chore: update workflows

This commit is contained in:
Dan Brodjieski
2026-06-16 08:38:39 -04:00
parent c1ade11692
commit 3632115c2f
9 changed files with 614 additions and 1 deletions

Binary file not shown.

50
.github/ISSUE_TEMPLATE/bug_report.md vendored Normal file
View File

@@ -0,0 +1,50 @@
---
name: Bug report
about: Create a report to help us improve
title: ''
labels: ''
assignees: ''
---
<!---
Please read this!
Before opening a new issue, make sure to search for keywords in the issues filtered by the "regression" or "bug" label and verify the issue you're about to submit isn't a duplicate.
--->
### Summary
(Summarize the bug encountered concisely)
### Steps to reproduce
(How one can reproduce the issue - this is very important)
### Operating System version
(macOS Version and build)
### Intel or Apple Silicon
(Intel based process or Apple Silicon Mac)
### What is the current *bug* behavior?
(What actually happens)
### What is the expected *correct* behavior?
(What you should see instead)
### Relevant logs and/or screenshots
(Paste any relevant logs - please use code blocks (```) to format console output, logs, and code as it's tough to read otherwise.)
### Output of checks
(Paste any output that occurs with the bug)
### Possible fixes
(If you can, link to the line of code that might be responsible for the problem)

View File

@@ -0,0 +1,40 @@
---
name: Feature Proposal
about: Suggest an idea for this project
title: ''
labels: ''
assignees: ''
---
### Problem to solve
<!-- What problem do we solve? -->
### Intended users
<!-- Who will use this feature? If known, include any of the following: types of users (e.g. Member) -->
### Further details
<!-- Include use cases, benefits, and/or goals (contributes to our vision?) -->
### Proposal
<!-- How are we going to solve the problem? -->
### Documentation
<!-- Relevant documentation to the feature-->
### Testing
<!-- What risks does this change pose? How might it affect the quality of the product? What additional test coverage or changes to tests will be needed? -->
### What does success look like, and how can we measure that?
<!-- Define both the success metrics and acceptance criteria. Note that success metrics indicate the desired business outcomes, while acceptance criteria indicate when the solution is working correctly. If there is no way to measure success, link to an issue that will implement a way to measure this. -->
### Links / references
<!-- Any relevant links or references -->

26
.github/cspell/cspell.json vendored Normal file
View File

@@ -0,0 +1,26 @@
{
"version": "0.2",
"language": "en",
"allowCompoundWords": true,
"dictionaries": ["project-words", "project-names"],
"words": [],
"ignoreWords": [],
"ignorePaths": [
"**/build/**",
"**/scripts/**",
"**/*.css",
"**/config/locales/**"
],
"dictionaryDefinitions":[
{
"name": "project-words",
"path": "./project-words.txt",
"addWords": true
},
{
"name": "project-names",
"path": "./project-names.txt",
"addWords": true
}
],
}

21
.github/cspell/project-names.txt vendored Normal file
View File

@@ -0,0 +1,21 @@
Brodjieski
CNSS
Colvin
DISA
Ekkehard
Elyse
Escobar
Gapinski
Gendler
Glemza
Golbig
Heiserman
Jamf
Kegerreis
LANL
Mahlman
Piñeyro
Stamerjohann
Jordy
Witteman
Zentral

340
.github/cspell/project-words.txt vendored Normal file
View File

@@ -0,0 +1,340 @@
addressbook
adminhostinfo
adoc
adoc
ahlt
AIOS
airprint
alacarte
allowi
amfi
Anyof
apachectl
apfs
APFS
apos
APPL
appleid
applepay
applicationaccess
appstore
asciidoctor
aslmanager
auditd
AUDITD
auditreduce
authorizationdb
autologin
autologoff
autologout
blankbd
blankcd
blankdvd
bluray
bootout
byoad
caldav
carddav
CCID
ccis
CERTDOMAIN
certificatetransparency
channeltimeout
chgrp
cisv
clientalivecountmax
clientaliveinterval
cmmc
cnssi
cnssi
collab
COMSEC
conferenceroomdisplay
configarray
configfiles
configurationprofile
configurator
contentfilter
controlcenter
coreservices
cref
csrutil
cupsctl
declarationtype
deidentification
desktopservices
destroyfvkeyonstandby
disa
diskmanagement
diskutil
displaysleep
docsub
doctitle
docver
dontAllowFDEDisable
drwx
drwxr
dseditgroup
dslocal
dvdram
ecdh
elif
ENDCONFIG
energysaver
esac
esim
EXEMPTGROUP
exfiltration
facetime
familycontrols
fdesetup
filevault
fips
FIPS
firmwarepasswd
FISMA
FPKI
garageband
genmoji
Genmoji
getaccountpolicies
getline
getnetworktimeserver
GPOS
gsub
harddisk
hibernatemode
highstandbythreshold
hmac
Hostbased
iacontrols
ibeacon
idprefix
idseparator
ifdef
ifndef
IMAP
IMAPS
ioreg
ISSO
kbdinteractiveauthentication
kcminit
labl
libexec
libraryvalidation
listallnetworkservices
locationd
locationmenu
Lockdown
logingracetime
loginitems
loginwindow
Loginwindow
loginwindowtext
lpadmin
lpstat
macsec
mcxloginscripts
mcxrefresh
mdmclient
minfree
Mirroing
mobileconfig
mobiledevice
motionapp
mscp
multifactor
Multifactor
networksetup
networkusagerules
newsyslog
nfsd
nistp
nofooter
nologin
nonlocal
noout
notenforcegroup
notificationsettings
notitle
nsmap
ntlm
nvram
OCSP
opendirectory
OPORDs
opticid
osascript
OSCP
osxserver
OTAPKI
passwordauthentication
passwordpolicy
pathlist
pdflogo
PEAP
permitrootlogin
persourcepenalties
pfctl
pgrep
pkcs
pkcs
PKINIT
plutil
pmset
powernap
ppid
PPPC
praudit
Preboot
Prefs
privs
psso
PSSO
pwpolicy
pydantic
pyyaml
reauthentication
Remediator
rootok
rstrip
rtfd
ruser
sandboxing
scap
scep
screencapture
screensharing
sectnums
serveralivecountmax
serveraliveinterval
setaccountpolicies
setallowsigned
setallowsignedapp
setglobalstate
setloggingopt
setnetworkserviceenabled
setpasswd
setpolicy
setremoteappleevents
setremotelogin
shareddefaults
shareddeviceconfiguration
sharingd
shellcommand
SHOWFULLNAME
SIPRNET
siri
Siri
smartcard
Smartcard
smartcards
Smartcards
SMIME
sntp
socketfilterfw
softwareupdate
spctl
spoofable
SSDP
standbydelayhigh
standbydelaylow
startupdisk
stig
stylesdir
subscribedcalendar
sysadminctl
syscall
SYSCALL
syspolicy
systemmigration
systempolicy
systempreferences
systemsettings
systemsetup
Systemsetup
systemuiserver
textutil
tftpd
themesdir
timemachine
toclevels
touchid
touristd
tvremote
UAMDM
uiagent
ulify
universalaccess
unusedconnectiontimeout
uucp
UUCP
uwtmp
venv
visionos
vulndiscussion
waivable
webcontent
womp
wvous
xattrname
xccdf
XCCDF
xlwt
xprotect
Xprotect
xrefstyle
xsan
YARA
Informatiebeveiliging
Maatregelenset
Nederlandse
nlmapgov
NLMAPGOV
Overheid
Sonoma
Sicherheit
Informationstechnik
OLED
WLAN
BKMG
chflags
chlk
cklb
DADMS
datefmt
DBCAC
DFARS
DISN
EUID
GOTS
IATT
IAVM
ICAM
idref
Intune
ISTIG
ITSM
LICEN
lxml
NIPR
nouchg
ocil
openpyxl
quotify
rgba
shdy
stigid
stigs
STIGS
sysprefs
uchg
VALUEONDEMAND
vared
xccdfrules
xtrace
ylabel
zipf
zparseopts
numpy
yaspin

View File

@@ -0,0 +1,53 @@
name: Build documentation site to nist-pages
on:
push:
branches: ["nist-pages-docs"]
workflow_dispatch:
permissions:
contents: write
pages: write
id-token: write
concurrency:
group: "pages"
cancel-in-progress: false
env:
BUILD_PATH: "."
SITE_PATH: "https://pages.nist.gov/"
BASE_PATH: "/macos_security"
jobs:
build:
name: Build
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup PNPM
uses: pnpm/action-setup@v2
with:
version: 8
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: "20"
cache: pnpm
cache-dependency-path: ${{ env.BUILD_PATH }}/pnpm-lock.yaml
- name: Install dependencies
run: pnpm install
working-directory: ${{ env.BUILD_PATH }}
- name: Build with Astro
run: |
pnpm astro build \
--site "${{ env.SITE_PATH }}" \
--base "${{ env.BASE_PATH }}"
working-directory: ${{ env.BUILD_PATH }}
- name: Upload to nist-pages
uses: peaceiris/actions-gh-pages@v3
with:
github_token: ${{ secrets.GITHUB_TOKEN }}
publish_dir: ${{ env.BUILD_PATH }}/dist
publish_branch: nist-pages

83
.github/workflows/container-publish.yml vendored Normal file
View File

@@ -0,0 +1,83 @@
name: Build and Publish Container
on:
workflow_dispatch:
env:
REGISTRY: ghcr.io
IMAGE_NAME: ${{ github.repository_owner }}/mscp_2.0
jobs:
build-and-push:
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
id-token: write # required for cosign keyless signing via OIDC
attestations: write
steps:
- name: Checkout repository
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
ref: dev_2.0
- name: Set up QEMU
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
- name: Log in to GitHub Container Registry
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract Docker metadata
id: meta
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5
with:
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
tags: |
type=raw,value=dev_2.0
type=sha,prefix=sha-,format=short
type=raw,value=latest
- name: Build and push Docker image
id: build-push
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
with:
context: .
platforms: linux/amd64,linux/arm64
push: true
no-cache: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Install cosign
uses: sigstore/cosign-installer@f713795cb21599bc4e5c4b58cbad1da852d7eeb9 # v3
- name: Sign image with cosign (keyless via GitHub OIDC)
env:
DIGEST: ${{ steps.build-push.outputs.digest }}
TAGS: ${{ steps.meta.outputs.tags }}
COSIGN_REGISTRY_USERNAME: ${{ github.actor }}
COSIGN_REGISTRY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
run: |
images=""
for tag in ${TAGS}; do
images+="${tag}@${DIGEST} "
done
cosign sign --yes ${images}
- name: Generate SBOM attestation
uses: actions/attest-build-provenance@92c65d2898f1f53cfdc910b962cecff86e7f8fcc # v1
with:
subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
subject-digest: ${{ steps.build-push.outputs.digest }}
push-to-registry: true

View File

@@ -1,6 +1,6 @@
---
mscp:
version: '2.1'
version: '2.0'
build: 22
build_date: '2026-06-11'
release_date: '2026-12-12'