2390 Commits

Author SHA1 Message Date
Bob Gendler
0bc65f86e8 Merge pull request #752 from brodjieski/dev_27
Some checks failed
CLI Smoke Tests / CLI smoke tests (push) Has been cancelled
Lint Code Base / pythonlint (push) Has been cancelled
Lint Code Base / yamllint (push) Has been cancelled
CLI Smoke Tests / CLI tests successful (push) Has been cancelled
Lint Code Base / Lint successful (push) Has been cancelled
Update default behavior to 27.0
2026-07-29 13:55:23 -04:00
Dan Brodjieski
361b95e034 chore: fix linting error 2026-07-28 17:10:23 -04:00
Dan Brodjieski
f77fdda03a chore: update cli-tests for macos 27 2026-07-28 17:09:01 -04:00
Dan Brodjieski
d59658ec35 Merge branch 'usnistgov:dev_27' into dev_27 2026-07-28 16:27:21 -04:00
Bob Gendler
16a6e0de99 Issue #738
Some checks failed
CLI Smoke Tests / CLI smoke tests (push) Has been cancelled
CLI Smoke Tests / CLI tests successful (push) Has been cancelled
Lint Code Base / pythonlint (push) Has been cancelled
Lint Code Base / yamllint (push) Has been cancelled
Lint Code Base / Lint successful (push) Has been cancelled
2026-07-28 15:50:44 -04:00
Bob Gendler
42456818f9 Merge pull request #751 from robertgendler/dev_27
macOS 27, iOS 27, visionOS 27

Issue #739
2026-07-28 15:49:01 -04:00
Bob Gendler
fb6d341704 Merge branch 'usnistgov:dev_27' into dev_27 2026-07-28 15:47:10 -04:00
Bob Gendler
6e73ef9c86 Merge branch 'main' into dev_27 2026-07-28 15:46:02 -04:00
github-actions[bot]
2b0b687f5c chore: bump build number to 37 [skip ci] 2026-07-28 19:45:39 +00:00
Bob Gendler
435a5afd1c Merge pull request #750 from brodjieski/fix_shell_syntax
fix: shell syntax for result

fixes 

Issue #744
Issue #745
Issue #746
Issue #747
Issue #748
2026-07-28 15:44:44 -04:00
Bob Gendler
77d29c01fd Fixed missing CCEs
Updated rules so scap/xccdf build for 27.
2026-07-28 15:43:33 -04:00
Bob Gendler
7db5341bfd Rule Fixes with CCEs
- updated and fixed cce fields
- updated and fixed ddm_info for com.apple.app.settings
- updated schema to support additional DDM payloads
2026-07-28 15:09:01 -04:00
Bob Gendler
19c83d302a Merge branch 'usnistgov:dev_27' into dev_27 2026-07-28 14:17:08 -04:00
Bob Gendler
6e0b893b1c Merge branch 'main' into dev_27 2026-07-28 14:15:40 -04:00
github-actions[bot]
35a9cc5738 chore: bump build number to 36 [skip ci] 2026-07-28 18:13:48 +00:00
Bob Gendler
4a1ae0bf01 Merge pull request #749 from brodjieski/main
Refactor and fix various issues in RuleLibrary and container builds
2026-07-28 14:12:53 -04:00
github-actions[bot]
d22bc8c9dc chore: bump build number to 35 [skip ci] 2026-07-28 18:07:09 +00:00
dependabot[bot]
3f062a8a44 chore(deps): bump pillow from 12.2.0 to 12.3.0 (#741)
Bumps [pillow](https://github.com/python-pillow/Pillow) from 12.2.0 to 12.3.0.
- [Release notes](https://github.com/python-pillow/Pillow/releases)
- [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst)
- [Commits](https://github.com/python-pillow/Pillow/compare/12.2.0...12.3.0)

---
updated-dependencies:
- dependency-name: pillow
  dependency-version: 12.3.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-28 14:06:17 -04:00
Bob Gendler
a71e7286fe Modified rules for 27
added macos_27 icloud_appleid_system_settings_disable, os_allow_prerelease_disable, os_config_data_install_enforce, system_settings_critical_update_install_enforce, system_settings_software_update_app_update_enforce, system_settings_software_update_enforce
Fixed fix script formatting system_settings_system_wide_preferences_configure
2026-07-27 16:19:56 -04:00
Bob Gendler
9384a579a9 updated checks for DDM 2026-07-27 10:53:05 -04:00
Bob Gendler
27e120eec8 Fixed YAML structure 2026-07-27 10:52:54 -04:00
Bob Gendler
7532f71b73 Updating dev_27 rules
- merged os_software_update_app_update_enforce with system_settings_software_update_app_update_enforce
- removed DDM for system_settings_siri_disable
- added DDM check to pam modules
- cleaned up rule yamls
2026-07-24 22:27:34 -04:00
Dan Brodjieski
1e82d818d5 fix: shell syntax for result
update the shell commands to correctly update the result value

Issue #744
Issue #745
Issue #746
Issue #747
Issue #748
2026-07-24 17:17:57 -04:00
Dan Brodjieski
15143c8592 chore: remove debug print statement 2026-07-24 16:08:23 -04:00
Bob Gendler
58582991ad Updating rules for 27.0.
Added CCE-XXXXX-X to rules
Updated checks for software update rules
Updated links in discussions

merged icloud_enterprisebook_sync with icloud_enterprisebook_metadata_sync_disable

merged os_airplay_password_require with os_airplay_outgoing_password_require

removed os_auto_dim_allow - not on any baselines or benchmarks

merged os_background_security_improvement_removal_disable with system_settings_background_security_improvement_removal_disable

merged os_config_profile_ui_install_disable with os_install_configuration_profile_disable

merged os_disallow_enterprise_app_trust with os_allow_enterprise_trust_disabled

merged os_erase_content_and_settings_disable with os_allow_enterprise_trust_disabled

merged os_exchange_prevent_move_enforce with os_mail_move_messages_disable

merged os_external_intelligence_integration_disable with system_settings_external_intelligence_sign_in_disable

merged os_external_intelligence_integration_sign_in_disable with system_settings_external_intelligence_sign_in_disable

merged os_image_generation_disable with os_image_playground_disable

removed os_safari_popups_disabled.yaml - not on any baseline or benchmark

merged os_siri_allow_dictation_disable with os_dictation_disable

removed os_time_offset_limit_configure - not on any baseline or benchmark

merged os_usb_accessories_when_locked_disable with system_settings_usb_restricted_mode

merged os_software_update_download_enforce and system_settings_download_software_update_enforce with system_settings_software_update_download_enforce

merged os_software_update_install_enforce and system_settings_macos_updates_install_enforce with system_settings_install_macos_updates_enforce

merged system_settings_security_update_install with system_settings_critical_update_install_enforce
2026-07-24 15:51:57 -04:00
Bob Gendler
4bc7b060b5 refactor[rules] Added 27.0 Only rules
- os_bluetooth_modification_disable, visionOS
- os_chat_disable, visionOS
- os_call_recording_disable, macOS
- system_settings_siri_AI_disable, macos, ios, visionOS
- os_apple_intelligence_pcc_disable, macOS
2026-07-17 22:53:46 -04:00
Dan Brodjieski
3bde04b87f fix: add preferred key to deep merge
if provided, the key will replace the contents instead of merging

issue #736
2026-07-17 15:52:03 -04:00
Dan Brodjieski
3a44141ba7 fix: fall back to recommended if ODV is not defined
Corrects an issue where if a rule has an ODV for a benchmark, but the benchmark value is missing, it would include the literal $ODV string, making it incorrect an invalid.

Fixed the rules missing the benchmark tags for ODV.

Added verification to ensure that ODVs and Benchmarks match up.

Issue #735
2026-07-17 15:18:52 -04:00
Dan Brodjieski
f18bdf9e96 refactor: add ODV structure validation 2026-07-17 14:48:25 -04:00
Dan Brodjieski
6801cda82b fix: correct org.opencontainers.image.revision label for non-default-branch builds
docker/metadata-action sets this label from github.sha, which for
workflow_run events is always the default branch's tip, not the
branch that actually triggered the build. entrypoint.sh's update
check reads this label, so dev_27 images always looked stale
against themselves. Override it with the resolved head_sha.
2026-07-16 16:57:59 -04:00
Dan Brodjieski
7d72610897 chore: sync README from main 2026-07-16 16:46:28 -04:00
Dan Brodjieski
5b5cda21c8 fix: compare update check against the running image's own tag
entrypoint.sh always checked ghcr's :latest manifest for a newer
build, so non-main images (e.g. dev_27) incorrectly reported an
update available since their SHA never matches main's latest. Bake
the image's tag in at build time and check against that tag instead.
2026-07-16 16:42:58 -04:00
Dan Brodjieski
fd5e75e137 fix: compare update check against the running image's own tag
entrypoint.sh always checked ghcr's :latest manifest for a newer
build, so non-main images (e.g. dev_27) incorrectly reported an
update available since their SHA never matches main's latest. Bake
the image's tag in at build time and check against that tag instead.
2026-07-16 16:42:09 -04:00
Dan Brodjieski
c6e2e0c36a chore: run Lint Code Base on dev_27 pushes
Push-triggered workflows use the branch's own copy, not main's, so
this was needed on dev_27 itself for the container-publish lint gate
to find a matching run.
2026-07-16 16:27:49 -04:00
Dan Brodjieski
0b326b3209 chore: update cli for 27 2026-07-16 16:20:53 -04:00
Dan Brodjieski
53dd084bb1 chore: update container build process 2026-07-16 16:18:33 -04:00
Dan Brodjieski
be948ab684 chore: remove scap cli test from 27 2026-07-16 16:01:30 -04:00
Dan Brodjieski
e23c87fd01 chore: sync actions with main 2026-07-16 15:58:05 -04:00
Dan Brodjieski
7c36be3a8c chore: update container build for 27 2026-07-16 15:40:29 -04:00
Dan Brodjieski
95cf8c6a91 fix: default os version for 27 2026-07-16 15:39:52 -04:00
Dan Brodjieski
44c5d2ea78 Merge branch 'usnistgov:main' into main 2026-07-16 15:28:47 -04:00
Dan Brodjieski
ad13f07d70 chore: update container build process 2026-07-16 15:25:15 -04:00
github-actions[bot]
11b5896e4f chore: bump build number to 34 [skip ci] 2026-07-16 15:21:09 +00:00
Matt Woodruff
bcfde5979a Fix the supported OS table (#734)
CIS links, BSI coverage, and CIS Benchmark coverage
2026-07-16 11:20:16 -04:00
Dan Brodjieski
e989bba280 Merge branch 'usnistgov:main' into main 2026-07-14 14:21:55 -04:00
Bob Gendler
c069bfb55b refactor[rules/baseline] Initial 27.0 Public Beta
- Updated rules for macOS 27.0, iOS 27.0, and visionOS 27.0 support
- Regenerated baseline files for Apple OSes 27.0
- Updated mscp_data to support 27.
2026-07-14 11:06:08 -04:00
github-actions[bot]
76fa8e44d7 chore: bump build number to 33 [skip ci] 2026-07-14 14:44:07 +00:00
Dan Brodjieski
b64cdf4c59 Refactor logging, rules, and improve GitHub Actions workflows (#722)
* fix: spinner text info for baseline migration

* fix: update CURRENT_USER discovery

change method to use the loginwindow.plist instead of console

* refactor: release string and format

* chore: correct reference to changelog

Issue #718

* refactor: configure logging to catch early CLI issues

* refactor: clarification and inclusion of custom rules

* refactor: correct platform overrides and adjust adoc/md output

* refactor: alias mobileconfig attribute to match yaml

* refactor: admin functions for release and new rule

* chore: lint cleanup and remove markdownlint

* chore(rule): correct validation issues

* chore: adjust spellcheck to main

* chore: correct spelling issues

* chore: update container build process

* chore: trigger container build on push to main

* chore: gate container build on lint and smoke tests

* chore: pin GitHub Actions to commit SHAs and update Node.js to 22 LTS

Pin all unpinned action references to immutable commit SHAs to prevent
supply chain attacks. Upgrade checkout/setup-node from v3 to v4 in
spellcheck workflow and bump Node.js from 20 (deprecated) to 22 LTS
in build_documentation workflow.

* chore: improve GitHub Actions workflow hygiene

- Pin cspell to 10.0.1 instead of @latest
- Add permissions: contents: read to spellcheck, cli-tests, and generate_baselines workflows
- Add concurrency group to generate_baselines to prevent race conditions on rapid pushes
- Add workflow_dispatch to generate_baselines and spellcheck
- Remove dead push-to-main trigger from labeler (labels PRs only)
- Add paths filter to label-sync pull_request_target trigger
- Remove redundant ref from generate_baselines checkout step
- Pin Python to 3.12.1 in cli-tests for consistency
- Remove unnecessary --user flag from pip install in lint workflow

* chore[deps]: update pillow dependency

* chore[rule]: sync enforcement info

issue #592

* chore[rule]: correct CIS ODV

issue #621

* chore[rule]: correct CIS ODV

issue #621

* refactor: filter out incomplete baselines

* feat: add tag mutation API to RuleLibrary

Stores source_file on Macsecurityrule (excluded from serialization) so
RuleLibrary.add_tag/remove_tag can write back to disk after filtering.
Each unique source file is written at most once to avoid redundant I/O
when the library spans multiple platform/version entries for the same rule.

* feat: add add_benchmark/remove_benchmark to RuleLibrary

Unlike tag mutations, benchmark entries are stored per OS version inside
the platforms dict, so both methods group rules by source file and apply
all version mutations to a single canonical object before writing to avoid
clobbering version entries not covered by the first object encountered.

* fix: switch RuleLibrary mutation write path to text-level patching

rule.to_yaml() was designed for custom/derived output and is lossy when
applied to source files — it flattens per-version CCE/STIG dicts and
renames canonical YAML keys (800-53r5 → nist_800_53r5). Replaced all
mutation method write calls with targeted text-level patching helpers
that modify only the specific lines that change, leaving the rest of
each source file untouched.

* chore: update workflow actions

* fix: include multiple mobileconfig payloads if defined in rule

using suggestion from @adrian-ib, changed the mobileconfig info build-out in the manifest to include multiple payloads if they exist

Issue #723

* chore: fix linting and spellcheck findings

* chore: update build action to recent releases

* fix: correct issue with granular profiles and add date

profiles are now generated with a create date in the description

Issue #678

* chore: updates to container build

add entrypoint that will check if latest container and alert the user if a new one is available

move container support files from project root

* chore: adjust to check for container SHA match

* chore: update container update message

* chore: cleanup progress bar messaging

* refactor: custom logo processing in guidance

when a custom logo file is defined at the CLI, it will be copied to the custom/images/ folder for reference in guidance generation.
2026-07-14 10:43:11 -04:00
github-actions[bot]
caf3454c19 chore: bump build number to 32 [skip ci] 2026-07-14 14:41:05 +00:00
Henry Stamerjohann
4456abdcc1 Add BSI indigo 1.6 changes and fixes (#731)
* Add BSI indigo 1.6 chnages and fixes.

- include `os_safari_clear_history_disable`,
  `os_safari_private_browsing_disable`, as a defaults deny measure,
  along the new rules

`os_safari_disable` and `os_siri_service_disable`that disallow use of
Safari browser on device based on `indigo ANNEX N` App denylist.

* Delete src/mscp/data/rules/os/os_siri_service_disable.yaml

---------

Co-authored-by: Bob Gendler <robert.gendler@nist.gov>
2026-07-14 10:40:14 -04:00