## bytedance/vArmor — v0.10.4…v0.10.5

_36 commits._

### Fixes
- **fix(status): avoid deadlock during periodic status refresh (#406)** (94105eb)
- **fix(networkproxy): override pod security defaults for injected containers (#407)** (97db6c3)
- **fix(auditor): tolerate null audit metadata (#404)** (99ae866)
- **fix(networkproxy): reject empty SecretRef header values (#402)** (2b7bc37)
- **fix(networkproxy): enforce custom HTTP methods and preserve method case (#401)** (7ef25db)
- **fix(networkproxy): reject padded MITM domain references (#400)** (cbc27a7)
- **fix(networkproxy): preserve mapped IPv6 CIDR address ranges (#399)** (d0a34b6)
- **fix(networkproxy): match bare IPv6 destinations as single hosts (#398)** (b342d01)
- **fix(networkproxy): reject equivalent MITM identities (#397)** (eda4455)
- **fix(networkproxy): preserve HTTP and DNS handling for MITM IP targets (#396)** (72742ba)
- **fix(networkproxy): hot-reload MITM certificates and trust bundles via file-based SDS (#395)** (902d016)
- **fix(networkproxy): validate port collisions with effective defaults (#394)** (6acc925)
- **fix(networkproxy): issue IP SANs for single-host CIDRs (#393)** (8711aaa)
- **fix(networkproxy): tolerate LDS updates before CDS (#392)** (62f4df9)
- **fix(networkproxy): preserve literal MITM header values (#391)** (a5544f2)
- **fix(networkproxy): match MITM wildcard hosts with authority ports (#390)** (387124a)
- **fix(networkproxy): match TLS SNI hosts case-insensitively (#389)** (f93b6cb)
- **fix(networkproxy): normalize escaped path separators before RBAC (#388)** (a86d9fb)
- **Fix default port matching in HTTP rules** — Fixed a security issue where HTTP proxy rules for ports 80 and 443 weren't properly matching requests with explicit default ports in the authority header, which could allow unauthorized traffic or incorrectly block allowed traffic. The fix now correctly handles both bare hostnames and hostnames with explicit default ports while maintaining all other rule constraints. (3770093)
- **Fix IPv6 address matching in network rules** — Corrected how IPv6 addresses are formatted and matched in network proxy rules for both MITM (man-in-the-middle) interception and HTTP traffic. IPv6 addresses in brackets (like [::1]) now properly match requests, and rules with explicit ports are preserved correctly, preventing legitimate requests from being incorrectly blocked or rejected. (8683d3f)
- **Network proxy MITM rule handling** — Fixed an issue where Layer 4 (L4) network rules were incorrectly filtered out in MITM (man-in-the-middle) proxy chains, causing some security allow, deny, and audit rules to be skipped. The system now preserves all applicable L4 rules and lets the network engine evaluate them at runtime based on actual destination IP and port information. (2e64fcb)
- **fix(networkproxy): preserve wildcard HTTP rules in MITM chains (#383)** (d1babbf)
- **fix(networkproxy): classify audit events by RBAC outcome (#382)** (c37f786)
- **fix(networkproxy): propagate vArmor namespace to existing workloads (#381)** (85c2aab)
- **fix(processtracer): reset state after stop failure (#380)** (4ca402c)
- **fix(processtracer): synchronize subscriber lifecycle (#378)** (2aa76bd)
- **fix(networkproxy): preserve maximum port range end (#375)** (954e561)

### Backend
- **Prepare for 0.10.5 release (#408)** (d995bdb)
- **Upgrade Nodejs package (#405)** (6818971)
- **HTTP domain matching now case-insensitive** — Fixed a security issue where HTTP host/domain matching treated domain names as case-sensitive, allowing attackers to bypass or break access rules by changing the capitalization of domain names in requests. Domain matching now correctly ignores case for exact matches, prefixes, suffixes, and regex patterns, while preserving case-sensitivity for HTTP methods, paths, and other headers. (2ae21b5)
- **policy: reject removal of immutable proxy config (#369)** (9ff982c)
- **policy: synchronize behavior subscriber registries (#371)** (d175e7f)

### Tests
- **test: fix invalid YAML in performance policies (#377)** (f1e227b)

### Docs
- **docs: correct NetworkProxy resource override path (#373)** (ed16044)

### Chore
- **ci: enforce Mozilla CA bundle verification (#379)** (94aace2)
- **chore(mitm): refresh embedded Mozilla CA bundle (#367)** (88c7b1b)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/bytedance/vArmor?utm_source=github-action)._