Skip to content

Conversation

@Mab879
Copy link
Member

@Mab879 Mab879 commented Jan 24, 2024

Description:

Move to /bin/false for disabling kernel modules.

Rationale:

It makes better error messages and follows vendor guidance.
The OVAL accepts both.

The STIG for RHEL, and OL, Ubuntu all use this format.

It makes better error messages and follows vendor guidance.
@Mab879 Mab879 added the Update Rule Issues or pull requests related to Rules updates. label Jan 24, 2024
@Mab879 Mab879 added this to the 0.1.72 milestone Jan 24, 2024
@github-actions
Copy link

Start a new ephemeral environment with changes proposed in this pull request:

Fedora Environment
Open in Gitpod

Oracle Linux 8 Environment
Open in Gitpod

@qlty-cloud-legacy
Copy link

Code Climate has analyzed commit b4ba631 and detected 0 issues on this pull request.

The test coverage on the diff in this pull request is 100.0% (50% is the threshold).

This pull request will bring the total coverage in the repository to 58.5% (0.0% change).

View more on Code Climate.

@Mab879 Mab879 added Ansible Ansible remediation update. Bash Bash remediation update. labels Jan 25, 2024
Copy link
Member

@marcusburghardt marcusburghardt left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great. CIS also has a preference for /bin/false.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ansible Ansible remediation update. Bash Bash remediation update. Update Rule Issues or pull requests related to Rules updates.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants