artifacts/artifacts.spec

80 lines
2.7 KiB
RPMSpec

#
# spec file for package artifacts
#
# Copyright (c) 2018 SUSE LINUX GmbH, Nuernberg, Germany.
#
# All modifications and additions to the file contributed by third parties
# remain the property of their copyright owners, unless otherwise agreed
# upon. The license for this file, and modifications and additions to the
# file, is the same license as for the pristine package itself (unless the
# license for the pristine package is not an Open Source License, in which
# case the license is the MIT License). An "Open Source License" is a
# license that conforms to the Open Source Definition (Version 1.9)
# published by the Open Source Initiative.
# Please submit bugfixes or comments via http://bugs.opensuse.org/
#
%define timestamp 20180628
Name: artifacts
Version: %{timestamp}
Release: 0
Summary: Digital Forensics Artifact Repository
License: Apache-2.0
Group: Productivity/Security
URL: https://github.com/ForensicArtifacts/artifacts/wiki
Source0: https://github.com/ForensicArtifacts/artifacts/releases/download/%{timestamp}/artifacts-%{timestamp}.tar.gz
Source1: https://github.com/ForensicArtifacts/artifacts/releases/download/%{timestamp}/artifacts-%{timestamp}.tar.gz.asc
# Key 0xD9625E5D7AD0177E by Joachim Metz https://github.com/joachimmetz
Source2: %{name}.keyring
BuildArch: noarch
%description
A community-sourced, machine-readable knowledge base of forensic
artifacts that can be used both as an information source and within
other tools.
Using artifacts in tools just requires reading YAML. (The Python code
in the project is merely used to validate that the artifacts follow
the specification.)
For some background on the artifacts system and how its developers
expect it to be used, see the BlackHat presentation and Youtube video
from the GRR team.
%package validator
Summary: Digital Forensics Artifact Repository Validator
Group: Productivity/Security
BuildRequires: python-setuptools
Requires: artifacts
%description validator
Python modules and program to validate the artifact data. It is
possible for programs to directly call these Python modules, but, by
design, said programs should work directly with the YAML files
themselves and not use these Python modules.
%prep
%setup -q -n artifacts-%{timestamp}
%build
python setup.py build
%install
python setup.py install --root=%{buildroot} --prefix=%{_prefix}
%files
%license LICENSE
%doc ACKNOWLEDGEMENTS AUTHORS README
%{_datadir}/artifacts
%files validator
%license LICENSE
%{python_sitelib}/artifacts-%{timestamp}-py2.7.egg-info
%{python_sitelib}/artifacts
%{_bindir}/validator.py
%{_bindir}/stats.py
%changelog