Skip to content

v0.1.0 — read-only CIS audit

Latest

Choose a tag to compare

@r4kh1m r4kh1m released this 28 Jul 23:21
v0.1.0
141d1a5

macos-cis-scan v0.1.0

Initial public release of a read-only NIST mSCP CIS audit wrapper.

Included

  • scan_cis.zsh — CIS Level 1 or Level 2 audit wrapper.
  • SHA256SUMS and SHA256SUMS.sig — integrity manifest and detached SSH
    signature.
  • r4kh1m-release-signing-key.pub — public key for manifest verification.

The release-signing key fingerprint is:

SHA256:Rt9xlHKnOMVeREiwG041268qY0kxu72vYVt+CntuF+4

Compatibility

macOS 14, 15, and 26 are accepted. The release was end-to-end tested on macOS
26 Apple Silicon. See Compatibility before using it on a
different target.

Safety contract

The generated mSCP audit is invoked only with --check. This release does not
run remediation commands.

Feedback

Use Discussions for questions and compatibility experience, Issues for
reproducible bugs, and GitHub private vulnerability reporting for security
findings. Never post an unredacted audit report.