bordenitllc / ubi-container-hardening

ubi-container-hardening
Apache License 2.0
0 stars 1 forks source link

Bordenit patch 5 #33

Closed bordenit closed 8 months ago

github-actions[bot] commented 8 months ago

Test Results

151 tests   - 11   127 :white_check_mark:  - 2   1s :stopwatch: ±0s   1 suites ± 0    11 :zzz: ±0    1 files   ± 0    13 :x:  - 9 

For more details on these failures, see this check.

Results for commit a47f7450. ± Comparison against base commit 5de147c1.

This pull request removes 12 and adds 1 tests. Note that renamed tests count towards both. ``` redhat-enterprise-linux-8-stig-baseline.SV-230221 ‑ The release "8.9" is still be within the support window ending on 30 April 2024 redhat-enterprise-linux-8-stig-baseline.SV-230245 ‑ File /var/log/messages is expected not to be more permissive than "0640" redhat-enterprise-linux-8-stig-baseline.SV-230245 ‑ File /var/log/messages is expected to exist redhat-enterprise-linux-8-stig-baseline.SV-230246 ‑ File /var/log/messages is expected to be owned by "root" redhat-enterprise-linux-8-stig-baseline.SV-230246 ‑ File /var/log/messages is expected to exist redhat-enterprise-linux-8-stig-baseline.SV-230247 ‑ File /var/log/messages group is expected to be in "root" redhat-enterprise-linux-8-stig-baseline.SV-230247 ‑ File /var/log/messages is expected to exist redhat-enterprise-linux-8-stig-baseline.SV-250315 ‑ Parse Config File /etc/security/faillock.conf dir is expected to cmp == "/var/log/faillock" redhat-enterprise-linux-8-stig-baseline.SV-250315 ‑ SELinux is expected not to be disabled redhat-enterprise-linux-8-stig-baseline.SV-250315 ‑ SELinux is expected to be enforcing … ``` ``` redhat-enterprise-linux-8-stig-baseline.SV-230221 ‑ The release "8.9" is still be within the support window ending on 31 May 2024 ```

:recycle: This comment has been updated with latest results.

bordenit commented 8 months ago

/lib/.build-id permission changes to the symlinks is probably a bad idea and DISA STIG should be changed to accommodate this path which was effectively moved from /lib/debug and includes symlinks rather than actual files.

https://unix.stackexchange.com/a/411736

sonarcloud[bot] commented 8 months ago

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
0.0% Duplication on New Code

See analysis details on SonarCloud