Revisions of openscap

Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 441166 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 47)
- openscap-1.2.12 / 21-11-2016
  - New features
    - separated stdout and stderr in SCE results and HTML report
    - HTML reports contain [ref] links for rules and groups
  - Maintenance
    - fixed ARF errors reported by the SCAPval tool
    - fixed CVE parsing (issue #550)
    - fixed namespace of ARF vocabulary according to NIST SP800-126 errata
    - fixed exporting OVAL Windows namespaces
    - fixed injecting xccdf:check-content-ref references in ARF results
    - fixed oscap-docker incompliance reporting (issue #475, RHBZ #1387248)
    - fixed oscap-docker man page (RHBZ #1387166)
    - fixed memory leaks and resource leaks
    - small fixes and refactoring, test suite fixes
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 435870 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 46)
- openscap-1.2.11 / 14-10-2016
  - New features
    - huge speed-up of generating HTML reports and guides
    - support remote datastream components (issue #526)
    - support tailoring of external datastreams
    - various attributes of remediation scripts are now shown in HTML report (issue #541)
    - new option generating OVAL results without system characteristics
    - remediation scripts in HTML report are now collapsed
    - support for extracting Ansible playbooks
    - enabled fetching remote resources in OVAL module
    - added Wind River Linux CPE
  - Maintenance
    - updated jQuery and bootstrap libraries in HTML reports
    - extended, improved and updated user manual
    - fixed issues with proxy in oscap-docker (RHBZ #1351952)
    - fixed a bug in OVAL arithmetic function
    - fixed a segmentation fault (issue #529)
    - fixed results of XCCDF rules with @role="unscored" (issue #525)
    - fixed invalid characters in OVAL results (issue #468)
    - fixed a segmentation fault in tailoring (RHBZ #1367896)
    - updated SUSE 11 CPE
    - fixed many memory issues
    - large refactoring of datastream module
    - new tests in upstream test suite
    - various small fixes and improvements
- openscap-1.2.10 / 29-06-2016
  - New features
    - support --benchmark-id when running `oscap xccdf generate guide`
    - added CPE support for OpenSUSE 42.1
  - Maintenance
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 391973 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 45)
- openscap 1.2.9 release
  - New features
    - oscap-chroot - a tool for offline scanning of filesystems mounted at arbitrary paths
    - enabled offline scanning in many probes
    - support for SCE in data streams
    - many improvements of verbose mode
    - verbose messages can be written on stderr
    - runlevel probe supports SUSE systems
    - new upstream tests
  - Maintenance
    - a lot of refactoring
    - fixes in various tests
    - OCILs are correctly placed in datastreams (issue #364)
    - oscap-vm can work with fusermount when guestunmount is not available
    - fixed oscap-docker HTTP communication issues (issue #304)
    - fixed oscap-docker tracebacks (issue #303, #317)
    - fixed container mounting in oscap-docker (issue #329)
    - added Fedora 25 CPE
    - only non-empty profiles are built (rhbz#1256879, rhbz#1302230)
    - fixed compiler errors on RHEL5 and SLES11
    - fixed sorting of groups in HTML report (issue #342)
    - fixed version/@time and version/@update in XCCDF Benchmark
    - fixed CPE definitions to work also in offline mode
    - fixed sysctl probe (issue #258)
    - fixed manual page for oscap-ssh (rhbz#1299969)
    - updated user manuals and manual pages
    - updated .gitignore
- dropped fix-missing-include.dif, not needed anymore
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 378600 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 44)
- enable the SCE (script checking engine)
  packaged in "openscap-engine-sce" subpackage.
- enable the CCE (Common Configuration Enumeration)
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 354754 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 43)
- openscap 1.2.8 release
  - Maintenance
    - textfilecontent54_probe does not produce false positives on non-UTF files (rhbz #1285757)
    - fixed oscap-docker
    - small improvements in verbose mode
    - oscap info module shows information about tailoring files
    - fixed build with CCE (issue #264)
    - fixed XCCDF score computation (issue #272)
    - fixed segmentation fault in variable probe (issue #277)
    - fixed broken support for OVAL directives
    - fixed bash completion
    - plugged memory leaks
    - fixed fresh static analysis (coverity) findings
    - fixed shellcheck warnings
    - new tests
    - refactoring in datastream module
    - many small bugfixes and typo fixes
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 348807 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 42)
- openscap 1.2.7 release
  - New features                                                                                                                                                                             
    - OVAL 5.11.1 fully supported                                                                                                                                                            
    - oscap-vm - tool for offline scanning of virtual machines                                                                                                                               
    - verbose mode                                                                                                                                                                           
    - added SLED, SLES and OpenSUSE CPE names                                                                                                                                                
    - show profile description in HTML report and guide                                                                                                                                      
    - group rules by PCI DSS identifier in HTML report                                                                                                                                       
    - preliminary support for Ansible Playbooks within xccdf:fix                                                                                                                             
    - added "How to contribute" and "Versioning" documents                                                                                                                                   
  - Maintenance                                                                                                                                                                              
    - using bziped RHSA documents in oscap-docker                                                                                                                                            
    - fixed errors of sysctl probe                                                                                                                                                           
    - fixed skip-valid option (issue #203)                                                                                                                                                   
    - fixed segmentation faults in SCE content reporting (issue #231)                                                                                                                        
    - fixed tracebacks of scap-as-rpm                                                                                                                                                        
    - fixed invalid memory reads in rpmverifyfile probe (issue #212)                                                                                                                         
    - updated README and user manual                                                                                                                                                         
    - many small bugfixes and new tests                                                                                                                                                      
- openscap-new-inventory.patch: upstreamed
- fix-missing-include.dif: refreshed, 1 hunk upstream
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 340304 from Factory Maintainer's avatar Factory Maintainer (factory-maintainer) (revision 41)
Automatic submission by obs-autosubmit
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 337016 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 40)
- openscap 1.2.6 release
  - New features
    - introduced OpenSCAP user manual
    - improved OVAL 5.11.1 support
      - added OVAL 5.11.1 XSD schemas and schematrons
      - support for core/platform schema versions
      - support for check_existence attribute in state entities
      - support for CIM datetime format
      - amended behavior of mask attribute
    - added support for remote .xml.bz2 files (use with --fetch-remote-resources)
    - rewrote oscap-docker to python, deeper integration with Atomic Host
    - introduced CPE name for Fedora 24 to the internal dictionary
  - HTML report & guide
    - results can be grouped by according to various aspects
    - printing supported (interactive elements are now hidden when printing)
    - table of content now shows only selected items (rule & groups)
    - references to RHSA are presented as links to website (rhbz#1243808)
  - Maintenance
    - scap-as-rpm can now build source rpm packages (srpms) (trac#469)
    - scap-as-rpm now supports python3
    - refactored oval processing into oval_session structure
    - many smaller bugfixes and new tests
- new openscap-docker subpackage
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 315206 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 39)
- openscap-1.2.5 update
 - maintenance
   - smaller bugfixes
   - plugged memory leaks
   - fixed fresh static analysis (coverity) findings
   - fixed shellcheck warnings
   - fixes for Solaris platform
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 313072 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 38)
- openscap-1.2.4 update
  - new features
    - OVAL 5.11 support 99.8% completed!
      - new symlink probe introduced
      - new process58 test capabilities
      - added possible_value support for external variables
      - added possible_restriction support for external variables
      - improved IP address comparisons
    - Added Scientific Linux CPEs
    - Added oscap-docker tool
    - Created man-page for oscap-ssh
  - HTML changes
    - improved visibility of selected XCCDF profile in guides and reports
    - render rule-result/message contents in reports
  - maintenance
    - Tests now pass on ppc64 little endian arch (rhbz#1215220)
    - partition probe now supports remount, bind and move mount options
    - Patched NIST OVAL-5.11 schemas to be backward compatible with
      OVAL-5.10 (rhbz#1220262)
    - fixed scap-as-rpm to work with vintage python (2.6)
    - better error reporting when a probe dies (i.e. due to OOM killer)
    - dropped selinux policy from upstream (rhbz#1209969)
    - fix segfault on invalid selectors (rhbz#1220944)
    - solaris support patches: file-system zones, systeminfo improvements
    - many smaller fixes and new tests
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 306169 from Factory Maintainer's avatar Factory Maintainer (factory-maintainer) (revision 37)
Automatic submission by obs-autosubmit
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 294719 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 36)
- openscap-1.2.2 update
 - new features
   - OVAL 5.11 support turned on by default
   - included OVAL 5.11 schematron rules
   - DataStream can now contain OVAL 5.11
   - `oscap ds sds-compose` now supports --skip-valid parameter
 - HTML report changes
   - Notably increased level of OVAL details
   - Table of contents is now generated for HTML guides
 - maitenance
   - rhbz#1182242, rhbz#1159289 - @var_check & @var_ref exporting
   - solaris build fixes
   - xccdf:fix/instance processing fixes
   - improved (none) epoch processing in rpm probe
   - environmentvariable58 now emits warning messages when appropriate
   - offline mode improvements
   - other bugfixes

- openscap-1.2.1 update
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 280877 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 35)
- openscpa-1.2.1 update
 - API changes
   - 5.11 schemas updated (from RC1 to gold)
   - oscap_source_new_from_memory can take bzip2ed content
 - HTML report changes
   - severity bar is now reversed (left-to-right)
 - maintenance
   - rhbz#1165139 - fix probe cancelation
   - dozen of bugfixes
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 263739 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 34)
- openscap-1.2.0 update
 - new features
   - native support of bzip2ed SCAP files (file extension needs to be '.xml.bz2')
   - improved performance on huge XML documents, especially DataStreams
   - minimized use of temp files to absolute minimum
   - added OVAL-5.11 release candidate schemas
 - API changes
   - overall 50 new symbols added to public API
   - introduced oscap_source abstraction for input files
     - further info: http://isimluk.livejournal.com/4859.html
     - all the parsers converted to use oscap_source abstraction
   - introduced ds_sds_session, high level API for playing with Source DataStreams
   - introduced cpe_session, abstraction to approach multiple CPE resources
   - introduced ds_rds_session, high level API for playing with Result DataStreams
     (ARF files)
   - deprecated dozens of API calls dependent on filepath
   - introduced API for waivers (xccdf:override) and modification of ARF
     - initial support for waivers in HTML Report
   - dozens of small improvements
 - maintenance
   - dozens of small fixes
   - dozens of memory leaks (whole test suite is now leak free)
   - updated gnulib
- openscap-1.1.0-fix-bashisms.patch: upstreamed

- openscap-1.1.1 update
  - Hint towards `oscap info` when profile is not found in oscap tool
  - HTML report changes:
    - Source OVAL results from ARF if available
    - Highlight notchecked rules, treat them as rules that need attention
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 247494 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 33)
- openscap-1.1.0 update
 - HTML report and guide redesign
 - dropped support for docbook
 - Introduced new probes (that are to be part of OVAL 5.11)
   - probe_systemdunitproperty
   - probe_systemdunitdependency
 - introduced raw bindings for python3
 - dozens of small bug fixes
Adrian Schröter's avatar Adrian Schröter (adrianSuSE) committed (revision 32)
Split 13.2 from Factory
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 239982 from Factory Maintainer's avatar Factory Maintainer (factory-maintainer) (revision 31)
Automatic submission by obs-autosubmit
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 238127 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 30)
- Remove unused build require on libnl-1_1 according to the 
  changelog, it stopped beign used in 2010
- libattr is also unused. (forwarded request 238064 from elvigia)
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 228095 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 29)
- openscap-1.0.8 update:
  - fixes related to Asset Reporting Format
    - Inject arf:report/@id into nested
      rule-result/check/check-content-ref/@href
    - Add hostname for each fqdn when generating ARF asset identification
      data
    - Add all MAC addresses from target-facts to ARF as asset
      identification data
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 226975 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 28)
- openscap-1.0.7 update:
 - fix namespaces for attributes in ARF relationship element
 - Avoid ".00" as the score in HTML report when score is 0.

- openscap-1.0.6 update:
 - fix process58 loginuid integer handling on 32bit
Displaying revisions 41 - 60 of 87
openSUSE Build Service is sponsored by