2025-08-03 - 2026-02-03

Overview

0 Active Pull Requests
333 Active Issues
Excluding merges, 2 authors have pushed 11 commits to main and 505 commits to all branches. On main, 82 files have changed and there have been 2994 additions and 8740 deletions.

10 Releases published by 1 user

Published tahoe_rev2 2025-12-18 18:21:37 +00:00

Published sequoia_rev4 2025-12-18 18:21:06 +00:00

Published visionos26_rev2 2025-12-18 18:20:36 +00:00

Published ios26_rev2 2025-12-18 18:20:16 +00:00

Published tahoe_rev1 2025-09-11 20:27:16 +01:00

Published visionos26_rev1 2025-09-11 19:36:27 +01:00

Published ios26_rev1 2025-09-11 19:31:12 +01:00

Published sonoma_rev5 2025-09-11 18:35:05 +01:00

Published sequoia_rev3 2025-09-11 17:20:38 +01:00

Published ios18_rev3 2025-09-11 16:22:42 +01:00

312 Issues closed from 1 user

Closed #329 profile_generator.py - All baselines use the same 'mobileconfigs' directory 2026-01-19 18:30:05 +00:00

Closed #328 Consider adding a mapping for Common Criteria GPOS 4.2.1 2026-01-19 18:30:05 +00:00

Closed #330 Suggest mapping to the NCSC CyberEssentials 2026-01-19 18:30:05 +00:00

Closed #332 Baselines path incorrect in Wiki documentation 2026-01-19 18:30:05 +00:00

Closed #333 Baseline names should be more descriptive. 2026-01-19 18:30:05 +00:00

Closed #331 Consider adding an 800-171 baseline 2026-01-19 18:30:05 +00:00

Closed #327 Suggest mapping to the ACSC ISM 2026-01-19 18:30:04 +00:00

Closed #325 Setting for TimeServer 2026-01-19 18:30:04 +00:00

Closed #326 sysprefs_ad_tracking_disable check 2026-01-19 18:30:04 +00:00

Closed #323 Filename tweak 2026-01-19 18:30:03 +00:00

Closed #322 Missing full paths 2026-01-19 18:30:03 +00:00

Closed #324 Additional rule Disable Improve Siri & Dictation 2026-01-19 18:30:03 +00:00

Closed #320 Overwriting baseline files 2026-01-19 18:30:03 +00:00

Closed #319 profile_generator.py doesn't work unless you change directory to the "scripts" directory first 2026-01-19 18:30:03 +00:00

Closed #321 rules listed in the wrong section in baselines 2026-01-19 18:30:03 +00:00

Closed #318 sysprefs_diagnostics_reports_disable 2026-01-19 18:30:02 +00:00

Closed #313 sysprefs_find_my_disable 2026-01-19 18:30:02 +00:00

Closed #314 Concurrent session limit for SSH is not working 2026-01-19 18:30:02 +00:00

Closed #317 Consider adding a GLBA baseline 2026-01-19 18:30:02 +00:00

Closed #316 os_camera_disable 2026-01-19 18:30:02 +00:00

Closed #315 os_siri_prompt_disable 2026-01-19 18:30:02 +00:00

Closed #310 Option to sign generated profiles please! 2026-01-19 18:30:01 +00:00

Closed #312 Add a default value / Arg to generate_script 2026-01-19 18:30:01 +00:00

Closed #311 Generate Guidance script - excel export 2026-01-19 18:30:01 +00:00

Closed #307 Check for Apple Mobile File Integrity 2026-01-19 18:30:00 +00:00

Closed #305 cross reference for how rules are implemented in a tool 2026-01-19 18:30:00 +00:00

Closed #306 audit_events Sandbox violations 2026-01-19 18:30:00 +00:00

Closed #304 custom reference data should be displayed in generated documents and spreadsheet 2026-01-19 18:30:00 +00:00

Closed #309 Check for Library Validation 2026-01-19 18:30:00 +00:00

Closed #308 Option to generate plists for custom configuration profiles 2026-01-19 18:30:00 +00:00

Closed #299 Cleanup references 2026-01-19 18:29:59 +00:00

Closed #298 metadata subsection to track changes in customized rules 2026-01-19 18:29:59 +00:00

Closed #301 os_mdm_require.yaml needs to be updated for macOS 11 2026-01-19 18:29:59 +00:00

Closed #300 CJIS Baseline 2026-01-19 18:29:59 +00:00

Closed #302 Re-Map os_guest_account_disable 2026-01-19 18:29:59 +00:00

Closed #303 Fix language in os_certificate_authority_trust 2026-01-19 18:29:59 +00:00

Closed #297 Definition of exemption 2026-01-19 18:29:58 +00:00

Closed #295 add (sub)subtitles for the documentation. 2026-01-19 18:29:58 +00:00

Closed #296 fixtext commands are broken; have newline chars instead of spaces 2026-01-19 18:29:58 +00:00

Closed #289 Creation of the Excel doc with Custom references, adds extra rows while the name is the same 2026-01-19 18:29:57 +00:00

Closed #294 Missing result for this test 2026-01-19 18:29:57 +00:00

Closed #293 Fix audit_files_(group/mode/owner)_configure 2026-01-19 18:29:57 +00:00

Closed #292 Use domain-specific naming in 'PayloadDisplayName' key of configuration profiles 2026-01-19 18:29:57 +00:00

Closed #291 mobileconfig creation ignores exempt preferences settings 2026-01-19 18:29:57 +00:00

Closed #290 os_sshd_key_exchange_algorithm_configure.yaml does not have a fallback to adding the relevant line 2026-01-19 18:29:57 +00:00

Closed #284 Rule - os_facetime_app_disable.yaml - STIG ID is listed as ASOX-14-002010. It should be APPL-11-002010 2026-01-19 18:29:56 +00:00

Closed #286 os_guest_access_smb_disable 2026-01-19 18:29:56 +00:00

Closed #285 Rule - os_filevault_user_account - Change needed for Apple silicon 2026-01-19 18:29:56 +00:00

Closed #283 Add "all_rules" to generate_baseline.py -l 2026-01-19 18:29:56 +00:00

Closed #287 os_airdrop_disable check and remediation are inconsistent 2026-01-19 18:29:56 +00:00

Closed #288 audit_flags_fm_configure 2026-01-19 18:29:56 +00:00

Closed #282 audit_control policy cnt vs ahlt 2026-01-19 18:29:55 +00:00

Closed #281 auth_ssh_smartcard_enforce rename 2026-01-19 18:29:55 +00:00

Closed #280 Prevent fixes when not needed 2026-01-19 18:29:55 +00:00

Closed #277 big_sur branch has two rules that claim to be APPL-11-000001 2026-01-19 18:29:54 +00:00

Closed #278 git clone is broken 2026-01-19 18:29:54 +00:00

Closed #274 ASOX is not a normal STIG ID 2026-01-19 18:29:54 +00:00

Closed #275 mismatch between STIG rules and current version for big_sur branch 2026-01-19 18:29:54 +00:00

Closed #276 compliance_count function in generated guidance script does not correctly count findings 2026-01-19 18:29:54 +00:00

Closed #279 custom rule that sets mobileconfig: false still ends up creating a .mobileprofile file 2026-01-19 18:29:54 +00:00

Closed #269 Directory services integration test returns multiple values 2026-01-19 18:29:53 +00:00

Closed #270 Add sections for project and local site authors to custom baselines 2026-01-19 18:29:53 +00:00

Closed #271 Tag and Compliance Script check for Intel vs Apple Silicon 2026-01-19 18:29:53 +00:00

Closed #273 setting pwpolicy_file 2026-01-19 18:29:53 +00:00

Closed #272 Errors generating CIS compliance profiles 2026-01-19 18:29:53 +00:00

Closed #268 14.3. Password Policy Supplemental duplicate entry? 2026-01-19 18:29:53 +00:00

Closed #266 Firmware password check does not work on Apple Silicon-based machines. 2026-01-19 18:29:52 +00:00

Closed #267 Sudoers authenticate on per -tty basis 2026-01-19 18:29:52 +00:00

Closed #265 Mobileconfig profiles do not honor compliance script exemptions 2026-01-19 18:29:52 +00:00

Closed #259 STIG Big_Sure os_ESS_installed 2026-01-19 18:29:51 +00:00

Closed #264 Compliance script run with --fix does not apply fixes unless --check was run first 2026-01-19 18:29:51 +00:00

Closed #262 baseline compliance script output to Unified Logging 2026-01-19 18:29:51 +00:00

Closed #260 ChallengeResponseAuthentication not present in macOS Monterey 2026-01-19 18:29:51 +00:00

Closed #261 JXA Checks are causing the generated baseline_compliance.sh to break 2026-01-19 18:29:51 +00:00

Closed #263 sysprefs_wifi_disable.yaml ignored for STIG compliance 2026-01-19 18:29:51 +00:00

Closed #258 os_sudo_timeout_configure adjust check for possible spaces 2026-01-19 18:29:50 +00:00

Closed #257 time server enforcement values possibly deprecated. 2026-01-19 18:29:50 +00:00

Closed #256 (dev_monterey) os_install_log_retention_policy and audit_flags_configure not remediating 2026-01-19 18:29:50 +00:00

Closed #252 Duplicate security controls and missing reference values in 2026-01-19 18:29:49 +00:00

Closed #254 mismatched test and remediate for Monterey os_blank_bluray_disable.yaml 2026-01-19 18:29:49 +00:00

Closed #255 Disable Siri prefpane 2026-01-19 18:29:49 +00:00

Closed #253 mismatched test and mobileconfig for Monterey os_burn_support_disable 2026-01-19 18:29:49 +00:00

Closed #248 os_sudoers_tty_configure.yaml check and fix don't work 2026-01-19 18:29:48 +00:00

Closed #249 missing EOS in some rules 2026-01-19 18:29:48 +00:00

Closed #251 Add an "id:" tag to the baseline .yaml files for easier distinction between baselines versus using the "title:" tag 2026-01-19 18:29:48 +00:00

Closed #247 Modify the arg checking to suit Jamf Pro policies 2026-01-19 18:29:48 +00:00

Closed #250 remediation for os_policy_banner_loginwindow_enforce creates a wrongly named directory 2026-01-19 18:29:48 +00:00

Closed #244 Test Rule 2 2026-01-19 18:29:47 +00:00

Closed #241 Stats Reporting Incorrect 2026-01-19 18:29:47 +00:00

Closed #243 Removing a rule from guidance will not remove the rule from audit file 2026-01-19 18:29:47 +00:00

Closed #242 audit_retention_configure_sixty_days remediation not getting picked up by Jamf Protect insights 2026-01-19 18:29:47 +00:00

Closed #245 Test screensaver timeout 2026-01-19 18:29:47 +00:00

Closed #246 TOC not being generated when asciidoctor-pdf 2.0.x is installed 2026-01-19 18:29:47 +00:00

Closed #239 Remove requirement for admin prompt when install ruby gems 2026-01-19 18:29:46 +00:00

Closed #238 os_software_update_deferral gives fails finding if 'enforcedSoftwareUpdateDelay' key is not set 2026-01-19 18:29:46 +00:00

Closed #240 pwpolicy_account_lockout_enforce should check if value is less than or equal 2026-01-19 18:29:46 +00:00

Closed #234 Update sshd Checks 2026-01-19 18:29:45 +00:00

Closed #237 Add an option to view a description of rules when creating a tailored baseline 2026-01-19 18:29:45 +00:00

Closed #236 Make Configuration Profile Display Names specific to payload 2026-01-19 18:29:45 +00:00

Closed #235 os_recovery_lock_enable has incorrect key 2026-01-19 18:29:45 +00:00

Closed #233 rules/os/os_library_validation_enabled.yaml fails with: "run_fix:242: command not found: This" 2026-01-19 18:29:45 +00:00

Closed #232 sysprefs_software_update_app_update_enforce 2026-01-19 18:29:45 +00:00

Closed #230 Ummm, HOWTO 2026-01-19 18:29:44 +00:00

Closed #229 sysprefs_screensaver_ask_for_password_delay_enforce not remediated 2026-01-19 18:29:44 +00:00

Closed #231 os_hibernate_mode_enable: remediation is not effective 2026-01-19 18:29:44 +00:00

Closed #227 Disabled launchctl reports incorrectly (Ventura) 2026-01-19 18:29:44 +00:00

Closed #226 Generate_baseline -t crash 2026-01-19 18:29:44 +00:00

Closed #228 Format problem in remediation of a number of 'os' section rules 2026-01-19 18:29:44 +00:00

Closed #225 Modify sysprefs_siri_disable to use "com.apple.assistant.support" instead of "com.apple.ironwood.support" 2026-01-19 18:29:43 +00:00

Closed #223 ODV - Parent value not being applied properly 2026-01-19 18:29:43 +00:00

Closed #224 sysprefs_system_wide_preferences_configure shared key doesn't exist on some systems 2026-01-19 18:29:43 +00:00

Closed #221 Profiles with multiple disabled Pref Panes keys not detected 2026-01-19 18:29:42 +00:00

Closed #222 Big Sur Compliance Script Error 2026-01-19 18:29:42 +00:00

Closed #220 Fix CIS mappings from new draft 2026-01-19 18:29:42 +00:00

Closed #217 os_sshd_permit_root_login_configure code fails to run the validation script 2026-01-19 18:29:41 +00:00

Closed #219 Rules missing 800-53 references 2026-01-19 18:29:41 +00:00

Closed #218 icloud_appleid_system_settings_disable checking script seems to be returning inconsistent data 2026-01-19 18:29:41 +00:00

Closed #216 auth_ssh_password_authentication_disable needs to be updated for Ventura 2026-01-19 18:29:40 +00:00

Closed #215 JCE CIS Level 1 Rules are showing 2.9.3 (Level 2) 2026-01-19 18:29:40 +00:00

Closed #213 system_settings_ssh_enable check 2026-01-19 18:29:40 +00:00

Closed #214 system_settings_system_wide_preferences_configure for loop syntax 2026-01-19 18:29:40 +00:00

Closed #212 os_sshd_fips_compliant remediate issue 2026-01-19 18:29:40 +00:00

Closed #211 os_sshd_key_exchange_algorithm_configure detection issue 2026-01-19 18:29:40 +00:00

Closed #207 How to run macOS security compliance script on multiple mac devices using workspaceone MDM 2026-01-19 18:29:39 +00:00

Closed #205 os_sshd_permit_root_login_configure remediation code appends "permitrootlogin no" 2026-01-19 18:29:39 +00:00

Closed #210 Generated compliance script debug mode 2026-01-19 18:29:39 +00:00

Closed #206 Consider creating a rule that turns off Xcode Ads for Xcode Cloud 2026-01-19 18:29:39 +00:00

Closed #208 os_install_log_retention_configure 2026-01-19 18:29:39 +00:00

Closed #209 os_hibernate_mode_enable Missing hibernatemode (and spelling error) 2026-01-19 18:29:39 +00:00

Closed #202 generate_baseline.py crash with custom baselines 2026-01-19 18:29:38 +00:00

Closed #204 Rogue Highlighter 4.0.0 is not compatible with built-in Ruby 2026-01-19 18:29:38 +00:00

Closed #203 DisableGuestAccount/EnableGuestAccount key 2026-01-19 18:29:38 +00:00

Closed #201 system_settings_time_machine_encrypted_configure.yaml incorrect tag for CIS 2026-01-19 18:29:37 +00:00

Closed #196 handful of settings aren't "fixed" by compliance script 2026-01-19 18:29:37 +00:00

Closed #200 Include check that FileVault cannot be disabled in system_settings_filevault_enforce or create new rule to check 2026-01-19 18:29:37 +00:00

Closed #199 os_hibernate_mode_enable: Standby setting for Apple silicon is incorrect 2026-01-19 18:29:37 +00:00

Closed #197 where is the page that describes how to install these ? 2026-01-19 18:29:37 +00:00

Closed #198 USB Restricted Mode 2026-01-19 18:29:37 +00:00

Closed #195 Tweak SSH rules for FIPS 186-5 addition of curve25519-sha256 2026-01-19 18:29:36 +00:00

Closed #194 JAMF integration? 2026-01-19 18:29:36 +00:00

Closed #193 checking for authenticated-root hangs forever when multiple OSes are available 2026-01-19 18:29:36 +00:00

Closed #190 Create a script who doesn't need answer to fix non compliant settings 2026-01-19 18:29:35 +00:00

Closed #191 Add Safari rules for Monterey (CIS) 2026-01-19 18:29:35 +00:00

Closed #192 Set rules with pathBlackList to deprecated 2026-01-19 18:29:35 +00:00

Closed #184 Script should explicitly set LANG=C to avoid problems with localized output 2026-01-19 18:29:34 +00:00

Closed #189 Add command to remove uchg flag from /etc/security/audit_control 2026-01-19 18:29:34 +00:00

Closed #185 forceInternetSharingOff is failing check, but the key is set in com.apple.MCX 2026-01-19 18:29:34 +00:00

Closed #186 os_anti_virus_installed returns unexpected result ('integer': 3) 2026-01-19 18:29:34 +00:00

Closed #188 Scutil is referenced without full path 2026-01-19 18:29:34 +00:00

Closed #187 os_secure_boot_verify - bputil 2026-01-19 18:29:34 +00:00

Closed #182 sshd checks sometimes fail for reasons other than the rule 2026-01-19 18:29:32 +00:00

Closed #183 Checks adding to /etc/sudoers.d directory fail on fresh 13.3 installs 2026-01-19 18:29:32 +00:00

Closed #181 generate_scap crash 2026-01-19 18:29:32 +00:00

Closed #180 Asciidoctor-pdf 2.3.6 [undefined method `absolute_path?' for File:Class] error 2026-01-19 18:29:31 +00:00

Closed #177 sshd banner check and fix 2026-01-19 18:29:31 +00:00

Closed #176 clientalivecountmax and clientaliveinterval 2026-01-19 18:29:31 +00:00

Closed #179 Provide indication of whether each Guideline corresponds to Apple's default setting 2026-01-19 18:29:31 +00:00

Closed #178 Using "heredoc" Breaks Commands 2026-01-19 18:29:31 +00:00

Closed #173 Ventura firewall mobileconfig fails to install 2026-01-19 18:29:30 +00:00

Closed #175 Rule 7.7 Secure User's Home Folder is not reporting correctly 2026-01-19 18:29:30 +00:00

Closed #172 os_policy_banner_ssh_configure fails on Ventura even after remediation 2026-01-19 18:29:30 +00:00

Closed #174 compliance script should be able to say which rules fail 2026-01-19 18:29:30 +00:00

Closed #171 firmware password requirement not applicable to Apple silicon according to STIG 2026-01-19 18:29:29 +00:00

Closed #170 Compliance percentage incorrect when exempted rules pass 2026-01-19 18:29:29 +00:00

Closed #169 os_anti_virus_installed rule 2026-01-19 18:29:29 +00:00

Closed #167 Application Layer Firewall new check required 2026-01-19 18:29:28 +00:00

Closed #163 Computers that fail os_time_offset_limit_configure 2026-01-19 18:29:28 +00:00

Closed #166 Remediations on audit_control cause chaos if file is missing 2026-01-19 18:29:28 +00:00

Closed #168 Fraudulent typo 2026-01-19 18:29:28 +00:00

Closed #164 Sonoma - sshd config updates 2026-01-19 18:29:28 +00:00

Closed #165 com.apple.locationmenu missing from supported_payloads 2026-01-19 18:29:28 +00:00

Closed #162 CIS Manual Recommendations not generating properly 2026-01-19 18:29:27 +00:00

Closed #161 Indicate manual rules that are included in the baseline 2026-01-19 18:29:27 +00:00

Closed #160 Compliance percentage incorrect when exempted rules pass #267 “best practice!!! 2026-01-19 18:29:27 +00:00

Closed #154 os_install_log_retention_configure - remediation does not match check 2026-01-19 18:29:26 +00:00

Closed #155 CIS Lvl 1 6.1.1 failing false positives 2026-01-19 18:29:26 +00:00

Closed #159 submit profiles by CIS section vs functionality section 2026-01-19 18:29:26 +00:00

Closed #157 Generate recommendations Python script relies on very out of date Ruby gems 2026-01-19 18:29:26 +00:00

Closed #158 Monterey 800-171 .GlobalPreferences settings mobile config not importing into JAMF 2026-01-19 18:29:26 +00:00

Closed #156 Wiki Compliance Script typo 2026-01-19 18:29:26 +00:00

Closed #151 audit_retention_configure fails to edit the /etc/security/audit_control file 2026-01-19 18:29:25 +00:00

Closed #153 os_anti_virus_installed errors: Load Failed 5 (Sonoma) 2026-01-19 18:29:25 +00:00

Closed #152 audit_flags_fm_configure fails in dev_sonoma because of the ^fm 2026-01-19 18:29:25 +00:00

Closed #148 Configuration Profile -locationmenu not working 2026-01-19 18:29:24 +00:00

Closed #149 os_sshd_unused_connection_timeout_configure for dev_sonoma typo error 2026-01-19 18:29:24 +00:00

Closed #150 icloud_appleid_system_settings_disable (dev_sonoma) refers to deprecated domain 2026-01-19 18:29:24 +00:00

Closed #147 pwpolicy_account_lockout_enforce issues with Sonoma 2026-01-19 18:29:23 +00:00

Closed #145 os_safari_javascript_enabled not detected properly 2026-01-19 18:29:23 +00:00

Closed #144 Configuration Profile Generation 2026-01-19 18:29:23 +00:00

Closed #142 os_recovery_lock_enable should not have a manual tag 2026-01-19 18:29:23 +00:00

Closed #143 feat: support syspolicy_check a new feature in Sonoma to determine if the provided macOS application will pass the current running configurations’ system policy. 2026-01-19 18:29:23 +00:00

Closed #146 Suppress Script Output Option 2026-01-19 18:29:23 +00:00

Closed #140 iCloud privacy relay disable not working 2026-01-19 18:29:22 +00:00

Closed #141 os_gatekeeper_enable - Sonoma - Misconfiguration 2026-01-19 18:29:22 +00:00

Closed #139 Space missing in $CURRENT_USER code in adoc files 2026-01-19 18:29:22 +00:00

Closed #138 build/cis_lvl1/cis_lvl1_compliance.sh: line 6359: syntax error near unexpected token `fi' 2026-01-19 18:29:21 +00:00

Closed #137 Add baseline tags to supplemental rules 2026-01-19 18:29:21 +00:00

Closed #133 Different payload type for system_settings_screensaver_timeout_enforce 2026-01-19 18:29:21 +00:00

Closed #136 Bug: syslog daemon changes break its usage on macOS 10.13 and above 2026-01-19 18:29:21 +00:00

Closed #135 Remove multiple NTP servers from system_settings_time_server_configure.yaml 2026-01-19 18:29:21 +00:00

Closed #134 system_settings_apple_watch_unlock_disable & system_settings_touchid_unlock_disable should not be mapped to AC-11 2026-01-19 18:29:21 +00:00

Closed #127 os_mail_app_disable results in annoying popups after every login 2026-01-19 18:29:20 +00:00

Closed #132 safariAllowPopups doesn't work in Sonoma (and possibly earlier versions) 2026-01-19 18:29:20 +00:00

Closed #131 Add requirement to review exemptions to smart card login. 2026-01-19 18:29:20 +00:00

Closed #129 Prohibit execution from /tmp 2026-01-19 18:29:20 +00:00

Closed #130 Tailored by is missing in PDF output 2026-01-19 18:29:20 +00:00

Closed #128 os_hibernate_mode_apple_silicon_enable checking is broken 2026-01-19 18:29:20 +00:00

Closed #126 Rules having both the fix and the profile 2026-01-19 18:29:19 +00:00

Closed #124 Rule: os_password_hint_remove reports wrong for Guest account in the as-is audit script 2026-01-19 18:29:19 +00:00

Closed #125 os_unlock_active_user_session_disable should be an ODV 2026-01-19 18:29:19 +00:00

Closed #118 generate_baseline.py invalid escape sequence 2026-01-19 18:29:18 +00:00

Closed #122 system_settings_remote_management_disable avoid undocumented mdmclient 2026-01-19 18:29:18 +00:00

Closed #123 os_root_disable alternative implementation 2026-01-19 18:29:18 +00:00

Closed #121 SIP protected services 2026-01-19 18:29:18 +00:00

Closed #116 pwpolicy_custom_regex_enforce fix statement and note 2026-01-19 18:29:17 +00:00

Closed #115 Rules are tagged with 'stig' that do not have STIG References 2026-01-19 18:29:17 +00:00

Closed #117 os_world_writable_system_folder_configure new restricted folder 2026-01-19 18:29:17 +00:00

Closed #110 os_setup_assistant_filevault_enforce checks for wrong type 2026-01-19 18:29:16 +00:00

Closed #113 DISA customer pointed out potential issue with regex in pwpolicy_custom_regex_enforce 2026-01-19 18:29:16 +00:00

Closed #114 SyntaxWarning for python string \| with sufficiently new python version 2026-01-19 18:29:16 +00:00

Closed #112 STIG guidance leads to inconsistent failed password account locking time 2026-01-19 18:29:16 +00:00

Closed #111 Retain previous finding if check fails 2026-01-19 18:29:16 +00:00

Closed #109 unable to generate tailored baseline 2026-01-19 18:29:16 +00:00

Closed #104 Add --no-rcs to compliance script 2026-01-19 18:29:15 +00:00

Closed #108 Update PDF & HTML based on platform 2026-01-19 18:29:15 +00:00

Closed #105 Set ODV values (and perhaps other things like excluded rules) non-interactively 2026-01-19 18:29:15 +00:00

Closed #106 pwpolicy_account_lockout_enforce not presenting expected result in Log 2026-01-19 18:29:15 +00:00

Closed #107 kickstart references in benchmarks 2026-01-19 18:29:15 +00:00

Closed #103 os_world_writable_system_folder_configure borken since Sonoma 14.4 2026-01-19 18:29:15 +00:00

Closed #100 generate_guidance fails when using all_rules on the Sonoma branch 2026-01-19 18:29:14 +00:00

Closed #102 Add SFR references to iOS documents 2026-01-19 18:29:14 +00:00

Closed #101 system_settings_system_wide_preferences_configure 2026-01-19 18:29:14 +00:00

Closed #98 pwpolicy_force_pin_enable 2026-01-19 18:29:14 +00:00

Closed #99 Feature Proposal: Generate guidance in Markdown format 2026-01-19 18:29:14 +00:00

Closed #94 Asciidoctor 2.0.23 breaks html and pdf output 2026-01-19 18:29:13 +00:00

Closed #96 Changing time server value is not respected, always, in the remediation section 2026-01-19 18:29:13 +00:00

Closed #97 authorizationdb rules 2026-01-19 18:29:13 +00:00

Closed #95 DISA STIG - Text Updates 2026-01-19 18:29:13 +00:00

Closed #92 Undefined reference to 'parser' in main() of generate_baseline.py 2026-01-19 18:29:12 +00:00

Closed #90 Add basic usage instructions 2026-01-19 18:29:12 +00:00

Closed #93 SyntaxWarning: invalid escape sequence '\|' 2026-01-19 18:29:12 +00:00

Closed #88 Scripts fail if yaml file has .yml extension 2026-01-19 18:29:12 +00:00

Closed #89 system_settings_siri_listen_disable result check incorrect 2026-01-19 18:29:12 +00:00

Closed #91 Store lastComplianceCheck date string as a regularised value 2026-01-19 18:29:12 +00:00

Closed #83 system_settings_wake_network_access_disable resets on check 2026-01-19 18:29:11 +00:00

Closed #87 system_settings_wake_network_access_disable failed in VM devices 2026-01-19 18:29:11 +00:00

Closed #86 system_settings_loginwindow_loginwindowtext_enable appear in the configuration profile when not selected 2026-01-19 18:29:11 +00:00

Closed #85 system_settings_system_wide_preferences_configure.yaml is missing full path to security binary 2026-01-19 18:29:11 +00:00

Closed #81 Consider adding the newsyslog.d directory to the newsyslog rules 2026-01-19 18:29:10 +00:00

Closed #79 remove system_settings_cd_dvd_sharing_disable 2026-01-19 18:29:10 +00:00

Closed #82 $ODV value not replaced correctly in nested dict 2026-01-19 18:29:10 +00:00

Closed #80 New privacy switches in macOS 15 are not managed by allowDiagnosticSubmission 2026-01-19 18:29:10 +00:00

Closed #78 system_settings_improve_assistive_voice_disable.yaml mis-identified CIS control number 2026-01-19 18:29:09 +00:00

Closed #77 system_settings_improve_search_disable.yaml mis-identified as a CIS Level 1 control 2026-01-19 18:29:09 +00:00

Closed #76 system_settings_software_update_enforce.yaml has been silently deprecated by Apple 2026-01-19 18:29:09 +00:00

Closed #74 fix for os_ssh_server_alive_interval_configure.yaml is not successful 2026-01-19 18:29:08 +00:00

Closed #72 "check" script in system_settings_screensaver_ask_for_password_delay_enforce.yaml throws a syntax error 2026-01-19 18:29:08 +00:00

Closed #71 STIG tag missing from system_settings_improve_assistive_voice_disable.yaml 2026-01-19 18:29:08 +00:00

Closed #73 Add Apple Intelligence Controls 2026-01-19 18:29:08 +00:00

Closed #75 os_world_writable_library_folder_configure.yaml blocked by SIP? 2026-01-19 18:29:08 +00:00

Closed #70 pwpolicy_special_character_enforce: enforce more than 1 special character. 2026-01-19 18:29:08 +00:00

Closed #69 os_install_log_retention_configure - TTL will be removed after update 2026-01-19 18:29:07 +00:00

Closed #68 Running compliance script generated by Jamf Compliance Editor in terminal and the GUI "Audit Run" results differ. (CISL1) 2026-01-19 18:29:07 +00:00

Closed #63 15.3/18.3 and 15.4/18.4 keys to add 2026-01-19 18:29:06 +00:00

Closed #64 Generate Guidance does not fill out Severity Column in xlsx spreadsheet 2026-01-19 18:29:06 +00:00

Closed #62 Create a 2.x release of mSCP 2026-01-19 18:29:06 +00:00

Closed #65 ScreenSaver 2026-01-19 18:29:06 +00:00

Closed #61 forelliN 2026-01-19 18:29:06 +00:00

Closed #66 Fix pwpolicy_upper_case_character_enforce.yaml 2026-01-19 18:29:06 +00:00

Closed #59 CIS1 Password length incorrect 2026-01-19 18:29:05 +00:00

Closed #58 openSSH 9.8 - SC-05 2026-01-19 18:29:05 +00:00

Closed #60 Compliance Count CIS lvl2 2026-01-19 18:29:05 +00:00

Closed #56 system_settings_siri_listen_disable not working as intended 2026-01-19 18:29:04 +00:00

Closed #55 macOS Major version specific Audit preference file domains 2026-01-19 18:29:04 +00:00

Closed #57 Multiple issues with pwpolicy_ on Sequoia (Using Jamf Connect with EntraID as the OIDC Provider) 2026-01-19 18:29:04 +00:00

Closed #49 User Preferences Revert to Defaults Following Reboot 2026-01-19 18:29:03 +00:00

Closed #51 Request for Script or Function to Rollback Executed Commands 2026-01-19 18:29:03 +00:00

Closed #50 Generate findings report in XLS and PDF format 2026-01-19 18:29:03 +00:00

Closed #54 generate_scap.py is not functioning as expected 2026-01-19 18:29:03 +00:00

Closed #48 MacOS 15 defintion for CCE-94310 "Configure Sudo To Log Events" calls the same testID twice 2026-01-19 18:29:02 +00:00

Closed #46 Platform SSO and os_unlock_active_user_session_disable 2026-01-19 18:29:02 +00:00

Closed #45 Inconsistent Output with Guest User Directory Detection Script 2026-01-19 18:29:02 +00:00

Closed #47 False negative with V-268546 - The macOS system must enforce multifactor authentication for privilege escalation through the sudo command. 2026-01-19 18:29:02 +00:00

Closed #41 SecureKeyboardEntry not working in Tahoe 2026-01-19 18:29:01 +00:00

Closed #43 system_settings_ssh_disable (Commands discrepancy) 2026-01-19 18:29:01 +00:00

Closed #40 CMMC Baselines (SSH set to both Disable and Enable) 2026-01-19 18:29:01 +00:00

Closed #42 Rule updates for Sequoia -- os_appleid_prompt_disable, os_icloud_storage_prompt_disable, and more... 2026-01-19 18:29:01 +00:00

Closed #39 os_authenticated_root_enable is need to supress the errors 2026-01-19 18:29:00 +00:00

Closed #37 launchctl list vs print-disabled 2026-01-19 18:29:00 +00:00

Closed #34 Output of check using jq for two DDM rules fail to match 2026-01-19 18:29:00 +00:00

Closed #36 False failures with os_unlock_active_user_session_disable (Sequioa Branch) 2026-01-19 18:29:00 +00:00

Closed #30 FileVault enforcement requires FileVault payload 2026-01-19 18:28:59 +00:00

Closed #29 Password enforcement fails with allowPasscodeModification=false 2026-01-19 18:28:59 +00:00

Closed #33 Time Machine encryption check fails with space in mount point - system_settings_time_machine_encrypted_configure 2026-01-19 18:28:59 +00:00

Closed #32 Generate a consolidated configuration profile 2026-01-19 18:28:59 +00:00

Closed #26 system_settings_cd_dvd_sharing_disable rule missing from macOS 14 Sequoia and macOS 15 Sonoma 2026-01-19 18:28:58 +00:00

Closed #28 pwpolicy_minimum_length_enforce fails when min length > ODV 2026-01-19 18:28:58 +00:00

Closed #25 Configure the default behavior of the check/remediate script when run from a MDM without flag support. 2026-01-19 18:28:58 +00:00

Closed #27 Typo in os_notes_transcription_summary_disable rule on iOS_26 branch 2026-01-19 18:28:58 +00:00

Closed #23 Typo for os_siri_assistant_disable 2026-01-19 18:28:57 +00:00

Closed #24 Typo in os_implement_cryptography and os_required_crypto_module in macOS Tahoe 2026-01-19 18:28:57 +00:00

Closed #22 Modifications to "authorizationdb" in 2.6.8 cause other commands to fail when run by root, sudo or by an mdm agent 2026-01-19 18:28:57 +00:00

Closed #19 system_settings_sleep_enforce rule has same detection limitations as os_sleep_and_display_sleep_apple_silicon_enable on Apple Silicon 2026-01-19 18:28:57 +00:00

Closed #21 Incorrect MacBook detection logic in os_sleep_and_display_sleep_apple_silicon_enable check script on Apple Silicon 2026-01-19 18:28:57 +00:00

Closed #15 Screen Saver Password Enforce needs CIS lvl1 and lvl2 tag 2026-01-19 18:28:56 +00:00

Closed #16 Typo in os_sshd_fips_compliant.yaml fix code 2026-01-19 18:28:56 +00:00

Closed #18 Data quality issues. 2026-01-19 18:28:56 +00:00

Closed #8 Rule system_settings_softwareupdate_current ODV missing interval 2026-01-19 18:28:55 +00:00

Closed #9 audit_flags_fm_configure fix script no longer working 2026-01-19 18:28:55 +00:00

Closed #10 Granular MobileConfig Output 2026-01-19 18:28:55 +00:00

Closed #4 Redacted 2026-01-19 18:28:54 +00:00

Closed #6 Issue with generating pdf with generate_guidance script 2026-01-19 18:28:54 +00:00

333 Issues created by 1 user

Opened #2 pwpolicy_history_enforce set incorrectly for Tahoe CIS lvl1 2026-01-19 18:28:53 +00:00

Opened #3 Tailoring system_settings_screensaver_ask_for_password_delay_enforce $ODV=0 does not create a custom rule 2026-01-19 18:28:53 +00:00

Opened #1 system_settings_screensaver_timeout_enforce set incorrectly for Tahoe CIS lvl1 2026-01-19 18:28:53 +00:00

Opened #5 Dev_2.0 spot check on rules - noticed a few empty platforms: {} mappings 2026-01-19 18:28:54 +00:00

Opened #6 Issue with generating pdf with generate_guidance script 2026-01-19 18:28:54 +00:00

Opened #4 Redacted 2026-01-19 18:28:54 +00:00

Opened #12 Consolidated and granular .mobileconfig outputs 2026-01-19 18:28:55 +00:00

Opened #9 audit_flags_fm_configure fix script no longer working 2026-01-19 18:28:55 +00:00

Opened #10 Granular MobileConfig Output 2026-01-19 18:28:55 +00:00

Opened #8 Rule system_settings_softwareupdate_current ODV missing interval 2026-01-19 18:28:55 +00:00

Opened #11 os_anti_virus_installed errors: Tahoe 2026-01-19 18:28:55 +00:00

Opened #7 manual tag not removable by rule customization 2026-01-19 18:28:55 +00:00

Opened #15 Screen Saver Password Enforce needs CIS lvl1 and lvl2 tag 2026-01-19 18:28:56 +00:00

Opened #13 Generate remediation scripts rather than depend on check script 2026-01-19 18:28:56 +00:00

Opened #16 Typo in os_sshd_fips_compliant.yaml fix code 2026-01-19 18:28:56 +00:00

Opened #14 rules/os/os_root_disable does more than prevent root login- it breaks functionality (and isn't actually needed) 2026-01-19 18:28:56 +00:00

Opened #17 os_unlock_active_user_session_disable negatively impacts Platform SSO Accounts 2026-01-19 18:28:56 +00:00

Opened #18 Data quality issues. 2026-01-19 18:28:56 +00:00

Opened #24 Typo in os_implement_cryptography and os_required_crypto_module in macOS Tahoe 2026-01-19 18:28:57 +00:00

Opened #21 Incorrect MacBook detection logic in os_sleep_and_display_sleep_apple_silicon_enable check script on Apple Silicon 2026-01-19 18:28:57 +00:00

Opened #23 Typo for os_siri_assistant_disable 2026-01-19 18:28:57 +00:00

Opened #20 Enhanced Unification of Documentation and Scripting - Dev_2.0 2026-01-19 18:28:57 +00:00

Opened #22 Modifications to "authorizationdb" in 2.6.8 cause other commands to fail when run by root, sudo or by an mdm agent 2026-01-19 18:28:57 +00:00

Opened #19 system_settings_sleep_enforce rule has same detection limitations as os_sleep_and_display_sleep_apple_silicon_enable on Apple Silicon 2026-01-19 18:28:57 +00:00

Opened #25 Configure the default behavior of the check/remediate script when run from a MDM without flag support. 2026-01-19 18:28:58 +00:00

Opened #29 Password enforcement fails with allowPasscodeModification=false 2026-01-19 18:28:58 +00:00

Opened #27 Typo in os_notes_transcription_summary_disable rule on iOS_26 branch 2026-01-19 18:28:58 +00:00

Opened #26 system_settings_cd_dvd_sharing_disable rule missing from macOS 14 Sequoia and macOS 15 Sonoma 2026-01-19 18:28:58 +00:00

Opened #30 FileVault enforcement requires FileVault payload 2026-01-19 18:28:58 +00:00

Opened #28 pwpolicy_minimum_length_enforce fails when min length > ODV 2026-01-19 18:28:58 +00:00

Opened #31 Incorrect logic in system_settings_softwareupdate_current 2026-01-19 18:28:59 +00:00

Opened #32 Generate a consolidated configuration profile 2026-01-19 18:28:59 +00:00

Opened #33 Time Machine encryption check fails with space in mount point - system_settings_time_machine_encrypted_configure 2026-01-19 18:28:59 +00:00

Opened #37 launchctl list vs print-disabled 2026-01-19 18:29:00 +00:00

Opened #35 Add safariAllowJavaScript 2026-01-19 18:29:00 +00:00

Opened #38 Rule pwpolicy_account_inactivity_enforce can lock-out user account 2026-01-19 18:29:00 +00:00

Opened #39 os_authenticated_root_enable is need to supress the errors 2026-01-19 18:29:00 +00:00

Opened #34 Output of check using jq for two DDM rules fail to match 2026-01-19 18:29:00 +00:00

Opened #36 False failures with os_unlock_active_user_session_disable (Sequioa Branch) 2026-01-19 18:29:00 +00:00

Opened #42 Rule updates for Sequoia -- os_appleid_prompt_disable, os_icloud_storage_prompt_disable, and more... 2026-01-19 18:29:01 +00:00

Opened #44 Create Python SCP Library 2026-01-19 18:29:01 +00:00

Opened #45 Inconsistent Output with Guest User Directory Detection Script 2026-01-19 18:29:01 +00:00

Opened #40 CMMC Baselines (SSH set to both Disable and Enable) 2026-01-19 18:29:01 +00:00

Opened #41 SecureKeyboardEntry not working in Tahoe 2026-01-19 18:29:01 +00:00

Opened #43 system_settings_ssh_disable (Commands discrepancy) 2026-01-19 18:29:01 +00:00

Opened #46 Platform SSO and os_unlock_active_user_session_disable 2026-01-19 18:29:02 +00:00

Opened #48 MacOS 15 defintion for CCE-94310 "Configure Sudo To Log Events" calls the same testID twice 2026-01-19 18:29:02 +00:00

Opened #47 False negative with V-268546 - The macOS system must enforce multifactor authentication for privilege escalation through the sudo command. 2026-01-19 18:29:02 +00:00

Opened #54 generate_scap.py is not functioning as expected 2026-01-19 18:29:03 +00:00

Opened #51 Request for Script or Function to Rollback Executed Commands 2026-01-19 18:29:03 +00:00

Opened #49 User Preferences Revert to Defaults Following Reboot 2026-01-19 18:29:03 +00:00

Opened #52 Migration from MSCP 1 to MSCP 2.0 2026-01-19 18:29:03 +00:00

Opened #53 com.apple.mail.managed 2026-01-19 18:29:03 +00:00

Opened #50 Generate findings report in XLS and PDF format 2026-01-19 18:29:03 +00:00

Opened #56 system_settings_siri_listen_disable not working as intended 2026-01-19 18:29:04 +00:00

Opened #55 macOS Major version specific Audit preference file domains 2026-01-19 18:29:04 +00:00

Opened #57 Multiple issues with pwpolicy_ on Sequoia (Using Jamf Connect with EntraID as the OIDC Provider) 2026-01-19 18:29:04 +00:00

Opened #58 openSSH 9.8 - SC-05 2026-01-19 18:29:05 +00:00

Opened #59 CIS1 Password length incorrect 2026-01-19 18:29:05 +00:00

Opened #60 Compliance Count CIS lvl2 2026-01-19 18:29:05 +00:00

Opened #63 15.3/18.3 and 15.4/18.4 keys to add 2026-01-19 18:29:06 +00:00

Opened #66 Fix pwpolicy_upper_case_character_enforce.yaml 2026-01-19 18:29:06 +00:00

Opened #61 forelliN 2026-01-19 18:29:06 +00:00

Opened #65 ScreenSaver 2026-01-19 18:29:06 +00:00

Opened #62 Create a 2.x release of mSCP 2026-01-19 18:29:06 +00:00

Opened #64 Generate Guidance does not fill out Severity Column in xlsx spreadsheet 2026-01-19 18:29:06 +00:00

Opened #68 Running compliance script generated by Jamf Compliance Editor in terminal and the GUI "Audit Run" results differ. (CISL1) 2026-01-19 18:29:07 +00:00

Opened #69 os_install_log_retention_configure - TTL will be removed after update 2026-01-19 18:29:07 +00:00

Opened #67 os_sshd_fips_compliant remediation does not gracefully handle previous similar configuration settings 2026-01-19 18:29:07 +00:00

Opened #75 os_world_writable_library_folder_configure.yaml blocked by SIP? 2026-01-19 18:29:08 +00:00

Opened #72 "check" script in system_settings_screensaver_ask_for_password_delay_enforce.yaml throws a syntax error 2026-01-19 18:29:08 +00:00

Opened #70 pwpolicy_special_character_enforce: enforce more than 1 special character. 2026-01-19 18:29:08 +00:00

Opened #71 STIG tag missing from system_settings_improve_assistive_voice_disable.yaml 2026-01-19 18:29:08 +00:00

Opened #74 fix for os_ssh_server_alive_interval_configure.yaml is not successful 2026-01-19 18:29:08 +00:00

Opened #73 Add Apple Intelligence Controls 2026-01-19 18:29:08 +00:00

Opened #78 system_settings_improve_assistive_voice_disable.yaml mis-identified CIS control number 2026-01-19 18:29:09 +00:00

Opened #76 system_settings_software_update_enforce.yaml has been silently deprecated by Apple 2026-01-19 18:29:09 +00:00

Opened #77 system_settings_improve_search_disable.yaml mis-identified as a CIS Level 1 control 2026-01-19 18:29:09 +00:00

Opened #80 New privacy switches in macOS 15 are not managed by allowDiagnosticSubmission 2026-01-19 18:29:10 +00:00

Opened #84 Enforce TouchID for password autofill 2026-01-19 18:29:10 +00:00

Opened #82 $ODV value not replaced correctly in nested dict 2026-01-19 18:29:10 +00:00

Opened #83 system_settings_wake_network_access_disable resets on check 2026-01-19 18:29:10 +00:00

Opened #79 remove system_settings_cd_dvd_sharing_disable 2026-01-19 18:29:10 +00:00

Opened #81 Consider adding the newsyslog.d directory to the newsyslog rules 2026-01-19 18:29:10 +00:00

Opened #88 Scripts fail if yaml file has .yml extension 2026-01-19 18:29:11 +00:00

Opened #85 system_settings_system_wide_preferences_configure.yaml is missing full path to security binary 2026-01-19 18:29:11 +00:00

Opened #87 system_settings_wake_network_access_disable failed in VM devices 2026-01-19 18:29:11 +00:00

Opened #86 system_settings_loginwindow_loginwindowtext_enable appear in the configuration profile when not selected 2026-01-19 18:29:11 +00:00

Opened #92 Undefined reference to 'parser' in main() of generate_baseline.py 2026-01-19 18:29:12 +00:00

Opened #93 SyntaxWarning: invalid escape sequence '\|' 2026-01-19 18:29:12 +00:00

Opened #91 Store lastComplianceCheck date string as a regularised value 2026-01-19 18:29:12 +00:00

Opened #90 Add basic usage instructions 2026-01-19 18:29:12 +00:00

Opened #89 system_settings_siri_listen_disable result check incorrect 2026-01-19 18:29:12 +00:00

Opened #98 pwpolicy_force_pin_enable 2026-01-19 18:29:13 +00:00

Opened #96 Changing time server value is not respected, always, in the remediation section 2026-01-19 18:29:13 +00:00

Opened #95 DISA STIG - Text Updates 2026-01-19 18:29:13 +00:00

Opened #94 Asciidoctor 2.0.23 breaks html and pdf output 2026-01-19 18:29:13 +00:00

Opened #97 authorizationdb rules 2026-01-19 18:29:13 +00:00

Opened #99 Feature Proposal: Generate guidance in Markdown format 2026-01-19 18:29:13 +00:00

Opened #104 Add --no-rcs to compliance script 2026-01-19 18:29:14 +00:00

Opened #101 system_settings_system_wide_preferences_configure 2026-01-19 18:29:14 +00:00

Opened #102 Add SFR references to iOS documents 2026-01-19 18:29:14 +00:00

Opened #103 os_world_writable_system_folder_configure borken since Sonoma 14.4 2026-01-19 18:29:14 +00:00

Opened #105 Set ODV values (and perhaps other things like excluded rules) non-interactively 2026-01-19 18:29:14 +00:00

Opened #100 generate_guidance fails when using all_rules on the Sonoma branch 2026-01-19 18:29:14 +00:00

Opened #107 kickstart references in benchmarks 2026-01-19 18:29:15 +00:00

Opened #108 Update PDF & HTML based on platform 2026-01-19 18:29:15 +00:00

Opened #106 pwpolicy_account_lockout_enforce not presenting expected result in Log 2026-01-19 18:29:15 +00:00

Opened #114 SyntaxWarning for python string \| with sufficiently new python version 2026-01-19 18:29:16 +00:00

Opened #112 STIG guidance leads to inconsistent failed password account locking time 2026-01-19 18:29:16 +00:00

Opened #109 unable to generate tailored baseline 2026-01-19 18:29:16 +00:00

Opened #113 DISA customer pointed out potential issue with regex in pwpolicy_custom_regex_enforce 2026-01-19 18:29:16 +00:00

Opened #110 os_setup_assistant_filevault_enforce checks for wrong type 2026-01-19 18:29:16 +00:00

Opened #111 Retain previous finding if check fails 2026-01-19 18:29:16 +00:00

Opened #117 os_world_writable_system_folder_configure new restricted folder 2026-01-19 18:29:17 +00:00

Opened #115 Rules are tagged with 'stig' that do not have STIG References 2026-01-19 18:29:17 +00:00

Opened #116 pwpolicy_custom_regex_enforce fix statement and note 2026-01-19 18:29:17 +00:00

Opened #120 os_asl_log_files_*_configure are completely broken 2026-01-19 18:29:18 +00:00

Opened #123 os_root_disable alternative implementation 2026-01-19 18:29:18 +00:00

Opened #119 os_newsyslog_files_*_configure don't take /etc/newsyslog.d into account 2026-01-19 18:29:18 +00:00

Opened #121 SIP protected services 2026-01-19 18:29:18 +00:00

Opened #118 generate_baseline.py invalid escape sequence 2026-01-19 18:29:18 +00:00

Opened #122 system_settings_remote_management_disable avoid undocumented mdmclient 2026-01-19 18:29:18 +00:00

Opened #124 Rule: os_password_hint_remove reports wrong for Guest account in the as-is audit script 2026-01-19 18:29:19 +00:00

Opened #125 os_unlock_active_user_session_disable should be an ODV 2026-01-19 18:29:19 +00:00

Opened #126 Rules having both the fix and the profile 2026-01-19 18:29:19 +00:00

Opened #129 Prohibit execution from /tmp 2026-01-19 18:29:20 +00:00

Opened #132 safariAllowPopups doesn't work in Sonoma (and possibly earlier versions) 2026-01-19 18:29:20 +00:00

Opened #128 os_hibernate_mode_apple_silicon_enable checking is broken 2026-01-19 18:29:20 +00:00

Opened #131 Add requirement to review exemptions to smart card login. 2026-01-19 18:29:20 +00:00

Opened #127 os_mail_app_disable results in annoying popups after every login 2026-01-19 18:29:20 +00:00

Opened #130 Tailored by is missing in PDF output 2026-01-19 18:29:20 +00:00

Opened #138 build/cis_lvl1/cis_lvl1_compliance.sh: line 6359: syntax error near unexpected token `fi' 2026-01-19 18:29:21 +00:00

Opened #133 Different payload type for system_settings_screensaver_timeout_enforce 2026-01-19 18:29:21 +00:00

Opened #137 Add baseline tags to supplemental rules 2026-01-19 18:29:21 +00:00

Opened #134 system_settings_apple_watch_unlock_disable & system_settings_touchid_unlock_disable should not be mapped to AC-11 2026-01-19 18:29:21 +00:00

Opened #136 Bug: syslog daemon changes break its usage on macOS 10.13 and above 2026-01-19 18:29:21 +00:00

Opened #135 Remove multiple NTP servers from system_settings_time_server_configure.yaml 2026-01-19 18:29:21 +00:00

Opened #141 os_gatekeeper_enable - Sonoma - Misconfiguration 2026-01-19 18:29:22 +00:00

Opened #140 iCloud privacy relay disable not working 2026-01-19 18:29:22 +00:00

Opened #143 feat: support syspolicy_check a new feature in Sonoma to determine if the provided macOS application will pass the current running configurations’ system policy. 2026-01-19 18:29:22 +00:00

Opened #139 Space missing in $CURRENT_USER code in adoc files 2026-01-19 18:29:22 +00:00

Opened #142 os_recovery_lock_enable should not have a manual tag 2026-01-19 18:29:22 +00:00

Opened #146 Suppress Script Output Option 2026-01-19 18:29:23 +00:00

Opened #144 Configuration Profile Generation 2026-01-19 18:29:23 +00:00

Opened #147 pwpolicy_account_lockout_enforce issues with Sonoma 2026-01-19 18:29:23 +00:00

Opened #145 os_safari_javascript_enabled not detected properly 2026-01-19 18:29:23 +00:00

Opened #149 os_sshd_unused_connection_timeout_configure for dev_sonoma typo error 2026-01-19 18:29:24 +00:00

Opened #150 icloud_appleid_system_settings_disable (dev_sonoma) refers to deprecated domain 2026-01-19 18:29:24 +00:00

Opened #148 Configuration Profile -locationmenu not working 2026-01-19 18:29:24 +00:00

Opened #152 audit_flags_fm_configure fails in dev_sonoma because of the ^fm 2026-01-19 18:29:25 +00:00

Opened #151 audit_retention_configure fails to edit the /etc/security/audit_control file 2026-01-19 18:29:25 +00:00

Opened #153 os_anti_virus_installed errors: Load Failed 5 (Sonoma) 2026-01-19 18:29:25 +00:00

Opened #154 os_install_log_retention_configure - remediation does not match check 2026-01-19 18:29:26 +00:00

Opened #158 Monterey 800-171 .GlobalPreferences settings mobile config not importing into JAMF 2026-01-19 18:29:26 +00:00

Opened #159 submit profiles by CIS section vs functionality section 2026-01-19 18:29:26 +00:00

Opened #157 Generate recommendations Python script relies on very out of date Ruby gems 2026-01-19 18:29:26 +00:00

Opened #156 Wiki Compliance Script typo 2026-01-19 18:29:26 +00:00

Opened #155 CIS Lvl 1 6.1.1 failing false positives 2026-01-19 18:29:26 +00:00

Opened #160 Compliance percentage incorrect when exempted rules pass #267 “best practice!!! 2026-01-19 18:29:27 +00:00

Opened #162 CIS Manual Recommendations not generating properly 2026-01-19 18:29:27 +00:00

Opened #161 Indicate manual rules that are included in the baseline 2026-01-19 18:29:27 +00:00

Opened #166 Remediations on audit_control cause chaos if file is missing 2026-01-19 18:29:28 +00:00

Opened #168 Fraudulent typo 2026-01-19 18:29:28 +00:00

Opened #165 com.apple.locationmenu missing from supported_payloads 2026-01-19 18:29:28 +00:00

Opened #164 Sonoma - sshd config updates 2026-01-19 18:29:28 +00:00

Opened #167 Application Layer Firewall new check required 2026-01-19 18:29:28 +00:00

Opened #163 Computers that fail os_time_offset_limit_configure 2026-01-19 18:29:28 +00:00

Opened #171 firmware password requirement not applicable to Apple silicon according to STIG 2026-01-19 18:29:29 +00:00

Opened #169 os_anti_virus_installed rule 2026-01-19 18:29:29 +00:00

Opened #170 Compliance percentage incorrect when exempted rules pass 2026-01-19 18:29:29 +00:00

Opened #172 os_policy_banner_ssh_configure fails on Ventura even after remediation 2026-01-19 18:29:30 +00:00

Opened #173 Ventura firewall mobileconfig fails to install 2026-01-19 18:29:30 +00:00

Opened #174 compliance script should be able to say which rules fail 2026-01-19 18:29:30 +00:00

Opened #176 clientalivecountmax and clientaliveinterval 2026-01-19 18:29:30 +00:00

Opened #177 sshd banner check and fix 2026-01-19 18:29:30 +00:00

Opened #175 Rule 7.7 Secure User's Home Folder is not reporting correctly 2026-01-19 18:29:30 +00:00

Opened #182 sshd checks sometimes fail for reasons other than the rule 2026-01-19 18:29:31 +00:00

Opened #179 Provide indication of whether each Guideline corresponds to Apple's default setting 2026-01-19 18:29:31 +00:00

Opened #180 Asciidoctor-pdf 2.3.6 [undefined method `absolute_path?' for File:Class] error 2026-01-19 18:29:31 +00:00

Opened #181 generate_scap crash 2026-01-19 18:29:31 +00:00

Opened #178 Using "heredoc" Breaks Commands 2026-01-19 18:29:31 +00:00

Opened #183 Checks adding to /etc/sudoers.d directory fail on fresh 13.3 installs 2026-01-19 18:29:32 +00:00

Opened #189 Add command to remove uchg flag from /etc/security/audit_control 2026-01-19 18:29:34 +00:00

Opened #185 forceInternetSharingOff is failing check, but the key is set in com.apple.MCX 2026-01-19 18:29:34 +00:00

Opened #186 os_anti_virus_installed returns unexpected result ('integer': 3) 2026-01-19 18:29:34 +00:00

Opened #187 os_secure_boot_verify - bputil 2026-01-19 18:29:34 +00:00

Opened #184 Script should explicitly set LANG=C to avoid problems with localized output 2026-01-19 18:29:34 +00:00

Opened #188 Scutil is referenced without full path 2026-01-19 18:29:34 +00:00

Opened #190 Create a script who doesn't need answer to fix non compliant settings 2026-01-19 18:29:35 +00:00

Opened #192 Set rules with pathBlackList to deprecated 2026-01-19 18:29:35 +00:00

Opened #191 Add Safari rules for Monterey (CIS) 2026-01-19 18:29:35 +00:00

Opened #195 Tweak SSH rules for FIPS 186-5 addition of curve25519-sha256 2026-01-19 18:29:36 +00:00

Opened #197 where is the page that describes how to install these ? 2026-01-19 18:29:36 +00:00

Opened #193 checking for authenticated-root hangs forever when multiple OSes are available 2026-01-19 18:29:36 +00:00

Opened #196 handful of settings aren't "fixed" by compliance script 2026-01-19 18:29:36 +00:00

Opened #194 JAMF integration? 2026-01-19 18:29:36 +00:00

Opened #200 Include check that FileVault cannot be disabled in system_settings_filevault_enforce or create new rule to check 2026-01-19 18:29:37 +00:00

Opened #199 os_hibernate_mode_enable: Standby setting for Apple silicon is incorrect 2026-01-19 18:29:37 +00:00

Opened #198 USB Restricted Mode 2026-01-19 18:29:37 +00:00

Opened #201 system_settings_time_machine_encrypted_configure.yaml incorrect tag for CIS 2026-01-19 18:29:37 +00:00

Opened #203 DisableGuestAccount/EnableGuestAccount key 2026-01-19 18:29:38 +00:00

Opened #204 Rogue Highlighter 4.0.0 is not compatible with built-in Ruby 2026-01-19 18:29:38 +00:00

Opened #207 How to run macOS security compliance script on multiple mac devices using workspaceone MDM 2026-01-19 18:29:38 +00:00

Opened #206 Consider creating a rule that turns off Xcode Ads for Xcode Cloud 2026-01-19 18:29:38 +00:00

Opened #202 generate_baseline.py crash with custom baselines 2026-01-19 18:29:38 +00:00

Opened #205 os_sshd_permit_root_login_configure remediation code appends "permitrootlogin no" 2026-01-19 18:29:38 +00:00

Opened #210 Generated compliance script debug mode 2026-01-19 18:29:39 +00:00

Opened #208 os_install_log_retention_configure 2026-01-19 18:29:39 +00:00

Opened #209 os_hibernate_mode_enable Missing hibernatemode (and spelling error) 2026-01-19 18:29:39 +00:00

Opened #212 os_sshd_fips_compliant remediate issue 2026-01-19 18:29:40 +00:00

Opened #216 auth_ssh_password_authentication_disable needs to be updated for Ventura 2026-01-19 18:29:40 +00:00

Opened #211 os_sshd_key_exchange_algorithm_configure detection issue 2026-01-19 18:29:40 +00:00

Opened #213 system_settings_ssh_enable check 2026-01-19 18:29:40 +00:00

Opened #214 system_settings_system_wide_preferences_configure for loop syntax 2026-01-19 18:29:40 +00:00

Opened #215 JCE CIS Level 1 Rules are showing 2.9.3 (Level 2) 2026-01-19 18:29:40 +00:00

Opened #217 os_sshd_permit_root_login_configure code fails to run the validation script 2026-01-19 18:29:41 +00:00

Opened #218 icloud_appleid_system_settings_disable checking script seems to be returning inconsistent data 2026-01-19 18:29:41 +00:00

Opened #219 Rules missing 800-53 references 2026-01-19 18:29:41 +00:00

Opened #221 Profiles with multiple disabled Pref Panes keys not detected 2026-01-19 18:29:42 +00:00

Opened #220 Fix CIS mappings from new draft 2026-01-19 18:29:42 +00:00

Opened #222 Big Sur Compliance Script Error 2026-01-19 18:29:42 +00:00

Opened #223 ODV - Parent value not being applied properly 2026-01-19 18:29:42 +00:00

Opened #226 Generate_baseline -t crash 2026-01-19 18:29:43 +00:00

Opened #225 Modify sysprefs_siri_disable to use "com.apple.assistant.support" instead of "com.apple.ironwood.support" 2026-01-19 18:29:43 +00:00

Opened #224 sysprefs_system_wide_preferences_configure shared key doesn't exist on some systems 2026-01-19 18:29:43 +00:00

Opened #228 Format problem in remediation of a number of 'os' section rules 2026-01-19 18:29:44 +00:00

Opened #229 sysprefs_screensaver_ask_for_password_delay_enforce not remediated 2026-01-19 18:29:44 +00:00

Opened #230 Ummm, HOWTO 2026-01-19 18:29:44 +00:00

Opened #227 Disabled launchctl reports incorrectly (Ventura) 2026-01-19 18:29:44 +00:00

Opened #231 os_hibernate_mode_enable: remediation is not effective 2026-01-19 18:29:44 +00:00

Opened #234 Update sshd Checks 2026-01-19 18:29:45 +00:00

Opened #233 rules/os/os_library_validation_enabled.yaml fails with: "run_fix:242: command not found: This" 2026-01-19 18:29:45 +00:00

Opened #232 sysprefs_software_update_app_update_enforce 2026-01-19 18:29:45 +00:00

Opened #235 os_recovery_lock_enable has incorrect key 2026-01-19 18:29:45 +00:00

Opened #236 Make Configuration Profile Display Names specific to payload 2026-01-19 18:29:45 +00:00

Opened #237 Add an option to view a description of rules when creating a tailored baseline 2026-01-19 18:29:45 +00:00

Opened #240 pwpolicy_account_lockout_enforce should check if value is less than or equal 2026-01-19 18:29:46 +00:00

Opened #241 Stats Reporting Incorrect 2026-01-19 18:29:46 +00:00

Opened #239 Remove requirement for admin prompt when install ruby gems 2026-01-19 18:29:46 +00:00

Opened #238 os_software_update_deferral gives fails finding if 'enforcedSoftwareUpdateDelay' key is not set 2026-01-19 18:29:46 +00:00

Opened #243 Removing a rule from guidance will not remove the rule from audit file 2026-01-19 18:29:47 +00:00

Opened #245 Test screensaver timeout 2026-01-19 18:29:47 +00:00

Opened #242 audit_retention_configure_sixty_days remediation not getting picked up by Jamf Protect insights 2026-01-19 18:29:47 +00:00

Opened #244 Test Rule 2 2026-01-19 18:29:47 +00:00

Opened #246 TOC not being generated when asciidoctor-pdf 2.0.x is installed 2026-01-19 18:29:47 +00:00

Opened #247 Modify the arg checking to suit Jamf Pro policies 2026-01-19 18:29:48 +00:00

Opened #251 Add an "id:" tag to the baseline .yaml files for easier distinction between baselines versus using the "title:" tag 2026-01-19 18:29:48 +00:00

Opened #250 remediation for os_policy_banner_loginwindow_enforce creates a wrongly named directory 2026-01-19 18:29:48 +00:00

Opened #249 missing EOS in some rules 2026-01-19 18:29:48 +00:00

Opened #248 os_sudoers_tty_configure.yaml check and fix don't work 2026-01-19 18:29:48 +00:00

Opened #252 Duplicate security controls and missing reference values in 2026-01-19 18:29:48 +00:00

Opened #253 mismatched test and mobileconfig for Monterey os_burn_support_disable 2026-01-19 18:29:49 +00:00

Opened #255 Disable Siri prefpane 2026-01-19 18:29:49 +00:00

Opened #254 mismatched test and remediate for Monterey os_blank_bluray_disable.yaml 2026-01-19 18:29:49 +00:00

Opened #256 (dev_monterey) os_install_log_retention_policy and audit_flags_configure not remediating 2026-01-19 18:29:50 +00:00

Opened #257 time server enforcement values possibly deprecated. 2026-01-19 18:29:50 +00:00

Opened #258 os_sudo_timeout_configure adjust check for possible spaces 2026-01-19 18:29:50 +00:00

Opened #263 sysprefs_wifi_disable.yaml ignored for STIG compliance 2026-01-19 18:29:51 +00:00

Opened #260 ChallengeResponseAuthentication not present in macOS Monterey 2026-01-19 18:29:51 +00:00

Opened #259 STIG Big_Sure os_ESS_installed 2026-01-19 18:29:51 +00:00

Opened #261 JXA Checks are causing the generated baseline_compliance.sh to break 2026-01-19 18:29:51 +00:00

Opened #264 Compliance script run with --fix does not apply fixes unless --check was run first 2026-01-19 18:29:51 +00:00

Opened #262 baseline compliance script output to Unified Logging 2026-01-19 18:29:51 +00:00

Opened #267 Sudoers authenticate on per -tty basis 2026-01-19 18:29:52 +00:00

Opened #265 Mobileconfig profiles do not honor compliance script exemptions 2026-01-19 18:29:52 +00:00

Opened #266 Firmware password check does not work on Apple Silicon-based machines. 2026-01-19 18:29:52 +00:00

Opened #273 setting pwpolicy_file 2026-01-19 18:29:53 +00:00

Opened #269 Directory services integration test returns multiple values 2026-01-19 18:29:53 +00:00

Opened #270 Add sections for project and local site authors to custom baselines 2026-01-19 18:29:53 +00:00

Opened #272 Errors generating CIS compliance profiles 2026-01-19 18:29:53 +00:00

Opened #271 Tag and Compliance Script check for Intel vs Apple Silicon 2026-01-19 18:29:53 +00:00

Opened #268 14.3. Password Policy Supplemental duplicate entry? 2026-01-19 18:29:53 +00:00

Opened #274 ASOX is not a normal STIG ID 2026-01-19 18:29:54 +00:00

Opened #279 custom rule that sets mobileconfig: false still ends up creating a .mobileprofile file 2026-01-19 18:29:54 +00:00

Opened #277 big_sur branch has two rules that claim to be APPL-11-000001 2026-01-19 18:29:54 +00:00

Opened #278 git clone is broken 2026-01-19 18:29:54 +00:00

Opened #275 mismatch between STIG rules and current version for big_sur branch 2026-01-19 18:29:54 +00:00

Opened #276 compliance_count function in generated guidance script does not correctly count findings 2026-01-19 18:29:54 +00:00

Opened #280 Prevent fixes when not needed 2026-01-19 18:29:55 +00:00

Opened #281 auth_ssh_smartcard_enforce rename 2026-01-19 18:29:55 +00:00

Opened #282 audit_control policy cnt vs ahlt 2026-01-19 18:29:55 +00:00

Opened #288 audit_flags_fm_configure 2026-01-19 18:29:56 +00:00

Opened #287 os_airdrop_disable check and remediation are inconsistent 2026-01-19 18:29:56 +00:00

Opened #285 Rule - os_filevault_user_account - Change needed for Apple silicon 2026-01-19 18:29:56 +00:00

Opened #284 Rule - os_facetime_app_disable.yaml - STIG ID is listed as ASOX-14-002010. It should be APPL-11-002010 2026-01-19 18:29:56 +00:00

Opened #286 os_guest_access_smb_disable 2026-01-19 18:29:56 +00:00

Opened #283 Add "all_rules" to generate_baseline.py -l 2026-01-19 18:29:56 +00:00

Opened #294 Missing result for this test 2026-01-19 18:29:57 +00:00

Opened #293 Fix audit_files_(group/mode/owner)_configure 2026-01-19 18:29:57 +00:00

Opened #290 os_sshd_key_exchange_algorithm_configure.yaml does not have a fallback to adding the relevant line 2026-01-19 18:29:57 +00:00

Opened #292 Use domain-specific naming in 'PayloadDisplayName' key of configuration profiles 2026-01-19 18:29:57 +00:00

Opened #291 mobileconfig creation ignores exempt preferences settings 2026-01-19 18:29:57 +00:00

Opened #289 Creation of the Excel doc with Custom references, adds extra rows while the name is the same 2026-01-19 18:29:57 +00:00

Opened #296 fixtext commands are broken; have newline chars instead of spaces 2026-01-19 18:29:58 +00:00

Opened #297 Definition of exemption 2026-01-19 18:29:58 +00:00

Opened #295 add (sub)subtitles for the documentation. 2026-01-19 18:29:58 +00:00

Opened #300 CJIS Baseline 2026-01-19 18:29:59 +00:00

Opened #303 Fix language in os_certificate_authority_trust 2026-01-19 18:29:59 +00:00

Opened #301 os_mdm_require.yaml needs to be updated for macOS 11 2026-01-19 18:29:59 +00:00

Opened #302 Re-Map os_guest_account_disable 2026-01-19 18:29:59 +00:00

Opened #299 Cleanup references 2026-01-19 18:29:59 +00:00

Opened #298 metadata subsection to track changes in customized rules 2026-01-19 18:29:59 +00:00

Opened #309 Check for Library Validation 2026-01-19 18:30:00 +00:00

Opened #304 custom reference data should be displayed in generated documents and spreadsheet 2026-01-19 18:30:00 +00:00

Opened #306 audit_events Sandbox violations 2026-01-19 18:30:00 +00:00

Opened #305 cross reference for how rules are implemented in a tool 2026-01-19 18:30:00 +00:00

Opened #307 Check for Apple Mobile File Integrity 2026-01-19 18:30:00 +00:00

Opened #308 Option to generate plists for custom configuration profiles 2026-01-19 18:30:00 +00:00

Opened #310 Option to sign generated profiles please! 2026-01-19 18:30:01 +00:00

Opened #312 Add a default value / Arg to generate_script 2026-01-19 18:30:01 +00:00

Opened #311 Generate Guidance script - excel export 2026-01-19 18:30:01 +00:00

Opened #317 Consider adding a GLBA baseline 2026-01-19 18:30:02 +00:00

Opened #314 Concurrent session limit for SSH is not working 2026-01-19 18:30:02 +00:00

Opened #316 os_camera_disable 2026-01-19 18:30:02 +00:00

Opened #313 sysprefs_find_my_disable 2026-01-19 18:30:02 +00:00

Opened #315 os_siri_prompt_disable 2026-01-19 18:30:02 +00:00

Opened #318 sysprefs_diagnostics_reports_disable 2026-01-19 18:30:02 +00:00

Opened #320 Overwriting baseline files 2026-01-19 18:30:03 +00:00

Opened #319 profile_generator.py doesn't work unless you change directory to the "scripts" directory first 2026-01-19 18:30:03 +00:00

Opened #321 rules listed in the wrong section in baselines 2026-01-19 18:30:03 +00:00

Opened #323 Filename tweak 2026-01-19 18:30:03 +00:00

Opened #324 Additional rule Disable Improve Siri & Dictation 2026-01-19 18:30:03 +00:00

Opened #322 Missing full paths 2026-01-19 18:30:03 +00:00

Opened #325 Setting for TimeServer 2026-01-19 18:30:04 +00:00

Opened #326 sysprefs_ad_tracking_disable check 2026-01-19 18:30:04 +00:00

Opened #327 Suggest mapping to the ACSC ISM 2026-01-19 18:30:04 +00:00

Opened #332 Baselines path incorrect in Wiki documentation 2026-01-19 18:30:05 +00:00

Opened #333 Baseline names should be more descriptive. 2026-01-19 18:30:05 +00:00

Opened #331 Consider adding an 800-171 baseline 2026-01-19 18:30:05 +00:00

Opened #329 profile_generator.py - All baselines use the same 'mobileconfigs' directory 2026-01-19 18:30:05 +00:00

Opened #328 Consider adding a mapping for Common Criteria GPOS 4.2.1 2026-01-19 18:30:05 +00:00

Opened #330 Suggest mapping to the NCSC CyberEssentials 2026-01-19 18:30:05 +00:00