Skip to content

v1.2.0-beta.5

Pre-release
Pre-release

Choose a tag to compare

@cocopuff2u cocopuff2u released this 15 Sep 18:31

Main App Changes

No changes this release.

Compliance Editor Changes

  • Fixed: Switching between rules could briefly leave the previous rule's details in the sidebar, including its ODV box, so a value typed at that moment landed on the wrong rule. The sidebar now clears the instant you pick a different rule. Thanks @jmahlman.
  • Changed: Title and discussion show $ODV as written in the rule instead of the filled-in number, and the ODV field is the only place the value appears. Changing an ODV no longer marks those fields as Modified or writes them into the rule's custom override. Overrides created by earlier betas are cleaned up the next time the rule is saved.
  • Added: $ODV placeholders are highlighted in the rule list and every rule field, and hovering shows the value for your compliance. A Highlight ODV Placeholders setting under Settings › Appearance › Rule Editor offers On, Off, or Always Show Value, and applies immediately.
  • Fixed: Rules you add or remove now stay that way when you close and reopen a project. A colon in the Benchmark Name, Author, Organization, or a new rule's title produced a file that couldn't be read, so the project quietly went back to the default rule set on every open. Affected projects recover on their own with no selections lost. Reported by @mahlmanj (#30). Thanks!
  • Added: mSCP Source setting under Settings › General › mSCP Rules. Pick Release (main) or a Beta branch such as dev_2.0 or dev_27, and the platform, version, and compliance lists for new projects come from that branch. Beta branches are discovered automatically, downloaded and kept up to date alongside main when Auto-Download is on, and can be opened or Repo Cache row under Settings › Advanced ›Storage.
  • Changed: Every project records the mfrom, and updates follow that branchregardless of the source selected in Settings. The New Project sheet shows a "Using beta branch" badge when a Beta source is active. The "Show mSCP Beta
  • Added: Exempt rules. The include checkbox now has a third state: one click on a checked rule turns it into a dash, meaning the rule stays in the baseby the compliance script, but nothingenforces it. A second click disables the rule as before, the space bar follows the same cycle, and Option-click disables directly. Exempt rules get an indreason as a tooltip, and the state is savedwith the project.
  • Added: An optional Exemption Reason Exempt Rule and Remove Exemption in theright-click and "…" menus, an exempt count in the bottom bar ("158 included (4 exempt)"), and Exempt, Modified,
    Disabled, and Flagged Rules entries in the match the Audit hub. Choosing DisabledRules shows them even with Hide Disabled on.

Build Hub Changes

  • Fixed: Tenable audit see_also links now point at the branch a Beta project was created from.
  • Added: Exempt rules build the way anl Build and every MDM upload. The auditpreferences carry exempt = true and the reason in every format (the Jamf schema defaults exempt rules to on
    with the reason pre-filled). The rules sta so they are still checked, and theirsettings are left out of the configuration profiles, DDM declarations, and vendor manifest. The README lists
    every exemption with its reason, and the Bules, 4 exempt".
  • Added: mSCP engine builds patch the project's exemptions into the generated org.<baseline>.audit.plist
    after the run. mSCP's own profiles still cgs; build with the M.A.C.E. engine to leavethem out.
  • Added: GitOps files for Fleet. The C in Local Build now also writesbuild/fleet_gitops/: the build's profiles, audit preferences, scripts, and DDM declarations under lib/, a
    default.yml with the matching label, concy entries, and a policies_per_rule.ymlfor per-rule tracking. Teams managing Fleet with fleetctl gitops get everything the Fleet export would upload,
    without the API integration.
  • Changed: The Local Build row is now "Compliance Reporting & Other MDM Files."

Audit Builder Hub Changes

  • Fixed: An ODV changed while the audit window was open was ignored, so the check ran against the old number
    even though the editor showed the new one.uses the current saved value. Thanks @jmahlman.
  • Changed: Rule titles in the audit lie actual value instead of $ODV, forexample "Set Account Lockout Time to 10 Minutes", so what you see matches what was checked.
  • Added: Include Exemptions dropdown uLocal Exemptions (deployed on this Mac inorg.<baseline>.audit), Compliance Exemptions (the rules marked Exempt in the project), or Local + Compliance,
    with live counts. If a rule is exempt in bhe Mac wins. Exempt rules keep their realPass or Fail and show the badge from the start of the run. The choice is remembered.
  • Added: Rule details now show an Exeme reason and its source, plus Review Comment and Disabled Justification blocks for flagged and disabled rules.
  • Added: Modified Rule block in the ruzed from the baseline lists each changedfield with its baseline and custom values, computed the moment the audit opens so a restored earlier run shows
    current edits. A summary line says whethers were changed, and each field is taggedAudit or Descriptive.
  • Added: Row badges for Exempt, Modifiext to each rule's title, in the same styleand colors as the Compliance Builder Hub, with matching entries in the Filter dropdown. The old override badge
    is now labelled Overridden so it can't be ule.
  • Changed: Exempt is indigo everywhere in the audit, including the reports and export sidebar. The Full
    Audit Scan and Profile Inspector descripti the Include Disabled Rules icon is red tomatch the Disabled badge.
  • Added: Exemptions in every export. TExemptions group (Show Exempt Indicator,Exemption Reasons, Exempt in Own Section) mirroring the Flagged for Review controls, an Exclude Exempt Rules
    switch that removes them from the whole rel Rules does, and an Exempt Rules switchunder Show Statuses to hide them from the listing only. CSV and XLSX get Exempt and Exemption Reason columns,
    JSON an exempt flag and reason, HTML and Pon callout, and the STIG checklist carriesthe reason in comments with the real status kept.
  • Changed: Pass rate leaves exempt rulroved exemption neither earns nor costscredit, and the Need Attention count no longer includes exempt failures.
  • Fixed: STIG IDs in the PDF results ts. The column is slightly wider so a full ID fits.

Documentation Builder Hub Changes

  • Added: Exempt group under Rule Options with Show Exempt Indicator, Include Reasons, and Own Section,
    matching the Disabled, Added, and Review g indigo EXEMPT badge and an Exemption Reason block in HTML and PDF, a callout in Markdown and AsciiDoc, exempt fields in JSON, and EXEMPT and
    EXEMPTION_REASON columns in CSV and XLSX, r by Status is on.
  • Fixed: Long discussions in the PDF were cut off mid-sentence at about 2,000 characters. The full text now
    renders and paginates by paragraph.
  • Fixed: AsciiDoc block admonitions from the mSCP rules leaked into HTML, PDF, and Markdown as raw
    [IMPORTANT] ==== … ==== markup. They now NOTE, WARNING, CAUTION, or TIP callouts,and the AsciiDoc output keeps the native syntax.
  • Fixed: The Both PDF color scheme onlLight and dark PDFs are now written side byside.
  • Fixed: Page Numbers now work without Format setting now applies to the"generated on" date in HTML and PDF, not only the release date.
  • Fixed: Underscores inside rule IDs ications, and discussions were eaten byitalic formatting in HTML and PDF, turning os_gatekeeper_enable into "osgatekeeperenable". Italics now only
    apply to whole words.
  • Fixed: PDF tables could leave a lone row, or a Tags label over a blank row, at a page bottom with the rest
    on the next page. Tables now keep their la

Rule Builder Hub Changes

No changes this release.

Feedback Needed

Application rules are in alpha. These rules were derived from CIS and DISA STIG official sooroughly tested. We are working with official and community macAdmin sources to find a permanent home for these rules.

Your feedback on application rule accuracy and usability is especially appreciated.

We'd love your help testing features to make sure everything works as expected.

If you run into any issues or have suggestions, please open an issue at [github.com/mace-app/mae-app/mace/issues).

Known Issues

  • UI font sizing: May vary depending on your system's accessibility, display, or font settiing fonts across every screen, so this is on hold for now.
  • Sequoia & below: Glass/blur effects don't look quite right on older macOS versions. Adjuswithout these effects will take time.
  • Console logging: May not capture all events. Logging is being improved incrementally as features are updated.