Skip to content

Releases: ovh/debian-cis

Release v3.4-1

18 Mar 15:54
d1bd1eb
Compare
Choose a tag to compare
  • fix: allow passwd-, group- and shadow- debian default permissions (#149)

Release v3.3-1

03 Mar 11:08
8320d0e
Compare
Choose a tag to compare
  • fix: missing shadowtools backup files is ok (#132)
  • feat: Dissociate iptables pkg name from command (#137)
  • fix: Catch unexpected failures (#140)
  • fix: Avoid find failures on too many files (#144)

Release v3.2-2

13 Dec 15:33
f1c1517
Compare
Choose a tag to compare
  • Fix 5.4.5 pattern search
  • Bump actions-ecosystem/action-get-latest-tag from 1 to 1.4.1
  • Bump luizm/action-sh-checker from v0.1.12 to v0.1.13
  • 99.5.4.5.2: fix bug where sha512 option rounds provoke KO
  • Bump dev-drprasad/delete-tag-and-release from v0.1.3 to v0.2.0
  • Bump luizm/action-sh-checker from 0.1.13 to 0.3.0
  • Bump metcalfc/changelog-generator from v0.4.4 to v1.0.0
  • FIX(2.2.1.4): Validate debian default ntp config
  • FIX(1.7.1.4): don't abort script in case of unconfined processes
  • Add silent mode and json summary
  • fix: kernel module detection
  • Honor --set-log-level parameter
  • Allow grub.cfg permission to be 600
  • Fix grub detection
  • Fix 3.4.2 audit rule
  • Skip NTP and Chrony config check if they are not installed
  • Fix empty fstab test
  • Update changelog for release 3.2-2

Release v3.1-6

02 Jun 12:04
334d743
Compare
Choose a tag to compare
  • Improve EXCEPTIONS management (1.1.21,6.1.10)
  • Fix bug linked with regex quoting (6.1.10-11-12-13-14)

Release v3.1-5

28 May 13:19
4ed8adf
Compare
Choose a tag to compare
  • Fix unbound EXCEPTIONS variable in some cases

Release v3.1-4

07 May 13:17
2950525
Compare
Choose a tag to compare
  • Add test to check stderr is empty
  • Fix 2.2.1.2 audit and apply
  • Accept lower values as valid 5.2.7 and 5.2.23
  • Add dir exceptions in 1.1.21 and 6.1.10

Release v3.1-3

13 Apr 09:21
Compare
Choose a tag to compare
  • Fix 4.1.11 permissions

Release v3.1-2

02 Apr 07:36
Compare
Choose a tag to compare
  • Fix case for sshd pattern searching

Release v3.1-1

26 Mar 11:27
cbd81b8
Compare
Choose a tag to compare
  • Various mispeling fixes
  • Fix div function that causes a display bug when runnin test with --only
  • Fix 4.1.1.4 bad pattern bug
  • Fix 5.4.2.2
  • Various verification that package is installed or file exist before running check (openssh, apparmor, crontab)

Release v3.1-0

15 Mar 07:36
Compare
Choose a tag to compare
  • Add missing HARDENING_LEVEL var for some checks
  • Add dealing with debian 11
  • Add warning for unsupported distributions and debian version
  • Remove bc dependency
  • Add 1.8.1-4 comprehensive tests
  • Add 3.1-3.x comprehensive tests
  • Add missing 3.4.x checks and tests (exotic protocol)
  • Add environment detection (container)
  • Improve kernel module detection
  • Improve partition detection
  • Add cli option to override loglevel
  • Improve 5.1.8 to allow more restrictive permissions
  • Upgrade mac and key to be debian10 CIS compliant
  • Fix path in 1.6.4