing a static analyzer for Nginx configuration files that identifies problematic settings negatively affecting security and performance. The project is led by Joshua Rogers, who discovered 55 vulnerabilities in the Squid proxy server several years ago. Gixy-Next was created as a fork of the Gixy-ng project, which continued the development of the Gixy toolkit, opened by Yandex in 2017 and not updated for the past two years.

The reason for creating the new fork is dissatisfaction with the actions of the maintainer of the Gixy-ng project, who allegedly misuses AI tools in development. The fork was created after automatically generated changes began to be added to the repository, which underwent insufficient review and led to regressions and altered behavior of the toolkit. The code started to include meaningless artifacts from AI application and functions that did not perform as they should. For instance, inflated fixes occupying thousands of lines were introduced that could have been replaced with a 10-line patch. Moreover, advertising was added to the documentation and built-in hints, and external pull requests were accepted while omitting author information.

Gixy-Next has been introduced, a fork of Gixy-ng, stripped of AI-generated changes.

In Gixy-Next, the codebase has been cleaned of the junk changes created by AI, bugs have been fixed, testing has been established on large NGINX configuration files, and modifications have been added to simplify the maintenance of the codebase. Among the new features of Gixy-Next compared to the original Gixy, the following are noted:

  • 19 new plugins that check the correctness of settings related to access control, DNS, proxying, and regular expressions, as well as identify settings that lead to additional overhead and reduced performance.

    Among the added plugins are: allow_without_deny, return_bypasses_allow_deny, proxy_pass_normalized, merge_slashes_on, resolver_external, stale_dns_cache, version_disclosure, invalid_regex, regex_redos, add_header_content_type, add_header_multiline, add_header_redefinition, default_server_flag, error_log_off, hash_without_default, if_is_evil, try_files_is_evil_too, unanchored_regex, low_keepalive_requests, worker_rlimit_nofile_vs_connections, proxy_buffering_off.

  • Standardized and reproducible output reports, suitable for automated parsing.
  • Support for map and geo modules.
  • Upgrade of plugins origins, ssrf, http_splitting, alias_traversal, and valid_referers to reduce false positives and more accurately detect issues.
  • Proper handling of additional configuration files included via the 'include' directive.
  • Improved verification of regular expressions.
  • Ability to build an Online scanner that functions within a browser.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster