SHA256
1
0
forked from pool/openscap
Commit Graph

291 Commits

Author SHA256 Message Date
Dominique Leuenberger
aa92ace405 Accepting request 1075297 from security
- remove _service confusion, we use final tarballs.

- Update to version 1.3.7:
  * openscap-1.3.7
  * Bump soname from 25.5.0 to 25.5.1
  * Bump version to openscap-1.3.7
  * Fix typos in docs
  * Remove a check for suspicious files
  * Add debian_evr_string tests to CMakeLists
  * Add a few unittests for debian_evr_string
  * Remove To be done
  * Move release guide to upstream
- add 0005-rename-requires-reqs-for-C-20-compatibility.patch
- rename patches
  openscap-opensuse-cpe.patch to 0001-Add-openSUSE-cpe-links.patch
  openscap-suse-cpe.patch to 0002-Add-SUSE-cpe-links.patch
  openscap-docker-add-suse.patch to 0003-Use-openSUSE-SUSE-cpe-links.patch
  oscap-remediate.service.in.patch to 0004-oscap-remediate-is-located-in-bindir.patch
- drop 0001-Use-correct-includes.patch (upstream)

OBS-URL: https://build.opensuse.org/request/show/1075297
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=82
2023-04-04 19:17:50 +00:00
19f9eddb36 - remove _service confusion, we use final tarballs.
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=282
2023-03-29 15:23:18 +00:00
0aea1b618f Accepting request 1075011 from home:kwk:branches:security
- Update to version 1.3.7:
  * openscap-1.3.7
  * Bump soname from 25.5.0 to 25.5.1
  * Bump version to openscap-1.3.7
  * Fix typos in docs
  * Remove a check for suspicious files
  * Add debian_evr_string tests to CMakeLists
  * Add a few unittests for debian_evr_string
  * Remove To be done
  * Move release guide to upstream
- add 0005-rename-requires-reqs-for-C-20-compatibility.patch
- rename patches
  openscap-opensuse-cpe.patch to 0001-Add-openSUSE-cpe-links.patch
  openscap-suse-cpe.patch to 0002-Add-SUSE-cpe-links.patch
  openscap-docker-add-suse.patch to 0003-Use-openSUSE-SUSE-cpe-links.patch
  oscap-remediate.service.in.patch to 0004-oscap-remediate-is-located-in-bindir.patch
- drop 0001-Use-correct-includes.patch (upstream)

OBS-URL: https://build.opensuse.org/request/show/1075011
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=281
2023-03-28 15:25:19 +00:00
Dominique Leuenberger
ea253578fa Accepting request 1060355 from security
- Require systemd for building, was pulled in before by indirect
  dependencies which don't exist anymore (forwarded request 1060354 from kukuk)

OBS-URL: https://build.opensuse.org/request/show/1060355
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=81
2023-01-23 17:32:26 +00:00
c38fca9782 Accepting request 1060354 from home:kukuk:cleanup
- Require systemd for building, was pulled in before by indirect
  dependencies which don't exist anymore

OBS-URL: https://build.opensuse.org/request/show/1060354
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=279
2023-01-23 08:38:59 +00:00
Dominique Leuenberger
fbbb5de23b Accepting request 1059915 from security
- 0001-Use-correct-includes.patch: fixed build with rpm 4.18 (forwarded request 1059914 from msmeissn)

OBS-URL: https://build.opensuse.org/request/show/1059915
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=80
2023-01-20 16:39:09 +00:00
e34ec4480d Accepting request 1059914 from home:msmeissn:branches:security
- 0001-Use-correct-includes.patch: fixed build with rpm 4.18

OBS-URL: https://build.opensuse.org/request/show/1059914
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=277
2023-01-20 09:25:38 +00:00
Dominique Leuenberger
7018bc8422 Accepting request 1005125 from security
- require shared library in the same version or newer (forwarded request 1005123 from dirkmueller)

OBS-URL: https://build.opensuse.org/request/show/1005125
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=79
2022-09-21 12:43:05 +00:00
1e960dc0e7 Accepting request 1005123 from home:dirkmueller:Factory
- require shared library in the same version or newer

OBS-URL: https://build.opensuse.org/request/show/1005123
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=275
2022-09-21 08:01:40 +00:00
Dominique Leuenberger
8295895d8c Accepting request 1003839 from security
- added Leap 15.4 and 15.5 dictionary entries. (bsc#1203408)

OBS-URL: https://build.opensuse.org/request/show/1003839
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=78
2022-09-15 20:59:50 +00:00
c6d4c4a847 - added Leap 15.4 and 15.5 dictionary entries. (bsc#1203408)
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=273
2022-09-15 08:29:50 +00:00
Dominique Leuenberger
fcaf78e3e9 Accepting request 956318 from security
- Conditionally drop optional gconf2-devel BuildRequires for
  openSUSE Tumbleweed and newer: gconf2 is being droppped from
  openSUSE Tumbleweed, build without gconf2 support. (forwarded request 956097 from iznogood)

OBS-URL: https://build.opensuse.org/request/show/956318
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=77
2022-02-21 16:46:42 +00:00
34acbd44f4 Accepting request 956097 from home:iznogood:branches:security
- Conditionally drop optional gconf2-devel BuildRequires for
  openSUSE Tumbleweed and newer: gconf2 is being droppped from
  openSUSE Tumbleweed, build without gconf2 support.

OBS-URL: https://build.opensuse.org/request/show/956097
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=272
2022-02-21 08:10:21 +00:00
Dominique Leuenberger
5dc13e330b Accepting request 949692 from security
update openscap to 1.3.6: put oscap-remediate into libexec at least on opensuse (bin is actually the wrost folder as it is not supposed to be called directly:/ ) (forwarded request 949314 from rfrohl)

OBS-URL: https://build.opensuse.org/request/show/949692
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=76
2022-01-29 19:59:21 +00:00
fca1a2040b Accepting request 949314 from home:rfrohl:branches:security
update openscap to 1.3.6: put oscap-remediate into libexec at least on opensuse (bin is actually the wrost folder as it is not supposed to be called directly:/ )

OBS-URL: https://build.opensuse.org/request/show/949314
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=271
2022-01-28 13:58:29 +00:00
Robert Frohl
e0a8343994 Accepting request 948434 from home:rfrohl:branches:security
update openscap to 1.3.6

OBS-URL: https://build.opensuse.org/request/show/948434
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=270
2022-01-25 09:01:20 +00:00
Dominique Leuenberger
65451281e7 Accepting request 936259 from security
- openscap-docker-add-suse.patch: add SLES support oscap-docker
  (bsc#1179314) (forwarded request 936258 from msmeissn)

OBS-URL: https://build.opensuse.org/request/show/936259
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=75
2021-12-07 23:00:03 +00:00
bed6d37e63 Accepting request 936258 from home:msmeissn:branches:security
- openscap-docker-add-suse.patch: add SLES support oscap-docker
  (bsc#1179314)

OBS-URL: https://build.opensuse.org/request/show/936258
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=269
2021-12-07 14:04:40 +00:00
Dominique Leuenberger
2e160e0025 Accepting request 924193 from security
- ship python3 docker module always

OBS-URL: https://build.opensuse.org/request/show/924193
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=74
2021-10-11 13:31:01 +00:00
0b1bd89f4f - ship python3 docker module always
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=268
2021-10-08 11:23:26 +00:00
14b3ae9893 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=267 2021-10-08 11:19:47 +00:00
f35bf00ac0 Accepting request 923072 from home:msmeissn:branches:security
- readjust python3 requirements for python3 to be on sles12 sp5
  and newer.

OBS-URL: https://build.opensuse.org/request/show/923072
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=266
2021-10-07 07:59:39 +00:00
Dominique Leuenberger
4900a85cb6 Accepting request 913461 from security
- Since upstream has moved to Python 3, switch the BuildRequires from
  python-devel to python3-devel. (forwarded request 912966 from StevenK)

OBS-URL: https://build.opensuse.org/request/show/913461
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=73
2021-08-23 08:08:13 +00:00
32df8e93ff Accepting request 912966 from home:StevenK:branches:security
- Since upstream has moved to Python 3, switch the BuildRequires from
  python-devel to python3-devel.

OBS-URL: https://build.opensuse.org/request/show/912966
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=265
2021-08-21 13:17:29 +00:00
Dominique Leuenberger
3dd75e5405 Accepting request 906323 from security
openscap: add opensuse tumbleweed - fix changes typo (forwarded request 906318 from rfrohl)

OBS-URL: https://build.opensuse.org/request/show/906323
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=72
2021-07-14 21:58:57 +00:00
6856c29fd1 Accepting request 906318 from home:rfrohl:branches:security
openscap: add opensuse tumbleweed - fix changes typo

OBS-URL: https://build.opensuse.org/request/show/906318
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=264
2021-07-14 15:49:59 +00:00
6f88887bae Accepting request 906300 from home:rfrohl:branches:security
openscap: add opensuse tumbleweed

OBS-URL: https://build.opensuse.org/request/show/906300
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=263
2021-07-14 15:10:59 +00:00
Dominique Leuenberger
54822eabd9 Accepting request 901561 from security
added missing CPEs again (forwarded request 901558 from rfrohl)

OBS-URL: https://build.opensuse.org/request/show/901561
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=71
2021-06-23 15:38:39 +00:00
862ac7d75f Accepting request 901558 from home:rfrohl:branches:security
added missing CPEs again

OBS-URL: https://build.opensuse.org/request/show/901558
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=261
2021-06-23 14:17:38 +00:00
Dominique Leuenberger
bce7b46f5b Accepting request 894646 from security
update openscap to 1.3.5 (forwarded request 894638 from rfrohl)

OBS-URL: https://build.opensuse.org/request/show/894646
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=70
2021-05-20 17:25:44 +00:00
afb06b7aac Accepting request 894638 from home:rfrohl:branches:security
update openscap to 1.3.5

OBS-URL: https://build.opensuse.org/request/show/894638
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=259
2021-05-20 14:23:59 +00:00
Dominique Leuenberger
0f73d900ee Accepting request 859046 from security
- 0001-Fix-memory-allocation.patch: fixed a crash during oscap oval eval (forwarded request 859045 from msmeissn)

OBS-URL: https://build.opensuse.org/request/show/859046
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=69
2020-12-29 14:52:30 +00:00
d258d10fad Accepting request 859045 from home:msmeissn:branches:security
- 0001-Fix-memory-allocation.patch: fixed a crash during oscap oval eval

OBS-URL: https://build.opensuse.org/request/show/859045
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=257
2020-12-28 15:26:44 +00:00
Dominique Leuenberger
bb18737f6b Accepting request 847312 from security
- openscap-leap-cpe-15.12.patch: add CPE dict entries for openSUSE
  Leap 15.1 and 15.2

- add dbus-1-devel buildrequires to enable systemd tests (bsc#1178301)

OBS-URL: https://build.opensuse.org/request/show/847312
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=68
2020-11-10 12:45:55 +00:00
75b3d9bbe9 - openscap-leap-cpe-15.12.patch: add CPE dict entries for openSUSE
Leap 15.1 and 15.2

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=255
2020-11-09 13:10:22 +00:00
e731fe8612 OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=254 2020-11-09 13:10:02 +00:00
e545210db4 Accepting request 847158 from home:msmeissn:branches:security
- add dbus-1-devel buildrequires to enable systemd tests (bsc#1178301)

OBS-URL: https://build.opensuse.org/request/show/847158
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=253
2020-11-09 12:48:33 +00:00
Dominique Leuenberger
4f0bdc7159 Accepting request 839126 from security
update openscap to 1.3.4 (forwarded request 839124 from rfrohl)

OBS-URL: https://build.opensuse.org/request/show/839126
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=67
2020-10-02 15:42:17 +00:00
156138e7cc Accepting request 839124 from home:rfrohl:branches:security
update openscap to 1.3.4

OBS-URL: https://build.opensuse.org/request/show/839124
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=251
2020-10-02 09:25:57 +00:00
Dominique Leuenberger
a537e6b3c5 Accepting request 800232 from security
(forwarded request 800231 from msmeissn)

OBS-URL: https://build.opensuse.org/request/show/800232
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=66
2020-05-05 16:56:04 +00:00
e32b796185 Accepting request 800231 from home:msmeissn:branches:security
OBS-URL: https://build.opensuse.org/request/show/800231
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=249
2020-05-05 06:22:29 +00:00
0cb0407eba Accepting request 799976 from home:msmeissn:branches:security
- openscap 1.3.3. Notable improvements in this release:
  - a Python script that can be used for CLI tailoring (autotailor) (thank you, Matěj Týč);
  - timezone for XCCDF TestResult start and end time (thank you, Jan Černý);
  - new yamlfilecontent independent probe (draft implementation),
    see the proposal https://github.com/OVAL-Community/OVAL/issues/91
    for additional information.
There are other changes as well, here is the list:
  - Introduced `urn:xccdf:fix:script:kubernetes` fix type in XCCDF;
  - Added ability to generate `machineconfig` fix;
  - Detect ambiguous scan target (utils/oscap-podman);
  - Fixed #170: The rpmverifyfile probe can't verify files from '/bin' directory;
  - The data system_info probe return for offline and online modes is consistent and actual;
  - Prevent crashes when complicated regexes are executed in textfilecontent58 probe;
  - Fixed #1512: Severity refinement lost in generated guide;
  - Fixed #1453: Pointer lost in Swig API;
  - Evaluation Characteristics of the XCCDF report are now consistent with OVAL entities;
    from system_info probe;
  - Fixed filepath pattern matching in offline mode in textfilecontent58 probe;
  - Fixed infinite recursion in systemdunitdependency probe;
  - Fixed the case when CMake couldn't find libacl or xattr.h.
- dropped 0001-Do-not-use-C-keyword-operator-as-a-function-paramete.patch: upstream

OBS-URL: https://build.opensuse.org/request/show/799976
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=248
2020-05-04 18:33:17 +00:00
Dominique Leuenberger
707d7498a2 Accepting request 788259 from security
- Add upstream patch to fix the scap-workbench build:
  * 0001-Do-not-use-C-keyword-operator-as-a-function-paramete.patch (forwarded request 788252 from cgiboudeaux)

OBS-URL: https://build.opensuse.org/request/show/788259
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=65
2020-03-25 22:48:03 +00:00
d3967e180d Accepting request 788252 from home:cgiboudeaux:branches:security
- Add upstream patch to fix the scap-workbench build:
  * 0001-Do-not-use-C-keyword-operator-as-a-function-paramete.patch

OBS-URL: https://build.opensuse.org/request/show/788252
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=246
2020-03-25 15:53:05 +00:00
Dominique Leuenberger
8b31c07db5 Accepting request 766084 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/766084
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=64
2020-01-21 20:00:33 +00:00
OBS User buildservice-autocommit
8b62f39da5 Accepting request 764315 from security
baserev update by copy to link target

OBS-URL: https://build.opensuse.org/request/show/764315
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=244
2020-01-14 20:10:52 +00:00
Dominique Leuenberger
0907bf39f6 Accepting request 764315 from security
- openscap 1.3.1
  - the test suite and build scripts were improved to support Debian 10
  - offline mode has received some love with a set of dedicated tests and various fixes in OVAL probes;
  - the oscap-docker wrapper is no longer dependent on Atomic 
  - Python binding are now more robust 
  - HTML reports and guides, generated by the scanner, are now more accessible for non-visual rendering agents 
  - Support of multi-check rules has been improved across the whole workflow 
  There are other changes as well, here is the list:
  * New features
    - Offline mode support for environmentvariable58 probe
    - The oscap-docker wrapper is available without Atomic
  + Maintenance, bug fixes
    - Improved support of multi-check rules (report, remediations, console output)
    - Improved HTML report look and feel, including printed version
    - Less clutter in verbose mode output; some warnings and errors demoted to verbose mode levels
    - Probe rpmverifyfile uses and returns canonical paths
    - Improved a11y of HTML reports and guides
    - Fixes and improvements for SWIG Python bindings
    - #1403 fixed: Scanner would not apply remediation for multicheck rules (verbosity)
    - Fixed URL link mechanism for Red Hat Errata
    - New STIG Viewer URI: public.cyber.mil
    - Probe selinuxsecuritycontext would not check if SELinux is enabled
    - Scanner would provide information about unsupported OVAL objects
    - Added more tests for offline mode (probes, remediation)
    - #528 fixed: Eval SCE script when /tmp is in mode noexec
    - #1173, RHBZ#1603347 fixed: Double chdir/chroot in probe rpmverifypackage

OBS-URL: https://build.opensuse.org/request/show/764315
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openscap?expand=0&rev=63
2020-01-14 20:10:52 +00:00
OBS User buildservice-autocommit
8b06e57aa6 Updating link to change in openSUSE:Factory/openscap revision 63.0
OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=534cb10161730fa838be45c9b7c56b59
2020-01-14 20:10:52 +00:00
440912201d - switch back to official release
- openscap 1.3.2

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=243
2020-01-14 14:09:00 +00:00
43fa6294ff - openscap 1.3.1
- the test suite and build scripts were improved to support Debian 10
  - offline mode has received some love with a set of dedicated tests and various fixes in OVAL probes;
  - the oscap-docker wrapper is no longer dependent on Atomic 
  - Python binding are now more robust 
  - HTML reports and guides, generated by the scanner, are now more accessible for non-visual rendering agents 
  - Support of multi-check rules has been improved across the whole workflow 
  There are other changes as well, here is the list:
  * New features
    - Offline mode support for environmentvariable58 probe
    - The oscap-docker wrapper is available without Atomic
  + Maintenance, bug fixes
    - Improved support of multi-check rules (report, remediations, console output)
    - Improved HTML report look and feel, including printed version
    - Less clutter in verbose mode output; some warnings and errors demoted to verbose mode levels
    - Probe rpmverifyfile uses and returns canonical paths
    - Improved a11y of HTML reports and guides
    - Fixes and improvements for SWIG Python bindings
    - #1403 fixed: Scanner would not apply remediation for multicheck rules (verbosity)
    - Fixed URL link mechanism for Red Hat Errata
    - New STIG Viewer URI: public.cyber.mil
    - Probe selinuxsecuritycontext would not check if SELinux is enabled
    - Scanner would provide information about unsupported OVAL objects
    - Added more tests for offline mode (probes, remediation)
    - #528 fixed: Eval SCE script when /tmp is in mode noexec
    - #1173, RHBZ#1603347 fixed: Double chdir/chroot in probe rpmverifypackage

OBS-URL: https://build.opensuse.org/package/show/security/openscap?expand=0&rev=242
2020-01-14 13:44:42 +00:00