debian-cis

PCI-DSS compliant Debian 10/11/12 hardening

OTHER License

Stars
719

Bot releases are visible (Hide)

debian-cis - Pre-release Latest Release

Published by github-actions[bot] 6 months ago

  • 6079b16 - fix: invalid behavior on sid/alternative in 5.3.4/99.5.4.5.1 (#237)
  • f7cdf43 - build(deps): bump metcalfc/changelog-generator from 4.2.0 to 4.3.1 (#234)
  • 43fc23e - fix: catch cidr network in ssh keys (#236)
  • 3bd4078 - fix: allow set-hardening-level option usage (#232)
debian-cis - Pre-release

Published by github-actions[bot] 8 months ago

debian-cis - Pre-release

Published by github-actions[bot] 8 months ago

  • 43fc23e - fix: catch cidr network in ssh keys (#236)
  • 3bd4078 - fix: allow set-hardening-level option usage (#232)
debian-cis - Pre-release

Published by github-actions[bot] 9 months ago

  • 3bd4078 - fix: allow set-hardening-level option usage (#232)
debian-cis - Release v4.1-4

Published by github-actions[bot] 9 months ago

  • allow multiple users in 5.2.18 (#228)
  • Allow multiple exception users to be defined for 99.5.2.4_ssh_keys_from (#221)
  • Syslog-ng fixes and enhancements (#226)
  • fix: Allow --only option to be called multiple times (#225)
  • fix: update Readme to clarify project usage (#223)
  • fix: typo in README. Update example of --audit usage (#222)
debian-cis - Pre-release

Published by github-actions[bot] 9 months ago

debian-cis - Pre-release

Published by github-actions[bot] 10 months ago

  • 5313799 - Allow multiple exception users to be defined for 99.5.2.4_ssh_keys_from (#221)
  • 73616af - Syslog-ng fixes and enhancements (#226)
  • c391723 - fix: Allow --only option to be called multiple times (#225)
  • 71019a5 - fix: update Readme to clarify project usage (#223)
  • fb4df82 - fix: typo in README. Update example of --audit usage (#222)
debian-cis - Pre-release

Published by github-actions[bot] 10 months ago

  • 71019a5 - fix: update Readme to clarify project usage (#223)
  • fb4df82 - fix: typo in README. Update example of --audit usage (#222)
debian-cis - Release v4.1-3

Published by github-actions[bot] 11 months ago

  • Adapt all scripts to yescrypt (#216)
  • build(deps): bump metcalfc/changelog-generator from 4.1.0 to 4.2.0 (#214)
  • fix: clean obsolete check 99.5.4.5.1, now handled by 5.3.4 (#215)
  • enh: remove ssh system sandbox check (#213)
  • build(deps): bump luizm/action-sh-checker from 0.7.0 to 0.8.0 (#210)
  • feat: advertise Debian 12 compatibility in readme
debian-cis - Pre-release

Published by github-actions[bot] 11 months ago

debian-cis - Pre-release

Published by github-actions[bot] 11 months ago

  • 0eb2e2f - enh: remove ssh system sandbox check (#213)
  • d6c3341 - build(deps): bump luizm/action-sh-checker from 0.7.0 to 0.8.0 (#210)
  • 2188577 - feat: advertise Debian 12 compatibility in readme
debian-cis - Pre-release

Published by github-actions[bot] 11 months ago

debian-cis - Pre-release

Published by github-actions[bot] about 1 year ago

  • 2188577f - feat: advertise Debian 12 compatibility in readme
debian-cis - Release v4.1-2

Published by github-actions[bot] about 1 year ago

  • fix: root_dir is still /opt/cis-hardening for the moment (#208)
debian-cis - Release v4.1-1

Published by github-actions[bot] about 1 year ago

  • fix: debian12 functional test pass is now mandatory (#207)
  • feat: Officialize Debian 12 support (#206)
  • Update the README to reflect on changes made in PR#204 (#205)
  • Replace CIS_ROOT_DIR by a more flexible system (#204)
  • feat: add nftables to firewall software allow list (#203)
  • build(deps): bump actions/checkout from 3 to 4 (#202)
  • fix: correct debian version check on 5.2.15 configuration generation (#199)
  • fix: chore, debug logs print correctly now (#197)
  • fix: chore debian manual update (#198)
  • build(deps): bump dev-drprasad/delete-tag-and-release (#184)
  • fix: added systemd-timesyncd to use_time_sync script (#189) (#190)
  • Update warn messages on 2.2.15_mta_localhost.sh (#193)
  • fix: enhance test 99.1.3 speed for large /etc/sudoers.d folders (#188)
  • feat: Add experimental debian12 functionnal tests (#187)
debian-cis - Pre-release

Published by github-actions[bot] about 1 year ago

  • 08aff5d - Update the README to reflect on changes made in PR#204 (#205)
  • 32886d3 - Replace CIS_ROOT_DIR by a more flexible system (#204)
  • 5370ec2 - feat: add nftables to firewall software allow list (#203)
  • 9d3fb18 - build(deps): bump actions/checkout from 3 to 4 (#202)
  • 6e79fcd - fix: correct debian version check on 5.2.15 configuration generation (#199)
  • 27edec6 - fix: chore, debug logs print correctly now (#197)
  • f2cc14c - fix: chore debian manual update (#198)
  • 46377fc - build(deps): bump dev-drprasad/delete-tag-and-release (#184)
  • a468b29 - fix: added systemd-timesyncd to use_time_sync script (#189) (#190)
  • db9ff8a - Update warn messages on 2.2.15_mta_localhost.sh (#193)
  • 6135c3d - fix: enhance test 99.1.3 speed for large /etc/sudoers.d folders (#188)
  • a6ad528 - feat: Add experimental debian12 functionnal tests (#187)
debian-cis - Pre-release

Published by github-actions[bot] about 1 year ago

  • 32886d3 - Replace CIS_ROOT_DIR by a more flexible system (#204)
  • 5370ec2 - feat: add nftables to firewall software allow list (#203)
  • 9d3fb18 - build(deps): bump actions/checkout from 3 to 4 (#202)
  • 6e79fcd - fix: correct debian version check on 5.2.15 configuration generation (#199)
  • 27edec6 - fix: chore, debug logs print correctly now (#197)
  • f2cc14c - fix: chore debian manual update (#198)
  • 46377fc - build(deps): bump dev-drprasad/delete-tag-and-release (#184)
  • a468b29 - fix: added systemd-timesyncd to use_time_sync script (#189) (#190)
  • db9ff8a - Update warn messages on 2.2.15_mta_localhost.sh (#193)
  • 6135c3d - fix: enhance test 99.1.3 speed for large /etc/sudoers.d folders (#188)
  • a6ad528 - feat: Add experimental debian12 functionnal tests (#187)
debian-cis - Release v4.0-1

Published by github-actions[bot] over 1 year ago

  • fix: 99.1.3_acc_sudoers_no_all: fix a race condition (#186)
  • fix: change auditd file rule remediation (#179)
  • fix: correct debian package compression override (#181)
  • fix: ensure mountpoints are properly detected (#177)
  • fix: correct search in 5.4.5_default_timeout in apply mode (#178)
  • fix: force xz compression during .deb build (#180)
  • feat: official Debian 11 compatibility (#176)
  • Bump luizm/action-sh-checker from 0.5.0 to 0.7.0 (#171)
debian-cis - Release v3.8-1

Published by github-actions[bot] over 1 year ago

  • fix: timeout of 99.1.3 (#168)
debian-cis - Release v3.7-1

Published by github-actions[bot] over 2 years ago

  • feat: add FIND_IGNORE_NOSUCHFILE_ERR flag (#159)