-
Notifications
You must be signed in to change notification settings - Fork 709
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add OL into jinja conditionals #12461
Conversation
Add OL into jinja conditionals in the following files: controls/anssi.yml auditd_configure_rules/audit_privileged_commands/audit_rules_privileged_commands_kmod/rule.yml auditing/configure_auditd_data_retention/auditd_audispd_encrypt_sent_records/rule.yml services/obsolete/package_rsync_removed/rule.yml services/rng/service_rngd_enabled/rule.yml system/bootloader-grub2/grub2_kernel_trust_cpu_rng/oval/shared.xml system/logging/log_rotation/ensure_logrotate_activated/oval/shared.xml system/permissions/restrictions/enable_execshield_settings/sysctl_kernel_exec_shield/ansible/shared.yml system/permissions/restrictions/enable_execshield_settings/sysctl_kernel_exec_shield/bash/shared.sh system/permissions/restrictions/enable_execshield_settings/sysctl_kernel_exec_shield/oval/shared.xml system/permissions/restrictions/enable_execshield_settings/sysctl_kernel_exec_shield/rule.yml system/software/sudo/sudo_add_env_reset/rule.yml system/software/sudo/sudo_add_ignore_dot/rule.yml system/software/sudo/sudo_add_passwd_timeout/rule.yml system/software/sudo/sudo_add_umask/rule.yml Remove package_audit-audispd-plugins_installed rule, the package is not available in OL products/ol9/profiles/default.profile Fix word error in sudo_add_ignore_dot rule Signed-off-by: Armando Acosta <[email protected]>
Hi @mrkanon. Thanks for your PR. I'm waiting for a ComplianceAsCode member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
This datastream diff is auto generated by the check Click here to see the full diffNew content has different text for rule 'xccdf_org.ssgproject.content_rule_sudo_add_ignore_dot'.
--- xccdf_org.ssgproject.content_rule_sudo_add_ignore_dot
+++ xccdf_org.ssgproject.content_rule_sudo_add_ignore_dot
@@ -5,7 +5,7 @@
[description]:
The sudo ignore_dot tag, when specified, will ignore the current directory
in the PATH environment variable.
-On Red Hat Enterprise Linux 8, env_reset is enabled by default
+On Red Hat Enterprise Linux 8, ignore_dot is enabled by default
This should be enabled by making sure that the ignore_dot tag exists in
/etc/sudoers configuration file or any sudo configuration snippets
in /etc/sudoers.d/. |
🤖 A k8s content image for this PR is available at: Click here to see how to deploy itIf you alread have Compliance Operator deployed: Otherwise deploy the content and operator together by checking out ComplianceAsCode/compliance-operator and: |
Code Climate has analyzed commit e42c89d and detected 0 issues on this pull request. The test coverage on the diff in this pull request is 100.0% (50% is the threshold). This pull request will bring the total coverage in the repository to 59.5% (0.0% change). View more on Code Climate. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The failing tests about automatus are because debian and ubuntu don't include the rule sysctl_kernel_exec_shield
Description:
Add OL into jinja conditionals in the following files:
controls/anssi.yml
auditd_configure_rules/audit_privileged_commands/audit_rules_privileged_commands_kmod/rule.yml auditing/configure_auditd_data_retention/auditd_audispd_encrypt_sent_records/rule.yml services/obsolete/package_rsync_removed/rule.yml
services/rng/service_rngd_enabled/rule.yml
system/bootloader-grub2/grub2_kernel_trust_cpu_rng/oval/shared.xml system/logging/log_rotation/ensure_logrotate_activated/oval/shared.xml system/permissions/restrictions/enable_execshield_settings/sysctl_kernel_exec_shield/ansible/shared.yml system/permissions/restrictions/enable_execshield_settings/sysctl_kernel_exec_shield/bash/shared.sh system/permissions/restrictions/enable_execshield_settings/sysctl_kernel_exec_shield/oval/shared.xml system/permissions/restrictions/enable_execshield_settings/sysctl_kernel_exec_shield/rule.yml system/software/sudo/sudo_add_env_reset/rule.yml
system/software/sudo/sudo_add_ignore_dot/rule.yml
system/software/sudo/sudo_add_passwd_timeout/rule.yml system/software/sudo/sudo_add_umask/rule.yml
Remove package_audit-audispd-plugins_installed rule, the package is not available in OL products/ol9/profiles/default.profile
Fix word error in sudo_add_ignore_dot rule
Rationale:
Filling OL gaps in jinja conditionals