linux-baseline
linux-baseline copied to clipboard
Test verification for package removal
We need to test a default setting for package removal, since the current state my be a little bit confusing for hardening implementors. See the following discussions:
- https://github.com/hardening-io/chef-os-hardening/pull/12
- https://github.com/hardening-io/ansible-os-hardening/pull/30
Currently, we decided to set the default for package removal to true:
default[:security][:packages][:clean] = true
Isn't this done here, or do I not understand the issue? https://github.com/hardening-io/tests-os-hardening/blob/master/lockdown/inspec/package_spec.rb