* Wed Jan 08 2025 abergmann@suse.com
- update to 1.4.1:
* New features
- Introduce "oscap-im" - script that can be used in Containerfiles to build
- hardened bootable container images to run as Image Mode Operating System
Maintenance, bug fix
- Add support for containers with no entrypoint/cmd in "oscap-docker"
- Stop printing useless component reference information in "oscap info"
- Fix missing declaration of PATH_MAX on Solaris
- Fix RPM database path in RPM probes (RHEL-55251, #2151)
- Fix issues reported by OpenScanHub after 1.4.0 release
- Fix failing test probes/filehash58/test_probes_filehash58.sh on s390x
- architecture
- Ensure xlink namespace exists (RHEL-34104)
- Minor fixes in test suite and CI
- update to 1.4.0:
* New features
- Introduce ability to generate Kickstarts for unattended OS installation using the oscap xccdf generate fix --fix-type kickstart command
- Add ability to process multi-profile JSON tailorings by the autotailor tool
* Removed features
- Removed cve, cvss, cvrf modules
- Removed ds submodules sds-compose, sds-add, sds-split, rds-create, rds-split
- Removed --template, --oval-template and --sce-template options from the xccdf generate submodule
- Remove the --skip-valid option (replaced by --skip-validation)
* Maintenance, bug fix
- Advertise path to SSG in remediation scripts
- Remove the option to build with PCRE
- Process CPE AL platforms if CPE dictionary isn't part of data stream
- Disable GConf probe by default (and remove dependencies from docs)
- Disable MD5 and SHA-1 by default
- Remove CPE dictionary
- Fix compiler warnings
- Update User Manual
- Remove SUSE/openSUSE CPE dictionary patches.
* drop 0001-Add-openSUSE-cpe-links.patch
* drop 0002-Add-SUSE-cpe-links.patch
- Set .so version to 33.
* Mon Sep 16 2024 meissner@suse.com
- disable sendmail buildrequires (seems unused)
- only use distribution-release to make work everywhere
* Sat May 04 2024 meissner@suse.com
- 0001-Add-openSUSE-cpe-links.patch: added Leap 15.6
* Wed Mar 20 2024 dcermak@suse.com
- Rename oscap-docker to oscap-containers and provide oscap-podman as well
(Relates to jsc#SLE-12852)
* Wed Mar 20 2024 rfrohl@suse.com
- update to 1.3.10:
* New features
- Dump all env. variables that affects the behaviour on INFO log level
- Support Blueprint services customization for masking
- Fix Blueprint template to be self-contained
- Add a refine-rule tailoring ability to autotailor
- Introduce JSON tailoring import option for autotailor
- Select rules based on reference
- Skip certain paths from scanning (controlled via env. variable)
- Introduce a limit of collected items (controlled via env. variable)
* Maintenance, bug fix
- Fix partition probe for PCRE2
- Fix NSS crypto backend
- Wrap Bash snippets in a subshell when generating a fix script
- Improve references in HTML guides and reports
- Update html report with OVAL details
- Rewrite dpkginfo probe without using APT
- Fix incorrect openscap-cpe-oval result filename
- Implement xccdf_session_get_rule_results function in XCCDF session API
- Implement xccdf_session_result_reset function in XCCDF session API
- drop 0005-rename-requires-reqs-for-C-20-compatibility.patch: fixed upstream
* Tue Feb 27 2024 jaime.marquinez.ferrandiz@fastmail.net
- Use the correct documentation's path.
* Thu Sep 21 2023 andreas.stieger@gmx.de
- update to 1.3.9:
* use PCRE2 library
* Fix offline mode (OVAL/sysctl)
* Fix leak of dpkg cache when dpkginfo_init is called multiple times
* Fix un-expanded variable in xccdf report output
* Fix issues when parsing profiles
* Fix minor problems and resource leaks
* Wed Jun 21 2023 rfrohl@suse.com
- openscap 1.3.8
* New features
- The boot-time remediation service for systemd's Offline Update mode is now disabled by default
- Add offline capabilities to the shadow OVAL probe
- Add offline capabilities to the sysctl OVAL probe
- Add 'auristorfs' to list of network fileystems
- Add new experimental linux-bound fwupdsecattr probe for system firmware security attributes (fwupd-based)
* Maintenance, bug fix
- Use ListUnitFiles D-Bus method to fetch all units in systemd OVAL probe
- Fix minor resource leaks
* Wed Mar 29 2023 meissner@suse.com
- remove _service confusion, we use final tarballs.
* Tue Mar 28 2023 kkaempf@suse.com
- Update to version 1.3.7:
* openscap-1.3.7
* Bump soname from 25.5.0 to 25.5.1
* Bump version to openscap-1.3.7
* Fix typos in docs
* Remove a check for suspicious files
* Add debian_evr_string tests to CMakeLists
* Add a few unittests for debian_evr_string
* Remove To be done
* Move release guide to upstream
- add 0005-rename-requires-reqs-for-C-20-compatibility.patch
- rename patches
openscap-opensuse-cpe.patch to 0001-Add-openSUSE-cpe-links.patch
openscap-suse-cpe.patch to 0002-Add-SUSE-cpe-links.patch
openscap-docker-add-suse.patch to 0003-Use-openSUSE-SUSE-cpe-links.patch
oscap-remediate.service.in.patch to 0004-oscap-remediate-is-located-in-bindir.patch
- drop 0001-Use-correct-includes.patch (upstream)