Skip to content

Releases: ansible-lockdown/UBUNTU20-CIS

CIS v2.0.1 Jan 2026 Updates

27 Jan 14:04
ff9d0d6

Choose a tag to compare

What's Changed

New Contributors

Full Changelog: 2.2.5...2.2.6

CIS v2.0.1 - Oct25 final updates

15 Oct 08:16
6d24677

Choose a tag to compare

Based on Ubuntu 20.04 CIS v2.0.1

Overview

  • issue 148 thanks to @karlg100
  • workflow updates for new pipeline
  • audit
    • updated files and variables
    • updated vars/audit.yml
    • improved when using local copies or archived

What's Changed

Full Changelog: 2.2.4...2.2.5

CIS v2.0.1 June 2025 Updates

07 Jul 13:00
99aabb8

Choose a tag to compare

Final release of v2.0.1

Overview

audit updates
workflow improvements
pre-commit updates

What's Changed

Full Changelog: 2.2.3...2.2.4

CIS v2.0.1 March 2025 Updates

18 Mar 16:02
6dfd156

Choose a tag to compare

CIS - V 2.0.1 - 27 Jun 2023

##Remediation
Pre-commit updates

What's Changed

Full Changelog: 2.2.2...2.2.3

CIS 2.0.1 - August 24 update

13 Aug 12:51
1e86d35

Choose a tag to compare

CIS - V 2.0.1 - 27 Jun 2023

Remediate

Issues closed and PRs merged - What's changed
Pre-commit updates
workflow updates

What's Changed

New Contributors

Full Changelog: 2.2.1...2.2.2

CIS 2.0.1 - March 24 update

20 Mar 13:15
09b76de

Choose a tag to compare

CIS - V 2.0.1 - 27 Jun 2023

Remediate

Issues closed and PRs merged - What's changed
Pre-commit updates
Many improvements to different controls

AUDIT

  • Audit only option added
  • New goss binary now supported
  • Audit variables tidied and moved

What's Changed

New Contributors

Full Changelog: 2.2.0...2.2.1

CIS 2.0.1

29 Sep 14:02
5f03547

Choose a tag to compare

What's Changed

New Contributors

Full Changelog: V1.1.3...2.1.1

What's Changed

New Contributors

Full Changelog: 2.1.1...2.2.0

CIS 2.0.1 Issues and improvements

25 Sep 13:59
7b5b701

Choose a tag to compare

What's Changed

New Contributors

Full Changelog: 2.0...2.1

CIS 1.1.0

22 Mar 13:28
132801d

Choose a tag to compare

  • lint files updated
  • ansible version updated
  • Lots of lint and standardisation changes
  • fqcn
  • Assertions for root and grub passwords
  • Import tasks to allow tags to be used
  • Warnings made standard
  • warn count feature added
  • workflow updates
  • wireless interface discovery
  • idempotency checks and updates

reboot variable changed from ubtu20_skip_reboot to skip_reboot (still default true)

Remediate portion

Issues and PRs address

  • #1 set bootloader pwd - Allowed unrestricted by default but set new variables

    • Added extra variable options ubtu20cis_set_grub_password and ubtu20cis_set_root_password (defaults true)
  • #2 Ensure locks for failed attempts

  • #3 root path integrity

  • thanks to @vbotka

    • #63 parse_etc_password
  • thanks to @makefu

    • #67 UFW incoming firewall ports (optional)
  • thanks to @CFoltin

    • #68 logrotate alignment
    • #69 stop rule overwrite UFW
  • thanks to @hackery

    • #70 TMOUT stops being repeated

Many improvements on multiple controls
Remediate and audit version now match. When using remediate will pull in latest version of audit for that release.

Audit

  • updated goss version used
  • aligned new variables with audit
  • audit path used now default to /opt from /var/tmp

What's Changed

New Contributors

Full Changelog: v1.1.2...V1.1.3

Added Issue/PR Templates and Fixes

01 Sep 14:58
a35f6d3

Choose a tag to compare

CIS Version: 1.1.0 (03-31-21)

Issue Fixes:
#20 - Typo in default/main.yml file

Enhancements:

  • Added Issue templates
  • Add PR template