Hi Vercel team,
I'm reporting a reproducible-looking WAF configuration issue that requires engineering clarification.
Our project initially had no active WAF configuration (active: null).
We successfully created an unpublished draft using the Vercel CLI. However, when we executed a single crs.update PATCH request to disable one CRS category, the API returned HTTP 200 and unexpectedly created an active WAF configuration.
The Audit Log recorded firewall-config-promoted with the same request ID as the PATCH operation.
No publish or activate command was executed.
Vercel Support previously advised that PATCH operations modify only the unpublished draft.
The newly active configuration contains no custom rules or IP blocks. Support has indicated that traffic should remain unaffected on Hobby, but the unexpected promotion still needs investigation.
We need help with:
- Why did the PATCH trigger a promotion?
- How can we safely restore the previous
active: nullstate? - Is this a known issue with first-time WAF configuration initialization?
We have stopped all configuration changes and preserved the Audit Log, configuration diffs and request identifiers.
Our Hobby plan does not allow us to submit a Security → Firewall support case.
Could a Vercel staff member help escalate this to the Firewall Engineering team? I can provide the project ID and full diagnostic evidence privately.
Thank you.