Compare commits

..

305 Commits

Author SHA256 Message Date
Ana Guerrero
95db74dba9 Accepting request 1236117 from security
- update to 1.4.1 (forwarded request 1236107 from abergmann)

OBS-URL: https://build.opensuse.org/request/show/1236117
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=89
2025-01-09 14:12:05 +00:00
Ana Guerrero
52f9c14241 Accepting request 1201408 from security
- disable sendmail buildrequires (seems unused)
- only use distribution-release to make work everywhere (forwarded request 1201407 from msmeissn)

OBS-URL: https://build.opensuse.org/request/show/1201408
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=88
2024-09-16 15:45:54 +00:00
2373f3a69a - disable sendmail buildrequires (seems unused)
- only use distribution-release to make work everywhere

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=295
2024-09-16 11:54:56 +00:00
Ana Guerrero
b25bde19dc Accepting request 1172088 from security
OBS-URL: https://build.opensuse.org/request/show/1172088
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=87
2024-05-06 15:53:23 +00:00
Wolfgang Frisch
40749d1a9c Accepting request 1171991 from home:msmeissn:branches:security
- 0001-Add-openSUSE-cpe-links.patch: added Leap 15.6

OBS-URL: https://build.opensuse.org/request/show/1171991
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=293
2024-05-06 07:39:11 +00:00
743af7f47b Accepting request 1159922 from home:michals
Cherry-pick SLE change.

- Rename oscap-docker to oscap-containers and provide oscap-podman as well
  (Relates to jsc#SLE-12852)

OBS-URL: https://build.opensuse.org/request/show/1159922
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=292
2024-05-05 14:47:35 +00:00
Dominique Leuenberger
de898fdea5 Accepting request 1159808 from security
openscap 1.3.10 (forwarded request 1159796 from rfrohl)

OBS-URL: https://build.opensuse.org/request/show/1159808
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=86
2024-03-20 20:18:25 +00:00
dead0955af Accepting request 1159796 from home:rfrohl:branches:security
openscap 1.3.10

OBS-URL: https://build.opensuse.org/request/show/1159796
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=290
2024-03-20 10:02:14 +00:00
Dominique Leuenberger
1be5a5c9a3 Accepting request 1153358 from security
OBS-URL: https://build.opensuse.org/request/show/1153358
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=85
2024-02-29 20:51:35 +00:00
Wolfgang Frisch
7f0764d69d Accepting request 1153020 from home:jaimeMF:branches:security
- Use the correct documentation's path.

OBS-URL: https://build.opensuse.org/request/show/1153020
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=288
2024-02-29 14:59:41 +00:00
Ana Guerrero
454ac23d76 Accepting request 1112946 from security
openscap 1.3.9 (forwarded request 1112900 from AndreasStieger)

OBS-URL: https://build.opensuse.org/request/show/1112946
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=84
2023-09-22 19:49:41 +00:00
10b9f1885e Accepting request 1112900 from home:AndreasStieger:branches:security
openscap 1.3.9

OBS-URL: https://build.opensuse.org/request/show/1112900
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=286
2023-09-22 07:09:26 +00:00
Dominique Leuenberger
13e1b83126 Accepting request 1094327 from security
openscap 1.3.8 (forwarded request 1094324 from rfrohl)

OBS-URL: https://build.opensuse.org/request/show/1094327
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=83
2023-06-21 20:40:15 +00:00
cde8ef6ae9 Accepting request 1094324 from home:rfrohl:branches:security
openscap 1.3.8

OBS-URL: https://build.opensuse.org/request/show/1094324
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=284
2023-06-21 09:18:16 +00:00
Dominique Leuenberger
aa92ace405 Accepting request 1075297 from security
- remove _service confusion, we use final tarballs.

- Update to version 1.3.7:
  * openscap-1.3.7
  * Bump soname from 25.5.0 to 25.5.1
  * Bump version to openscap-1.3.7
  * Fix typos in docs
  * Remove a check for suspicious files
  * Add debian_evr_string tests to CMakeLists
  * Add a few unittests for debian_evr_string
  * Remove To be done
  * Move release guide to upstream
- add 0005-rename-requires-reqs-for-C-20-compatibility.patch
- rename patches
  openscap-opensuse-cpe.patch to 0001-Add-openSUSE-cpe-links.patch
  openscap-suse-cpe.patch to 0002-Add-SUSE-cpe-links.patch
  openscap-docker-add-suse.patch to 0003-Use-openSUSE-SUSE-cpe-links.patch
  oscap-remediate.service.in.patch to 0004-oscap-remediate-is-located-in-bindir.patch
- drop 0001-Use-correct-includes.patch (upstream)

OBS-URL: https://build.opensuse.org/request/show/1075297
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=82
2023-04-04 19:17:50 +00:00
19f9eddb36 - remove _service confusion, we use final tarballs.
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=282
2023-03-29 15:23:18 +00:00
0aea1b618f Accepting request 1075011 from home:kwk:branches:security
- Update to version 1.3.7:
  * openscap-1.3.7
  * Bump soname from 25.5.0 to 25.5.1
  * Bump version to openscap-1.3.7
  * Fix typos in docs
  * Remove a check for suspicious files
  * Add debian_evr_string tests to CMakeLists
  * Add a few unittests for debian_evr_string
  * Remove To be done
  * Move release guide to upstream
- add 0005-rename-requires-reqs-for-C-20-compatibility.patch
- rename patches
  openscap-opensuse-cpe.patch to 0001-Add-openSUSE-cpe-links.patch
  openscap-suse-cpe.patch to 0002-Add-SUSE-cpe-links.patch
  openscap-docker-add-suse.patch to 0003-Use-openSUSE-SUSE-cpe-links.patch
  oscap-remediate.service.in.patch to 0004-oscap-remediate-is-located-in-bindir.patch
- drop 0001-Use-correct-includes.patch (upstream)

OBS-URL: https://build.opensuse.org/request/show/1075011
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=281
2023-03-28 15:25:19 +00:00
Dominique Leuenberger
ea253578fa Accepting request 1060355 from security
- Require systemd for building, was pulled in before by indirect
  dependencies which don't exist anymore (forwarded request 1060354 from kukuk)

OBS-URL: https://build.opensuse.org/request/show/1060355
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=81
2023-01-23 17:32:26 +00:00
c38fca9782 Accepting request 1060354 from home:kukuk:cleanup
- Require systemd for building, was pulled in before by indirect
  dependencies which don't exist anymore

OBS-URL: https://build.opensuse.org/request/show/1060354
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=279
2023-01-23 08:38:59 +00:00
Dominique Leuenberger
fbbb5de23b Accepting request 1059915 from security
- 0001-Use-correct-includes.patch: fixed build with rpm 4.18 (forwarded request 1059914 from msmeissn)

OBS-URL: https://build.opensuse.org/request/show/1059915
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=80
2023-01-20 16:39:09 +00:00
e34ec4480d Accepting request 1059914 from home:msmeissn:branches:security
- 0001-Use-correct-includes.patch: fixed build with rpm 4.18

OBS-URL: https://build.opensuse.org/request/show/1059914
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=277
2023-01-20 09:25:38 +00:00
Dominique Leuenberger
7018bc8422 Accepting request 1005125 from security
- require shared library in the same version or newer (forwarded request 1005123 from dirkmueller)

OBS-URL: https://build.opensuse.org/request/show/1005125
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=79
2022-09-21 12:43:05 +00:00
1e960dc0e7 Accepting request 1005123 from home:dirkmueller:Factory
- require shared library in the same version or newer

OBS-URL: https://build.opensuse.org/request/show/1005123
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=275
2022-09-21 08:01:40 +00:00
Dominique Leuenberger
8295895d8c Accepting request 1003839 from security
- added Leap 15.4 and 15.5 dictionary entries. (bsc#1203408)

OBS-URL: https://build.opensuse.org/request/show/1003839
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=78
2022-09-15 20:59:50 +00:00
c6d4c4a847 - added Leap 15.4 and 15.5 dictionary entries. (bsc#1203408)
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=273
2022-09-15 08:29:50 +00:00
Dominique Leuenberger
fcaf78e3e9 Accepting request 956318 from security
- Conditionally drop optional gconf2-devel BuildRequires for
  openSUSE Tumbleweed and newer: gconf2 is being droppped from
  openSUSE Tumbleweed, build without gconf2 support. (forwarded request 956097 from iznogood)

OBS-URL: https://build.opensuse.org/request/show/956318
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=77
2022-02-21 16:46:42 +00:00
34acbd44f4 Accepting request 956097 from home:iznogood:branches:security
- Conditionally drop optional gconf2-devel BuildRequires for
  openSUSE Tumbleweed and newer: gconf2 is being droppped from
  openSUSE Tumbleweed, build without gconf2 support.

OBS-URL: https://build.opensuse.org/request/show/956097
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=272
2022-02-21 08:10:21 +00:00
Dominique Leuenberger
5dc13e330b Accepting request 949692 from security
update openscap to 1.3.6: put oscap-remediate into libexec at least on opensuse (bin is actually the wrost folder as it is not supposed to be called directly:/ ) (forwarded request 949314 from rfrohl)

OBS-URL: https://build.opensuse.org/request/show/949692
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=76
2022-01-29 19:59:21 +00:00
fca1a2040b Accepting request 949314 from home:rfrohl:branches:security
update openscap to 1.3.6: put oscap-remediate into libexec at least on opensuse (bin is actually the wrost folder as it is not supposed to be called directly:/ )

OBS-URL: https://build.opensuse.org/request/show/949314
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=271
2022-01-28 13:58:29 +00:00
Robert Frohl
e0a8343994 Accepting request 948434 from home:rfrohl:branches:security
update openscap to 1.3.6

OBS-URL: https://build.opensuse.org/request/show/948434
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=270
2022-01-25 09:01:20 +00:00
Dominique Leuenberger
65451281e7 Accepting request 936259 from security
- openscap-docker-add-suse.patch: add SLES support oscap-docker
  (bsc#1179314) (forwarded request 936258 from msmeissn)

OBS-URL: https://build.opensuse.org/request/show/936259
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=75
2021-12-07 23:00:03 +00:00
bed6d37e63 Accepting request 936258 from home:msmeissn:branches:security
- openscap-docker-add-suse.patch: add SLES support oscap-docker
  (bsc#1179314)

OBS-URL: https://build.opensuse.org/request/show/936258
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=269
2021-12-07 14:04:40 +00:00
Dominique Leuenberger
2e160e0025 Accepting request 924193 from security
- ship python3 docker module always

OBS-URL: https://build.opensuse.org/request/show/924193
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=74
2021-10-11 13:31:01 +00:00
0b1bd89f4f - ship python3 docker module always
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=268
2021-10-08 11:23:26 +00:00
14b3ae9893 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=267 2021-10-08 11:19:47 +00:00
f35bf00ac0 Accepting request 923072 from home:msmeissn:branches:security
- readjust python3 requirements for python3 to be on sles12 sp5
  and newer.

OBS-URL: https://build.opensuse.org/request/show/923072
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=266
2021-10-07 07:59:39 +00:00
Dominique Leuenberger
4900a85cb6 Accepting request 913461 from security
- Since upstream has moved to Python 3, switch the BuildRequires from
  python-devel to python3-devel. (forwarded request 912966 from StevenK)

OBS-URL: https://build.opensuse.org/request/show/913461
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=73
2021-08-23 08:08:13 +00:00
32df8e93ff Accepting request 912966 from home:StevenK:branches:security
- Since upstream has moved to Python 3, switch the BuildRequires from
  python-devel to python3-devel.

OBS-URL: https://build.opensuse.org/request/show/912966
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=265
2021-08-21 13:17:29 +00:00
Dominique Leuenberger
3dd75e5405 Accepting request 906323 from security
openscap: add opensuse tumbleweed - fix changes typo (forwarded request 906318 from rfrohl)

OBS-URL: https://build.opensuse.org/request/show/906323
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=72
2021-07-14 21:58:57 +00:00
6856c29fd1 Accepting request 906318 from home:rfrohl:branches:security
openscap: add opensuse tumbleweed - fix changes typo

OBS-URL: https://build.opensuse.org/request/show/906318
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=264
2021-07-14 15:49:59 +00:00
6f88887bae Accepting request 906300 from home:rfrohl:branches:security
openscap: add opensuse tumbleweed

OBS-URL: https://build.opensuse.org/request/show/906300
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=263
2021-07-14 15:10:59 +00:00
Dominique Leuenberger
54822eabd9 Accepting request 901561 from security
added missing CPEs again (forwarded request 901558 from rfrohl)

OBS-URL: https://build.opensuse.org/request/show/901561
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=71
2021-06-23 15:38:39 +00:00
862ac7d75f Accepting request 901558 from home:rfrohl:branches:security
added missing CPEs again

OBS-URL: https://build.opensuse.org/request/show/901558
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=261
2021-06-23 14:17:38 +00:00
Dominique Leuenberger
bce7b46f5b Accepting request 894646 from security
update openscap to 1.3.5 (forwarded request 894638 from rfrohl)

OBS-URL: https://build.opensuse.org/request/show/894646
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=70
2021-05-20 17:25:44 +00:00
afb06b7aac Accepting request 894638 from home:rfrohl:branches:security
update openscap to 1.3.5

OBS-URL: https://build.opensuse.org/request/show/894638
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=259
2021-05-20 14:23:59 +00:00
Dominique Leuenberger
0f73d900ee Accepting request 859046 from security
- 0001-Fix-memory-allocation.patch: fixed a crash during oscap oval eval (forwarded request 859045 from msmeissn)

OBS-URL: https://build.opensuse.org/request/show/859046
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=69
2020-12-29 14:52:30 +00:00
d258d10fad Accepting request 859045 from home:msmeissn:branches:security
- 0001-Fix-memory-allocation.patch: fixed a crash during oscap oval eval

OBS-URL: https://build.opensuse.org/request/show/859045
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=257
2020-12-28 15:26:44 +00:00
Dominique Leuenberger
bb18737f6b Accepting request 847312 from security
- openscap-leap-cpe-15.12.patch: add CPE dict entries for openSUSE
  Leap 15.1 and 15.2

- add dbus-1-devel buildrequires to enable systemd tests (bsc#1178301)

OBS-URL: https://build.opensuse.org/request/show/847312
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=68
2020-11-10 12:45:55 +00:00
75b3d9bbe9 - openscap-leap-cpe-15.12.patch: add CPE dict entries for openSUSE
Leap 15.1 and 15.2

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=255
2020-11-09 13:10:22 +00:00
e731fe8612 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=254 2020-11-09 13:10:02 +00:00
e545210db4 Accepting request 847158 from home:msmeissn:branches:security
- add dbus-1-devel buildrequires to enable systemd tests (bsc#1178301)

OBS-URL: https://build.opensuse.org/request/show/847158
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=253
2020-11-09 12:48:33 +00:00
Dominique Leuenberger
4f0bdc7159 Accepting request 839126 from security
update openscap to 1.3.4 (forwarded request 839124 from rfrohl)

OBS-URL: https://build.opensuse.org/request/show/839126
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=67
2020-10-02 15:42:17 +00:00
156138e7cc Accepting request 839124 from home:rfrohl:branches:security
update openscap to 1.3.4

OBS-URL: https://build.opensuse.org/request/show/839124
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=251
2020-10-02 09:25:57 +00:00
Dominique Leuenberger
a537e6b3c5 Accepting request 800232 from security
(forwarded request 800231 from msmeissn)

OBS-URL: https://build.opensuse.org/request/show/800232
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=66
2020-05-05 16:56:04 +00:00
e32b796185 Accepting request 800231 from home:msmeissn:branches:security
OBS-URL: https://build.opensuse.org/request/show/800231
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=249
2020-05-05 06:22:29 +00:00
0cb0407eba Accepting request 799976 from home:msmeissn:branches:security
- openscap 1.3.3. Notable improvements in this release:
  - a Python script that can be used for CLI tailoring (autotailor) (thank you, Matěj Týč);
  - timezone for XCCDF TestResult start and end time (thank you, Jan Černý);
  - new yamlfilecontent independent probe (draft implementation),
    see the proposal https://github.com/OVAL-Community/OVAL/issues/91
    for additional information.
There are other changes as well, here is the list:
  - Introduced `urn:xccdf:fix:script:kubernetes` fix type in XCCDF;
  - Added ability to generate `machineconfig` fix;
  - Detect ambiguous scan target (utils/oscap-podman);
  - Fixed #170: The rpmverifyfile probe can't verify files from '/bin' directory;
  - The data system_info probe return for offline and online modes is consistent and actual;
  - Prevent crashes when complicated regexes are executed in textfilecontent58 probe;
  - Fixed #1512: Severity refinement lost in generated guide;
  - Fixed #1453: Pointer lost in Swig API;
  - Evaluation Characteristics of the XCCDF report are now consistent with OVAL entities;
    from system_info probe;
  - Fixed filepath pattern matching in offline mode in textfilecontent58 probe;
  - Fixed infinite recursion in systemdunitdependency probe;
  - Fixed the case when CMake couldn't find libacl or xattr.h.
- dropped 0001-Do-not-use-C-keyword-operator-as-a-function-paramete.patch: upstream

OBS-URL: https://build.opensuse.org/request/show/799976
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=248
2020-05-04 18:33:17 +00:00
Dominique Leuenberger
707d7498a2 Accepting request 788259 from security
- Add upstream patch to fix the scap-workbench build:
  * 0001-Do-not-use-C-keyword-operator-as-a-function-paramete.patch (forwarded request 788252 from cgiboudeaux)

OBS-URL: https://build.opensuse.org/request/show/788259
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=65
2020-03-25 22:48:03 +00:00
d3967e180d Accepting request 788252 from home:cgiboudeaux:branches:security
- Add upstream patch to fix the scap-workbench build:
  * 0001-Do-not-use-C-keyword-operator-as-a-function-paramete.patch

OBS-URL: https://build.opensuse.org/request/show/788252
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=246
2020-03-25 15:53:05 +00:00
Dominique Leuenberger
8b31c07db5 Accepting request 766084 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/766084
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=64
2020-01-21 20:00:33 +00:00
OBS User buildservice-autocommit
8b62f39da5 Accepting request 764315 from security
baserev update by copy to link target

OBS-URL: https://build.opensuse.org/request/show/764315
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=244
2020-01-14 20:10:52 +00:00
Dominique Leuenberger
0907bf39f6 Accepting request 764315 from security
- openscap 1.3.1
  - the test suite and build scripts were improved to support Debian 10
  - offline mode has received some love with a set of dedicated tests and various fixes in OVAL probes;
  - the oscap-docker wrapper is no longer dependent on Atomic 
  - Python binding are now more robust 
  - HTML reports and guides, generated by the scanner, are now more accessible for non-visual rendering agents 
  - Support of multi-check rules has been improved across the whole workflow 
  There are other changes as well, here is the list:
  * New features
    - Offline mode support for environmentvariable58 probe
    - The oscap-docker wrapper is available without Atomic
  + Maintenance, bug fixes
    - Improved support of multi-check rules (report, remediations, console output)
    - Improved HTML report look and feel, including printed version
    - Less clutter in verbose mode output; some warnings and errors demoted to verbose mode levels
    - Probe rpmverifyfile uses and returns canonical paths
    - Improved a11y of HTML reports and guides
    - Fixes and improvements for SWIG Python bindings
    - #1403 fixed: Scanner would not apply remediation for multicheck rules (verbosity)
    - Fixed URL link mechanism for Red Hat Errata
    - New STIG Viewer URI: public.cyber.mil
    - Probe selinuxsecuritycontext would not check if SELinux is enabled
    - Scanner would provide information about unsupported OVAL objects
    - Added more tests for offline mode (probes, remediation)
    - #528 fixed: Eval SCE script when /tmp is in mode noexec
    - #1173, RHBZ#1603347 fixed: Double chdir/chroot in probe rpmverifypackage

OBS-URL: https://build.opensuse.org/request/show/764315
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=63
2020-01-14 20:10:52 +00:00
OBS User buildservice-autocommit
8b06e57aa6 Updating link to change in openSUSE:Factory/openscap revision 63.0
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=534cb10161730fa838be45c9b7c56b59
2020-01-14 20:10:52 +00:00
440912201d - switch back to official release
- openscap 1.3.2

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=243
2020-01-14 14:09:00 +00:00
43fa6294ff - openscap 1.3.1
- the test suite and build scripts were improved to support Debian 10
  - offline mode has received some love with a set of dedicated tests and various fixes in OVAL probes;
  - the oscap-docker wrapper is no longer dependent on Atomic 
  - Python binding are now more robust 
  - HTML reports and guides, generated by the scanner, are now more accessible for non-visual rendering agents 
  - Support of multi-check rules has been improved across the whole workflow 
  There are other changes as well, here is the list:
  * New features
    - Offline mode support for environmentvariable58 probe
    - The oscap-docker wrapper is available without Atomic
  + Maintenance, bug fixes
    - Improved support of multi-check rules (report, remediations, console output)
    - Improved HTML report look and feel, including printed version
    - Less clutter in verbose mode output; some warnings and errors demoted to verbose mode levels
    - Probe rpmverifyfile uses and returns canonical paths
    - Improved a11y of HTML reports and guides
    - Fixes and improvements for SWIG Python bindings
    - #1403 fixed: Scanner would not apply remediation for multicheck rules (verbosity)
    - Fixed URL link mechanism for Red Hat Errata
    - New STIG Viewer URI: public.cyber.mil
    - Probe selinuxsecuritycontext would not check if SELinux is enabled
    - Scanner would provide information about unsupported OVAL objects
    - Added more tests for offline mode (probes, remediation)
    - #528 fixed: Eval SCE script when /tmp is in mode noexec
    - #1173, RHBZ#1603347 fixed: Double chdir/chroot in probe rpmverifypackage

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=242
2020-01-14 13:44:42 +00:00
Dominique Leuenberger
07bbae3c10 Accepting request 763678 from security
- temporary openscap 1.3.1 git snapshot
  - make it build with new RPM  (bsc#1160720)

- use distribution-release instead of dummy-release

OBS-URL: https://build.opensuse.org/request/show/763678
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=62
2020-01-12 22:25:36 +00:00
31b86a44ed OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=240 2020-01-12 18:07:15 +00:00
57e2d03c9f Accepting request 763602 from home:msmeissn:branches:security
- temporary openscap 1.3.1 git snapshot
  - make it build with new RPM  (bsc#1160720)

OBS-URL: https://build.opensuse.org/request/show/763602
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=239
2020-01-12 12:37:02 +00:00
c92b50e50e - openscap-new-rpm.patch: use the recent RPM defines, some old
ones got obsoleted

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=238
2020-01-11 17:24:43 +00:00
af55f05af1 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=237 2020-01-11 09:34:55 +00:00
5bfd648668 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=236 2020-01-11 09:27:40 +00:00
dfe7310c7f - use distribution-release instead of dummy-release
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=235
2020-01-11 09:02:02 +00:00
2167e3e34e OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=234 2020-01-11 08:58:18 +00:00
Dominique Leuenberger
5ade1b57a0 Accepting request 709970 from security
OBS-URL: https://build.opensuse.org/request/show/709970
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=61
2019-06-14 18:43:03 +00:00
Robert Frohl
f7b7f9df1b Accepting request 709892 from home:rfrohl:branches:security
update openscap to version 1.3.1

OBS-URL: https://build.opensuse.org/request/show/709892
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=232
2019-06-14 12:32:39 +00:00
Dominique Leuenberger
99de27cad5 Accepting request 689029 from security
add missing obsoletes (forwarded request 688824 from rfrohl)

OBS-URL: https://build.opensuse.org/request/show/689029
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=60
2019-03-27 15:22:05 +00:00
96f998b11f Accepting request 688824 from home:rfrohl:branches:security
add missing obsoletes

OBS-URL: https://build.opensuse.org/request/show/688824
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=230
2019-03-27 09:30:35 +00:00
491045a433 Accepting request 688437 from home:iznogood:branches:security
- Drop gconf2-devel BuildRequires: It is not mandatory, so lets
  build without this obsolete package.
- Add pkgconfig(glib-2.0) and pkgconfig(gobject-2.0) BuildRequires:
  They are also optional, but not obsolete, and previously pulled
  in via gconf2-devel dependency, so lets build support for them.

OBS-URL: https://build.opensuse.org/request/show/688437
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=229
2019-03-27 09:29:58 +00:00
Dominique Leuenberger
41308542a9 Accepting request 653777 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/653777
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=59
2018-12-04 19:57:52 +00:00
afba4b9563 fixed %post %pre syntax
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=227
2018-11-27 07:18:16 +00:00
8c59323331 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=226 2018-11-22 10:56:58 +00:00
4d33f05db9 Accepting request 651059 from home:rfrohl:branches:security
- Update to openscap-1.3.0 
  - move to cmake
- improve unit test, planned for inclusion with 1.3.1
  - tests do no complete as of yet, still future work needed

OBS-URL: https://build.opensuse.org/request/show/651059
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=225
2018-11-22 10:48:01 +00:00
Yuchen Lin
102cbbd841 Accepting request 635251 from security
- openscap-xattr.patch: build against new libattr

OBS-URL: https://build.opensuse.org/request/show/635251
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=58
2018-09-13 10:11:29 +00:00
619b3160ac - openscap-xattr.patch: build against new libattr
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=223
2018-09-12 05:56:15 +00:00
Dominique Leuenberger
1ef6929acc Accepting request 614943 from security
- scap-yast2sec-xccdf.xml: remove platform cpe match, as it is impossible
  to match both opensuse and sles or official suse_linux_enterprise_server
  names at once. (bsc#1091040)

- openscap-1.2.17
  - New features
    - HTML Guide user experience improvements
    - New options in HTML report "Group By" menu
    - oscap-ssh supports --oval-results (issue #863)
  - Maintenance
    - Support comparing state record elements with item
    - Updated Bash completion
    - Make Bash role headers consistent with --help output
    - Fixed problems reported by Coverity (issue #909)
    - Fixed CVE schema to support 4 to 7 digits CVEs
    - Fix output of generated bash role missing fix message
    - Fix oscap-docker to clean up temporary image (RHBZ #1454637)
    - Fix Ansible remediations generation
    - Add a newline between ids in xccdf info (issue #968)
    - Fix unknown subtype handling in oval_subtype_parse (issue #986)
    - Outsourced the pthreads feature check and setup
    - Speed up in debug mode
    - Refactored the Python handling in build scripts
    - Prevent reading from host in offline mode (issue #1001)
    - Many probes use OWN offline mode
    - Improve offline mode logic in OVAL probes
    - Do not use chroot in system_info probe
    - Prevent a segfault in oscap_seterr on Solaris
    - Out of tree build is possible
    - Use chroot for RPM probes in offline mode

OBS-URL: https://build.opensuse.org/request/show/614943
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=57
2018-06-08 21:18:08 +00:00
3b96c1ea55 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=221 2018-06-07 13:25:46 +00:00
f38bdeafcc OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=220 2018-06-07 11:43:22 +00:00
4b365c9471 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=219 2018-06-07 11:36:14 +00:00
ce492ea8b2 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=218 2018-06-07 11:32:55 +00:00
26a9a39cb7 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=217 2018-06-07 11:26:19 +00:00
8e2deae43b OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=216 2018-06-07 09:11:44 +00:00
01a370031b - New features
- HTML Guide user experience improvements
    - New options in HTML report "Group By" menu
    - oscap-ssh supports --oval-results (issue #863)
  - Maintenance
    - Support comparing state record elements with item
    - Updated Bash completion
    - Make Bash role headers consistent with --help output
    - Fixed problems reported by Coverity (issue #909)
    - Fixed CVE schema to support 4 to 7 digits CVEs
    - Fix output of generated bash role missing fix message
    - Fix oscap-docker to clean up temporary image (RHBZ #1454637)
    - Fix Ansible remediations generation
    - Add a newline between ids in xccdf info (issue #968)
    - Fix unknown subtype handling in oval_subtype_parse (issue #986)
    - Outsourced the pthreads feature check and setup
    - Speed up in debug mode
    - Refactored the Python handling in build scripts
    - Prevent reading from host in offline mode (issue #1001)
    - Many probes use OWN offline mode
    - Improve offline mode logic in OVAL probes
    - Do not use chroot in system_info probe
    - Prevent a segfault in oscap_seterr on Solaris
    - Out of tree build is possible
    - Use chroot for RPM probes in offline mode
    - PEP8 accepts lines up to 99 characters
    - New configure parameter --with-oscap-temp-dir (issue #1016)
    - Fixed OVAL record elements namespace and SEXP conversion
    - Removed '\r' characters from help output (issue #1023)
    - Full Python 3 compatibility

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=215
2018-06-07 09:03:58 +00:00
4db5e7cc47 - scap-yast2sec-xccdf.xml: remove platform cpe match, as it is impossible
to match both opensuse and sles or official suse_linux_enterprise_server

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=214
2018-06-07 08:47:17 +00:00
29a0cf99ec - remove platform cpe match, as it is impossible to match
both opensuse and sles or official suse_linux_enterprise_server
  names at once. (bsc#1091040)

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=213
2018-06-07 08:47:03 +00:00
23a8401a21 - openscap-1.2.17
- New features                                                                                                                                                                             
    - HTML Guide user experience improvements                                                                                                                                                
    - New options in HTML report "Group By" menu                                                                                                                                             
    - oscap-ssh supports --oval-results (issue #863)                                                                                                                                         
  - Maintenance                                                                                                                                                                              
    - Support comparing state record elements with item                                                                                                                                      
    - Updated Bash completion                                                                                                                                                                
    - Make Bash role headers consistent with --help output                                                                                                                                   
    - Fixed problems reported by Coverity (issue #909)                                                                                                                                       
    - Fixed CVE schema to support 4 to 7 digits CVEs                                                                                                                                         
    - Fix output of generated bash role missing fix message                                                                                                                                  
    - Fix oscap-docker to clean up temporary image (RHBZ #1454637)                                                                                                                           
    - Fix Ansible remediations generation                                                                                                                                                    
    - Add a newline between ids in xccdf info (issue #968)                                                                                                                                   
    - Fix unknown subtype handling in oval_subtype_parse (issue #986)                                                                                                                        
    - Outsourced the pthreads feature check and setup                                                                                                                                        
    - Speed up in debug mode                                                                                                                                                                 
    - Refactored the Python handling in build scripts                                                                                                                                        
    - Prevent reading from host in offline mode (issue #1001)                                                                                                                                
    - Many probes use OWN offline mode                                                                                                                                                       
    - Improve offline mode logic in OVAL probes                                                                                                                                              
    - Do not use chroot in system_info probe                                                                                                                                                 
    - Prevent a segfault in oscap_seterr on Solaris                                                                                                                                          
    - Out of tree build is possible                                                                                                                                                          
    - Use chroot for RPM probes in offline mode                                                                                                                                              
    - PEP8 accepts lines up to 99 characters                                                                                                                                                 
    - New configure parameter --with-oscap-temp-dir (issue #1016)                                                                                                                            
    - Fixed OVAL record elements namespace and SEXP conversion                                                                                                                               
    - Removed '\r' characters from help output (issue #1023)

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=212
2018-05-29 09:47:57 +00:00
Dominique Leuenberger
6c9a9dd73b Accepting request 601561 from security
- openscap-new-suse.patch: handle SLE15 and openSUSE Leap 42.3 and 15.0
  (bsc#1091040) (forwarded request 601560 from msmeissn)

OBS-URL: https://build.opensuse.org/request/show/601561
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=56
2018-04-27 14:08:52 +00:00
27ae7c8e8c Accepting request 601560 from home:msmeissn:branches:security
- openscap-new-suse.patch: handle SLE15 and openSUSE Leap 42.3 and 15.0
  (bsc#1091040)

OBS-URL: https://build.opensuse.org/request/show/601560
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=210
2018-04-26 13:26:15 +00:00
Dominique Leuenberger
ee5ae20257 Accepting request 583006 from security
- Replace old $RPM_* shell vars. (forwarded request 583005 from jengelh)

OBS-URL: https://build.opensuse.org/request/show/583006
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=55
2018-03-07 09:35:14 +00:00
da4441b12a Accepting request 583005 from home:jengelh:branches:security
- Replace old $RPM_* shell vars.

OBS-URL: https://build.opensuse.org/request/show/583005
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=208
2018-03-05 15:23:38 +00:00
ddbf5be776 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=207 2018-03-05 13:31:32 +00:00
b38d166f2f OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=206 2018-03-05 13:13:41 +00:00
5a159d70e7 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=205 2018-03-05 13:06:12 +00:00
0510e1e4b7 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=204 2018-03-05 12:52:43 +00:00
b6d47735b2 - replace oscap-scan.init by oscap-scan.service, add a /usr/bin/oscap-scan
helper tool for this. (bsc#1083115)

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=203
2018-03-05 12:41:14 +00:00
Dominique Leuenberger
7a541fe677 Accepting request 579041 from security
- disable scap-as-rpm binary to avoid python2 dependency. (bsc#1082135)

OBS-URL: https://build.opensuse.org/request/show/579041
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=54
2018-02-23 14:29:34 +00:00
078a8851d4 - disable scap-as-rpm binary to avoid python2 dependency. (bsc#1082135)
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=201
2018-02-22 15:23:58 +00:00
67516938ac OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=200 2018-02-22 14:50:12 +00:00
0102e47e88 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=199 2018-02-22 13:59:55 +00:00
4812708f17 - disable scap-as-rpm binary to avoid python2 dependency.
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=198
2018-02-22 13:41:50 +00:00
8ac1ef8247 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=197 2018-02-22 13:41:34 +00:00
Dominique Leuenberger
2982f16f69 Accepting request 544846 from security
Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468) (forwarded request 544729 from RBrownSUSE)

OBS-URL: https://build.opensuse.org/request/show/544846
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=53
2017-11-24 09:54:25 +00:00
05ea99b703 Accepting request 544729 from home:RBrownSUSE:branches:security
Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)

OBS-URL: https://build.opensuse.org/request/show/544729
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=195
2017-11-23 14:58:40 +00:00
Dominique Leuenberger
be3414c095 Accepting request 544183 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/544183
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=52
2017-11-22 10:22:13 +00:00
Dominique Leuenberger
9845139534 Accepting request 541803 from security
- openscap-1.2.16
  - New features
    - oscap can generate output that is compatible with STIG Viewer.
    - CVRF parsing and export has been implemented.
    - oscap info command has been expanded.
    - The AIX platform is supported.
    - Many documentation improvements.
    - Numerous other improvements of existing features.
  - Maintenance
    - Huge cross-platform improvements.
    - Memory leaks fixed (RHBZ#1485876).
    - SELinux fixes.
    - Many coverity fixes.
    - Numerous other bugfixes.
- buildrequire procps-devel

OBS-URL: https://build.opensuse.org/request/show/541803
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=51
2017-11-15 16:00:37 +00:00
69d55966cf OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=192 2017-11-14 15:21:10 +00:00
fd2df3e5a6 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=191 2017-11-14 15:02:28 +00:00
99499cd1d3 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=190 2017-11-14 14:38:14 +00:00
128a9a554b - openscap-productid-cvrf.patch: add a --productid selector
for "oscap cvrf" as upstream does not detect the system yet.
  (might go away)

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=189
2017-11-14 14:29:43 +00:00
f8d1dd749f - buildrequire procps-devel
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=188
2017-11-14 12:32:22 +00:00
3c4e03f325 - buildrequir procps-devel
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=187
2017-11-14 12:32:14 +00:00
eb2044117e OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=186 2017-11-14 12:29:40 +00:00
c298f4a117 - openscap-1.2.16
- New features
    - oscap can generate output that is compatible with STIG Viewer.
    - CVRF parsing and export has been implemented.
    - oscap info command has been expanded.
    - The AIX platform is supported.
    - Many documentation improvements.
    - Numerous other improvements of existing features.
  - Maintenance
    - Huge cross-platform improvements.
    - Memory leaks fixed (RHBZ#1485876).
    - SELinux fixes.
    - Many coverity fixes.
    - Numerous other bugfixes.

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=185
2017-11-14 12:15:40 +00:00
Dominique Leuenberger
7f3f508bf4 Accepting request 518767 from security
- openscap-1.2.15 / 25-08-2017
  - New features                                                                                                                                                                             
    - short profile names can be used instead of long IDs                                                                                                                                    
    - new option --rule allows to evaluate only a single rule                                                                                                                                
    - new option --fix-type in "oscap xccdf generate fix" allows choosing                                                                                                                    
      remediation script type without typing long URL                                                                                                                                        
    - "oscap info" shows profile titles                                                                                                                                                      
    - OVAL details in HTML report are easier to read                                                                                                                                         
    - HTML report is smaller because unselected rules are removed                                                                                                                            
    - HTML report supports NIST 800-171 and CJIS                                                                                                                                             
    - remediation scripts contain headers with useful information                                                                                                                            
    - remediation scripts report progress when they run                                                                                                                                      
    - basic support for Oracle Linux (CPEs, runlevels)                                                                                                                                       
    - remediation scripts can be generated from datastreams that contain                                                                                                                     
      multiple XCCDF benchmarks (issue #772)                                                                                                                                                 
    - basic support for OVAL 5.11.2 (only schemas, no features)                                                                                                                              
    - enabled offline RPM database in rpminfo probe (issue #778)                                                                                                                             
    - added Fedora 28 CPE                                                                                                                                                                    
  - Maintenance                                                                                                                                                                              
    - fixed oscap-docker with Docker >= 2.0 (issue #794)                                                                                                                                     
    - fixed behavior of sysctl probe to be consistent with sysctl tool                                                                                                                       
    - fixed generating remediation scripts (issue #723, #773)                                                                                                                                
    - severity of tailored rules is not discarded (issue #739)                                                                                                                               
    - fixed errors in RPM probes initialization                                                                                                                                              
    - oscap-docker shows all warnings reported by oscap (issue #713)                                                                                                                         
    - small improvements in verbose mode                                                                                                                                                     
    - standard C operations are used instead of custom OpenSCAP operations                                                                                                                   
    - fixed compiler warnings                                                                                                                                                                
    - fixed missing header files                                                                                                                                                             
    - fixed resource leaks (issue #715)

OBS-URL: https://build.opensuse.org/request/show/518767
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=50
2017-08-28 13:16:32 +00:00
be41d8de13 - openscap-1.2.15 / 25-08-2017
- New features                                                                                                                                                                             
    - short profile names can be used instead of long IDs                                                                                                                                    
    - new option --rule allows to evaluate only a single rule                                                                                                                                
    - new option --fix-type in "oscap xccdf generate fix" allows choosing                                                                                                                    
      remediation script type without typing long URL                                                                                                                                        
    - "oscap info" shows profile titles                                                                                                                                                      
    - OVAL details in HTML report are easier to read                                                                                                                                         
    - HTML report is smaller because unselected rules are removed                                                                                                                            
    - HTML report supports NIST 800-171 and CJIS                                                                                                                                             
    - remediation scripts contain headers with useful information                                                                                                                            
    - remediation scripts report progress when they run                                                                                                                                      
    - basic support for Oracle Linux (CPEs, runlevels)                                                                                                                                       
    - remediation scripts can be generated from datastreams that contain                                                                                                                     
      multiple XCCDF benchmarks (issue #772)                                                                                                                                                 
    - basic support for OVAL 5.11.2 (only schemas, no features)                                                                                                                              
    - enabled offline RPM database in rpminfo probe (issue #778)                                                                                                                             
    - added Fedora 28 CPE                                                                                                                                                                    
  - Maintenance                                                                                                                                                                              
    - fixed oscap-docker with Docker >= 2.0 (issue #794)                                                                                                                                     
    - fixed behavior of sysctl probe to be consistent with sysctl tool                                                                                                                       
    - fixed generating remediation scripts (issue #723, #773)                                                                                                                                
    - severity of tailored rules is not discarded (issue #739)                                                                                                                               
    - fixed errors in RPM probes initialization                                                                                                                                              
    - oscap-docker shows all warnings reported by oscap (issue #713)                                                                                                                         
    - small improvements in verbose mode                                                                                                                                                     
    - standard C operations are used instead of custom OpenSCAP operations                                                                                                                   
    - fixed compiler warnings                                                                                                                                                                
    - fixed missing header files                                                                                                                                                             
    - fixed resource leaks (issue #715)

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=183
2017-08-25 13:42:56 +00:00
Yuchen Lin
a814530fd4 Accepting request 486410 from security
- Remove line-trailing whitespace from last changelog entry.
- Rename %soname to %sover to better reflect its use.
- Replace unnecessary %__-type macro indirections.

- openscap-1.2.14 / 21-03-2017
  - New features
    - Detailed information about ARF files in 'oscap info' (issue #664)
    - XSLT template creating XCCDF files from OVAL files
    - Generating remediation scripts from ARF
    - Significant improvements of User Manual (issue #249, #513)
    - HTML report UX improvements (issue #601, #620, #622, #655)
    - Warnings are shown by default
    - Verbose mode is available in 'xccdf remediate' module (issue #520)
    - Added Fedora 26, Fedora 27 and OpenSUSE 42.2 CPEs (issue #698)
    - Support for Anaconda remediation in HTML report
  - Maintenance
    - Fixed CPE dictionary to identify RHEVH as RHEL7 (RHBZ #1420038)
    - Fixed systemd probes crashes inside containers (RHBZ #1431186, issue #700)
    - Added a warning on non-existing XCCDF Benchmarks (issue #614)
    - Fixed output on terminals with white background (RHBZ #1365911, issue #512)
    - Error handling in oscap-vm (RHBZ #1391754)
    - Fixed SCE stderr stalling (RHBZ #1420811)
    - Fixed Android OVAL schema (issue #279)
    - Fixed absolute filepath parsing in OVAL (RHBZ #1312831, #1312824)
    - Fixes based on Coverity scan report (issue #581, #634, #681)
    - Fixed duplicated error messages (issue #707)
    - Fixed XCCDF score calculation (issue #617)
    - Fixed segmentation faults in RPM probes (RHBZ #1414303, #1414312)
    - Fixed failing DataStream build if "@" is in filepath
    - Fixed missing header in result-oriented Ansible remediations

OBS-URL: https://build.opensuse.org/request/show/486410
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=49
2017-04-12 15:35:15 +00:00
32c1e2af94 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=181 2017-04-07 11:21:07 +00:00
ad166be9c5 Accepting request 486359 from home:jengelh:branches:security
- Remove line-trailing whitespace from last changelog entry.
- Rename %soname to %sover to better reflect its use.

OBS-URL: https://build.opensuse.org/request/show/486359
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=180
2017-04-07 11:11:30 +00:00
75f2a2ef28 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=179 2017-04-07 11:11:21 +00:00
ae7828b162 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=178 2017-04-07 11:09:18 +00:00
46c29bfaf0 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=177 2017-03-21 16:49:08 +00:00
a65fcb6897 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=176 2017-03-21 16:31:53 +00:00
47a1d0d6f6 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=175 2017-03-21 14:39:33 +00:00
02c3b71e6c OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=174 2017-03-21 13:57:45 +00:00
e5bf5e59f3 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=173 2017-03-21 13:07:28 +00:00
6851872d5b OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=172 2017-03-21 12:31:31 +00:00
90f776a3a7 - openscap-1.2.14 / 21-03-2017
- New features                                                                                                                                                                             
    - Detailed information about ARF files in 'oscap info' (issue #664)                                                                                                                      
    - XSLT template creating XCCDF files from OVAL files                                                                                                                                     
    - Generating remediation scripts from ARF                                                                                                                                                
    - Significant improvements of User Manual (issue #249, #513)                                                                                                                             
    - HTML report UX improvements (issue #601, #620, #622, #655)                                                                                                                             
    - Warnings are shown by default                                                                                                                                                          
    - Verbose mode is available in 'xccdf remediate' module (issue #520)                                                                                                                     
    - Added Fedora 26, Fedora 27 and OpenSUSE 42.2 CPEs (issue #698)                                                                                                                         
    - Support for Anaconda remediation in HTML report                                                                                                                                        
  - Maintenance                                                                                                                                                                              
    - Fixed CPE dictionary to identify RHEVH as RHEL7 (RHBZ #1420038)                                                                                                                        
    - Fixed systemd probes crashes inside containers (RHBZ #1431186, issue #700)                                                                                                             
    - Added a warning on non-existing XCCDF Benchmarks (issue #614)                                                                                                                          
    - Fixed output on terminals with white background (RHBZ #1365911, issue #512)                                                                                                            
    - Error handling in oscap-vm (RHBZ #1391754)                                                                                                                                             
    - Fixed SCE stderr stalling (RHBZ #1420811)                                                                                                                                              
    - Fixed Android OVAL schema (issue #279)                                                                                                                                                 
    - Fixed absolute filepath parsing in OVAL (RHBZ #1312831, #1312824)                                                                                                                      
    - Fixes based on Coverity scan report (issue #581, #634, #681)                                                                                                                           
    - Fixed duplicated error messages (issue #707)                                                                                                                                           
    - Fixed XCCDF score calculation (issue #617)                                                                                                                                             
    - Fixed segmentation faults in RPM probes (RHBZ #1414303, #1414312)                                                                                                                      
    - Fixed failing DataStream build if "@" is in filepath                                                                                                                                   
    - Fixed missing header in result-oriented Ansible remediations                                                                                                                           
    - Memory leak and resource leak fixes (issue #635, #636)                                                                                                                                 
    - New upstream tests                                                                                                                                                                     
    - Many minor fixes and improvements

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=171
2017-03-21 12:22:06 +00:00
Dominique Leuenberger
d4ba59b1a5 Accepting request 449070 from security
- openscap-1.2.13 / 05-01-2017
  - Maintenance
    - we always build system_info OVAL probe, fixed configure output accordingly
    - warn when the user requests to generate an ARF from XCCDF 1.1
    - fixed a segfault when loading an OVAL file with invalid family attribute
    - added --thin-results CLI override to oscap xccdf eval
    - added --without-syschar CLI override to oscap xccdf eval
    - fixed a segfault when freeing xccdf_policy of the default profile
    - removed ARF schematron workaround when there are no applicable checks
    - fixed verbose output in oscap xccdf generate fix
    - do not filter fix by applicability when generating remediations from results
    - fixed memory leaks, resource leaks and other minor issues

OBS-URL: https://build.opensuse.org/request/show/449070
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=48
2017-01-09 10:01:01 +00:00
66bcb524f7 - openscap-1.2.13 / 05-01-2017
- Maintenance
    - we always build system_info OVAL probe, fixed configure output accordingly
    - warn when the user requests to generate an ARF from XCCDF 1.1
    - fixed a segfault when loading an OVAL file with invalid family attribute
    - added --thin-results CLI override to oscap xccdf eval
    - added --without-syschar CLI override to oscap xccdf eval
    - fixed a segfault when freeing xccdf_policy of the default profile
    - removed ARF schematron workaround when there are no applicable checks
    - fixed verbose output in oscap xccdf generate fix
    - do not filter fix by applicability when generating remediations from results
    - fixed memory leaks, resource leaks and other minor issues

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=169
2017-01-06 14:38:48 +00:00
Dominique Leuenberger
ec7d4313b9 Accepting request 441166 from security
- openscap-1.2.12 / 21-11-2016
  - New features
    - separated stdout and stderr in SCE results and HTML report
    - HTML reports contain [ref] links for rules and groups
  - Maintenance
    - fixed ARF errors reported by the SCAPval tool
    - fixed CVE parsing (issue #550)
    - fixed namespace of ARF vocabulary according to NIST SP800-126 errata
    - fixed exporting OVAL Windows namespaces
    - fixed injecting xccdf:check-content-ref references in ARF results
    - fixed oscap-docker incompliance reporting (issue #475, RHBZ #1387248)
    - fixed oscap-docker man page (RHBZ #1387166)
    - fixed memory leaks and resource leaks
    - small fixes and refactoring, test suite fixes

OBS-URL: https://build.opensuse.org/request/show/441166
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=47
2016-11-22 17:58:17 +00:00
4bb4bf0fc8 - New features
- separated stdout and stderr in SCE results and HTML report
    - HTML reports contain [ref] links for rules and groups
  - Maintenance
    - fixed ARF errors reported by the SCAPval tool
    - fixed CVE parsing (issue #550)
    - fixed namespace of ARF vocabulary according to NIST SP800-126 errata
    - fixed exporting OVAL Windows namespaces
    - fixed injecting xccdf:check-content-ref references in ARF results
    - fixed oscap-docker incompliance reporting (issue #475, RHBZ #1387248)
    - fixed oscap-docker man page (RHBZ #1387166)
    - fixed memory leaks and resource leaks
    - small fixes and refactoring, test suite fixes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=167
2016-11-21 09:41:33 +00:00
76f0dfc61c - openscap-1.2.12 / 21-11-2016
- New features                                                                                                                                                                             
    - separated stdout and stderr in SCE results and HTML report                                                                                                                             
    - HTML reports contain [ref] links for rules and groups                                                                                                                                  
  - Maintenance                                                                                                                                                                              
    - fixed ARF errors reported by the SCAPval tool                                                                                                                                          
    - fixed CVE parsing (issue #550)                                                                                                                                                         
    - fixed namespace of ARF vocabulary according to NIST SP800-126 errata                                                                                                                   
    - fixed exporting OVAL Windows namespaces                                                                                                                                                
    - fixed injecting xccdf:check-content-ref references in ARF results                                                                                                                      
    - fixed oscap-docker incompliance reporting (issue #475, RHBZ #1387248)                                                                                                                  
    - fixed oscap-docker man page (RHBZ #1387166)                                                                                                                                            
    - fixed memory leaks and resource leaks                                                                                                                                                  
    - small fixes and refactoring, test suite fixes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=166
2016-11-21 09:40:53 +00:00
Dominique Leuenberger
dd23f9a623 Accepting request 435870 from security
- openscap-1.2.11 / 14-10-2016
  - New features
    - huge speed-up of generating HTML reports and guides
    - support remote datastream components (issue #526)
    - support tailoring of external datastreams
    - various attributes of remediation scripts are now shown in HTML report (issue #541)
    - new option generating OVAL results without system characteristics
    - remediation scripts in HTML report are now collapsed
    - support for extracting Ansible playbooks
    - enabled fetching remote resources in OVAL module
    - added Wind River Linux CPE
  - Maintenance
    - updated jQuery and bootstrap libraries in HTML reports
    - extended, improved and updated user manual
    - fixed issues with proxy in oscap-docker (RHBZ #1351952)
    - fixed a bug in OVAL arithmetic function
    - fixed a segmentation fault (issue #529)
    - fixed results of XCCDF rules with @role="unscored" (issue #525)
    - fixed invalid characters in OVAL results (issue #468)
    - fixed a segmentation fault in tailoring (RHBZ #1367896)
    - updated SUSE 11 CPE
    - fixed many memory issues
    - large refactoring of datastream module
    - new tests in upstream test suite
    - various small fixes and improvements
- openscap-1.2.10 / 29-06-2016
  - New features
    - support --benchmark-id when running `oscap xccdf generate guide`
    - added CPE support for OpenSUSE 42.1
  - Maintenance

OBS-URL: https://build.opensuse.org/request/show/435870
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=46
2016-10-19 11:14:04 +00:00
7fa2172dc6 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=164 2016-10-18 07:42:31 +00:00
477af14752 - openscap-1.2.11 / 14-10-2016
- New features
    - huge speed-up of generating HTML reports and guides
    - support remote datastream components (issue #526)
    - support tailoring of external datastreams
    - various attributes of remediation scripts are now shown in HTML report (issue #541)
    - new option generating OVAL results without system characteristics
    - remediation scripts in HTML report are now collapsed
    - support for extracting Ansible playbooks
    - enabled fetching remote resources in OVAL module
    - added Wind River Linux CPE
  - Maintenance
    - updated jQuery and bootstrap libraries in HTML reports
    - extended, improved and updated user manual
    - fixed issues with proxy in oscap-docker (RHBZ #1351952)
    - fixed a bug in OVAL arithmetic function
    - fixed a segmentation fault (issue #529)
    - fixed results of XCCDF rules with @role="unscored" (issue #525)
    - fixed invalid characters in OVAL results (issue #468)
    - fixed a segmentation fault in tailoring (RHBZ #1367896)
    - updated SUSE 11 CPE
    - fixed many memory issues
    - large refactoring of datastream module
    - new tests in upstream test suite
    - various small fixes and improvements
- openscap-1.2.10 / 29-06-2016
  - New features
    - support --benchmark-id when running `oscap xccdf generate guide`
    - added CPE support for OpenSUSE 42.1
  - Maintenance

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=163
2016-10-18 07:16:58 +00:00
Dominique Leuenberger
6f127116f5 Accepting request 391973 from security
- openscap 1.2.9 release
  - New features
    - oscap-chroot - a tool for offline scanning of filesystems mounted at arbitrary paths
    - enabled offline scanning in many probes
    - support for SCE in data streams
    - many improvements of verbose mode
    - verbose messages can be written on stderr
    - runlevel probe supports SUSE systems
    - new upstream tests
  - Maintenance
    - a lot of refactoring
    - fixes in various tests
    - OCILs are correctly placed in datastreams (issue #364)
    - oscap-vm can work with fusermount when guestunmount is not available
    - fixed oscap-docker HTTP communication issues (issue #304)
    - fixed oscap-docker tracebacks (issue #303, #317)
    - fixed container mounting in oscap-docker (issue #329)
    - added Fedora 25 CPE
    - only non-empty profiles are built (rhbz#1256879, rhbz#1302230)
    - fixed compiler errors on RHEL5 and SLES11
    - fixed sorting of groups in HTML report (issue #342)
    - fixed version/@time and version/@update in XCCDF Benchmark
    - fixed CPE definitions to work also in offline mode
    - fixed sysctl probe (issue #258)
    - fixed manual page for oscap-ssh (rhbz#1299969)
    - updated user manuals and manual pages
    - updated .gitignore
- dropped fix-missing-include.dif, not needed anymore

OBS-URL: https://build.opensuse.org/request/show/391973
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=45
2016-04-30 21:31:39 +00:00
555cce08b2 - New features
- oscap-chroot - a tool for offline scanning of filesystems mounted at arbitrary paths
    - enabled offline scanning in many probes
    - support for SCE in data streams
    - many improvements of verbose mode
    - verbose messages can be written on stderr
    - runlevel probe supports SUSE systems
    - new upstream tests
  - Maintenance
    - a lot of refactoring
    - fixes in various tests
    - OCILs are correctly placed in datastreams (issue #364)
    - oscap-vm can work with fusermount when guestunmount is not available
    - fixed oscap-docker HTTP communication issues (issue #304)
    - fixed oscap-docker tracebacks (issue #303, #317)
    - fixed container mounting in oscap-docker (issue #329)
    - added Fedora 25 CPE
    - only non-empty profiles are built (rhbz#1256879, rhbz#1302230)
    - fixed compiler errors on RHEL5 and SLES11
    - fixed sorting of groups in HTML report (issue #342)
    - fixed version/@time and version/@update in XCCDF Benchmark
    - fixed CPE definitions to work also in offline mode
    - fixed sysctl probe (issue #258)
    - fixed manual page for oscap-ssh (rhbz#1299969)
    - updated user manuals and manual pages
    - updated .gitignore

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=161
2016-04-28 15:54:23 +00:00
bcacd01e79 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=160 2016-04-28 15:54:06 +00:00
70a316a1c5 - dropped fix-missing-include.dif, not needed anymore
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=159
2016-04-28 15:20:44 +00:00
bbaadf429b OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=158 2016-04-28 15:18:52 +00:00
fec937d301 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=157 2016-04-28 13:30:20 +00:00
0be622f517 - openscap 1.2.9 release
- New features                                                                                                                                                                             
    - oscap-chroot - a tool for offline scanning of filesystems mounted at arbitrary paths                                                                                                   
    - enabled offline scanning in many probes                                                                                                                                                
    - support for SCE in data streams                                                                                                                                                        
    - many improvements of verbose mode                                                                                                                                                      
    - verbose messages can be written on stderr                                                                                                                                              
    - runlevel probe supports SUSE systems                                                                                                                                                   
    - new upstream tests                                                                                                                                                                     
  - Maintenance                                                                                                                                                                              
    - a lot of refactoring                                                                                                                                                                   
    - fixes in various tests                                                                                                                                                                 
    - OCILs are correctly placed in datastreams (issue #364)                                                                                                                                 
    - oscap-vm can work with fusermount when guestunmount is not available                                                                                                                   
    - fixed oscap-docker HTTP communication issues (issue #304)                                                                                                                              
    - fixed oscap-docker tracebacks (issue #303, #317)                                                                                                                                       
    - fixed container mounting in oscap-docker (issue #329)                                                                                                                                  
    - added Fedora 25 CPE                                                                                                                                                                    
    - only non-empty profiles are built (rhbz#1256879, rhbz#1302230)                                                                                                                         
    - fixed compiler errors on RHEL5 and SLES11                                                                                                                                              
    - fixed sorting of groups in HTML report (issue #342)                                                                                                                                    
    - fixed version/@time and version/@update in XCCDF Benchmark                                                                                                                             
    - fixed CPE definitions to work also in offline mode                                                                                                                                     
    - fixed sysctl probe (issue #258)                                                                                                                                                        
    - fixed manual page for oscap-ssh (rhbz#1299969)                                                                                                                                         
    - updated user manuals and manual pages                                                                                                                                                  
    - updated .gitignore

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=156
2016-04-28 12:53:05 +00:00
Dominique Leuenberger
27c5679785 Accepting request 378600 from security
- enable the SCE (script checking engine)
  packaged in "openscap-engine-sce" subpackage.
- enable the CCE (Common Configuration Enumeration)

OBS-URL: https://build.opensuse.org/request/show/378600
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=44
2016-03-26 14:27:37 +00:00
14b3c5ae96 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=154 2016-03-23 11:00:47 +00:00
66ad6c2088 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=153 2016-03-23 10:50:27 +00:00
8120fab210 packaged in "openscap-engine-sce" subpackage.
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=152
2016-03-23 10:43:09 +00:00
bc955772b8 - enable the SCE (script checking engine)
- enable the CCE (Common Configuration Enumeration)

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=151
2016-03-23 10:24:34 +00:00
Dominique Leuenberger
e0ed3f63ea Accepting request 354754 from security
- openscap 1.2.8 release
  - Maintenance
    - textfilecontent54_probe does not produce false positives on non-UTF files (rhbz #1285757)
    - fixed oscap-docker
    - small improvements in verbose mode
    - oscap info module shows information about tailoring files
    - fixed build with CCE (issue #264)
    - fixed XCCDF score computation (issue #272)
    - fixed segmentation fault in variable probe (issue #277)
    - fixed broken support for OVAL directives
    - fixed bash completion
    - plugged memory leaks
    - fixed fresh static analysis (coverity) findings
    - fixed shellcheck warnings
    - new tests
    - refactoring in datastream module
    - many small bugfixes and typo fixes

OBS-URL: https://build.opensuse.org/request/show/354754
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=43
2016-01-21 22:44:00 +00:00
e5564e2ae3 - openscap 1.2.8 release
- Maintenance
    - textfilecontent54_probe does not produce false positives on non-UTF files (rhbz #1285757)
    - fixed oscap-docker
    - small improvements in verbose mode
    - oscap info module shows information about tailoring files
    - fixed build with CCE (issue #264)
    - fixed XCCDF score computation (issue #272)
    - fixed segmentation fault in variable probe (issue #277)
    - fixed broken support for OVAL directives
    - fixed bash completion
    - plugged memory leaks
    - fixed fresh static analysis (coverity) findings
    - fixed shellcheck warnings
    - new tests
    - refactoring in datastream module
    - many small bugfixes and typo fixes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=149
2016-01-19 10:25:06 +00:00
Dominique Leuenberger
94085afd87 Accepting request 348807 from security
- openscap 1.2.7 release
  - New features                                                                                                                                                                             
    - OVAL 5.11.1 fully supported                                                                                                                                                            
    - oscap-vm - tool for offline scanning of virtual machines                                                                                                                               
    - verbose mode                                                                                                                                                                           
    - added SLED, SLES and OpenSUSE CPE names                                                                                                                                                
    - show profile description in HTML report and guide                                                                                                                                      
    - group rules by PCI DSS identifier in HTML report                                                                                                                                       
    - preliminary support for Ansible Playbooks within xccdf:fix                                                                                                                             
    - added "How to contribute" and "Versioning" documents                                                                                                                                   
  - Maintenance                                                                                                                                                                              
    - using bziped RHSA documents in oscap-docker                                                                                                                                            
    - fixed errors of sysctl probe                                                                                                                                                           
    - fixed skip-valid option (issue #203)                                                                                                                                                   
    - fixed segmentation faults in SCE content reporting (issue #231)                                                                                                                        
    - fixed tracebacks of scap-as-rpm                                                                                                                                                        
    - fixed invalid memory reads in rpmverifyfile probe (issue #212)                                                                                                                         
    - updated README and user manual                                                                                                                                                         
    - many small bugfixes and new tests                                                                                                                                                      
- openscap-new-inventory.patch: upstreamed
- fix-missing-include.dif: refreshed, 1 hunk upstream

OBS-URL: https://build.opensuse.org/request/show/348807
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=42
2015-12-16 16:43:00 +00:00
b2e2d22272 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=147 2015-12-14 08:19:26 +00:00
4b5ac2cdec OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=146 2015-12-04 10:58:11 +00:00
bf543a29a6 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=145 2015-12-04 10:36:28 +00:00
d41de1b761 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=144 2015-12-03 16:40:27 +00:00
8d54ea3b8e - openscap 1.2.7 release
- New features                                                                                                                                                                             
    - OVAL 5.11.1 fully supported                                                                                                                                                            
    - oscap-vm - tool for offline scanning of virtual machines                                                                                                                               
    - verbose mode                                                                                                                                                                           
    - added SLED, SLES and OpenSUSE CPE names                                                                                                                                                
    - show profile description in HTML report and guide                                                                                                                                      
    - group rules by PCI DSS identifier in HTML report                                                                                                                                       
    - preliminary support for Ansible Playbooks within xccdf:fix                                                                                                                             
    - added "How to contribute" and "Versioning" documents                                                                                                                                   
  - Maintenance                                                                                                                                                                              
    - using bziped RHSA documents in oscap-docker                                                                                                                                            
    - fixed errors of sysctl probe                                                                                                                                                           
    - fixed skip-valid option (issue #203)                                                                                                                                                   
    - fixed segmentation faults in SCE content reporting (issue #231)                                                                                                                        
    - fixed tracebacks of scap-as-rpm                                                                                                                                                        
    - fixed invalid memory reads in rpmverifyfile probe (issue #212)                                                                                                                         
    - updated README and user manual                                                                                                                                                         
    - many small bugfixes and new tests                                                                                                                                                      
- openscap-new-inventory.patch: upstreamed
- fix-missing-include.dif: refreshed, 1 hunk upstream

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=143
2015-12-03 13:08:43 +00:00
Stephan Kulow
8d852f0048 Accepting request 340304 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/340304
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=41
2015-10-25 18:13:06 +00:00
Dominique Leuenberger
26630cb11c Accepting request 337016 from security
- openscap 1.2.6 release
  - New features
    - introduced OpenSCAP user manual
    - improved OVAL 5.11.1 support
      - added OVAL 5.11.1 XSD schemas and schematrons
      - support for core/platform schema versions
      - support for check_existence attribute in state entities
      - support for CIM datetime format
      - amended behavior of mask attribute
    - added support for remote .xml.bz2 files (use with --fetch-remote-resources)
    - rewrote oscap-docker to python, deeper integration with Atomic Host
    - introduced CPE name for Fedora 24 to the internal dictionary
  - HTML report & guide
    - results can be grouped by according to various aspects
    - printing supported (interactive elements are now hidden when printing)
    - table of content now shows only selected items (rule & groups)
    - references to RHSA are presented as links to website (rhbz#1243808)
  - Maintenance
    - scap-as-rpm can now build source rpm packages (srpms) (trac#469)
    - scap-as-rpm now supports python3
    - refactored oval processing into oval_session structure
    - many smaller bugfixes and new tests
- new openscap-docker subpackage

OBS-URL: https://build.opensuse.org/request/show/337016
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=40
2015-10-14 14:44:34 +00:00
9e48751654 - openscap-new-inventory.patch: find out the CPE ids of
SUSE Linux Enterprise and openSUSE versions.

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=140
2015-10-09 14:57:21 +00:00
bffb547538 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=139 2015-10-07 15:00:34 +00:00
4b4f421f42 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=138 2015-10-07 14:59:25 +00:00
8715e38cfc OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=137 2015-10-07 14:54:11 +00:00
0f07ed8cf6 - new openscap-docker subpackage
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=136
2015-10-07 14:40:50 +00:00
069487e388 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=135 2015-10-07 14:34:37 +00:00
517cb9d0f1 u
M    openscap.spec

Diff for working copy: .
Index: openscap.spec
===================================================================

--- openscap.spec	(revision c86548ec47e882d642c97e427035b5b3)
+++ openscap.spec	(working copy)
@@ -74,6 +74,13 @@
 %description -n libopenscap%{soname}
 The OpenSCAP C Library for easy integration with SCAP.
 
+%package docker
+Summary:        Docker plugin for OpenSCAP
+Group:          System/Libraries
+
+%description docker
+This package contains the Docker support for OpenSCAP.
+
 
 %package devel
 Requires:       %{name} = %{version}-%{release}
@@ -241,10 +248,14 @@
 %{_libdir}/*.so
 %{_libdir}/pkgconfig/*.pc
 
+%files docker
+%defattr(-, root, root)
+%{python_sitearch}/*
+
 %if 0%{?with_bindings}
 %files -n python-openscap
 %defattr(-, root, root)
-%{python_sitearch}/*
+%{python_sitearch}/oscap_docker_python
 
 %files -n perl-openscap
 %defattr(-, root, root)

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=134
2015-10-07 14:33:06 +00:00
d9711fcd1b OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=133 2015-10-05 12:24:09 +00:00
2593aea15d - openscap 1.2.6 release
- New features
    - introduced OpenSCAP user manual
    - improved OVAL 5.11.1 support
      - added OVAL 5.11.1 XSD schemas and schematrons
      - support for core/platform schema versions
      - support for check_existence attribute in state entities
      - support for CIM datetime format
      - amended behavior of mask attribute
    - added support for remote .xml.bz2 files (use with --fetch-remote-resources)
    - rewrote oscap-docker to python, deeper integration with Atomic Host
    - introduced CPE name for Fedora 24 to the internal dictionary
  - HTML report & guide
    - results can be grouped by according to various aspects
    - printing supported (interactive elements are now hidden when printing)
    - table of content now shows only selected items (rule & groups)
    - references to RHSA are presented as links to website (rhbz#1243808)
  - Maintenance
    - scap-as-rpm can now build source rpm packages (srpms) (trac#469)
    - scap-as-rpm now supports python3
    - refactored oval processing into oval_session structure
    - many smaller bugfixes and new tests

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=132
2015-10-05 11:46:16 +00:00
Stephan Kulow
90426d344b Accepting request 315206 from security
- openscap-1.2.5 update
 - maintenance
   - smaller bugfixes
   - plugged memory leaks
   - fixed fresh static analysis (coverity) findings
   - fixed shellcheck warnings
   - fixes for Solaris platform

OBS-URL: https://build.opensuse.org/request/show/315206
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=39
2015-07-08 04:59:43 +00:00
8cf933142b - openscap-1.2.5 update
- maintenance
   - smaller bugfixes
   - plugged memory leaks
   - fixed fresh static analysis (coverity) findings
   - fixed shellcheck warnings
   - fixes for Solaris platform

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=130
2015-07-06 11:46:24 +00:00
Dominique Leuenberger
513f14d1e9 Accepting request 313072 from security
- openscap-1.2.4 update
  - new features
    - OVAL 5.11 support 99.8% completed!
      - new symlink probe introduced
      - new process58 test capabilities
      - added possible_value support for external variables
      - added possible_restriction support for external variables
      - improved IP address comparisons
    - Added Scientific Linux CPEs
    - Added oscap-docker tool
    - Created man-page for oscap-ssh
  - HTML changes
    - improved visibility of selected XCCDF profile in guides and reports
    - render rule-result/message contents in reports
  - maintenance
    - Tests now pass on ppc64 little endian arch (rhbz#1215220)
    - partition probe now supports remount, bind and move mount options
    - Patched NIST OVAL-5.11 schemas to be backward compatible with
      OVAL-5.10 (rhbz#1220262)
    - fixed scap-as-rpm to work with vintage python (2.6)
    - better error reporting when a probe dies (i.e. due to OOM killer)
    - dropped selinux policy from upstream (rhbz#1209969)
    - fix segfault on invalid selectors (rhbz#1220944)
    - solaris support patches: file-system zones, systeminfo improvements
    - many smaller fixes and new tests

OBS-URL: https://build.opensuse.org/request/show/313072
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=38
2015-06-23 10:00:11 +00:00
faa84ec7fb OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=128 2015-06-22 13:37:59 +00:00
c1283142d9 - openscap-1.2.4 update
- new features
    - OVAL 5.11 support 99.8% completed!
      - new symlink probe introduced
      - new process58 test capabilities
      - added possible_value support for external variables
      - added possible_restriction support for external variables
      - improved IP address comparisons
    - Added Scientific Linux CPEs
    - Added oscap-docker tool
    - Created man-page for oscap-ssh
  - HTML changes
    - improved visibility of selected XCCDF profile in guides and reports
    - render rule-result/message contents in reports
  - maintenance
    - Tests now pass on ppc64 little endian arch (rhbz#1215220)
    - partition probe now supports remount, bind and move mount options
    - Patched NIST OVAL-5.11 schemas to be backward compatible with
      OVAL-5.10 (rhbz#1220262)
    - fixed scap-as-rpm to work with vintage python (2.6)
    - better error reporting when a probe dies (i.e. due to OOM killer)
    - dropped selinux policy from upstream (rhbz#1209969)
    - fix segfault on invalid selectors (rhbz#1220944)
    - solaris support patches: file-system zones, systeminfo improvements
    - many smaller fixes and new tests

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=127
2015-06-22 09:42:15 +00:00
Stephan Kulow
308772d933 Accepting request 306169 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/306169
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=37
2015-05-11 17:38:55 +00:00
cd55f7dc7d - openscap-1.2.3 update
- new features
   - oscap-ssh -- handy utility to run remote scan over ssh
   - glob_to_regexp OVAL function added
 - HTML changes
   - show rationale elements
   - show fixtext elements
   - show Benchmark's front-matter, description and notices
   - show warnings for Groups and Rules
   - improved handling of multiple fixes within a single Rule
   - scroll evaluation characteristic if they overflow
 - maintenance
   - OVAL 5.11 schema fixes
   - Coverity and memory leak fixes
   - skip transient files when traversing /proc (trac#457)

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=125
2015-05-03 07:56:39 +00:00
Dominique Leuenberger
20401bd4cd Accepting request 294719 from security
- openscap-1.2.2 update
 - new features
   - OVAL 5.11 support turned on by default
   - included OVAL 5.11 schematron rules
   - DataStream can now contain OVAL 5.11
   - `oscap ds sds-compose` now supports --skip-valid parameter
 - HTML report changes
   - Notably increased level of OVAL details
   - Table of contents is now generated for HTML guides
 - maitenance
   - rhbz#1182242, rhbz#1159289 - @var_check & @var_ref exporting
   - solaris build fixes
   - xccdf:fix/instance processing fixes
   - improved (none) epoch processing in rpm probe
   - environmentvariable58 now emits warning messages when appropriate
   - offline mode improvements
   - other bugfixes

- openscap-1.2.1 update

OBS-URL: https://build.opensuse.org/request/show/294719
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=36
2015-04-10 07:51:03 +00:00
124567a319 - openscap-1.2.2 update
- new features
   - OVAL 5.11 support turned on by default
   - included OVAL 5.11 schematron rules
   - DataStream can now contain OVAL 5.11
   - `oscap ds sds-compose` now supports --skip-valid parameter
 - HTML report changes
   - Notably increased level of OVAL details
   - Table of contents is now generated for HTML guides
 - maitenance
   - rhbz#1182242, rhbz#1159289 - @var_check & @var_ref exporting
   - solaris build fixes
   - xccdf:fix/instance processing fixes
   - improved (none) epoch processing in rpm probe
   - environmentvariable58 now emits warning messages when appropriate
   - offline mode improvements
   - other bugfixes
- openscap-1.2.1 update

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=123
2015-04-07 09:36:35 +00:00
Dominique Leuenberger
ad0890887f Accepting request 280877 from security
- openscpa-1.2.1 update
 - API changes
   - 5.11 schemas updated (from RC1 to gold)
   - oscap_source_new_from_memory can take bzip2ed content
 - HTML report changes
   - severity bar is now reversed (left-to-right)
 - maintenance
   - rhbz#1165139 - fix probe cancelation
   - dozen of bugfixes

OBS-URL: https://build.opensuse.org/request/show/280877
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=35
2015-01-14 10:44:52 +00:00
36c6eae53e - openscpa-1.2.1 update
- API changes
   - 5.11 schemas updated (from RC1 to gold)
   - oscap_source_new_from_memory can take bzip2ed content
 - HTML report changes
   - severity bar is now reversed (left-to-right)
 - maintenance
   - rhbz#1165139 - fix probe cancelation
   - dozen of bugfixes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=121
2015-01-12 09:44:35 +00:00
Dominique Leuenberger
5789663cea Accepting request 263739 from security
- openscap-1.2.0 update
 - new features
   - native support of bzip2ed SCAP files (file extension needs to be '.xml.bz2')
   - improved performance on huge XML documents, especially DataStreams
   - minimized use of temp files to absolute minimum
   - added OVAL-5.11 release candidate schemas
 - API changes
   - overall 50 new symbols added to public API
   - introduced oscap_source abstraction for input files
     - further info: http://isimluk.livejournal.com/4859.html
     - all the parsers converted to use oscap_source abstraction
   - introduced ds_sds_session, high level API for playing with Source DataStreams
   - introduced cpe_session, abstraction to approach multiple CPE resources
   - introduced ds_rds_session, high level API for playing with Result DataStreams
     (ARF files)
   - deprecated dozens of API calls dependent on filepath
   - introduced API for waivers (xccdf:override) and modification of ARF
     - initial support for waivers in HTML Report
   - dozens of small improvements
 - maintenance
   - dozens of small fixes
   - dozens of memory leaks (whole test suite is now leak free)
   - updated gnulib
- openscap-1.1.0-fix-bashisms.patch: upstreamed

- openscap-1.1.1 update
  - Hint towards `oscap info` when profile is not found in oscap tool
  - HTML report changes:
    - Source OVAL results from ARF if available
    - Highlight notchecked rules, treat them as rules that need attention

OBS-URL: https://build.opensuse.org/request/show/263739
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=34
2014-12-03 21:48:19 +00:00
795d12e3e0 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=119 2014-12-02 12:50:29 +00:00
e68db1f763 - openscap-1.1.0-fix-bashisms.patch: upstreamed
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=118
2014-12-02 12:46:26 +00:00
85a3903be3 - openscap-1.2.0 update
- new features
   - native support of bzip2ed SCAP files (file extension needs to be '.xml.bz2')
   - improved performance on huge XML documents, especially DataStreams
   - minimized use of temp files to absolute minimum
   - added OVAL-5.11 release candidate schemas
 - API changes
   - overall 50 new symbols added to public API
   - introduced oscap_source abstraction for input files
     - further info: http://isimluk.livejournal.com/4859.html
     - all the parsers converted to use oscap_source abstraction
   - introduced ds_sds_session, high level API for playing with Source DataStreams
   - introduced cpe_session, abstraction to approach multiple CPE resources
   - introduced ds_rds_session, high level API for playing with Result DataStreams
     (ARF files)
   - deprecated dozens of API calls dependent on filepath
   - introduced API for waivers (xccdf:override) and modification of ARF
     - initial support for waivers in HTML Report
   - dozens of small improvements
 - maintenance
   - dozens of small fixes
   - dozens of memory leaks (whole test suite is now leak free)
   - updated gnulib
- Remove unused build require on libnl-1_1 according to the

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=117
2014-12-02 12:45:22 +00:00
f503b7ad65 - openscap-1.1.1 update
- Hint towards `oscap info` when profile is not found in oscap tool
  - HTML report changes:
    - Source OVAL results from ARF if available
    - Highlight notchecked rules, treat them as rules that need attention
  - HTML guide changes:
    - Variable Substitution improvements
    - Show benchmark title
    - Show info about selected profile
    - Avoid cdf12:notice, show only its contents
  - bugfixes:
    - improved handling of fqdn in XCCDF
    - memory leaks
    - static analysis fixes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=116
2014-12-01 12:39:14 +00:00
c36700dc75 Accepting request 263389 from home:Ledest:bashisms
fix bashism in oscap-scan.cron script

OBS-URL: https://build.opensuse.org/request/show/263389
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=115
2014-12-01 12:33:36 +00:00
Stephan Kulow
81e8ad109f Accepting request 247494 from security
- openscap-1.1.0 update
 - HTML report and guide redesign
 - dropped support for docbook
 - Introduced new probes (that are to be part of OVAL 5.11)
   - probe_systemdunitproperty
   - probe_systemdunitdependency
 - introduced raw bindings for python3
 - dozens of small bug fixes

OBS-URL: https://build.opensuse.org/request/show/247494
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=33
2014-09-05 07:34:20 +00:00
68ca51a38a OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=113 2014-09-03 12:18:44 +00:00
618821d9a6 - openscap-1.1.0 update
- HTML report and guide redesign
 - dropped support for docbook
 - Introduced new probes (that are to be part of OVAL 5.11)
   - probe_systemdunitproperty
   - probe_systemdunitdependency
 - introduced raw bindings for python3
 - dozens of small bug fixes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=112
2014-09-03 12:10:47 +00:00
Stephan Kulow
b9b0ea120c Accepting request 239982 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/239982
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=31
2014-07-10 06:17:37 +00:00
ce95a2fa9b - openscap-1.0.9 update
- xccdf_session_export_arf must not return 0 if the export failed
 - expose xccdf_policy_get_value_of_item as public API
 - skip "Signature" when parsing sds_index without spewing out an error
 - return non-zero when cannot resolve XCCDF
 - consider the last set-value as the effective set-value and export only one
 - test suite fixes
 - do not destroy SVG data in XCCDFs when generating guide or report

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=110
2014-07-02 12:59:37 +00:00
Stephan Kulow
937a2adb2d Accepting request 238127 from security
- Remove unused build require on libnl-1_1 according to the 
  changelog, it stopped beign used in 2010
- libattr is also unused. (forwarded request 238064 from elvigia)

OBS-URL: https://build.opensuse.org/request/show/238127
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=30
2014-06-23 07:23:59 +00:00
58c0105121 Accepting request 238064 from home:elvigia:branches:security
- Remove unused build require on libnl-1_1 according to the 
  changelog, it stopped beign used in 2010
- libattr is also unused.

OBS-URL: https://build.opensuse.org/request/show/238064
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=108
2014-06-20 09:02:46 +00:00
Stephan Kulow
e4d6f7f8cd Accepting request 228095 from security
- openscap-1.0.8 update:
  - fixes related to Asset Reporting Format
    - Inject arf:report/@id into nested
      rule-result/check/check-content-ref/@href
    - Add hostname for each fqdn when generating ARF asset identification
      data
    - Add all MAC addresses from target-facts to ARF as asset
      identification data

OBS-URL: https://build.opensuse.org/request/show/228095
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=29
2014-03-30 05:55:59 +00:00
189e79eb96 - openscap-1.0.8 update:
- fixes related to Asset Reporting Format
    - Inject arf:report/@id into nested
      rule-result/check/check-content-ref/@href
    - Add hostname for each fqdn when generating ARF asset identification
      data
    - Add all MAC addresses from target-facts to ARF as asset
      identification data

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=106
2014-03-28 13:27:20 +00:00
Stephan Kulow
a3587e8652 Accepting request 226975 from security
- openscap-1.0.7 update:
 - fix namespaces for attributes in ARF relationship element
 - Avoid ".00" as the score in HTML report when score is 0.

- openscap-1.0.6 update:
 - fix process58 loginuid integer handling on 32bit

OBS-URL: https://build.opensuse.org/request/show/226975
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=28
2014-03-22 08:09:03 +00:00
5e1b16f041 - openscap-1.0.7 update:
- fix namespaces for attributes in ARF relationship element
 - Avoid ".00" as the score in HTML report when score is 0.

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=104
2014-03-21 12:47:33 +00:00
0992278369 - openscap-1.0.6 update:
- fix process58 loginuid integer handling on 32bit

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=103
2014-03-19 09:17:18 +00:00
Stephan Kulow
cf57fd64ae Accepting request 226350 from security
- openscap-1.0.5 update:
 - XCCDF titles and description support xccdf:sub resolution
 - HTML Report lists only applicable cpe platforms
 - TestResult element contains applicable cpe platforms
 - Introduced XCCDF 1.2 schematron validation
 - XCCDF bug fixes
    - tailoring profiles shall regards inherited refine-values (trac#373)
    - rule-result now always includes at least one check
 - Other bug fixes:
    - Dpkginfo probe collects epoch in evr
    - Updated examplary openscap-content based on the latest facts from
      Red Hat Enterprise Linux 6
    - Minor changes

OBS-URL: https://build.opensuse.org/request/show/226350
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=27
2014-03-18 13:15:47 +00:00
11106b3f8b - openscap-1.0.5 update:
- XCCDF titles and description support xccdf:sub resolution
 - HTML Report lists only applicable cpe platforms
 - TestResult element contains applicable cpe platforms
 - Introduced XCCDF 1.2 schematron validation
 - XCCDF bug fixes
    - tailoring profiles shall regards inherited refine-values (trac#373)
    - rule-result now always includes at least one check
 - Other bug fixes:
    - Dpkginfo probe collects epoch in evr
    - Updated examplary openscap-content based on the latest facts from
      Red Hat Enterprise Linux 6
    - Minor changes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=101
2014-03-17 07:13:53 +00:00
Stephan Kulow
69e5a7fc08 Accepting request 222332 from security
- openscap-1.0.4 update:
 - Introduced xccdf_tailoring_remove_profile to API
 - OVAL bug fixes

OBS-URL: https://build.opensuse.org/request/show/222332
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=26
2014-02-15 07:06:13 +00:00
92e2ce9219 - openscap-1.0.4 update:
- Introduced xccdf_tailoring_remove_profile to API
 - OVAL bug fixes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=99
2014-02-14 10:23:10 +00:00
Stephan Kulow
b7683e12a4 Accepting request 213907 from security
- openscap-1.0.3 update:
  - bug fixes
    - a few coverity issues
    - a few memory leak plugs
    - broken comparison of huge integet in OVAL
- fix-return.patch: removed, has upstream fix

OBS-URL: https://build.opensuse.org/request/show/213907
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=25
2014-01-14 20:51:03 +00:00
61c5603ba0 - fix-return.patch: removed, has upstream fix
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=97
2014-01-14 17:14:46 +00:00
6045eedad2 - openscap-1.0.3 update:
- bug fixes
    - a few coverity issues
    - a few memory leak plugs
    - broken comparison of huge integet in OVAL

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=96
2014-01-14 16:43:45 +00:00
Stephan Kulow
39f19cfd0f Accepting request 213430 from security
- openscap-1.0.2 update:
  - XCCDF generate fix now supports tailoring file
  - XCCDF bug fixes
    - Generate guide points to RHSA pages (rhbz#1018291)
    - Generate report ommits remediation when assesment passed
      (rhbz#1029879)
    - $PATH variable is available for SCE checks (rhbz#1026833)
    - Tailoring of top-level Group elements via API fixed
    - Fix-filtering should not drop fixes (affected SSG)
    - Generated fix file is created with sane permissions (trac#362)
    - Inherit parent's namespace when exporting oscap_text with HTML
      trait
  - OVAL bug fixes:
    - Handful of xinetd probe fixes
    - Handful of process and process58 fixes
    - Obsoleted textfilecontent now supports text ent comparisons
    - rpm*_item/epoch is reported as '(none)' when needed
    - Fixed dozen of flaws in ipv4 and ipv6_address comparison
      (CIDR handling)
    - Made integer and floating type number parsing much stricter
    - Fixed floating point numbers comparisons (trac#366)
    - Fixed case-insensitive comparisons
    - Item filtering fixes in probes
    - Consolidated some of comparisons in results model and probes
     (trac#367)
  - Other bug fixes:
    - Workaround libxml2 bug handling x509 xmldsig (gnomebz#350248)
    - Fixed static build (--disable-shared)
    - Format assertions (-Werror=format-security) turned on by default
    - SCE scripts are notified when parent (oscap) is killed

OBS-URL: https://build.opensuse.org/request/show/213430
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=24
2014-01-10 20:21:38 +00:00
bef795226a - fix-return.patch: Fixed a void return
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=94
2014-01-10 11:01:03 +00:00
78aa0d74d6 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=93 2014-01-10 10:41:10 +00:00
4ef63de556 - openscap-1.0.2 update:
- XCCDF generate fix now supports tailoring file
  - XCCDF bug fixes
    - Generate guide points to RHSA pages (rhbz#1018291)
    - Generate report ommits remediation when assesment passed
      (rhbz#1029879)
    - $PATH variable is available for SCE checks (rhbz#1026833)
    - Tailoring of top-level Group elements via API fixed
    - Fix-filtering should not drop fixes (affected SSG)
    - Generated fix file is created with sane permissions (trac#362)
    - Inherit parent's namespace when exporting oscap_text with HTML
      trait
  - OVAL bug fixes:
    - Handful of xinetd probe fixes
    - Handful of process and process58 fixes
    - Obsoleted textfilecontent now supports text ent comparisons
    - rpm*_item/epoch is reported as '(none)' when needed
    - Fixed dozen of flaws in ipv4 and ipv6_address comparison
      (CIDR handling)
    - Made integer and floating type number parsing much stricter
    - Fixed floating point numbers comparisons (trac#366)
    - Fixed case-insensitive comparisons
    - Item filtering fixes in probes
    - Consolidated some of comparisons in results model and probes
     (trac#367)
  - Other bug fixes:
    - Workaround libxml2 bug handling x509 xmldsig (gnomebz#350248)
    - Fixed static build (--disable-shared)
    - Format assertions (-Werror=format-security) turned on by default
    - SCE scripts are notified when parent (oscap) is killed

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=92
2014-01-10 10:26:02 +00:00
Stephan Kulow
9da4a98f56 Accepting request 209232 from security
- move the gconf probe to openscap-extra-probes to reduce
  dependencies of the core probe set.

OBS-URL: https://build.opensuse.org/request/show/209232
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=23
2013-12-03 13:26:49 +00:00
8144982cda - move the gconf probe to openscap-extra-probes to reduce
dependencies of the core probe set.

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=90
2013-12-02 16:54:33 +00:00
Stephan Kulow
41f05103c8 Accepting request 208809 from security
- openscap-1.0.1 update:
 - versioned interface is used to handle internal SCE plug-in
 - build-in gnulib package was updated to current version
 - bug fixes:
    - selinux_domain_label and posix_capability properties
      were reintroduced to OVAL system characteristics model
    - selinux_domain_label now collects the domain/type
      (not the context)
    - oscap oval collect reports progress on stdout (not on the stderr)
    - typo in the manual page (rhbz#1032537), and another small
      clarification

OBS-URL: https://build.opensuse.org/request/show/208809
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=22
2013-11-28 15:51:52 +00:00
44e3357a41 - openscap-1.0.1 update:
- versioned interface is used to handle internal SCE plug-in
 - build-in gnulib package was updated to current version
 - bug fixes:
    - selinux_domain_label and posix_capability properties
      were reintroduced to OVAL system characteristics model
    - selinux_domain_label now collects the domain/type
      (not the context)
    - oscap oval collect reports progress on stdout (not on the stderr)
    - typo in the manual page (rhbz#1032537), and another small
      clarification

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=88
2013-11-28 12:57:38 +00:00
Stephan Kulow
e64c4adb66 Accepting request 207593 from security
- openscap-1.0.0 / 19-11-2013
  - Improved heuristic to distinguish 'local' and 'remote' file systems
  - Improved comparison of EntityStateEVRStringType (trac#355)
  - Link against librpm (if available) to include rpmvercmp
    (on other platforms we fall back to the build-in rpmvercmp)
  - Bug fixes
- openscap-0.9.13 / 08-11-2013
  - Moved SCE to separate shared library (libopenscap_sce.so)
  - Introduction of scap-as-rpm tool
  - Improvements of sql and sql57 probes
  - Improvements of SELinux policy
  - Amendments based on SCAP 1.2 Errata (sp800-126r2-errata-20120409.pdf)
  - Minor improvements in state_entity processing
  - Introduction of CPE name for Fedora 21 to the internal dictionary
  - Added support for ind-def:pid/@xsi:nil (rhbz#1013011)
  - Improved error reporting
  - Bug fixes
    - Changed CPE name regex to be more permissive
    - avoided reports from the library to the stdout and stderr
    - plugged several memory leaks
    - improved xccdf:check-content-refs processing
    - misspelling in syslog message (rhbz#1021695)
    - fixed OVAL's <field> element processing
    - fixes based on static analysers
    - test suite is locale independent
- new library major version 8

OBS-URL: https://build.opensuse.org/request/show/207593
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=21
2013-11-20 09:48:55 +00:00
61eba0b7be - new library major version 8
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=86
2013-11-19 14:21:52 +00:00
5ee9f9d332 - openscap-1.0.0 / 19-11-2013
- Improved heuristic to distinguish 'local' and 'remote' file systems
  - Improved comparison of EntityStateEVRStringType (trac#355)
  - Link against librpm (if available) to include rpmvercmp
    (on other platforms we fall back to the build-in rpmvercmp)
  - Bug fixes
- openscap-0.9.13 / 08-11-2013
  - Moved SCE to separate shared library (libopenscap_sce.so)
  - Introduction of scap-as-rpm tool
  - Improvements of sql and sql57 probes
  - Improvements of SELinux policy
  - Amendments based on SCAP 1.2 Errata (sp800-126r2-errata-20120409.pdf)
  - Minor improvements in state_entity processing
  - Introduction of CPE name for Fedora 21 to the internal dictionary
  - Added support for ind-def:pid/@xsi:nil (rhbz#1013011)
  - Improved error reporting
  - Bug fixes
    - Changed CPE name regex to be more permissive
    - avoided reports from the library to the stdout and stderr
    - plugged several memory leaks
    - improved xccdf:check-content-refs processing
    - misspelling in syslog message (rhbz#1021695)
    - fixed OVAL's <field> element processing
    - fixes based on static analysers
    - test suite is locale independent

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=85
2013-11-19 12:51:39 +00:00
Tomáš Chvátal
374dd718e3 Accepting request 202982 from security
- Updated to 0.9.12
  - tailoring improvements (@id, version, and benchmark ref attributes)
  - XCCDF 1.1 tailoring extension
  - improved robustness of CPE dictionary parser and exporter
    - and added misc CPE 2.3 elements
  - added Fedora 20 to internal CPE dictionary
  - updated OVAL's results_to_html stylesheet from Mitre Corporation.
  - profiles with duplicate selects (same @idref) now export correctly
  - test improvements
  - bug fixes
    - fixed IPv6 export in TestResult/target-address
    - consistently inject target-id-ref into TestResult in ARFs
    - improved rpmdb manipulation (rhbz#999903)
    - solaris build fixes
    - spelling of name of default language fixed (oscap_text related)
    - fixed CPE names matching (generalization vs. specialization)

OBS-URL: https://build.opensuse.org/request/show/202982
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=20
2013-10-11 14:40:01 +00:00
2ac55a0bb1 - Updated to 0.9.12
- tailoring improvements (@id, version, and benchmark ref attributes)
  - XCCDF 1.1 tailoring extension
  - improved robustness of CPE dictionary parser and exporter
    - and added misc CPE 2.3 elements
  - added Fedora 20 to internal CPE dictionary
  - updated OVAL's results_to_html stylesheet from Mitre Corporation.
  - profiles with duplicate selects (same @idref) now export correctly
  - test improvements
  - bug fixes
    - fixed IPv6 export in TestResult/target-address
    - consistently inject target-id-ref into TestResult in ARFs
    - improved rpmdb manipulation (rhbz#999903)
    - solaris build fixes
    - spelling of name of default language fixed (oscap_text related)
    - fixed CPE names matching (generalization vs. specialization)

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=83
2013-10-11 13:24:48 +00:00
Stephan Kulow
ae274832cd Accepting request 183561 from security
- Updated to 0.9.11
  - bugfixes
- Updated to 0.9.10
  - bugfixes
- Updated to 0.9.9
  - --oval-results also exports CPE OVAL results
  - added --benchmark-id to select a component-ref by ID of Benchmark it's pointing to
  - OVAL variable_instance processing (or so called value multiset) and the processing
    of @variable_instance attribute to OVAL Result Definition, OVAL Result Test and
    Collected Objects.
  - improved test coverage of OVAL variable processing
  - introduced new internal data type: oval_smc
  - added support for evaluating OVAL definitions against an RPM database, a.k.a. rpm
    database offline mode
  - bug fixes and dead code removal

OBS-URL: https://build.opensuse.org/request/show/183561
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=18
2013-07-18 15:32:45 +00:00
f91430ce81 - Updated to 0.9.11
- bugfixes
- Updated to 0.9.10
  - bugfixes
- Updated to 0.9.9
  - --oval-results also exports CPE OVAL results
  - added --benchmark-id to select a component-ref by ID of Benchmark it's pointing to
  - OVAL variable_instance processing (or so called value multiset) and the processing
    of @variable_instance attribute to OVAL Result Definition, OVAL Result Test and
    Collected Objects.
  - improved test coverage of OVAL variable processing
  - introduced new internal data type: oval_smc
  - added support for evaluating OVAL definitions against an RPM database, a.k.a. rpm
    database offline mode
  - bug fixes and dead code removal

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=81
2013-07-17 15:31:02 +00:00
Stephan Kulow
7269f143e2 Accepting request 179323 from security
- updated to 0.9.8
  - added experimental support for offline mode scanning to the OVAL
    check engine (i.e. scanning of virtual host disk images)
  - improved OVAL variables processing
  - bug fixes and dead code removal

  - fix-missing-include.dif

OBS-URL: https://build.opensuse.org/request/show/179323
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=17
2013-06-18 08:34:22 +00:00
f98fb7e2ab added libattr-devel br
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=79
2013-06-17 12:37:59 +00:00
1fb68dee49 - updated to 0.9.8
- added experimental support for offline mode scanning to the OVAL
    check engine (i.e. scanning of virtual host disk images)
  - improved OVAL variables processing
  - bug fixes and dead code removal
  - fix-missing-include.dif

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=78
2013-06-17 11:45:11 +00:00
Stephan Kulow
628415a8ab Accepting request 174618 from security
- fix build on SLE11 - possible 64Bit issue
  - fix-missing-include.dif (forwarded request 174495 from mcalmer)

OBS-URL: https://build.opensuse.org/request/show/174618
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=16
2013-05-07 13:17:06 +00:00
973b9bbcd4 Accepting request 174495 from systemsmanagement:spacewalk
- fix build on SLE11 - possible 64Bit issue
  - fix-missing-include.dif

OBS-URL: https://build.opensuse.org/request/show/174495
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=76
2013-05-06 11:09:31 +00:00
d4e59709ba - updated to 0.9.7
- bugfixes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=75
2013-04-29 09:21:46 +00:00
Stephan Kulow
40e9effbfc Accepting request 173371 from security
- updated to 0.9.6
  - new command-line module added as preview: "oscap ds sds-add"
  - improved xccdf:fix processing (support of DataStreams and CPE)
  - internal selinux policy preview
  - added Fedora 19 to default CPE dictionary
  - bug fixes

OBS-URL: https://build.opensuse.org/request/show/173371
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=15
2013-04-26 05:41:33 +00:00
4adf9ac3de - updated to 0.9.6
- new command-line module added as preview: "oscap ds sds-add"
  - improved xccdf:fix processing (support of DataStreams and CPE)
  - internal selinux policy preview
  - added Fedora 19 to default CPE dictionary
  - bug fixes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=73
2013-04-25 11:31:14 +00:00
Stephan Kulow
e00b631cc7 Accepting request 161603 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/161603
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=14
2013-04-02 10:33:27 +00:00
d4b10797b3 - bumped SOVERSION from 2 to 3.
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=71
2013-03-21 09:35:54 +00:00
a7e6da3567 - updated to 0.9.5
- oscap xccdf remediate (new oscap module which introduces offline
    remediation; the remediation based on existing xccdf:testresult file)
  - added support for sce into datastream (sce scripts can now be
    embedded into the datastream file similarly as oval can)
  - improved bash completion and documentation
  - bug fixes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=70
2013-03-20 10:08:56 +00:00
Stephan Kulow
6735435aa3 Accepting request 157811 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/157811
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=13
2013-03-08 08:28:20 +00:00
2a2ef2800b - DOWNGRADED SOVERSION from 3 to 2.
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=68
2013-02-27 09:22:01 +00:00
d92845f535 - updated to 0.9.4
- high Level API
  - improved Text Substitution Processing
  - technical Preview of Online Remediation Execution
     (the oscap xccdf eval --remediate)
  - improved Library Internal Error Reporting.
  - the oscap xccd export-oval-variables now support DataStreams.
  - improved documentation
  - improved schema files.
  - tailoring file support
  - profile shadowing support
  - bug Fixes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=67
2013-02-27 08:54:24 +00:00
Stephan Kulow
29b8a93bd3 Accepting request 147554 from security
- updated to 0.9.3
  - Embedded CPE dictionary (allows users to ommit --cpe argument)
  - improvements of DataStream and CPE processing on RHEL5
  - changed API of various functions in cpe_dict, benchmark and
    xccdf_policy to use string timestamp instead of time_t [1]
  - fixed several issues found by Coverity and cppcheck static code
    analysis
  - bug fixes
- bumped SOVERSION from 2 to 3.

OBS-URL: https://build.opensuse.org/request/show/147554
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=11
2013-01-10 12:47:57 +00:00
66cd53bece OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=65 2013-01-08 14:15:34 +00:00
3022bc5f44 - bumped SOVERSION from 2 to 3.
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=64
2013-01-08 11:16:23 +00:00
54ce671d5f - updated to 0.9.3
- Embedded CPE dictionary (allows users to ommit --cpe argument)
  - improvements of DataStream and CPE processing on RHEL5
  - changed API of various functions in cpe_dict, benchmark and
    xccdf_policy to use string timestamp instead of time_t [1]
  - fixed several issues found by Coverity and cppcheck static code
    analysis
  - bug fixes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=63
2013-01-08 10:49:19 +00:00
Stephan Kulow
8ca61008e9 Accepting request 142947 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/142947
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=10
2012-11-28 10:44:51 +00:00
37a54ac362 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=61 2012-11-19 16:00:06 +00:00
657a772e04 - updated to 0.9.2:
- rewritten the heuristic for pattern matching on path and filepath
- CPE 2.3 language applicability testing
- new ds_sds_index API providing a datastream overview
- CPEs in source datastreams are automatically registered and used
   for XCCDF evaluation
- --cpe option autodetects CPE dictionary and language
- CVE support (validate feed, print CVEs)
- introduced info module
- made "$oscap xccdf generate custom" work again -> man page update
- bug fixes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=60
2012-11-19 15:47:31 +00:00
ff3916539d - updated to 0.9.1:
- the http in the check-content-ref/@hrefhref support
  - the cpedict support
  - obsoleted the oscap_reporter
  - send start and finish messages to the syslog
  - the XCCDF multi-check evaluation support
  - "oscap oval validate-xml" autodetect a document type
  - bug fixes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=59
2012-10-25 14:28:29 +00:00
Stephan Kulow
c6e1dd2fce Accepting request 136321 from security
- updated to 0.9.0:
  * few public headers were renamed to follow common schema
  * cve and cce modules are not build by default -> these modules are not
    utilized by oscap tool and thus untested.
  * --enable-bindings configure option was split into --enable-python and
    support of SCAP datastream support was improved
  * plus fixes in OVAL and XCCDF modules. oscap tool reports support of
    XCCDF 1.2 and OVAL 5.10.1
- libopenscap.so major version changed from 1 to 2.

OBS-URL: https://build.opensuse.org/request/show/136321
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=9
2012-10-03 07:21:12 +00:00
3bd4726560 disable python
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=57
2012-09-28 08:12:19 +00:00
43c9e63728 - libopenscap.so major version changed from 1 to 2.
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=56
2012-09-28 08:02:10 +00:00
7d747c4369 - updated to 0.9.0:
* few public headers were renamed to follow common schema
  * cve and cce modules are not build by default -> these modules are not
    utilized by oscap tool and thus untested.
  * --enable-bindings configure option was split into --enable-python and
    support of SCAP datastream support was improved
  * plus fixes in OVAL and XCCDF modules. oscap tool reports support of
    XCCDF 1.2 and OVAL 5.10.1

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=55
2012-09-28 07:55:55 +00:00
Ismail Dönmez
1ac17a27a7 Accepting request 134109 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/134109
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=8
2012-09-14 10:32:43 +00:00
5a6f8aeeca - updated to 0.8.5:
- added rpmverifypackage probe
  - added initial support for source and result datastreams
  - added xccdf 1.2 dc-status support
  - several probes were updated to conform to OVAL 5.10.1
  - bug fixes
  This release is able to evaluate the DISA STIG content.

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=53
2012-08-29 07:56:51 +00:00
Ismail Dönmez
148d0a09d8 Accepting request 130325 from security
- updated to 0.8.4
  - added OVAL schemas 5.9, 5.10.1
  - alloc.h is no more public api
  - bug fixes

OBS-URL: https://build.opensuse.org/request/show/130325
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=7
2012-08-07 19:50:50 +00:00
6fcae95a10 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=51 2012-08-07 12:59:02 +00:00
bb02132874 - updated to 0.8.4
- added OVAL schemas 5.9, 5.10.1
  - alloc.h is no more public api
  - bug fixes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=50
2012-08-07 12:58:20 +00:00
Stephan Kulow
0f0b560bde Accepting request 129892 from security
- Fix schema_version of scap-rhel6-oval.xml (to 5.8) (forwarded request 129774 from dmacvicar)

OBS-URL: https://build.opensuse.org/request/show/129892
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=6
2012-08-04 19:44:36 +00:00
eb783a4d92 Accepting request 129774 from home:dmacvicar:branches:security
- Fix schema_version of scap-rhel6-oval.xml (to 5.8)

OBS-URL: https://build.opensuse.org/request/show/129774
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=48
2012-08-04 07:37:50 +00:00
Stephan Kulow
4fc01b8bfd Accepting request 129599 from security
- Updated to 0.8.3
  - added XCCDF 1.2 schemas
  - changed XCCDF report format
  - updated schemas for OVAL 5.10
  - added additional OVAL schemas - 5.3, 5.4, 5.5, 5.6, 5.7
  - multi version support for XCCDF and OVAL
  - a schema version of an imported and exported content is same
  - added rpmverifyfile probe
  - results are validated only if an OSCAP_FULL_VALIDATION variable is set
  - bug fixes

- add OVAL/XCCDF content based on yast2-security checks
  and set them as the default content (using symlinks)

- require libnl-devel on older SUSE version

OBS-URL: https://build.opensuse.org/request/show/129599
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=5
2012-08-04 07:22:55 +00:00
6b9bdd29b4 rpmverify as wildcard, as older versions dont have it
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=46
2012-08-01 15:30:01 +00:00
687c3ed211 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=45 2012-08-01 12:27:52 +00:00
a40bde38a5 Accepting request 129551 from home:dmacvicar:branches:security
- add OVAL/XCCDF content based on yast2-security checks
  and set them as the default content (using symlinks)

OBS-URL: https://build.opensuse.org/request/show/129551
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=44
2012-08-01 11:50:20 +00:00
ffaa244002 obsoleted
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=43
2012-08-01 09:56:34 +00:00
35e0d41701 - Updated to 0.8.3
- added XCCDF 1.2 schemas
  - changed XCCDF report format
  - updated schemas for OVAL 5.10
  - added additional OVAL schemas - 5.3, 5.4, 5.5, 5.6, 5.7
  - multi version support for XCCDF and OVAL
  - a schema version of an imported and exported content is same
  - added rpmverifyfile probe
  - results are validated only if an OSCAP_FULL_VALIDATION variable is set
  - bug fixes
- require libnl-devel on older SUSE version

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=42
2012-08-01 09:43:48 +00:00
e4923cff48 0.8.3
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=41
2012-08-01 09:43:26 +00:00
Ismail Dönmez
a948821521 Accepting request 129176 from security
Fix build with missing gets declaration (glibc 2.16) (forwarded request 129169 from a_jaeger)

OBS-URL: https://build.opensuse.org/request/show/129176
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=4
2012-07-30 09:17:49 +00:00
Roman Drahtmueller
dfd5d8718a Accepting request 129169 from home:a_jaeger:FactoryFix
Fix build with missing gets declaration (glibc 2.16)

OBS-URL: https://build.opensuse.org/request/show/129169
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=39
2012-07-28 14:30:29 +00:00
Stephan Kulow
263a6c5451 Accepting request 113792 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/113792
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=2
2012-04-17 05:47:26 +00:00
50ce8ceb61 - Updated to 0.8.2
- XCCDF check-import support
  - XSLT transformation for XCCDF 1.1 to 1.2 migration
  - SCE reports now optionally use the new check-import functionality
    and don't need separate SCE result files
  - bug fixes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=37
2012-03-30 14:22:49 +00:00
72f31ad752 Accepting request 110881 from home:mcalmer:branches:security
- require libnl-devel on older SUSE version

OBS-URL: https://build.opensuse.org/request/show/110881
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=36
2012-03-26 09:33:19 +00:00
Stephan Kulow
d4f34270a5 Accepting request 110151 from security
new package for factory inclusion

OBS-URL: https://build.opensuse.org/request/show/110151
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=1
2012-03-22 11:37:31 +00:00
51f0008129 Accepting request 109970 from home:babelworx:ldig:branches:security
license update: LGPL-2.1+
There is no GPL-3.0+ in this package. Also, the Fedora spec file states LGPL-2.1+. This appears to be the correct license

OBS-URL: https://build.opensuse.org/request/show/109970
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=34
2012-03-20 12:49:59 +00:00
61c9e71bfd x
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=33
2012-03-01 16:20:51 +00:00
15e3713e02 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=32 2012-03-01 14:08:33 +00:00
28267a6b70 also capability and unixODBC,
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=31
2012-03-01 12:24:10 +00:00
f0343239d8 selinux added
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=30
2012-03-01 10:55:49 +00:00
c915d712fe add gconf2-devel libblkid-devel
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=29
2012-03-01 10:47:23 +00:00
162fd106f2 libacl-devel
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=28
2012-03-01 10:41:51 +00:00
9fe0ccacc9 x
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=27
2012-03-01 10:31:24 +00:00
bdccc7884c x
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=26
2012-03-01 10:03:45 +00:00
eb7bf75cec groups, changelog
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=25
2012-03-01 09:27:11 +00:00
0a033139d9 - some cleanups to make it factory acceptable
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=24
2012-02-29 21:47:30 +00:00
46d215b316 correct libnl
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=23
2012-02-29 15:51:50 +00:00
c3a66c5a42 x
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=22
2012-02-29 15:30:34 +00:00
1c3e9a59b1 Accepting request 107462 from home:mcalmer:branches:security
- Update to 0.8.1
- introduce Script Check Engine
- Added an OVAL Directives schema to allow for a tool
  to supply a set of directives to more easily specify
  desired results content.
- Enhanced OVAL Results directives to allow for more flexibility
  in allowed results content
- added new OVAL objects(all OVAL 5.8 objects are covered now)
- update dpkgprobe
- all issues reported by coverity are fixed
- add capability to export OVAL Variables from XCCDF
- added cvss score calculator from vector

OBS-URL: https://build.opensuse.org/request/show/107462
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=21
2012-02-28 22:36:15 +00:00
dbf1cb368a doesnt build without probes
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=20
2011-05-02 15:28:19 +00:00
ae8b9cb11a x
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=19
2011-05-02 14:58:45 +00:00
9e79ec22b3 x
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=18
2011-05-02 14:17:42 +00:00
4aed793e33 x
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=17
2011-05-02 12:33:13 +00:00
1606a1b8e3 added libxslt-devel
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=16
2011-05-02 12:24:06 +00:00
41d8fe29d9 - Updated to 0.7.2
- OVAL 5.7 is supported
  - content for Red Hat Enterprise Linux 6.1 - draft
  - oscap tool enable user to skip content validation before evaluation
  - bugfixes

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=15
2011-04-29 13:56:47 +00:00
073bc92874 x
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=14
2011-04-29 13:56:22 +00:00
Stephan Kleine
dd56af082d OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=13 2010-07-05 00:20:43 +00:00
Stephan Kleine
6740ce45f0 - Update to 0.5.12
- Proper subpackages added

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=12
2010-07-05 00:18:40 +00:00
e4733e0fd4 make check doesnt
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=11
2009-11-19 16:58:39 +00:00
c2adaea72a -findlang
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=10
2009-11-19 16:22:37 +00:00
a311297e8d disable probes for now as they do not build.
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=9
2009-11-19 16:00:57 +00:00
040e4908a7 disable silence
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=8
2009-11-19 15:28:19 +00:00
48dd2577e9 assneeded=0
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=7
2009-11-19 15:10:06 +00:00
d38ef06fda autoreconf, add pkg-config
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=6
2009-11-19 14:43:35 +00:00
b3cb7df1c5 fix asneeded
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=5
2009-11-19 14:31:51 +00:00
e0bae6d4ed swig-devel does not exist
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=4
2009-11-19 14:19:05 +00:00
643df568a0 more buildreqs
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=3
2009-11-19 14:14:08 +00:00
8c865970ba +python-devel
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=2
2009-11-19 13:52:00 +00:00
0c69aca216 initial 0.5.5 import
- open SCAP protocol implementation

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=1
2009-11-19 12:51:01 +00:00
3 changed files with 0 additions and 342 deletions

View File

@ -1,220 +0,0 @@
From 48685f390b865f6edd7df8dba955c03dff6045e8 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Klaus=20K=C3=A4mpf?= <kkaempf@suse.de>
Date: Tue, 28 Mar 2023 12:02:43 +0200
Subject: [PATCH 1/5] Add openSUSE cpe links
---
cpe/openscap-cpe-dict.xml | 24 +++++++
cpe/openscap-cpe-oval.xml | 127 ++++++++++++++++++++++++++++++++++++++
2 files changed, 151 insertions(+)
Index: openscap-1.3.10/cpe/openscap-cpe-dict.xml
===================================================================
--- openscap-1.3.10.orig/cpe/openscap-cpe-dict.xml
+++ openscap-1.3.10/cpe/openscap-cpe-dict.xml
@@ -53,4 +53,32 @@
<title xml:lang="en-us">Fedora 35</title>
<check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="openscap-cpe-oval.xml">oval:org.open-scap.cpe.fedora:def:35</check>
</cpe-item>
+ <cpe-item name="cpe:/o:opensuse:leap:15.1">
+ <title xml:lang="en-us">openSUSE Leap 15.1</title>
+ <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="openscap-cpe-oval.xml">oval:org.open-scap.cpe.opensuse:def:151</check>
+ </cpe-item>
+ <cpe-item name="cpe:/o:opensuse:leap:15.2">
+ <title xml:lang="en-us">openSUSE Leap 15.2</title>
+ <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="openscap-cpe-oval.xml">oval:org.open-scap.cpe.opensuse:def:152</check>
+ </cpe-item>
+ <cpe-item name="cpe:/o:opensuse:leap:15.3">
+ <title xml:lang="en-us">openSUSE Leap 15.3</title>
+ <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="openscap-cpe-oval.xml">oval:org.open-scap.cpe.opensuse:def:153</check>
+ </cpe-item>
+ <cpe-item name="cpe:/o:opensuse:leap:15.4">
+ <title xml:lang="en-us">openSUSE Leap 15.4</title>
+ <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="openscap-cpe-oval.xml">oval:org.open-scap.cpe.opensuse:def:154</check>
+ </cpe-item>
+ <cpe-item name="cpe:/o:opensuse:leap:15.5">
+ <title xml:lang="en-us">openSUSE Leap 15.5</title>
+ <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="openscap-cpe-oval.xml">oval:org.open-scap.cpe.opensuse:def:155</check>
+ </cpe-item>
+ <cpe-item name="cpe:/o:opensuse:leap:15.6">
+ <title xml:lang="en-us">openSUSE Leap 15.6</title>
+ <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="openscap-cpe-oval.xml">oval:org.open-scap.cpe.opensuse:def:156</check>
+ </cpe-item>
+ <cpe-item name="cpe:/o:opensuse:tumbleweed">
+ <title xml:lang="en-us">openSUSE Tumbleweed</title>
+ <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="openscap-cpe-oval.xml">oval:org.open-scap.cpe.opensuse:def:9999</check>
+ </cpe-item>
</cpe-list>
Index: openscap-1.3.10/cpe/openscap-cpe-oval.xml
===================================================================
--- openscap-1.3.10.orig/cpe/openscap-cpe-oval.xml
+++ openscap-1.3.10/cpe/openscap-cpe-oval.xml
@@ -690,6 +690,97 @@
<criterion comment="openSUSE Leap 15.0 is installed" test_ref="oval:org.open-scap.cpe.opensuse:tst:150"/>
</criteria>
</definition>
+ <definition class="inventory" id="oval:org.open-scap.cpe.opensuse:def:151" version="1">
+ <metadata>
+ <title>openSUSE Leap 15.1</title>
+ <affected family="unix">
+ <platform>openSUSE Leap 15.1</platform>
+ </affected>
+ <reference ref_id="cpe:/o:opensuse:leap:15.1" source="CPE"/>
+ <description>The operating system installed on the system is openSUSE Leap 15.1</description>
+ </metadata>
+ <criteria>
+ <criterion comment="openSUSE Leap 15.1 is installed" test_ref="oval:org.open-scap.cpe.opensuse:tst:151"/>
+ </criteria>
+ </definition>
+ <definition class="inventory" id="oval:org.open-scap.cpe.opensuse:def:152" version="1">
+ <metadata>
+ <title>openSUSE Leap 15.2</title>
+ <affected family="unix">
+ <platform>openSUSE Leap 15.2</platform>
+ </affected>
+ <reference ref_id="cpe:/o:opensuse:leap:15.2" source="CPE"/>
+ <description>The operating system installed on the system is openSUSE Leap 15.2</description>
+ </metadata>
+ <criteria>
+ <criterion comment="openSUSE Leap 15.2 is installed" test_ref="oval:org.open-scap.cpe.opensuse:tst:152"/>
+ </criteria>
+ </definition>
+ <definition class="inventory" id="oval:org.open-scap.cpe.opensuse:def:153" version="1">
+ <metadata>
+ <title>openSUSE Leap 15.3</title>
+ <affected family="unix">
+ <platform>openSUSE Leap 15.3</platform>
+ </affected>
+ <reference ref_id="cpe:/o:opensuse:leap:15.3" source="CPE"/>
+ <description>The operating system installed on the system is openSUSE Leap 15.3</description>
+ </metadata>
+ <criteria>
+ <criterion comment="openSUSE Leap 15.3 is installed" test_ref="oval:org.open-scap.cpe.opensuse:tst:153"/>
+ </criteria>
+ </definition>
+ <definition class="inventory" id="oval:org.open-scap.cpe.opensuse:def:154" version="1">
+ <metadata>
+ <title>openSUSE Leap 15.4</title>
+ <affected family="unix">
+ <platform>openSUSE Leap 15.4</platform>
+ </affected>
+ <reference ref_id="cpe:/o:opensuse:leap:15.4" source="CPE"/>
+ <description>The operating system installed on the system is openSUSE Leap 15.4</description>
+ </metadata>
+ <criteria>
+ <criterion comment="openSUSE Leap 15.4 is installed" test_ref="oval:org.open-scap.cpe.opensuse:tst:154"/>
+ </criteria>
+ </definition>
+ <definition class="inventory" id="oval:org.open-scap.cpe.opensuse:def:155" version="1">
+ <metadata>
+ <title>openSUSE Leap 15.5</title>
+ <affected family="unix">
+ <platform>openSUSE Leap 15.5</platform>
+ </affected>
+ <reference ref_id="cpe:/o:opensuse:leap:15.5" source="CPE"/>
+ <description>The operating system installed on the system is openSUSE Leap 15.5</description>
+ </metadata>
+ <criteria>
+ <criterion comment="openSUSE Leap 15.5 is installed" test_ref="oval:org.open-scap.cpe.opensuse:tst:155"/>
+ </criteria>
+ </definition>
+ <definition class="inventory" id="oval:org.open-scap.cpe.opensuse:def:156" version="1">
+ <metadata>
+ <title>openSUSE Leap 15.6</title>
+ <affected family="unix">
+ <platform>openSUSE Leap 15.6</platform>
+ </affected>
+ <reference ref_id="cpe:/o:opensuse:leap:15.6" source="CPE"/>
+ <description>The operating system installed on the system is openSUSE Leap 15.6</description>
+ </metadata>
+ <criteria>
+ <criterion comment="openSUSE Leap 15.6 is installed" test_ref="oval:org.open-scap.cpe.opensuse:tst:156"/>
+ </criteria>
+ </definition>
+ <definition class="inventory" id="oval:org.open-scap.cpe.opensuse:def:9999" version="1">
+ <metadata>
+ <title>openSUSE Tumbleweed</title>
+ <affected family="unix">
+ <platform>openSUSE Tumbleweed</platform>
+ </affected>
+ <reference ref_id="cpe:/o:opensuse:tumbleweed" source="CPE"/>
+ <description>The operating system installed on the system is openSUSE Tumbleweed</description>
+ </metadata>
+ <criteria>
+ <criterion comment="openSUSE Tumbleweed is installed" test_ref="oval:org.open-scap.cpe.opensuse:tst:9999"/>
+ </criteria>
+ </definition>
<definition class="inventory" id="oval:org.open-scap.cpe.wrlinux:def:1" version="1" >
<metadata>
<title>Wind River Linux</title>
@@ -1087,6 +1178,41 @@
<object object_ref="oval:org.open-scap.cpe.openSUSE-release:obj:1"/>
<state state_ref="oval:org.open-scap.cpe.opensuse:ste:150"/>
</rpminfo_test>
+ <rpminfo_test check_existence="at_least_one_exists" id="oval:org.open-scap.cpe.opensuse:tst:151" version="2" check="at least one" comment="openSUSE-release is version 15.1"
+ xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <object object_ref="oval:org.open-scap.cpe.openSUSE-release:obj:1"/>
+ <state state_ref="oval:org.open-scap.cpe.opensuse:ste:151"/>
+ </rpminfo_test>
+ <rpminfo_test check_existence="at_least_one_exists" id="oval:org.open-scap.cpe.opensuse:tst:152" version="2" check="at least one" comment="openSUSE-release is version 15.2"
+ xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <object object_ref="oval:org.open-scap.cpe.openSUSE-release:obj:1"/>
+ <state state_ref="oval:org.open-scap.cpe.opensuse:ste:152"/>
+ </rpminfo_test>
+ <rpminfo_test check_existence="at_least_one_exists" id="oval:org.open-scap.cpe.opensuse:tst:153" version="2" check="at least one" comment="openSUSE-release is version 15.3"
+ xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <object object_ref="oval:org.open-scap.cpe.openSUSE-release:obj:1"/>
+ <state state_ref="oval:org.open-scap.cpe.opensuse:ste:153"/>
+ </rpminfo_test>
+ <rpminfo_test check_existence="at_least_one_exists" id="oval:org.open-scap.cpe.opensuse:tst:154" version="2" check="at least one" comment="openSUSE-release is version 15.4"
+ xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <object object_ref="oval:org.open-scap.cpe.openSUSE-release:obj:1"/>
+ <state state_ref="oval:org.open-scap.cpe.opensuse:ste:154"/>
+ </rpminfo_test>
+ <rpminfo_test check_existence="at_least_one_exists" id="oval:org.open-scap.cpe.opensuse:tst:155" version="2" check="at least one" comment="openSUSE-release is version 15.5"
+ xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <object object_ref="oval:org.open-scap.cpe.openSUSE-release:obj:1"/>
+ <state state_ref="oval:org.open-scap.cpe.opensuse:ste:155"/>
+ </rpminfo_test>
+ <rpminfo_test check_existence="at_least_one_exists" id="oval:org.open-scap.cpe.opensuse:tst:156" version="2" check="at least one" comment="openSUSE-release is version 15.6"
+ xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <object object_ref="oval:org.open-scap.cpe.openSUSE-release:obj:1"/>
+ <state state_ref="oval:org.open-scap.cpe.opensuse:ste:156"/>
+ </rpminfo_test>
+ <rpminfo_test check_existence="at_least_one_exists" id="oval:org.open-scap.cpe.opensuse:tst:9999" version="2" check="at least one" comment="openSUSE-release is openSUSE Tumbleweed"
+ xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <object object_ref="oval:org.open-scap.cpe.openSUSE-release:obj:1"/>
+ <state state_ref="oval:org.open-scap.cpe.opensuse:ste:9999"/>
+ </rpminfo_test>
<family_test check_existence="at_least_one_exists" id="oval:org.open-scap.cpe.wrlinux:tst:1" version="1" check="only one"
comment="Installed operating system is part of the Unix family."
xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
@@ -1415,6 +1541,28 @@
<rpminfo_state id="oval:org.open-scap.cpe.opensuse:ste:150" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<version operation="pattern match">^15.0$</version>
</rpminfo_state>
+ <rpminfo_state id="oval:org.open-scap.cpe.opensuse:ste:151" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <version operation="pattern match">^15.1$</version>
+ </rpminfo_state>
+ <rpminfo_state id="oval:org.open-scap.cpe.opensuse:ste:152" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <version operation="pattern match">^15.2$</version>
+ </rpminfo_state>
+ <rpminfo_state id="oval:org.open-scap.cpe.opensuse:ste:153" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <version operation="pattern match">^15.3$</version>
+ </rpminfo_state>
+ <rpminfo_state id="oval:org.open-scap.cpe.opensuse:ste:154" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <version operation="pattern match">^15.4$</version>
+ </rpminfo_state>
+ <rpminfo_state id="oval:org.open-scap.cpe.opensuse:ste:155" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <version operation="pattern match">^15.5$</version>
+ </rpminfo_state>
+ <rpminfo_state id="oval:org.open-scap.cpe.opensuse:ste:156" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <version operation="pattern match">^15.6$</version>
+ </rpminfo_state>
+ <rpminfo_state id="oval:org.open-scap.cpe.opensuse:ste:9999" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <!-- matching for timestamp -->
+ <version operation="pattern match">^\d{8}$</version>
+ </rpminfo_state>
<textfilecontent54_state
id="oval:org.open-scap.cpe.wrlinux-release:ste:8"
comment="Check the /etc/wrlinux-release file for VERSION 8 specification."

View File

@ -1,119 +0,0 @@
From 8ef63951ad8e87a65cb252601a03bd958631f94c Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Klaus=20K=C3=A4mpf?= <kkaempf@suse.de>
Date: Tue, 28 Mar 2023 12:04:28 +0200
Subject: [PATCH 2/5] Add SUSE cpe links
---
cpe/openscap-cpe-dict.xml | 16 +++++++++++++++
cpe/openscap-cpe-oval.xml | 42 +++++++++++++++++++++++++++++++++++++++
2 files changed, 58 insertions(+)
diff --git a/cpe/openscap-cpe-dict.xml b/cpe/openscap-cpe-dict.xml
index cf52bee..85917a8 100644
--- a/cpe/openscap-cpe-dict.xml
+++ b/cpe/openscap-cpe-dict.xml
@@ -77,4 +77,20 @@
<title xml:lang="en-us">openSUSE Tumbleweed</title>
<check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="openscap-cpe-oval.xml">oval:org.open-scap.cpe.opensuse:def:9999</check>
</cpe-item>
+ <cpe-item name="cpe:/o:suse:sles:12">
+ <title xml:lang="en-us">SUSE Linux Enterprise Server 12</title>
+ <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="openscap-cpe-oval.xml">oval:org.open-scap.cpe.sles:def:12</check>
+ </cpe-item>
+ <cpe-item name="cpe:/o:suse:sled:12">
+ <title xml:lang="en-us">SUSE Linux Enterprise Desktop 12</title>
+ <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="openscap-cpe-oval.xml">oval:org.open-scap.cpe.sled:def:12</check>
+ </cpe-item>
+ <cpe-item name="cpe:/o:suse:sles:15">
+ <title xml:lang="en-us">SUSE Linux Enterprise Server 15</title>
+ <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="openscap-cpe-oval.xml">oval:org.open-scap.cpe.sles:def:15</check>
+ </cpe-item>
+ <cpe-item name="cpe:/o:suse:sled:15">
+ <title xml:lang="en-us">SUSE Linux Enterprise Desktop 15</title>
+ <check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="openscap-cpe-oval.xml">oval:org.open-scap.cpe.sled:def:15</check>
+ </cpe-item>
</cpe-list>
diff --git a/cpe/openscap-cpe-oval.xml b/cpe/openscap-cpe-oval.xml
index a402c7f..531297b 100644
--- a/cpe/openscap-cpe-oval.xml
+++ b/cpe/openscap-cpe-oval.xml
@@ -768,6 +768,32 @@
<criterion comment="openSUSE Tumbleweed is installed" test_ref="oval:org.open-scap.cpe.opensuse:tst:9999"/>
</criteria>
</definition>
+ <definition class="inventory" id="oval:org.open-scap.cpe.sles:def:15" version="1">
+ <metadata>
+ <title>SUSE Linux Enterprise Server 15</title>
+ <affected family="unix">
+ <platform>SUSE Linux Enterprise Server 15</platform>
+ </affected>
+ <reference ref_id="cpe:/o:suse:sles:15" source="CPE"/>
+ <description>The operating system installed on the system is SUSE Linux Enterprise Server 15</description>
+ </metadata>
+ <criteria>
+ <criterion comment="SLES 15 is installed" test_ref="oval:org.open-scap.cpe.sles:tst:15"/>
+ </criteria>
+ </definition>
+ <definition class="inventory" id="oval:org.open-scap.cpe.sled:def:15" version="1">
+ <metadata>
+ <title>SUSE Linux Enterprise Desktop 15</title>
+ <affected family="unix">
+ <platform>SUSE Linux Enterprise Desktop 15</platform>
+ </affected>
+ <reference ref_id="cpe:/o:suse:sled:15" source="CPE"/>
+ <description>The operating system installed on the system is SUSE Linux Enterprise Desktop 15</description>
+ </metadata>
+ <criteria>
+ <criterion comment="SLED 15 is installed" test_ref="oval:org.open-scap.cpe.sled:tst:15"/>
+ </criteria>
+ </definition>
<definition class="inventory" id="oval:org.open-scap.cpe.wrlinux:def:1" version="1" >
<metadata>
<title>Wind River Linux</title>
@@ -1110,6 +1136,11 @@
<object object_ref="oval:org.open-scap.cpe.sles-release:obj:1"/>
<state state_ref="oval:org.open-scap.cpe.sles:ste:12"/>
</rpminfo_test>
+ <rpminfo_test check_existence="at_least_one_exists" id="oval:org.open-scap.cpe.sles:tst:15" version="1" check="at least one" comment="sles-release is version 15"
+ xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <object object_ref="oval:org.open-scap.cpe.sles-release:obj:1"/>
+ <state state_ref="oval:org.open-scap.cpe.sles:ste:15"/>
+ </rpminfo_test>
<rpminfo_test check_existence="at_least_one_exists" id="oval:org.open-scap.cpe.sled:tst:10" version="1" check="at least one" comment="sled-release is version 10"
xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:org.open-scap.cpe.sled-release:obj:1"/>
@@ -1125,6 +1156,11 @@
<object object_ref="oval:org.open-scap.cpe.sled-release:obj:1"/>
<state state_ref="oval:org.open-scap.cpe.sled:ste:12"/>
</rpminfo_test>
+ <rpminfo_test check_existence="at_least_one_exists" id="oval:org.open-scap.cpe.sled:tst:15" version="1" check="at least one" comment="sled-release is version 15"
+ xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <object object_ref="oval:org.open-scap.cpe.sled-release:obj:1"/>
+ <state state_ref="oval:org.open-scap.cpe.sled:ste:15"/>
+ </rpminfo_test>
<rpminfo_test check_existence="at_least_one_exists" id="oval:org.open-scap.cpe.opensuse:tst:1" version="1" check="at least one" comment="openSUSE-release is version 11.4"
xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:org.open-scap.cpe.openSUSE-release:obj:1"/>
@@ -1490,6 +1526,9 @@
<rpminfo_state id="oval:org.open-scap.cpe.sles:ste:12" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<version operation="pattern match">^12($|[^\d])</version>
</rpminfo_state>
+ <rpminfo_state id="oval:org.open-scap.cpe.sles:ste:15" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <version operation="pattern match">^15($|[^\d])</version>
+ </rpminfo_state>
<rpminfo_state id="oval:org.open-scap.cpe.sled:ste:10" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<version operation="pattern match">^10($|[^\d])</version>
</rpminfo_state>
@@ -1499,6 +1538,9 @@
<rpminfo_state id="oval:org.open-scap.cpe.sled:ste:12" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<version operation="pattern match">^12($|[^\d])</version>
</rpminfo_state>
+ <rpminfo_state id="oval:org.open-scap.cpe.sled:ste:15" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
+ <version operation="pattern match">^15($|[^\d])</version>
+ </rpminfo_state>
<rpminfo_state id="oval:org.open-scap.cpe.opensuse:ste:2" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<name operation="pattern match">^openSUSE-release</name>
</rpminfo_state>
--
2.40.0

BIN
openscap-1.3.10.tar.gz (Stored with Git LFS)

Binary file not shown.