Skip to content

rhel: fix openscap profile allowlists (HMS-9095)#1778

Merged
supakeen merged 1 commit intoosbuild:mainfrom
croissanne:fix-oscap-allowlist
Aug 21, 2025
Merged

rhel: fix openscap profile allowlists (HMS-9095)#1778
supakeen merged 1 commit intoosbuild:mainfrom
croissanne:fix-oscap-allowlist

Conversation

@croissanne
Copy link
Member

Updated based on
https://github.com/osbuild/image-builder-crc/tree/8311bea5e2fc331ac27fc79c50349a381a006696/distributions, which uses the oscap tooling to fetch a list of supported profiles per distro.

@croissanne croissanne requested a review from a team as a code owner August 21, 2025 10:46
@croissanne croissanne force-pushed the fix-oscap-allowlist branch from 244eba0 to 2b6721d Compare August 21, 2025 10:58
Copy link
Contributor

@mvo5 mvo5 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@croissanne croissanne changed the title rhel: fix openscap profile allowlists rhel: fix openscap profile allowlists (HMS-9095) Aug 21, 2025
Copy link
Member

@supakeen supakeen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving but I don't have the backstory if these are now actually the correct allow lists for each major?

@croissanne
Copy link
Member Author

Approving but I don't have the backstory if these are now actually the correct allow lists for each major?

they should be. the list i linked to is generated from https://github.com/osbuild/image-builder-crc/blob/8311bea5e2fc331ac27fc79c50349a381a006696/cmd/oscap/main.go ; which calls oscap to list profiles of all the datastreams.

@supakeen supakeen enabled auto-merge August 21, 2025 11:17
@supakeen supakeen added this pull request to the merge queue Aug 21, 2025
Merged via the queue into osbuild:main with commit 6aace0a Aug 21, 2025
24 checks passed
@croissanne croissanne deleted the fix-oscap-allowlist branch August 21, 2025 12:22
croissanne added a commit to croissanne/osbuild-composer that referenced this pull request Aug 21, 2025
Changes with 0.178.0
----------------
  - Update osbuild dependency commit ID to latest (osbuild/images#1763)
    - Author: SchutzBot, Reviewers: Achilleas Koutsou, Simon de Vlieger
  - many: drop `ISORootKickstart` (osbuild/images#1769)
    - Author: Simon de Vlieger, Reviewers: Brian C. Lane, Tomáš Hozza
  - many: drop the workload.Workload type entirely (osbuild/images#1770)
    - Author: Michael Vogt, Reviewers: Simon de Vlieger, Tomáš Hozza
  - platform: drop hardcoded platforms and rename PlatformConf (osbuild/images#1739)
    - Author: Michael Vogt, Reviewers: Brian C. Lane, Simon de Vlieger
  - rhel: fix openscap profile allowlists (HMS-9095) (osbuild/images#1778)
    - Author: Sanne Raymaekers, Reviewers: Michael Vogt, Simon de Vlieger

— Somewhere on the Internet, 2025-08-21
croissanne added a commit to osbuild/osbuild-composer that referenced this pull request Aug 21, 2025
Changes with 0.178.0
----------------
  - Update osbuild dependency commit ID to latest (osbuild/images#1763)
    - Author: SchutzBot, Reviewers: Achilleas Koutsou, Simon de Vlieger
  - many: drop `ISORootKickstart` (osbuild/images#1769)
    - Author: Simon de Vlieger, Reviewers: Brian C. Lane, Tomáš Hozza
  - many: drop the workload.Workload type entirely (osbuild/images#1770)
    - Author: Michael Vogt, Reviewers: Simon de Vlieger, Tomáš Hozza
  - platform: drop hardcoded platforms and rename PlatformConf (osbuild/images#1739)
    - Author: Michael Vogt, Reviewers: Brian C. Lane, Simon de Vlieger
  - rhel: fix openscap profile allowlists (HMS-9095) (osbuild/images#1778)
    - Author: Sanne Raymaekers, Reviewers: Michael Vogt, Simon de Vlieger

— Somewhere on the Internet, 2025-08-21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants