makit v0.4.0
- Security guides in
docs/security/(one page per topic); every finding links its page for the running version,
andmakit docs <topic|RULE-ID>shows it offline. makit scanchecks configuration too (posture): SSH, firewall, exposed services, Docker vs ufw, egress, container
privileges/socket/root/tmp, updates, kernel, mounts, fail2ban, AppArmor, auditd, log shipping, secret permissions.
--only malware,posture,vulns.makit harden: kernel sysctls, /dev/shm noexec (--tmp-noexecfor /tmp), SSH limits, fail2ban sshd jail,
AppArmor, auditd rules. Part ofmakit init(--no-hardento skip).makit firewall --docker(published container ports follow ufw) and--egress PORTS(containers may connect out
only to those ports);makit initenables--dockerwhen Docker is installed.makit schedule scan daily|weekly|hourly|off [--webhook=URL]: scheduled scans, reports in /var/log/makit/scans,
webhook alerts; consent recorded once.- Catalog: new React2Shell sample hash;
docfield on checks and rules. - Setup tab: server hardening, Docker firewall, scheduled scan.
- Tests: posture and documentation-link tests; e2e covers a misconfigured container; CI proves the egress policy on
real VMs (HTTPS passes, HTTP is rejected) and runs a scheduled scan.
curl -fsSL https://raw.githubusercontent.com/material-atomic/makit/v0.4.0/install.sh | bashSource tarball SHA256 (MAKIT_SHA256): f9d7fd8a22728739a3990d4aee3bd74077ec57bf787c147f13550623cfb2aec3
makit-core binaries: see SHA256SUMS (verified by install.sh).