forked from rancher/security-scan
-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[pull] master from rancher:master #11
Open
pull
wants to merge
35
commits into
cfkoehler:master
Choose a base branch
from
rancher:master
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
…2 configs Signed-off-by: Derek Nola <[email protected]>
Signed-off-by: Derek Nola <[email protected]>
Signed-off-by: Derek Nola <[email protected]>
Fix audits and remediation for RKE2 2.X Checks
Signed-off-by: Derek Nola <[email protected]>
Signed-off-by: Derek Nola <[email protected]>
Signed-off-by: Derek Nola <[email protected]>
Fix audits and remediations for RKE2 4.X
fix condition for etcd node detection for k3s
) * Add new yaml validation around checks nature for each profiles' yaml file - Verifies if text: contains Automated or Manual - Verifies if Automated matches scored true and Manual matches scored false * Fix check types: generic profiles * Fix check types: k3s cis-1.23 * Fix check types: k3s cis-1.24 * Fix check types: k3s cis-1.7 * Fix check types: k3s cis-1.8 * Fix check types: rke cis-1.23 * Fix check types: rke cis-1.24 * Fix check types: rke cis-1.7 * Fix check types + Add line breaks: rke cis-1.8 * Fix check types: rke2 cis-1.23 * Fix check types: rke2 cis-1.24 * Fix check types: rke2 cis-1.7 * Fix check types: rke2 cis-1.8
* Fix generic profiles * Fix k3s 1.7 and 1.8 profiles * Fix rke2 1.7 and 1.8 profiles * Fix rke1 1.7 and 1.8 profiles
rke2: set scored:false for audit log checks in permissive profiles
also updated remediation
k3s: fix 1.1.11 check for all the profiles
rke2: fix master etcd checks
rke2 fix failed checks for permissive profiles
chore(deps): update dependency vmware-tanzu/sonobuoy to v0.57.2
Signed-off-by: Derek Nola <[email protected]>
Signed-off-by: Derek Nola <[email protected]>
Correct pod-manifest permissions, all manual for rke2-cis-1.24
…2-2.x chore(deps): update module github.com/urfave/cli/v2 to v2.27.5
…-0.x chore(deps): update dependency aquasecurity/kube-bench to v0.9.1
…iigi-xx-1.x chore(deps): update rancher/mirrored-tonistiigi-xx docker tag to v1.5.0
…-kube-bench-0.x chore(deps): update module github.com/aquasecurity/kube-bench to v0.9.1
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
See Commits and Changes for more details.
Created by pull[bot]
Can you help keep this open source service alive? 💖 Please sponsor : )