content
content copied to clipboard
Security automation content in SCAP, Bash, Ansible, and other formats
This PR contains the following updates: | Package | Change | |---|---| | quay.io/konflux-ci/tekton-catalog/task-clair-scan | `8ec7d7b` -> `ee558db` | | quay.io/konflux-ci/tekton-catalog/task-git-clone-oci-ta | `ea64f5b` -> `0a89e1a` | | quay.io/konflux-ci/tekton-catalog/task-init | `4072de8`...
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | quay.io/konflux-ci/konflux-vanguard/task-rpms-signature-scan | tekton-bundle | digest | `13cf619` -> `90c2b32` | --- ### Configuration...
#### Description: - Add ATEX testing to the upstream CI workflows - It posts the resulting tests link as a comment to the pull request when it finishes. #### Rationale:...
#### Description: - enhance test scenarios so that they account for cases when there exists / does not exist Authselect - improve Ansible remediation so that it is aligned with...
#### Description: * Add three new rules for RHEL 10 CIS 1.4.2. #### Rationale: Update the rules to match upstream.
#### Description: - add debian support for audit_rules_networkconfig_modification #### Rationale: - Debian based OS don't have an /etc/sysconfig directory. #### Review Hints: - Debian OVAL check file is a symlink...
#### Description of problem: Test `service_disabled.fail` for rule `service_systemd-journal-upload_enabled` fails #### SCAP Security Guide Version: 1144a738d7cbe8f82f810dc6aac00b26b7b25ab9 #### Operating System Version: 10.1 #### Steps to Reproduce: 1. Run automatus tests for...
This commit introduces new rule `group_server_with_gui_removed` and adds it to CIS profile according to RHEL 10 CIS Benchmark v1.0.1, requirement 2.1.19. Although the requirement title suggests to remove only the...
#### Description: - Add a repo file so that `rpms.lock.file` can be properly maintained. #### Rationale: - MintMaker requires a repo file to keep rpms.lock.yaml up to date. The repo...
Sponsored by 21Software #### Description of problem: `audit-rules.service` fails when using the `audit_rules_file_deletion_events` rule group on `Raspberry Pi 5`: ```bash root@raspberrypi5:~# systemctl list-units --state=failed UNIT LOAD ACTIVE SUB DESCRIPTION *...