NGINX Early Hints: HTTP 103 Benchmarked on Enterprise Linux
NGINX early hints support arrived in 1.29.0, but every stock Enterprise Linux, Debian and Ubuntu package still ships something older. We install a current NGINX from GetPageSpeed, configure the safe HTTP/2 gate, and benchmark what HTTP 103 does to LCP with interleaved arms and an A/A noise control.
#Headers, #Http3, #Nginx, #Optimization, #Performance, #Proxy, #RockyLinux
NGINX early hints support arrived in 1.29.0, but every stock Enterprise Linux, Debian and Ubuntu package still ships something older. We install a current NGINX from GetPageSpeed, configure the safe HTTP/2 gate, and benchmark what HTTP 103 does to LCP with interleaved arms and an A/A noise control.
#Headers, #Http3, #Nginx, #Optimization, #Performance, #Proxy, #RockyLinux
π Fresh updates from GetPageSpeed!
- replace
The replace package ships a binary that follows deprecated MySQL's replace syntax.
Did you know? The original MySQL replace syntax was designed to simplify data updates without needing complex queries!
- varnish
This is Varnish Cache, a high-performance HTTP accelerator.
Did you know? Varnish can significantly speed up your website by caching content and reducing server load!
- varnish-devel
Development files for Varnish are included in this package.
Did you know? Varnish is often used by major websites to handle millions of requests per second!
- varnish-docs
This package contains documentation files for Varnish.
Did you know? Comprehensive documentation can help developers optimize their use of Varnish for specific applications!
- varnish-modules
This is a collection of modules ("vmods") extending Varnish VCL used.
Did you know? Varnish modules allow developers to customize caching behavior for different types of content!
- lastversion
- replace
0.0.5-1, 0.0.6-1, 0.0.7-1 released to Amazon Linux 2, Amazon Linux 2023, Enterprise Linux 10, 7, 8, 9, Fedora Linux 43, and SUSE Linux Enterprise 16. The replace package ships a binary that follows deprecated MySQL's replace syntax.
Did you know? The original MySQL replace syntax was designed to simplify data updates without needing complex queries!
- varnish
6.0.18-1 released to Amazon Linux 2, Amazon Linux 2023, Enterprise Linux 10, 7, 8, 9, Fedora Linux 43, and SUSE Linux Enterprise 16. This is Varnish Cache, a high-performance HTTP accelerator.
Did you know? Varnish can significantly speed up your website by caching content and reducing server load!
- varnish-devel
6.0.18-1 released to Amazon Linux 2, Amazon Linux 2023, Enterprise Linux 10, 7, 8, 9, Fedora Linux 43, and SUSE Linux Enterprise 16. Development files for Varnish are included in this package.
Did you know? Varnish is often used by major websites to handle millions of requests per second!
- varnish-docs
6.0.18-1 released to Amazon Linux 2, Amazon Linux 2023, Enterprise Linux 10, 7, 8, 9, Fedora Linux 43, and SUSE Linux Enterprise 16. This package contains documentation files for Varnish.
Did you know? Comprehensive documentation can help developers optimize their use of Varnish for specific applications!
- varnish-modules
6.0.18+0.15.1-1 released to Amazon Linux 2, Amazon Linux 2023, Enterprise Linux 10, 7, 8, 9, Fedora Linux 43, and SUSE Linux Enterprise 16. This is a collection of modules ("vmods") extending Varnish VCL used.
Did you know? Varnish modules allow developers to customize caching behavior for different types of content!
- lastversion
3.6.13-1 released to Amazon Linux 2, Amazon Linux 2023, Enterprise Linux 10, 7, 8, 9, Fedora Linux 43, and SUSENGINX ESI: Replace Varnish for Magento 2
Replace Varnish with NGINX ESI for Magento 2. See the tested configuration, selective X-Magento-Tags purge, gzip-safe stitching, and benchmarks against Varnish OSS.
#Caching, #Magento2, #Nginx, #NGINXModule, #Performance, #Varnish
Replace Varnish with NGINX ESI for Magento 2. See the tested configuration, selective X-Magento-Tags purge, gzip-safe stitching, and benchmarks against Varnish OSS.
#Caching, #Magento2, #Nginx, #NGINXModule, #Performance, #Varnish
π **Fresh updates from GetPageSpeed!**
- **telegram-desktop**
Messaging app focused on speed and security.
Did you know? Telegram's MTProto protocol was designed by the brothers behind the VK social network.
- **shairport-sync**
Emulates an AirPort Express for streaming audio to your devices.
Did you know? Shairport Sync can stream to multiple devices simultaneously, creating a synchronized multi-room audio system.
- **shairport-sync-firewalld**
FirewallD configuration files for shairport-sync.
Did you know? FirewallD is the default firewall manager on RHEL and Fedora, using zones to simplify rule management.
- **nginx-module-esi**
Native Edge Side Includes with per-fragment caching for NGINX.
Did you know? ESI allows you to cache page fragments independently, dramatically improving dynamic page performance.
- **ea-nginx-esi**
Native ESI with parallel fragment fetching for cPanel's EA NGINX.
Did you know? Parallel fragment fetching lets a page assemble multiple cached pieces simultaneously, cutting response times.
- **sw-nginx-module-esi**
Native Edge Side Includes for NGINX with per-fragment caching.
Did you know? This module is built for Software Collections (SCL), letting you run it alongside the system NGINX.
- **nginx-module-cache-purge**
Purge content from FastCGI, proxy, and other caches directly via NGINX.
Did you know? Cache purging is essential for instantly invalidating stale content without restarting NGINX.
- **ea-
- **telegram-desktop**
7.1.1 released to Amazon Linux, Enterprise Linux, Fedora, and SUSE.Messaging app focused on speed and security.
Did you know? Telegram's MTProto protocol was designed by the brothers behind the VK social network.
- **shairport-sync**
5.2.2 released to Amazon Linux, Enterprise Linux, Fedora, and SUSE.Emulates an AirPort Express for streaming audio to your devices.
Did you know? Shairport Sync can stream to multiple devices simultaneously, creating a synchronized multi-room audio system.
- **shairport-sync-firewalld**
5.2.2 released to Amazon Linux, Enterprise Linux, Fedora, and SUSE.FirewallD configuration files for shairport-sync.
Did you know? FirewallD is the default firewall manager on RHEL and Fedora, using zones to simplify rule management.
- **nginx-module-esi**
1.0.0 and 1.0.1 released for NGINX 1.30.4 and 1.31.4 to Amazon Linux, Enterprise Linux, Fedora, and SUSE.Native Edge Side Includes with per-fragment caching for NGINX.
Did you know? ESI allows you to cache page fragments independently, dramatically improving dynamic page performance.
- **ea-nginx-esi**
1.0.0 and 1.0.1 released to Enterprise Linux.Native ESI with parallel fragment fetching for cPanel's EA NGINX.
Did you know? Parallel fragment fetching lets a page assemble multiple cached pieces simultaneously, cutting response times.
- **sw-nginx-module-esi**
1.0.0 and 1.0.1 released to Enterprise Linux.Native Edge Side Includes for NGINX with per-fragment caching.
Did you know? This module is built for Software Collections (SCL), letting you run it alongside the system NGINX.
- **nginx-module-cache-purge**
2.6.0 released for NGINX 1.30.4 and 1.31.4 to Amazon Linux, Enterprise Linux, Fedora, and SUSE.Purge content from FastCGI, proxy, and other caches directly via NGINX.
Did you know? Cache purging is essential for instantly invalidating stale content without restarting NGINX.
- **ea-
π **Fresh updates from GetPageSpeed**
- n98-magerun2
The Swiss army knife for Magento developers, sysadmins, and DevOps β now updated to v10.
Did you know? n98-magerun2 can run over 300 commands, from cache management to database operations, all without leaving your terminal.
- n98-magerun2-completion-bash
Install this package to enable tab-completion of functions and installed commands for n98-magerun2 in Bash.
Did you know? Tab-completion can save you dozens of keystrokes per day β especially when youβre juggling multiple Magento projects.
- n98-magerun2-completion-zsh
Install this package to enable tab-completion of functions and installed commands for n98-magerun2 in Zsh.
Did you know? Zsh completion is even smarter than Bash β it can suggest options based on context, not just command names.
- lua-resty-session
Flexible and secure session library for nginx-module-lua, now updated to 4.2.0.
Did you know? This library supports multiple storage backends (shared dict, Redis, memcached) and is widely used in OpenResty applications.
- lua5.1-resty-session
The same flexible session library, but built specifically for Lua 5.1 environments.
Did you know? Lua 5.1 is still the most widely deployed Lua version β it powers everything from Nginx to game engines.
- firewalld-ipset-aws-v4
Fresh Amazon Web Services IPv4 ranges for your firewalld ipset configuration.
Did you know? AWS publishes its IP ranges as a JSON file β and this package
- n98-magerun2
10.0.1 released to Amazon Linux 2023, Enterprise Linux 8β10, and Fedora 43.The Swiss army knife for Magento developers, sysadmins, and DevOps β now updated to v10.
Did you know? n98-magerun2 can run over 300 commands, from cache management to database operations, all without leaving your terminal.
- n98-magerun2-completion-bash
10.0.1 released to Amazon Linux 2023, Enterprise Linux 8β10, and Fedora 43.Install this package to enable tab-completion of functions and installed commands for n98-magerun2 in Bash.
Did you know? Tab-completion can save you dozens of keystrokes per day β especially when youβre juggling multiple Magento projects.
- n98-magerun2-completion-zsh
10.0.1 released to Amazon Linux 2023, Enterprise Linux 8β10, and Fedora 43.Install this package to enable tab-completion of functions and installed commands for n98-magerun2 in Zsh.
Did you know? Zsh completion is even smarter than Bash β it can suggest options based on context, not just command names.
- lua-resty-session
4.2.0 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43, and SUSE Linux Enterprise 16.Flexible and secure session library for nginx-module-lua, now updated to 4.2.0.
Did you know? This library supports multiple storage backends (shared dict, Redis, memcached) and is widely used in OpenResty applications.
- lua5.1-resty-session
4.2.0 released to Amazon Linux 2023, Enterprise Linux 8β10, and Fedora 43.The same flexible session library, but built specifically for Lua 5.1 environments.
Did you know? Lua 5.1 is still the most widely deployed Lua version β it powers everything from Nginx to game engines.
- firewalld-ipset-aws-v4
20260825 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43, and SUSE Linux Enterprise 16.Fresh Amazon Web Services IPv4 ranges for your firewalld ipset configuration.
Did you know? AWS publishes its IP ranges as a JSON file β and this package
π **Fresh updates from GetPageSpeed!**
A new wave of package updates is now available across our RPM repository. Here's what's new:
---
- **telegram-desktop**
Messaging app focused on speed and security.
Did you know? Telegram's MTProto protocol was designed by the brothers behind the VK social network.
- **n98-magerun2**
The swiss army knife for Magento developers, sysadmins and devops.
Did you know? n98-magerun2 can generate a Magento 2 project from scratch with a single command.
- **n98-magerun2-completion-bash**
Enables tab-completion of functions and installed commands for n98-magerun2.
Did you know? Bash completion can save developers hundreds of keystrokes daily.
- **n98-magerun2-completion-zsh**
Enables tab-completion of functions and installed commands for n98-magerun2 in Zsh.
Did you know? Zsh completion is even more powerful than Bash, supporting fuzzy matching.
- **lua-resty-lmdb**
Safe API for manipulating LMDB databases using nginx-module-lua.
Did you know? LMDB is extremely fast β it can perform over 1 million transactions per second on modern hardware.
- **lua5.1-resty-lmdb**
LMDB bindings for Lua 5.1 with nginx-module-lua.
Did you know? Lua 5.1 remains the most widely used version in embedded environments like OpenResty.
- **firewalld-ipset-aws-v4**
Amazon Web Services IPv4 ranges for firewalld.
Did you know? AWS publishes its IP ranges in JSON format, updated daily.
- **firewalld-ipset-aws-v6**
Amazon Web Services IPv6 ranges for firewalld.
Did you know? AWS IPv6 adoption has grown steadily, with many services now dual-stack.
-
A new wave of package updates is now available across our RPM repository. Here's what's new:
---
- **telegram-desktop**
7.1.3 released to Amazon Linux, Enterprise Linux, Fedora, and SUSE.Messaging app focused on speed and security.
Did you know? Telegram's MTProto protocol was designed by the brothers behind the VK social network.
- **n98-magerun2**
10.0.2 released to Amazon Linux, Enterprise Linux, and Fedora.The swiss army knife for Magento developers, sysadmins and devops.
Did you know? n98-magerun2 can generate a Magento 2 project from scratch with a single command.
- **n98-magerun2-completion-bash**
10.0.2 released to Amazon Linux, Enterprise Linux, and Fedora.Enables tab-completion of functions and installed commands for n98-magerun2.
Did you know? Bash completion can save developers hundreds of keystrokes daily.
- **n98-magerun2-completion-zsh**
10.0.2 released to Amazon Linux, Enterprise Linux, and Fedora.Enables tab-completion of functions and installed commands for n98-magerun2 in Zsh.
Did you know? Zsh completion is even more powerful than Bash, supporting fuzzy matching.
- **lua-resty-lmdb**
1.7.0 released to Amazon Linux, Enterprise Linux, Fedora, and SUSE.Safe API for manipulating LMDB databases using nginx-module-lua.
Did you know? LMDB is extremely fast β it can perform over 1 million transactions per second on modern hardware.
- **lua5.1-resty-lmdb**
1.7.0 released to Amazon Linux, Enterprise Linux, and Fedora.LMDB bindings for Lua 5.1 with nginx-module-lua.
Did you know? Lua 5.1 remains the most widely used version in embedded environments like OpenResty.
- **firewalld-ipset-aws-v4**
20260828 released to Amazon Linux, Enterprise Linux, Fedora, and SUSE.Amazon Web Services IPv4 ranges for firewalld.
Did you know? AWS publishes its IP ranges in JSON format, updated daily.
- **firewalld-ipset-aws-v6**
20260828 released to Amazon Linux, Enterprise Linux, Fedora, and SUSE.Amazon Web Services IPv6 ranges for firewalld.
Did you know? AWS IPv6 adoption has grown steadily, with many services now dual-stack.
-
NGINX Post-Quantum TLS: X25519MLKEM768 with OpenSSL 3.5
Our RPM builds now link OpenSSL 3.5, so hybrid post-quantum key exchange with X25519MLKEM768 works out of the box. Here is how to verify it, the one common hardening directive that silently turns it off, and where Debian and Ubuntu currently stand.
#Cryptography, #Http3, #MlKem, #Nginx, #Openssl, #PostQuantum, #Security, #Tls
Our RPM builds now link OpenSSL 3.5, so hybrid post-quantum key exchange with X25519MLKEM768 works out of the box. Here is how to verify it, the one common hardening directive that silently turns it off, and where Debian and Ubuntu currently stand.
#Cryptography, #Http3, #MlKem, #Nginx, #Openssl, #PostQuantum, #Security, #Tls
NGINX Certificate Compression: RFC 8879 for Every Browser
NGINX certificate compression (RFC 8879) shrinks the TLS handshake by around 20% on every fresh connection, and it takes one directive. The catch is packaging: your distributionβs NGINX is too old to have the directive, and its OpenSSL was built without the brotli algorithm that Chrome is the only browser to ask for. Measured, and with the one directive that stops NGINX from starting.
#Brotli, #Compression, #Nginx, #Openssl, #Performance, #Security, #SSL, #Tls
NGINX certificate compression (RFC 8879) shrinks the TLS handshake by around 20% on every fresh connection, and it takes one directive. The catch is packaging: your distributionβs NGINX is too old to have the directive, and its OpenSSL was built without the brotli algorithm that Chrome is the only browser to ask for. Measured, and with the one directive that stops NGINX from starting.
#Brotli, #Compression, #Nginx, #Openssl, #Performance, #Security, #SSL, #Tls
Post-Quantum NGINX: OpenSSL 3.5 on Debian and Ubuntu
Every Debian and Ubuntu suite we publish now links our ABI-isolated OpenSSL 3.5 LTS build, so post-quantum key exchange, Encrypted Client Hello and TLS certificate compression arrive on DEB too. Ubuntu 20.04βs NGINX no longer links end-of-life OpenSSL 1.1.1.
#Apt, #Debian, #Eol, #Nginx, #Openssl, #PostQuantum, #Security, #Tls, #Ubuntu
Every Debian and Ubuntu suite we publish now links our ABI-isolated OpenSSL 3.5 LTS build, so post-quantum key exchange, Encrypted Client Hello and TLS certificate compression arrive on DEB too. Ubuntu 20.04βs NGINX no longer links end-of-life OpenSSL 1.1.1.
#Apt, #Debian, #Eol, #Nginx, #Openssl, #PostQuantum, #Security, #Tls, #Ubuntu
π **Fresh updates from GetPageSpeed!**
- firewalld-ipset-aws-v4
Amazon Web Services IPv4 ranges, packaged for firewalld ipset use.
Did you know? AWS publishes its IP ranges as a single JSON file, updated daily β perfect for automating firewall rules.
- firewalld-ipset-aws-v6
Amazon Web Services IPv6 ranges for firewalld ipset configuration.
Did you know? IPv6 adoption on AWS has grown steadily, and many services now support dual-stack endpoints by default.
- nginx-iplist-aws-v4
NGINX IP list configuration for AWS IPv4 ranges β ideal for geo- or network-based access control.
Did you know? NGINX can load IP lists from files at runtime, allowing you to update AWS ranges without reloading the server.
- nginx-iplist-aws-v6
NGINX IP list configuration for AWS IPv6 ranges.
Did you know? Using
- libxquic
XQUIC β an open-source implementation of the QUIC protocol developed by Alibaba.
Did you know? QUIC is built on UDP and was originally designed by Google to reduce connection latency compared to TCP+TLS.
- libxquic-devel
Development headers and metadata for building applications against libxquic.
Did you know? QUIC's connection migration feature lets a connection survive
- firewalld-ipset-aws-v4
20260829 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.Amazon Web Services IPv4 ranges, packaged for firewalld ipset use.
Did you know? AWS publishes its IP ranges as a single JSON file, updated daily β perfect for automating firewall rules.
- firewalld-ipset-aws-v6
20260829 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.Amazon Web Services IPv6 ranges for firewalld ipset configuration.
Did you know? IPv6 adoption on AWS has grown steadily, and many services now support dual-stack endpoints by default.
- nginx-iplist-aws-v4
20260829 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.NGINX IP list configuration for AWS IPv4 ranges β ideal for geo- or network-based access control.
Did you know? NGINX can load IP lists from files at runtime, allowing you to update AWS ranges without reloading the server.
- nginx-iplist-aws-v6
20260829 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.NGINX IP list configuration for AWS IPv6 ranges.
Did you know? Using
ngx_http_geo_module, you can map AWS IPs to variables and use them in allow/deny rules or rate limiting.- libxquic
1.9.6 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.XQUIC β an open-source implementation of the QUIC protocol developed by Alibaba.
Did you know? QUIC is built on UDP and was originally designed by Google to reduce connection latency compared to TCP+TLS.
- libxquic-devel
1.9.6 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.Development headers and metadata for building applications against libxquic.
Did you know? QUIC's connection migration feature lets a connection survive
OpenSSL 4.0 for NGINX: Why We Ship 3.5 LTS Instead
OpenSSL 4.0 for NGINX drops out of support in May 2027. OpenSSL 3.5 LTS runs to April 2030 and already does post-quantum key exchange. Here is the arithmetic behind our choice, and the one 4.0 feature worth having.
#Ech, #Lts, #Nginx, #Openssl, #Packaging, #PostQuantum, #Security, #Tls
OpenSSL 4.0 for NGINX drops out of support in May 2027. OpenSSL 3.5 LTS runs to April 2030 and already does post-quantum key exchange. Here is the arithmetic behind our choice, and the one 4.0 feature worth having.
#Ech, #Lts, #Nginx, #Openssl, #Packaging, #PostQuantum, #Security, #Tls
π Fresh updates from GetPageSpeed
- gixy
A static security analyzer for NGINX configurations that helps prevent common misconfigurations and vulnerabilities.
Did you know? Gixy can detect issues like SSRF, host header injection, and CRLF injection before they ever reach production.
- gixy-deep
Installs Gixy together with ReDoctor, enabling optional deep analysis of regular expressions in your NGINX configs.
Did you know? ReDoctor can uncover catastrophic backtracking in regex patterns β a common cause of ReDoS attacks and CPU spikes.
- python3-gixy
Python 3 bindings for the Gixy NGINX security analyzer.
Did you know? Gixy is written in Python and can be easily extended with custom security checks via plugins.
- python36-gixy
Python 3.6 build of Gixy for legacy Enterprise Linux 7 systems.
Did you know? EL7 remains widely used in production, and this build ensures older systems stay protected with the latest NGINX security checks.
- fail2ban-trusted-lists-helper
Exempts any IP found in
Did you know? This helper lets you maintain a single trusted-IP directory β perfect for keeping your monitoring or VPN IPs permanently whitelisted.
- gixy
0.2.52 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SUSE Linux Enterprise 16.A static security analyzer for NGINX configurations that helps prevent common misconfigurations and vulnerabilities.
Did you know? Gixy can detect issues like SSRF, host header injection, and CRLF injection before they ever reach production.
- gixy-deep
0.2.52 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SUSE Linux Enterprise 16.Installs Gixy together with ReDoctor, enabling optional deep analysis of regular expressions in your NGINX configs.
Did you know? ReDoctor can uncover catastrophic backtracking in regex patterns β a common cause of ReDoS attacks and CPU spikes.
- python3-gixy
0.2.52 released to Amazon Linux 2/2023, Enterprise Linux 8β10, Fedora 43/44, and SUSE Linux Enterprise 16.Python 3 bindings for the Gixy NGINX security analyzer.
Did you know? Gixy is written in Python and can be easily extended with custom security checks via plugins.
- python36-gixy
0.2.52 released to Enterprise Linux 7.Python 3.6 build of Gixy for legacy Enterprise Linux 7 systems.
Did you know? EL7 remains widely used in production, and this build ensures older systems stay protected with the latest NGINX security checks.
- fail2ban-trusted-lists-helper
20260602 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SUSE Linux Enterprise 16.Exempts any IP found in
/usr/share/trusted-lists/plain/*.txt from every fail2ban jail.Did you know? This helper lets you maintain a single trusted-IP directory β perfect for keeping your monitoring or VPN IPs permanently whitelisted.
π **Fresh updates from GetPageSpeed**
- **firewalld-ipset-aws-v4**
Amazon Web Services IPv4 ranges for firewalld ipset.
Did you know? Firewalld uses ipsets to efficiently manage thousands of IP addresses without cluttering the main ruleset.
- **firewalld-ipset-aws-v6**
Amazon Web Services IPv6 ranges for firewalld ipset.
Did you know? IPv6 ranges are increasingly critical as AWS expands its dual-stack support across services.
- **nginx-iplist-aws-v4**
NGINX IP list configuration for AWS IPv4 ranges.
Did you know? NGINX can use geo/allow lists to restrict access by cloud provider IP ranges, a common trick for API security.
- **nginx-iplist-aws-v6**
NGINX IP list configuration for AWS IPv6 ranges.
Did you know? Combining v4 and v6 lists ensures full coverage as more clients adopt IPv6.
- **aws-lc**
AWS-LC is a general-purpose cryptographic library maintained by the AWS Cryptography team.
Did you know? AWS-LC is a fork of BoringSSL, optimized for AWS workloads and used in services like S3 and CloudFront.
- **aws-lc-devel**
Headers and pkg-config files for building software against AWS-LC.
Did you know? The devel package is essential for compiling applications that link against AWS-LC, ensuring ABI compatibility.
- **aws-lc-libs**
- **firewalld-ipset-aws-v4**
20260901 released to Amazon Linux 2 & 2023, Enterprise Linux 7β10, Fedora 43 & 44, and SUSE Linux Enterprise 16.Amazon Web Services IPv4 ranges for firewalld ipset.
Did you know? Firewalld uses ipsets to efficiently manage thousands of IP addresses without cluttering the main ruleset.
- **firewalld-ipset-aws-v6**
20260901 released to Amazon Linux 2 & 2023, Enterprise Linux 7β10, Fedora 43 & 44, and SUSE Linux Enterprise 16.Amazon Web Services IPv6 ranges for firewalld ipset.
Did you know? IPv6 ranges are increasingly critical as AWS expands its dual-stack support across services.
- **nginx-iplist-aws-v4**
20260901 released to Amazon Linux 2 & 2023, Enterprise Linux 7β10, Fedora 43 & 44, and SUSE Linux Enterprise 16.NGINX IP list configuration for AWS IPv4 ranges.
Did you know? NGINX can use geo/allow lists to restrict access by cloud provider IP ranges, a common trick for API security.
- **nginx-iplist-aws-v6**
20260901 released to Amazon Linux 2 & 2023, Enterprise Linux 7β10, Fedora 43 & 44, and SUSE Linux Enterprise 16.NGINX IP list configuration for AWS IPv6 ranges.
Did you know? Combining v4 and v6 lists ensures full coverage as more clients adopt IPv6.
- **aws-lc**
5.7.0 released to Amazon Linux 2 & 2023, Enterprise Linux 7β10, Fedora 43 & 44, and SUSE Linux Enterprise 16.AWS-LC is a general-purpose cryptographic library maintained by the AWS Cryptography team.
Did you know? AWS-LC is a fork of BoringSSL, optimized for AWS workloads and used in services like S3 and CloudFront.
- **aws-lc-devel**
5.7.0 released to Amazon Linux 2 & 2023, Enterprise Linux 7β10, Fedora 43 & 44, and SUSE Linux Enterprise 16.Headers and pkg-config files for building software against AWS-LC.
Did you know? The devel package is essential for compiling applications that link against AWS-LC, ensuring ABI compatibility.
- **aws-lc-libs**
5.7.0 released tozstd-nginx-module: Maintained, Tested and Packaged
The canonical Zstandard module for NGINX has had no release since 2023. We continue it: the streaming bugs that truncated large responses are fixed and regression-tested, and it ships as nginx-module-zstd on every distribution we build for.
#Compression, #Http, #Nginx, #Packaging, #Testing, #Zstd
The canonical Zstandard module for NGINX has had no release since 2023. We continue it: the streaming bugs that truncated large responses are fixed and regression-tested, and it ships as nginx-module-zstd on every distribution we build for.
#Compression, #Http, #Nginx, #Packaging, #Testing, #Zstd
π1
π **Fresh updates from GetPageSpeed**
- freenginx
Freenginx is an HTTP and reverse proxy server, as well as a mail proxy server.
Did you know? Freenginx is a community-driven fork of nginx created by its original author, Igor Sysoev.
- freenginx-ech
Provides key generation and rotation for Encrypted Client Hello (ECH, RFC 9849).
Did you know? ECH encrypts the full TLS handshake, hiding the requested hostname from network observers.
- firewalld-ipset-aws-v6
Provides Amazon Web Services IPv6 ranges for firewalld ipset use.
Did you know? AWS publishes its IP ranges in JSON format, updated daily.
- firewalld-ipset-googlebot-v4/v6
Provides Google Search crawler (Googlebot) IP ranges for firewalld.
Did you know? Googlebot respects robots.txt, but verifying its IP addresses helps prevent fake crawler traffic.
- firewalld-ipset-google-special-crawlers-v4/v6
Provides Google special-case crawlers (AdsBot, etc.) IP ranges for firewalld.
Did you know? AdsBot checks ad landing page quality, separate from regular search indexing.
- firewalld-ipset-google-user-fetchers-v4/v6
Provides Google user-triggered fetchers IP ranges for firewalld.
Did you know? Google user-triggered fetchers include requests from Google's cache refresh and URL inspection tools.
- firewalld-ipset-google-v4/v6
Combined Google crawler IP ranges (Googlebot, special-crawlers, user-fetchers) for firewalld.
Did you know? Google's crawler IP space is shared with other Google services, so always verify with reverse
- freenginx
1.31.4 released to Amazon Linux, Enterprise Linux, Fedora, and SUSE.Freenginx is an HTTP and reverse proxy server, as well as a mail proxy server.
Did you know? Freenginx is a community-driven fork of nginx created by its original author, Igor Sysoev.
- freenginx-ech
1.31.4 released to Amazon Linux, Enterprise Linux, Fedora, and SUSE.Provides key generation and rotation for Encrypted Client Hello (ECH, RFC 9849).
Did you know? ECH encrypts the full TLS handshake, hiding the requested hostname from network observers.
- firewalld-ipset-aws-v6
20260902 released to Amazon Linux, Enterprise Linux, Fedora, and SUSE.Provides Amazon Web Services IPv6 ranges for firewalld ipset use.
Did you know? AWS publishes its IP ranges in JSON format, updated daily.
- firewalld-ipset-googlebot-v4/v6
20260902 released to Amazon Linux, Enterprise Linux, Fedora, and SUSE.Provides Google Search crawler (Googlebot) IP ranges for firewalld.
Did you know? Googlebot respects robots.txt, but verifying its IP addresses helps prevent fake crawler traffic.
- firewalld-ipset-google-special-crawlers-v4/v6
20260902 released to Amazon Linux, Enterprise Linux, Fedora, and SUSE.Provides Google special-case crawlers (AdsBot, etc.) IP ranges for firewalld.
Did you know? AdsBot checks ad landing page quality, separate from regular search indexing.
- firewalld-ipset-google-user-fetchers-v4/v6
20260902 released to Amazon Linux, Enterprise Linux, Fedora, and SUSE.Provides Google user-triggered fetchers IP ranges for firewalld.
Did you know? Google user-triggered fetchers include requests from Google's cache refresh and URL inspection tools.
- firewalld-ipset-google-v4/v6
20260902 released to Amazon Linux, Enterprise Linux, Fedora, and SUSE.Combined Google crawler IP ranges (Googlebot, special-crawlers, user-fetchers) for firewalld.
Did you know? Google's crawler IP space is shared with other Google services, so always verify with reverse
π **Fresh updates from GetPageSpeed**
- **nginx**
High-performance HTTP and reverse proxy server.
Did you know? NGINX was created by Igor Sysoev and first released in 2004 to solve the C10K problem.
- **nginx-ech**
Key generation and rotation for Encrypted Client Hello (ECH, RFC 9849).
Did you know? ECH encrypts the entire TLS handshake, hiding the Server Name Indication (SNI) from network observers.
- **telegram-desktop**
Official Telegram messaging app for Linux desktop.
Did you know? Telegram's MTProto protocol was designed by Nikolai Durov, brother of founder Pavel Durov.
- **nginx-module-media-framework**
Distributed framework for live video streaming.
Did you know? This module supports adaptive bitrate streaming, letting viewers automatically get the best quality for their connection.
- **nginx-module-brotli**
Brotli compression dynamic modules for NGINX.
Did you know? Brotli was developed by Google and can compress text up to 20% better than gzip.
- **nginx-module-waf**
Web application firewall module for NGINX.
Did you know? A WAF can block SQL injection, XSS, and other OWASP Top 10 attacks before they reach your application.
- **nginx-module-security**
- **nginx**
1.31.5 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.High-performance HTTP and reverse proxy server.
Did you know? NGINX was created by Igor Sysoev and first released in 2004 to solve the C10K problem.
- **nginx-ech**
1.31.5 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.Key generation and rotation for Encrypted Client Hello (ECH, RFC 9849).
Did you know? ECH encrypts the entire TLS handshake, hiding the Server Name Indication (SNI) from network observers.
- **telegram-desktop**
7.1.5 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.Official Telegram messaging app for Linux desktop.
Did you know? Telegram's MTProto protocol was designed by Nikolai Durov, brother of founder Pavel Durov.
- **nginx-module-media-framework**
1.31.5+2.1.0 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.Distributed framework for live video streaming.
Did you know? This module supports adaptive bitrate streaming, letting viewers automatically get the best quality for their connection.
- **nginx-module-brotli**
1.31.5+0.1.4 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.Brotli compression dynamic modules for NGINX.
Did you know? Brotli was developed by Google and can compress text up to 20% better than gzip.
- **nginx-module-waf**
1.31.5+6.1.10 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.Web application firewall module for NGINX.
Did you know? A WAF can block SQL injection, XSS, and other OWASP Top 10 attacks before they reach your application.
- **nginx-module-security**
1.31.5+1.0.4 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLπ **Fresh updates from GetPageSpeed**
- nginx
High-performance HTTP and reverse proxy server.
Did you know? nginx is used by over 30% of the world's busiest websites.
- nginx-ech
Key generation and rotation for Encrypted Client Hello (ECH, RFC 9849).
Did you know? ECH encrypts the SNI field, preventing ISPs from seeing which website you visit.
- freenginx
Community-driven fork of nginx, focused on openness and transparency.
Did you know? freenginx was created by nginx's original author, Igor Sysoev.
- freenginx-ech
ECH key generation and rotation for freenginx.
Did you know? ECH is a successor to TLS 1.3's encrypted handshake extensions.
- firewalld-ipset-aws-v4
Amazon Web Services IPv4 ranges for firewalld.
Did you know? AWS publishes its IP ranges as a JSON file, updated daily.
- firewalld-ipset-aws-v6
Amazon Web Services IPv6 ranges for firewalld.
Did you know? IPv6 adoption continues to grow, with AWS supporting dual-stack networking.
- nginx-iplist-aws-v4
NGINX IP list configuration for AWS IPv4 ranges.
Did
- nginx
1.31.5 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.High-performance HTTP and reverse proxy server.
Did you know? nginx is used by over 30% of the world's busiest websites.
- nginx-ech
1.31.5 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.Key generation and rotation for Encrypted Client Hello (ECH, RFC 9849).
Did you know? ECH encrypts the SNI field, preventing ISPs from seeing which website you visit.
- freenginx
1.31.4 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.Community-driven fork of nginx, focused on openness and transparency.
Did you know? freenginx was created by nginx's original author, Igor Sysoev.
- freenginx-ech
1.31.4 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.ECH key generation and rotation for freenginx.
Did you know? ECH is a successor to TLS 1.3's encrypted handshake extensions.
- firewalld-ipset-aws-v4
20260904 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.Amazon Web Services IPv4 ranges for firewalld.
Did you know? AWS publishes its IP ranges as a JSON file, updated daily.
- firewalld-ipset-aws-v6
20260904 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.Amazon Web Services IPv6 ranges for firewalld.
Did you know? IPv6 adoption continues to grow, with AWS supporting dual-stack networking.
- nginx-iplist-aws-v4
20260904 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SLES 16.NGINX IP list configuration for AWS IPv4 ranges.
Did
π **Fresh updates from GetPageSpeed**
- telegram-desktop
A messaging app focused on speed and security.
Did you know? Telegram's MTProto protocol was designed by the brothers Nikolai and Pavel Durov, with security audits by independent experts.
- gvisor
An application kernel written in Go that provides a secure sandbox for running untrusted code.
Did you know? gVisor runs in userspace, intercepting syscalls without needing hardware virtualization, making it lightweight and portable.
- shairport-sync
Emulates an AirPort Express to stream audio from Apple devices to your Linux box.
Did you know? Shairport-Sync can output to multiple devices simultaneously, including AirPlay 1 and 2, plus legacy AirTunes.
- shairport-sync-firewalld
FirewallD integration files for Shairport Sync.
Did you know? This package ensures your firewall doesn't block AirPlay traffic, so your speakers just work.
- sw-nginx-module-lua
Embeds Lua scripting power directly into Nginx HTTP servers.
Did you know? With ngx_lua, you can write complex request handling logic in Lua without leaving your Nginx config.
- sw-nginx-module-array-var
Adds array-typed variable support to Nginx configuration files.
Did you know? This module lets you iterate over lists in Nginx, making configs far more dynamic.
- sw-nginx-module-captcha
Generates and validates CAPT
- telegram-desktop
7.2.5 released to Amazon Linux 2/2023, Enterprise Linux 7β10, Fedora 43/44, and SUSE Linux Enterprise 16.A messaging app focused on speed and security.
Did you know? Telegram's MTProto protocol was designed by the brothers Nikolai and Pavel Durov, with security audits by independent experts.
- gvisor
20260831.0 released to Amazon Linux 2023, Enterprise Linux 8β10, and Fedora 43/44.An application kernel written in Go that provides a secure sandbox for running untrusted code.
Did you know? gVisor runs in userspace, intercepting syscalls without needing hardware virtualization, making it lightweight and portable.
- shairport-sync
5.5 released to Amazon Linux 2023, Enterprise Linux 7β10, Fedora 43/44, and SUSE Linux Enterprise 16.Emulates an AirPort Express to stream audio from Apple devices to your Linux box.
Did you know? Shairport-Sync can output to multiple devices simultaneously, including AirPlay 1 and 2, plus legacy AirTunes.
- shairport-sync-firewalld
5.5 released to Amazon Linux 2023, Enterprise Linux 7β10, Fedora 43/44, and SUSE Linux Enterprise 16.FirewallD integration files for Shairport Sync.
Did you know? This package ensures your firewall doesn't block AirPlay traffic, so your speakers just work.
- sw-nginx-module-lua
1.30.4+0.10.31+0.3.4 released to Enterprise Linux 7β9.Embeds Lua scripting power directly into Nginx HTTP servers.
Did you know? With ngx_lua, you can write complex request handling logic in Lua without leaving your Nginx config.
- sw-nginx-module-array-var
1.30.4+0.6+0.3.4 released to Enterprise Linux 7β9.Adds array-typed variable support to Nginx configuration files.
Did you know? This module lets you iterate over lists in Nginx, making configs far more dynamic.
- sw-nginx-module-captcha
1.30.4+0.0.1 released to Enterprise Linux 7β9.Generates and validates CAPT
NGINX RADIUS Authentication: No More htpasswd Files
Stock NGINX cannot talk to RADIUS. The nginx-module-auth-radius package adds RFC 2865 authentication with multi-server failover, verified end to end against FreeRADIUS, including the BlastRADIUS compatibility gotcha.
#Authentication, #NginxModules, #Radius, #Security
Stock NGINX cannot talk to RADIUS. The nginx-module-auth-radius package adds RFC 2865 authentication with multi-server failover, verified end to end against FreeRADIUS, including the BlastRADIUS compatibility gotcha.
#Authentication, #NginxModules, #Radius, #Security
NGINX TLS Vulnerability Fixes: BREACH, SWEET32, ROBOT
One directive, ssl_protocols TLSv1.3;, eliminates ROBOT, SWEET32 and Lucky13 outright. BREACH survives in HTTP compression and needs a scoped gzip off. Every fix runtime-tested, plus the post-quantum step beyond.
#ContentShapeError, #TargetTierPro, #Tls
One directive, ssl_protocols TLSv1.3;, eliminates ROBOT, SWEET32 and Lucky13 outright. BREACH survives in HTTP compression and needs a scoped gzip off. Every fix runtime-tested, plus the post-quantum step beyond.
#ContentShapeError, #TargetTierPro, #Tls
NGINX proxy_pass: URI Rewriting, Variables, and DNS Gotchas
The exact proxy_pass URI rewriting rules, variable resolution gotchas, and three verified ways to fix NGINXβs frozen-DNS problem, including the upstream-jdomain module.
#Dns, #Nginx, #ProxyPass, #ReverseProxy, #Upstream
The exact proxy_pass URI rewriting rules, variable resolution gotchas, and three verified ways to fix NGINXβs frozen-DNS problem, including the upstream-jdomain module.
#Dns, #Nginx, #ProxyPass, #ReverseProxy, #Upstream
π1