New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Integrate the Lynis scanner into OpenQA - phase 2 #11998
Conversation
ae6e643
to
5485a63
Compare
81a8847
to
e04da9d
Compare
4f31996
to
d08738a
Compare
Minor comments: Support lynis on other architectures, support both text and gnome mode image on all architectures. To
|
Done. |
For the VR content. It would be more readable for reviewer. such as: SLE text mode (all arches): SLE gnome mode (all arches): openSUSE TW (x86-64 only): how do you think about it? :) |
|
I just check the baseline is empty, am I right? or it is only renamed and without baseline update? |
|
okay, I got it. because it show 0 in github, but it is fine if it's just renamed only. |
Further questitons,
|
Correct.
. Depends on the testing results later on, e.g., if the baselines need to be revised according to OS's changing (not fixed IMO) |
okay I got it. thanks for information. |
poo#88894 - [sle][security][sle15sp3] Integrate the Lynis scanner into OpenQA - phase 2 Support lynis on other architectures; Support both text and gnome mode image for all architectures Support lynis on TW for x86_64 arches. Also revise code to support some exceptions allowed in baselines.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM. Thanks for the changes.
@okurz I have revised code according to your comments, please help to check again. |
Support lynis on other architectures;
Support both text and gnome images for all architectures;
Supprot lynis on TW for x86_64 arches.
Revised code to allow some exceptions.
NOTE:
Please ignore the soft fails. I will open a low priority poo to track the unstable exceptions later;
The baselines will be reviewed/approved by developer, if you want to check them it is very cool too.
Related ticket: https://progress.opensuse.org/issues/88894
Needles: NA
Verification run:
SLE text mode (all arches):
x86-64: https://openqa.suse.de/tests/5519434
ppc64le: https://openqa.suse.de/tests/5519505
s390x: https://openqa.suse.de/tests/5519433
aarch64: https://openqa.suse.de/tests/5519431
SLE gnome mode (all arches):
x86-64: https://openqa.suse.de/tests/5519439
ppc64le: https://openqa.suse.de/tests/5519436
s390x: https://openqa.suse.de/tests/5572531
aarch64: https://openqa.suse.de/tests/5519435
openSUSE TW (x86-64 only):
textmode: https://openqa.opensuse.org/tests/1644460
gnome: https://openqa.opensuse.org/tests/1644459