Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Oct24_ devel to main #420

Merged
merged 87 commits into from
Oct 18, 2024
Merged

Oct24_ devel to main #420

merged 87 commits into from
Oct 18, 2024

Conversation

uk-bolly
Copy link
Member

@uk-bolly uk-bolly commented Oct 15, 2024

Overall Review of Changes:
Rebase took place to fix some historical errors

Issue Fixes:
#351
#352
#355
#356
#358
#366
#367
#368
#369
#370
#371
#372
#376
#383
#384
#385
#387
#388
#389
#390
#393
#394
#395
#396
#400
#402
#404
#406
#407
#409
#410
#411
#412
#413
#416
#419
#421

Enhancements:
jmespath removed
idempotency updates
tag improval
may issues

How has this been tested?:
Please give an overview of how these changes were tested. If they were not please use N/A

uk-bolly and others added 30 commits March 11, 2024 11:55
Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Mark Bolwell <[email protected]>
updates:
- [github.com/ansible-community/ansible-lint: v24.2.0 → v24.2.1](ansible/ansible-lint@v24.2.0...v24.2.1)
…nfig

[pre-commit.ci] pre-commit autoupdate
* added conditional to user password check #354 thanks to @bbaassssiiee

Signed-off-by: Mark Bolwell <[email protected]>

* updated logic to check root passwd locked

Signed-off-by: Mark Bolwell <[email protected]>

* Updated

Signed-off-by: Mark Bolwell <[email protected]>

* lint and audit order change

Signed-off-by: Mark Bolwell <[email protected]>

* updated for documentation format

Signed-off-by: Mark Bolwell <[email protected]>

---------

Signed-off-by: Mark Bolwell <[email protected]>
If changes to the system-wide crypto policy are required to meet local
site policy for the openSSH server, these changes should be done with a sub-policy
assigned to the system-wide crypto policy.

The role defaults can be overridden by the user's vars.
The user should implement a .pmod file, and add its basename to `rhel8cis_allowed_crypto_policies_modules`.
The role vars are harder to change due to the 21 priority levels of Ansible.

Signed-off-by: Bas Meijer <[email protected]>
* #359 addressed thanks to @bbaassssiiee

Signed-off-by: Mark Bolwell <[email protected]>

* sysctl matches requirement & handler added

Signed-off-by: Mark Bolwell <[email protected]>

* container updated and cautions updated

Signed-off-by: Mark Bolwell <[email protected]>

* issues #360 addressed thanks to @bbaassssiiee

Signed-off-by: Mark Bolwell <[email protected]>

* updated

Signed-off-by: Mark Bolwell <[email protected]>

* Added #361 ensure local interface on 3.4.2.2

Signed-off-by: Mark Bolwell <[email protected]>

* issue #363 addressed

Signed-off-by: Mark Bolwell <[email protected]>

* variable naming and lint

Signed-off-by: Mark Bolwell <[email protected]>

* variable naming and lint

Signed-off-by: Mark Bolwell <[email protected]>

* updated handler

Signed-off-by: Mark Bolwell <[email protected]>

* variable naming and lint updates

Signed-off-by: Mark Bolwell <[email protected]>

* updated

Signed-off-by: Mark Bolwell <[email protected]>

* fix issues with pam_unix

Signed-off-by: Mark Bolwell <[email protected]>

* added extra options

Signed-off-by: Mark Bolwell <[email protected]>

* issue #365 addressed

Signed-off-by: Mark Bolwell <[email protected]>

* fixed commenting alternate file

Signed-off-by: Mark Bolwell <[email protected]>

* updated var name to discovered

Signed-off-by: Mark Bolwell <[email protected]>

* renamed variable tomake it clearer

Signed-off-by: Mark Bolwell <[email protected]>

* updated

Signed-off-by: Mark Bolwell <[email protected]>

* fix typo

Signed-off-by: Mark Bolwell <[email protected]>

* updated discovered variable naming

Signed-off-by: Mark Bolwell <[email protected]>

* updated variable naming

Signed-off-by: Mark Bolwell <[email protected]>

---------

Signed-off-by: Mark Bolwell <[email protected]>
updates:
- [github.com/pre-commit/pre-commit-hooks: v4.5.0 → v4.6.0](pre-commit/pre-commit-hooks@v4.5.0...v4.6.0)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
updates:
- [github.com/ansible-community/ansible-lint: v24.2.1 → v24.2.2](ansible/ansible-lint@v24.2.1...v24.2.2)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
updates:
- [github.com/Yelp/detect-secrets: v1.4.0 → v1.5.0](Yelp/detect-secrets@v1.4.0...v1.5.0)
- [github.com/gitleaks/gitleaks: v8.18.2 → v8.18.3](gitleaks/gitleaks@v8.18.2...v8.18.3)
- [github.com/ansible-community/ansible-lint: v24.2.2 → v24.6.0](ansible/ansible-lint@v24.2.2...v24.6.0)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Signed-off-by: Tomáš Kuba <[email protected]>
* Update Alma 8 GPG Key

Update AlmaLinux.yml

Signed-off-by: ajython <[email protected]>

* Update AlmaLinux.yml

Replace depricated Alma 8 GPG key 

Signed-off-by: ajython <[email protected]>

---------

Signed-off-by: ajython <[email protected]>
* updated path to match disa for audit tools

Signed-off-by: Mark Bolwell <[email protected]>

* updated dict control

Signed-off-by: Mark Bolwell <[email protected]>

* updated nullok logic

Signed-off-by: Mark Bolwell <[email protected]>

* updated typos

Signed-off-by: Mark Bolwell <[email protected]>

* updated typ thanks to @msachikanta

Signed-off-by: Mark Bolwell <[email protected]>

---------

Signed-off-by: Mark Bolwell <[email protected]>
updates:
- [github.com/gitleaks/gitleaks: v8.18.3 → v8.18.4](gitleaks/gitleaks@v8.18.3...v8.18.4)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
* interactive user vars updates

Signed-off-by: Mark Bolwell <[email protected]>

* improved conditionals checks

Signed-off-by: Mark Bolwell <[email protected]>

* Tidy up titles

Signed-off-by: Mark Bolwell <[email protected]>

* updated with latest devel

Signed-off-by: Mark Bolwell <[email protected]>

* removed file not required

Signed-off-by: Mark Bolwell <[email protected]>

* improved logic for /dev/null home dirs

Signed-off-by: Mark Bolwell <[email protected]>

* Updated workflow to new runner

Signed-off-by: Mark Bolwell <[email protected]>

---------

Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Mark Bolwell <[email protected]>
updates:
- [github.com/ansible-community/ansible-lint: v24.6.0 → v24.6.1](ansible/ansible-lint@v24.6.0...v24.6.1)
uk-bolly and others added 24 commits August 22, 2024 13:23
Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Mark Bolwell <[email protected]>
updates:
- [github.com/gitleaks/gitleaks: v8.18.4 → v8.19.2](gitleaks/gitleaks@v8.18.4...v8.19.2)
- [github.com/ansible-community/ansible-lint: v24.7.0 → v24.9.0](ansible/ansible-lint@v24.7.0...v24.9.0)
…nfig

[pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/ansible-community/ansible-lint: v24.9.0 → v24.9.2](ansible/ansible-lint@v24.9.0...v24.9.2)
…nfig

[pre-commit.ci] pre-commit autoupdate
Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Mark Bolwell <[email protected]>
updates:
- [github.com/pre-commit/pre-commit-hooks: v4.6.0 → v5.0.0](pre-commit/pre-commit-hooks@v4.6.0...v5.0.0)
- [github.com/gitleaks/gitleaks: v8.19.2 → v8.20.1](gitleaks/gitleaks@v8.19.2...v8.20.1)
…nfig

[pre-commit.ci] pre-commit autoupdate
removed group from control not required 6.2.10
Signed-off-by: Roy Scheepers <[email protected]>
@uk-bolly uk-bolly marked this pull request as ready for review October 17, 2024 15:45
Copy link
Contributor

@georgenalen georgenalen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

@uk-bolly uk-bolly merged commit 0576f15 into main Oct 18, 2024
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

9 participants