Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New release to main #70

Merged
merged 45 commits into from
Apr 15, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
45 commits
Select commit Hold shift + click to select a range
830d42c
Fixing issue https://code.siemens.com/infosec-pss-gov/security-crafte…
DianaMariaDDM Dec 6, 2023
269b56b
Fixing issue https://code.siemens.com/infosec-pss-gov/security-crafte…
DianaMariaDDM Dec 6, 2023
9e7ef28
Fixing issue https://code.siemens.com/infosec-pss-gov/security-crafte…
DianaMariaDDM Dec 6, 2023
592fbbd
Fixing issue https://code.siemens.com/infosec-pss-gov/security-crafte…
DianaMariaDDM Dec 7, 2023
7bc0c12
Fixing issue https://code.siemens.com/infosec-pss-gov/security-crafte…
DianaMariaDDM Dec 20, 2023
9a4d9fb
Merge pull request #21 from siemens/siemens/feat/r_2.1.2_chrony_config
uk-bolly Jan 26, 2024
758bb04
Merge pull request #25 from siemens/siemens/feat/r_4.2.20_clientalive…
uk-bolly Jan 26, 2024
53b254a
Merge pull request #29 from siemens/siemens/feat/r_1.6.1.x_r_1.9_impo…
uk-bolly Jan 26, 2024
710425b
Removing trailing whitespaces
DianaMariaDDM Jan 30, 2024
9488e19
Removing trailing whitespaces and fixing an end-of-file
DianaMariaDDM Jan 30, 2024
a95bdb1
Merge pull request #23 from siemens/siemens/feat/r_2.2.17_masking_ser…
uk-bolly Jan 30, 2024
75ea3ec
Merge pull request #31 from siemens/siemens/feat/r_4.2.x_ssh_conf_files
uk-bolly Jan 30, 2024
6a3c7ec
Refactoring docs
DianaMariaDDM Feb 1, 2024
4a7ce35
Small fixings for https://code.siemens.com/infosec-pss-gov/security-c…
DianaMariaDDM Feb 14, 2024
c28b8a4
Removing trailing whitespace
DianaMariaDDM Feb 14, 2024
8bf9197
Fixing fail message so that is states the correct number of the rule …
DianaMariaDDM Feb 14, 2024
f5ec60c
Fixing inconsistencies for issue https://code.siemens.com/infosec-pss…
DianaMariaDDM Feb 15, 2024
5593023
Fixing minor syntax issues by adding missing "PATCH" keywords or miss…
DianaMariaDDM Feb 15, 2024
9ee76ca
Fixing PRELIM task "PRELIM | 4.3.3 | Find all sudoers files" mentione…
DianaMariaDDM Feb 15, 2024
3bec70e
Removing 1.1.2.1 from multiline task 1.1.2.2 ,1.1.2.3, 1.1.2.4 becaus…
DianaMariaDDM Feb 15, 2024
e8f766f
Removing prelim for installing authconfig, as it is not used.
DianaMariaDDM Feb 16, 2024
e14d248
[pre-commit.ci] pre-commit autoupdate
pre-commit-ci[bot] Feb 19, 2024
a480622
Removing the 6.1.12 duplicate task and adding it to the 6.1.10 task a…
DianaMariaDDM Feb 21, 2024
f6e12ab
De-commenting allow and deny variables for sshd.
DianaMariaDDM Feb 21, 2024
5b2165d
Removing double import of cis_5.3.yml.
DianaMariaDDM Feb 22, 2024
fdd3c87
Merge pull request #18 from ansible-lockdown/pre-commit-ci-update-config
uk-bolly Feb 22, 2024
19a64e3
Merge pull request #35 from siemens/siemens/feat/new_docs
uk-bolly Feb 22, 2024
95c7f19
Merge pull request #39 from siemens/siemens/feat/ensure_root_psswd_fix
uk-bolly Feb 22, 2024
1c3bc34
Merge pull request #43 from siemens/siemens/feat/fixing_prelim_find_a…
uk-bolly Feb 22, 2024
283366c
Merge pull request #45 from siemens/siemens/feat/r_1.1.2.1
uk-bolly Feb 22, 2024
c9ce3e1
Merge pull request #47 from siemens/siemens/feat/fixing_inconsistencies
uk-bolly Feb 22, 2024
27f69f8
Merge pull request #49 from siemens/siemens/feat/minor_syntax_fixes
uk-bolly Feb 22, 2024
fb93017
Merge pull request #53 from siemens/siemens/feat/remove_6.1.12_duplicate
uk-bolly Feb 22, 2024
a452618
Merge pull request #55 from siemens/siemens/feat/fixing_double_import…
uk-bolly Feb 22, 2024
46b8d7d
Merge branch 'devel' into siemens/feat/removing_prelim_install_authco…
DianaMariaDDM Feb 23, 2024
66f73f5
Merge pull request #51 from siemens/siemens/feat/removing_prelim_inst…
uk-bolly Feb 23, 2024
3c751d4
As authconfig is not needed anymore, the variable related to its inst…
DianaMariaDDM Feb 23, 2024
6282533
Merge pull request #57 from siemens/siemens/feat/removing_unneeded_var
uk-bolly Feb 23, 2024
b238cf5
Feb 24 updates to devel (#58)
uk-bolly Mar 6, 2024
0c20b83
updated ansible fact naming and checkout action (#64)
uk-bolly Mar 14, 2024
2f5391b
[pre-commit.ci] pre-commit autoupdate (#65)
pre-commit-ci[bot] Mar 19, 2024
b52bde5
4.2.16: Add variable for SSH MaxAuthTries (#66)
tom-henderson Mar 26, 2024
3a1efa0
4.2.16: Correct variable name and required max value (#67)
tom-henderson Mar 27, 2024
6fc3814
March 24 updates (#68)
uk-bolly Mar 27, 2024
b66f414
[pre-commit.ci] pre-commit autoupdate (#69)
pre-commit-ci[bot] Apr 15, 2024
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions .github/workflows/devel_pipeline_validation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -44,13 +44,13 @@

steps:
- name: Clone ${{ github.event.repository.name }}
uses: actions/checkout@v3
uses: actions/checkout@v4
with:
ref: ${{ github.event.pull_request.head.sha }}

# Pull in terraform code for linux servers
- name: Clone github IaC plan
uses: actions/checkout@v3
uses: actions/checkout@v4
with:
repository: ansible-lockdown/github_linux_IaC
path: .github/workflows/github_linux_IaC
Expand Down Expand Up @@ -125,6 +125,7 @@
env:
ANSIBLE_HOST_KEY_CHECKING: "false"
ANSIBLE_DEPRECATION_WARNINGS: "false"
ANSIBLE_INJECT_FACT_VARS: "false"

# Remove test system - User secrets to keep if necessary

Expand Down
5 changes: 3 additions & 2 deletions .github/workflows/main_pipeline_validation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,13 +33,13 @@

steps:
- name: Clone ${{ github.event.repository.name }}
uses: actions/checkout@v3
uses: actions/checkout@v4
with:
ref: ${{ github.event.pull_request.head.sha }}

# Pull in terraform code for linux servers
- name: Clone github IaC plan
uses: actions/checkout@v3
uses: actions/checkout@v4
with:
repository: ansible-lockdown/github_linux_IaC
path: .github/workflows/github_linux_IaC
Expand Down Expand Up @@ -114,6 +114,7 @@
env:
ANSIBLE_HOST_KEY_CHECKING: "false"
ANSIBLE_DEPRECATION_WARNINGS: "false"
ANSIBLE_INJECT_FACT_VARS: "false"

# Remove test system - User secrets to keep if necessary

Expand Down
8 changes: 4 additions & 4 deletions .pre-commit-config.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ ci:

repos:
- repo: https://github.com/pre-commit/pre-commit-hooks
rev: v4.4.0
rev: v4.6.0
hooks:
# Safety
- id: detect-aws-credentials
Expand Down Expand Up @@ -37,13 +37,13 @@ repos:
exclude: .config/.gitleaks-report.json

- repo: https://github.com/gitleaks/gitleaks
rev: v8.17.0
rev: v8.18.2
hooks:
- id: gitleaks
args: ['--baseline-path', '.config/.gitleaks-report.json']

- repo: https://github.com/ansible-community/ansible-lint
rev: v6.18.0
rev: v24.2.1
hooks:
- id: ansible-lint
name: Ansible-lint
Expand All @@ -62,6 +62,6 @@ repos:
- ansible-core>=2.10.1

- repo: https://github.com/adrienverge/yamllint.git
rev: v1.32.0 # or higher tag
rev: v1.35.1 # or higher tag
hooks:
- id: yamllint
28 changes: 28 additions & 0 deletions Changelog.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,33 @@
# Amazon 2023 CIS - 26th June 2023

## 1.0.1

- thanks to @DianaMariaDDM
- #59
- #60
- #61
- #62

- #64 thanks to @tom-henderson

- extended with new options to force changes for 4.6.1.1|2|3 default false
- amzn2023cis_force_user_maxdays
- amzn2023cis_force_user_mindays
- amzn2023cis_force_user_warndays

- pre-commit updates

- general tidy up

## 1.0 Multiple changes

- Audit binary updated goss 0.4.4
- audit_only option now added
- audit_only: true

- Many Prs and associated issues
massive thanks to @DianaMariaDDM for all the PRs and Issues and time

## 0.91

- issue #2 thanks to @babinskiy
Expand Down
Loading
Loading