content
content copied to clipboard
Security automation content in SCAP, Bash, Ansible, and other formats
#### Description: - Implement stig rule UBTU-24-100850 #### Rationale: - UBTU-24-100850 specifies ssh_config instead of sshd_config, so it's not a duplicate
#### Description: - Add pkg override for rule vlock_installed #### Rationale:
#### Description: - _Create slmicro6 product and general profile_ #### Rationale: - _Create slmicro6 product and general profile_
#### Description: - Remove Jinja2 from `var_network_filtering_service.var`,`var_mount_option_proc_hidepid.var`,`var_authselect_profile.var`,`var_audispd_remote_server.var` #### Rationale: - The reason to remove Jinja2 macros is because trestle-bot (and any other external solution processing CaC/content files) fails to process...
#### Description of problem: Failing rules: - sebool_polyinstantiation_enabled - sebool_selinuxuser_execstack - sebool_selinuxuser_execmod #### SCAP Security Guide Version: 95222edc12b4689c6d72115ddc748281427e895e #### Operating System Version: RHEL9, RHEL10 #### Steps to Reproduce: 1. Run...
Rule `ensure_pam_wheel_group_empty` is failing in `anaconda-ostree` and `bootc-image-builder` tests
#### Description of problem: The rule is failing in Image Mode #### SCAP Security Guide Version: 95222edc12b4689c6d72115ddc748281427e895e #### Operating System Version: RHEL10, RHEL9 #### Steps to Reproduce: 1. Run productization...
This PR contains the following updates: | Package | Change | Notes | |---|---|---| | quay.io/konflux-ci/tekton-catalog/task-apply-tags | `0.1` -> `0.2` | :warning:[migration](https://redirect.github.com/redhat-appstudio/build-definitions/blob/main/task/apply-tags/0.2/MIGRATION.md):warning: | | quay.io/konflux-ci/tekton-catalog/task-build-image-index | `37328a4` -> `9c95b1f` |...
#### Description: - Mark UBTU-24-200610 as automated
Hi ComplianceAsCode team, Thank you for your excellent work on SCAP Security Guide and related benchmarks. Are there any plans or timelines for supporting **CIS Level 2 Server benchmarks for...
# Downstream background [Yocto Project](https://www.yoctoproject.org/): > The Yocto Project (YP) is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture. Yocto is...