Waivers cleanup (scap-security-guide 0.1.74 stabilization) #253
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
I have checked 2 recent stabilization test runs and checked
warn
if some of the waivers are still there or gone/hardening/.*/cis[^/]*/sshd_use_approved_ciphers
-sshd_use_approved_ciphers
fails for all CIS profiles in all test cases ComplianceAsCode/content#12096 closed as completed/scanning/disa-alignment/.*/CCE-90811-1
- CCE-90811-1 isnotselected
by SSG, however for DISA STIG itfail
ComplianceAsCode/content#11803 closed as completed/static-checks/html-links/http://chrony.tuxfamily.org/
- CCE-90811-1 isnotselected
by SSG, however for DISA STIG itfail
ComplianceAsCode/content#11803 closed as completed/hardening/host-os/oscap/ism_o/firewalld_sshd_port_enabled
- firewalld_sshd_port_enabled fails on aarch64 in ism_o profile ComplianceAsCode/content#12233 closed as completed/scanning/disa-alignment/.*/accounts_tmout
- rule accounts_tmout is misaligned with DISA STIG ComplianceAsCode/content#11548 issue still opened. I will double check and close issue as not relevant anymoreThe rest of issues are without reported issue.
On this PR, I will perform daily productization test run to see if some of the waiver removals was incorrect.