Revisions of openscap
Stephan Kulow (coolo)
accepted
request 226975
from
Marcus Meissner (msmeissn)
(revision 28)
- openscap-1.0.7 update: - fix namespaces for attributes in ARF relationship element - Avoid ".00" as the score in HTML report when score is 0. - openscap-1.0.6 update: - fix process58 loginuid integer handling on 32bit
Stephan Kulow (coolo)
accepted
request 226350
from
Marcus Meissner (msmeissn)
(revision 27)
- openscap-1.0.5 update: - XCCDF titles and description support xccdf:sub resolution - HTML Report lists only applicable cpe platforms - TestResult element contains applicable cpe platforms - Introduced XCCDF 1.2 schematron validation - XCCDF bug fixes - tailoring profiles shall regards inherited refine-values (trac#373) - rule-result now always includes at least one check - Other bug fixes: - Dpkginfo probe collects epoch in evr - Updated examplary openscap-content based on the latest facts from Red Hat Enterprise Linux 6 - Minor changes
Stephan Kulow (coolo)
accepted
request 222332
from
Marcus Meissner (msmeissn)
(revision 26)
- openscap-1.0.4 update: - Introduced xccdf_tailoring_remove_profile to API - OVAL bug fixes
Stephan Kulow (coolo)
accepted
request 213907
from
Marcus Meissner (msmeissn)
(revision 25)
- openscap-1.0.3 update: - bug fixes - a few coverity issues - a few memory leak plugs - broken comparison of huge integet in OVAL - fix-return.patch: removed, has upstream fix
Stephan Kulow (coolo)
accepted
request 213430
from
Marcus Meissner (msmeissn)
(revision 24)
- openscap-1.0.2 update: - XCCDF generate fix now supports tailoring file - XCCDF bug fixes - Generate guide points to RHSA pages (rhbz#1018291) - Generate report ommits remediation when assesment passed (rhbz#1029879) - $PATH variable is available for SCE checks (rhbz#1026833) - Tailoring of top-level Group elements via API fixed - Fix-filtering should not drop fixes (affected SSG) - Generated fix file is created with sane permissions (trac#362) - Inherit parent's namespace when exporting oscap_text with HTML trait - OVAL bug fixes: - Handful of xinetd probe fixes - Handful of process and process58 fixes - Obsoleted textfilecontent now supports text ent comparisons - rpm*_item/epoch is reported as '(none)' when needed - Fixed dozen of flaws in ipv4 and ipv6_address comparison (CIDR handling) - Made integer and floating type number parsing much stricter - Fixed floating point numbers comparisons (trac#366) - Fixed case-insensitive comparisons - Item filtering fixes in probes - Consolidated some of comparisons in results model and probes (trac#367) - Other bug fixes: - Workaround libxml2 bug handling x509 xmldsig (gnomebz#350248) - Fixed static build (--disable-shared) - Format assertions (-Werror=format-security) turned on by default - SCE scripts are notified when parent (oscap) is killed
Stephan Kulow (coolo)
accepted
request 209232
from
Marcus Meissner (msmeissn)
(revision 23)
- move the gconf probe to openscap-extra-probes to reduce dependencies of the core probe set.
Stephan Kulow (coolo)
accepted
request 208809
from
Marcus Meissner (msmeissn)
(revision 22)
- openscap-1.0.1 update: - versioned interface is used to handle internal SCE plug-in - build-in gnulib package was updated to current version - bug fixes: - selinux_domain_label and posix_capability properties were reintroduced to OVAL system characteristics model - selinux_domain_label now collects the domain/type (not the context) - oscap oval collect reports progress on stdout (not on the stderr) - typo in the manual page (rhbz#1032537), and another small clarification
Stephan Kulow (coolo)
accepted
request 207593
from
Marcus Meissner (msmeissn)
(revision 21)
- openscap-1.0.0 / 19-11-2013 - Improved heuristic to distinguish 'local' and 'remote' file systems - Improved comparison of EntityStateEVRStringType (trac#355) - Link against librpm (if available) to include rpmvercmp (on other platforms we fall back to the build-in rpmvercmp) - Bug fixes - openscap-0.9.13 / 08-11-2013 - Moved SCE to separate shared library (libopenscap_sce.so) - Introduction of scap-as-rpm tool - Improvements of sql and sql57 probes - Improvements of SELinux policy - Amendments based on SCAP 1.2 Errata (sp800-126r2-errata-20120409.pdf) - Minor improvements in state_entity processing - Introduction of CPE name for Fedora 21 to the internal dictionary - Added support for ind-def:pid/@xsi:nil (rhbz#1013011) - Improved error reporting - Bug fixes - Changed CPE name regex to be more permissive - avoided reports from the library to the stdout and stderr - plugged several memory leaks - improved xccdf:check-content-refs processing - misspelling in syslog message (rhbz#1021695) - fixed OVAL's <field> element processing - fixes based on static analysers - test suite is locale independent - new library major version 8
Tomáš Chvátal (scarabeus_factory)
accepted
request 202982
from
Marcus Meissner (msmeissn)
(revision 20)
- Updated to 0.9.12 - tailoring improvements (@id, version, and benchmark ref attributes) - XCCDF 1.1 tailoring extension - improved robustness of CPE dictionary parser and exporter - and added misc CPE 2.3 elements - added Fedora 20 to internal CPE dictionary - updated OVAL's results_to_html stylesheet from Mitre Corporation. - profiles with duplicate selects (same @idref) now export correctly - test improvements - bug fixes - fixed IPv6 export in TestResult/target-address - consistently inject target-id-ref into TestResult in ARFs - improved rpmdb manipulation (rhbz#999903) - solaris build fixes - spelling of name of default language fixed (oscap_text related) - fixed CPE names matching (generalization vs. specialization)
Adrian Schröter (adrianSuSE)
committed
(revision 19)
Split 13.1 from Factory
Stephan Kulow (coolo)
accepted
request 183561
from
Marcus Meissner (msmeissn)
(revision 18)
- Updated to 0.9.11 - bugfixes - Updated to 0.9.10 - bugfixes - Updated to 0.9.9 - --oval-results also exports CPE OVAL results - added --benchmark-id to select a component-ref by ID of Benchmark it's pointing to - OVAL variable_instance processing (or so called value multiset) and the processing of @variable_instance attribute to OVAL Result Definition, OVAL Result Test and Collected Objects. - improved test coverage of OVAL variable processing - introduced new internal data type: oval_smc - added support for evaluating OVAL definitions against an RPM database, a.k.a. rpm database offline mode - bug fixes and dead code removal
Stephan Kulow (coolo)
accepted
request 179323
from
Marcus Meissner (msmeissn)
(revision 17)
- updated to 0.9.8 - added experimental support for offline mode scanning to the OVAL check engine (i.e. scanning of virtual host disk images) - improved OVAL variables processing - bug fixes and dead code removal - fix-missing-include.dif
Stephan Kulow (coolo)
accepted
request 174618
from
Marcus Meissner (msmeissn)
(revision 16)
- fix build on SLE11 - possible 64Bit issue - fix-missing-include.dif (forwarded request 174495 from mcalmer)
Stephan Kulow (coolo)
accepted
request 173371
from
Marcus Meissner (msmeissn)
(revision 15)
- updated to 0.9.6 - new command-line module added as preview: "oscap ds sds-add" - improved xccdf:fix processing (support of DataStreams and CPE) - internal selinux policy preview - added Fedora 19 to default CPE dictionary - bug fixes
Stephan Kulow (coolo)
accepted
request 161603
from
Factory Maintainer (factory-maintainer)
(revision 14)
Automatic submission by obs-autosubmit
Stephan Kulow (coolo)
accepted
request 157811
from
Factory Maintainer (factory-maintainer)
(revision 13)
Automatic submission by obs-autosubmit
Adrian Schröter (adrianSuSE)
committed
(revision 12)
Split 12.3 from Factory
Stephan Kulow (coolo)
accepted
request 147554
from
Marcus Meissner (msmeissn)
(revision 11)
- updated to 0.9.3 - Embedded CPE dictionary (allows users to ommit --cpe argument) - improvements of DataStream and CPE processing on RHEL5 - changed API of various functions in cpe_dict, benchmark and xccdf_policy to use string timestamp instead of time_t [1] - fixed several issues found by Coverity and cppcheck static code analysis - bug fixes - bumped SOVERSION from 2 to 3.
Stephan Kulow (coolo)
accepted
request 142947
from
Factory Maintainer (factory-maintainer)
(revision 10)
Automatic submission by obs-autosubmit
Stephan Kulow (coolo)
accepted
request 136321
from
Marcus Meissner (msmeissn)
(revision 9)
- updated to 0.9.0: * few public headers were renamed to follow common schema * cve and cce modules are not build by default -> these modules are not utilized by oscap tool and thus untested. * --enable-bindings configure option was split into --enable-python and support of SCAP datastream support was improved * plus fixes in OVAL and XCCDF modules. oscap tool reports support of XCCDF 1.2 and OVAL 5.10.1 - libopenscap.so major version changed from 1 to 2.
Displaying revisions 61 - 80 of 88