SHA256
1
0
forked from pool/openscap
Commit Graph

302 Commits

Author SHA256 Message Date
Dominique Leuenberger
a537e6b3c5 Accepting request 800232 from security
(forwarded request 800231 from msmeissn)

OBS-URL: https://build.opensuse.org/request/show/800232
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=66
2020-05-05 16:56:04 +00:00
e32b796185 Accepting request 800231 from home:msmeissn:branches:security
OBS-URL: https://build.opensuse.org/request/show/800231
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=249
2020-05-05 06:22:29 +00:00
0cb0407eba Accepting request 799976 from home:msmeissn:branches:security
- openscap 1.3.3. Notable improvements in this release:
  - a Python script that can be used for CLI tailoring (autotailor) (thank you, Matěj Týč);
  - timezone for XCCDF TestResult start and end time (thank you, Jan Černý);
  - new yamlfilecontent independent probe (draft implementation),
    see the proposal https://github.com/OVAL-Community/OVAL/issues/91
    for additional information.
There are other changes as well, here is the list:
  - Introduced `urn:xccdf:fix:script:kubernetes` fix type in XCCDF;
  - Added ability to generate `machineconfig` fix;
  - Detect ambiguous scan target (utils/oscap-podman);
  - Fixed #170: The rpmverifyfile probe can't verify files from '/bin' directory;
  - The data system_info probe return for offline and online modes is consistent and actual;
  - Prevent crashes when complicated regexes are executed in textfilecontent58 probe;
  - Fixed #1512: Severity refinement lost in generated guide;
  - Fixed #1453: Pointer lost in Swig API;
  - Evaluation Characteristics of the XCCDF report are now consistent with OVAL entities;
    from system_info probe;
  - Fixed filepath pattern matching in offline mode in textfilecontent58 probe;
  - Fixed infinite recursion in systemdunitdependency probe;
  - Fixed the case when CMake couldn't find libacl or xattr.h.
- dropped 0001-Do-not-use-C-keyword-operator-as-a-function-paramete.patch: upstream

OBS-URL: https://build.opensuse.org/request/show/799976
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=248
2020-05-04 18:33:17 +00:00
Dominique Leuenberger
707d7498a2 Accepting request 788259 from security
- Add upstream patch to fix the scap-workbench build:
  * 0001-Do-not-use-C-keyword-operator-as-a-function-paramete.patch (forwarded request 788252 from cgiboudeaux)

OBS-URL: https://build.opensuse.org/request/show/788259
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=65
2020-03-25 22:48:03 +00:00
d3967e180d Accepting request 788252 from home:cgiboudeaux:branches:security
- Add upstream patch to fix the scap-workbench build:
  * 0001-Do-not-use-C-keyword-operator-as-a-function-paramete.patch

OBS-URL: https://build.opensuse.org/request/show/788252
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=246
2020-03-25 15:53:05 +00:00
Dominique Leuenberger
8b31c07db5 Accepting request 766084 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/766084
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=64
2020-01-21 20:00:33 +00:00
OBS User buildservice-autocommit
8b62f39da5 Accepting request 764315 from security
baserev update by copy to link target

OBS-URL: https://build.opensuse.org/request/show/764315
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=244
2020-01-14 20:10:52 +00:00
Dominique Leuenberger
0907bf39f6 Accepting request 764315 from security
- openscap 1.3.1
  - the test suite and build scripts were improved to support Debian 10
  - offline mode has received some love with a set of dedicated tests and various fixes in OVAL probes;
  - the oscap-docker wrapper is no longer dependent on Atomic 
  - Python binding are now more robust 
  - HTML reports and guides, generated by the scanner, are now more accessible for non-visual rendering agents 
  - Support of multi-check rules has been improved across the whole workflow 
  There are other changes as well, here is the list:
  * New features
    - Offline mode support for environmentvariable58 probe
    - The oscap-docker wrapper is available without Atomic
  + Maintenance, bug fixes
    - Improved support of multi-check rules (report, remediations, console output)
    - Improved HTML report look and feel, including printed version
    - Less clutter in verbose mode output; some warnings and errors demoted to verbose mode levels
    - Probe rpmverifyfile uses and returns canonical paths
    - Improved a11y of HTML reports and guides
    - Fixes and improvements for SWIG Python bindings
    - #1403 fixed: Scanner would not apply remediation for multicheck rules (verbosity)
    - Fixed URL link mechanism for Red Hat Errata
    - New STIG Viewer URI: public.cyber.mil
    - Probe selinuxsecuritycontext would not check if SELinux is enabled
    - Scanner would provide information about unsupported OVAL objects
    - Added more tests for offline mode (probes, remediation)
    - #528 fixed: Eval SCE script when /tmp is in mode noexec
    - #1173, RHBZ#1603347 fixed: Double chdir/chroot in probe rpmverifypackage

OBS-URL: https://build.opensuse.org/request/show/764315
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=63
2020-01-14 20:10:52 +00:00
OBS User buildservice-autocommit
8b06e57aa6 Updating link to change in openSUSE:Factory/openscap revision 63.0
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=534cb10161730fa838be45c9b7c56b59
2020-01-14 20:10:52 +00:00
440912201d - switch back to official release
- openscap 1.3.2

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=243
2020-01-14 14:09:00 +00:00
43fa6294ff - openscap 1.3.1
- the test suite and build scripts were improved to support Debian 10
  - offline mode has received some love with a set of dedicated tests and various fixes in OVAL probes;
  - the oscap-docker wrapper is no longer dependent on Atomic 
  - Python binding are now more robust 
  - HTML reports and guides, generated by the scanner, are now more accessible for non-visual rendering agents 
  - Support of multi-check rules has been improved across the whole workflow 
  There are other changes as well, here is the list:
  * New features
    - Offline mode support for environmentvariable58 probe
    - The oscap-docker wrapper is available without Atomic
  + Maintenance, bug fixes
    - Improved support of multi-check rules (report, remediations, console output)
    - Improved HTML report look and feel, including printed version
    - Less clutter in verbose mode output; some warnings and errors demoted to verbose mode levels
    - Probe rpmverifyfile uses and returns canonical paths
    - Improved a11y of HTML reports and guides
    - Fixes and improvements for SWIG Python bindings
    - #1403 fixed: Scanner would not apply remediation for multicheck rules (verbosity)
    - Fixed URL link mechanism for Red Hat Errata
    - New STIG Viewer URI: public.cyber.mil
    - Probe selinuxsecuritycontext would not check if SELinux is enabled
    - Scanner would provide information about unsupported OVAL objects
    - Added more tests for offline mode (probes, remediation)
    - #528 fixed: Eval SCE script when /tmp is in mode noexec
    - #1173, RHBZ#1603347 fixed: Double chdir/chroot in probe rpmverifypackage

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=242
2020-01-14 13:44:42 +00:00
Dominique Leuenberger
07bbae3c10 Accepting request 763678 from security
- temporary openscap 1.3.1 git snapshot
  - make it build with new RPM  (bsc#1160720)

- use distribution-release instead of dummy-release

OBS-URL: https://build.opensuse.org/request/show/763678
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=62
2020-01-12 22:25:36 +00:00
31b86a44ed OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=240 2020-01-12 18:07:15 +00:00
57e2d03c9f Accepting request 763602 from home:msmeissn:branches:security
- temporary openscap 1.3.1 git snapshot
  - make it build with new RPM  (bsc#1160720)

OBS-URL: https://build.opensuse.org/request/show/763602
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=239
2020-01-12 12:37:02 +00:00
c92b50e50e - openscap-new-rpm.patch: use the recent RPM defines, some old
ones got obsoleted

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=238
2020-01-11 17:24:43 +00:00
af55f05af1 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=237 2020-01-11 09:34:55 +00:00
5bfd648668 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=236 2020-01-11 09:27:40 +00:00
dfe7310c7f - use distribution-release instead of dummy-release
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=235
2020-01-11 09:02:02 +00:00
2167e3e34e OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=234 2020-01-11 08:58:18 +00:00
Dominique Leuenberger
5ade1b57a0 Accepting request 709970 from security
OBS-URL: https://build.opensuse.org/request/show/709970
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=61
2019-06-14 18:43:03 +00:00
Robert Frohl
f7b7f9df1b Accepting request 709892 from home:rfrohl:branches:security
update openscap to version 1.3.1

OBS-URL: https://build.opensuse.org/request/show/709892
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=232
2019-06-14 12:32:39 +00:00
Dominique Leuenberger
99de27cad5 Accepting request 689029 from security
add missing obsoletes (forwarded request 688824 from rfrohl)

OBS-URL: https://build.opensuse.org/request/show/689029
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=60
2019-03-27 15:22:05 +00:00
96f998b11f Accepting request 688824 from home:rfrohl:branches:security
add missing obsoletes

OBS-URL: https://build.opensuse.org/request/show/688824
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=230
2019-03-27 09:30:35 +00:00
491045a433 Accepting request 688437 from home:iznogood:branches:security
- Drop gconf2-devel BuildRequires: It is not mandatory, so lets
  build without this obsolete package.
- Add pkgconfig(glib-2.0) and pkgconfig(gobject-2.0) BuildRequires:
  They are also optional, but not obsolete, and previously pulled
  in via gconf2-devel dependency, so lets build support for them.

OBS-URL: https://build.opensuse.org/request/show/688437
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=229
2019-03-27 09:29:58 +00:00
Dominique Leuenberger
41308542a9 Accepting request 653777 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/653777
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=59
2018-12-04 19:57:52 +00:00
afba4b9563 fixed %post %pre syntax
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=227
2018-11-27 07:18:16 +00:00
8c59323331 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=226 2018-11-22 10:56:58 +00:00
4d33f05db9 Accepting request 651059 from home:rfrohl:branches:security
- Update to openscap-1.3.0 
  - move to cmake
- improve unit test, planned for inclusion with 1.3.1
  - tests do no complete as of yet, still future work needed

OBS-URL: https://build.opensuse.org/request/show/651059
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=225
2018-11-22 10:48:01 +00:00
Yuchen Lin
102cbbd841 Accepting request 635251 from security
- openscap-xattr.patch: build against new libattr

OBS-URL: https://build.opensuse.org/request/show/635251
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=58
2018-09-13 10:11:29 +00:00
619b3160ac - openscap-xattr.patch: build against new libattr
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=223
2018-09-12 05:56:15 +00:00
Dominique Leuenberger
1ef6929acc Accepting request 614943 from security
- scap-yast2sec-xccdf.xml: remove platform cpe match, as it is impossible
  to match both opensuse and sles or official suse_linux_enterprise_server
  names at once. (bsc#1091040)

- openscap-1.2.17
  - New features
    - HTML Guide user experience improvements
    - New options in HTML report "Group By" menu
    - oscap-ssh supports --oval-results (issue #863)
  - Maintenance
    - Support comparing state record elements with item
    - Updated Bash completion
    - Make Bash role headers consistent with --help output
    - Fixed problems reported by Coverity (issue #909)
    - Fixed CVE schema to support 4 to 7 digits CVEs
    - Fix output of generated bash role missing fix message
    - Fix oscap-docker to clean up temporary image (RHBZ #1454637)
    - Fix Ansible remediations generation
    - Add a newline between ids in xccdf info (issue #968)
    - Fix unknown subtype handling in oval_subtype_parse (issue #986)
    - Outsourced the pthreads feature check and setup
    - Speed up in debug mode
    - Refactored the Python handling in build scripts
    - Prevent reading from host in offline mode (issue #1001)
    - Many probes use OWN offline mode
    - Improve offline mode logic in OVAL probes
    - Do not use chroot in system_info probe
    - Prevent a segfault in oscap_seterr on Solaris
    - Out of tree build is possible
    - Use chroot for RPM probes in offline mode

OBS-URL: https://build.opensuse.org/request/show/614943
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=57
2018-06-08 21:18:08 +00:00
3b96c1ea55 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=221 2018-06-07 13:25:46 +00:00
f38bdeafcc OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=220 2018-06-07 11:43:22 +00:00
4b365c9471 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=219 2018-06-07 11:36:14 +00:00
ce492ea8b2 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=218 2018-06-07 11:32:55 +00:00
26a9a39cb7 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=217 2018-06-07 11:26:19 +00:00
8e2deae43b OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=216 2018-06-07 09:11:44 +00:00
01a370031b - New features
- HTML Guide user experience improvements
    - New options in HTML report "Group By" menu
    - oscap-ssh supports --oval-results (issue #863)
  - Maintenance
    - Support comparing state record elements with item
    - Updated Bash completion
    - Make Bash role headers consistent with --help output
    - Fixed problems reported by Coverity (issue #909)
    - Fixed CVE schema to support 4 to 7 digits CVEs
    - Fix output of generated bash role missing fix message
    - Fix oscap-docker to clean up temporary image (RHBZ #1454637)
    - Fix Ansible remediations generation
    - Add a newline between ids in xccdf info (issue #968)
    - Fix unknown subtype handling in oval_subtype_parse (issue #986)
    - Outsourced the pthreads feature check and setup
    - Speed up in debug mode
    - Refactored the Python handling in build scripts
    - Prevent reading from host in offline mode (issue #1001)
    - Many probes use OWN offline mode
    - Improve offline mode logic in OVAL probes
    - Do not use chroot in system_info probe
    - Prevent a segfault in oscap_seterr on Solaris
    - Out of tree build is possible
    - Use chroot for RPM probes in offline mode
    - PEP8 accepts lines up to 99 characters
    - New configure parameter --with-oscap-temp-dir (issue #1016)
    - Fixed OVAL record elements namespace and SEXP conversion
    - Removed '\r' characters from help output (issue #1023)
    - Full Python 3 compatibility

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=215
2018-06-07 09:03:58 +00:00
4db5e7cc47 - scap-yast2sec-xccdf.xml: remove platform cpe match, as it is impossible
to match both opensuse and sles or official suse_linux_enterprise_server

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=214
2018-06-07 08:47:17 +00:00
29a0cf99ec - remove platform cpe match, as it is impossible to match
both opensuse and sles or official suse_linux_enterprise_server
  names at once. (bsc#1091040)

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=213
2018-06-07 08:47:03 +00:00
23a8401a21 - openscap-1.2.17
- New features                                                                                                                                                                             
    - HTML Guide user experience improvements                                                                                                                                                
    - New options in HTML report "Group By" menu                                                                                                                                             
    - oscap-ssh supports --oval-results (issue #863)                                                                                                                                         
  - Maintenance                                                                                                                                                                              
    - Support comparing state record elements with item                                                                                                                                      
    - Updated Bash completion                                                                                                                                                                
    - Make Bash role headers consistent with --help output                                                                                                                                   
    - Fixed problems reported by Coverity (issue #909)                                                                                                                                       
    - Fixed CVE schema to support 4 to 7 digits CVEs                                                                                                                                         
    - Fix output of generated bash role missing fix message                                                                                                                                  
    - Fix oscap-docker to clean up temporary image (RHBZ #1454637)                                                                                                                           
    - Fix Ansible remediations generation                                                                                                                                                    
    - Add a newline between ids in xccdf info (issue #968)                                                                                                                                   
    - Fix unknown subtype handling in oval_subtype_parse (issue #986)                                                                                                                        
    - Outsourced the pthreads feature check and setup                                                                                                                                        
    - Speed up in debug mode                                                                                                                                                                 
    - Refactored the Python handling in build scripts                                                                                                                                        
    - Prevent reading from host in offline mode (issue #1001)                                                                                                                                
    - Many probes use OWN offline mode                                                                                                                                                       
    - Improve offline mode logic in OVAL probes                                                                                                                                              
    - Do not use chroot in system_info probe                                                                                                                                                 
    - Prevent a segfault in oscap_seterr on Solaris                                                                                                                                          
    - Out of tree build is possible                                                                                                                                                          
    - Use chroot for RPM probes in offline mode                                                                                                                                              
    - PEP8 accepts lines up to 99 characters                                                                                                                                                 
    - New configure parameter --with-oscap-temp-dir (issue #1016)                                                                                                                            
    - Fixed OVAL record elements namespace and SEXP conversion                                                                                                                               
    - Removed '\r' characters from help output (issue #1023)

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=212
2018-05-29 09:47:57 +00:00
Dominique Leuenberger
6c9a9dd73b Accepting request 601561 from security
- openscap-new-suse.patch: handle SLE15 and openSUSE Leap 42.3 and 15.0
  (bsc#1091040) (forwarded request 601560 from msmeissn)

OBS-URL: https://build.opensuse.org/request/show/601561
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=56
2018-04-27 14:08:52 +00:00
27ae7c8e8c Accepting request 601560 from home:msmeissn:branches:security
- openscap-new-suse.patch: handle SLE15 and openSUSE Leap 42.3 and 15.0
  (bsc#1091040)

OBS-URL: https://build.opensuse.org/request/show/601560
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=210
2018-04-26 13:26:15 +00:00
Dominique Leuenberger
ee5ae20257 Accepting request 583006 from security
- Replace old $RPM_* shell vars. (forwarded request 583005 from jengelh)

OBS-URL: https://build.opensuse.org/request/show/583006
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=55
2018-03-07 09:35:14 +00:00
da4441b12a Accepting request 583005 from home:jengelh:branches:security
- Replace old $RPM_* shell vars.

OBS-URL: https://build.opensuse.org/request/show/583005
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=208
2018-03-05 15:23:38 +00:00
ddbf5be776 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=207 2018-03-05 13:31:32 +00:00
b38d166f2f OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=206 2018-03-05 13:13:41 +00:00
5a159d70e7 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=205 2018-03-05 13:06:12 +00:00
0510e1e4b7 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=204 2018-03-05 12:52:43 +00:00
b6d47735b2 - replace oscap-scan.init by oscap-scan.service, add a /usr/bin/oscap-scan
helper tool for this. (bsc#1083115)

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=203
2018-03-05 12:41:14 +00:00