From 3dd52a496bcb635d3b292cabbe3bf2d6afbf0b22 Mon Sep 17 00:00:00 2001 From: dev-sec CI Date: Tue, 19 May 2020 10:06:32 +0000 Subject: [PATCH] update inspec.yml and changelog --- CHANGELOG.md | 68 +++++----------------------------------------------- inspec.yml | 3 ++- 2 files changed, 8 insertions(+), 63 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 365a7c8..96898d2 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,73 +1,17 @@ -# Change Log +# Changelog -## [1.5.0](https://github.com/dev-sec/ssl-baseline/tree/1.5.0) (2020-03-13) -[Full Changelog](https://github.com/dev-sec/ssl-baseline/compare/1.5.0...1.5.0) +## [1.3.1](https://github.com/dev-sec/ssl-baseline/tree/1.3.1) (2020-05-19) -**Merged pull requests:** - -- debug force\_ssl [\#30](https://github.com/dev-sec/ssl-baseline/pull/30) ([micheelengronne](https://github.com/micheelengronne)) -- Update for Inspec 4 [\#29](https://github.com/dev-sec/ssl-baseline/pull/29) ([micheelengronne](https://github.com/micheelengronne)) - -## [1.5.0](https://github.com/dev-sec/ssl-baseline/tree/1.5.0) (2020-03-12) -[Full Changelog](https://github.com/dev-sec/ssl-baseline/compare/1.4.0...1.5.0) - -**Merged pull requests:** - -- force\_ssl disable the check for SSL [\#28](https://github.com/dev-sec/ssl-baseline/pull/28) ([micheelengronne](https://github.com/micheelengronne)) - -## [1.4.0](https://github.com/dev-sec/ssl-baseline/tree/1.4.0) (2019-05-16) -[Full Changelog](https://github.com/dev-sec/ssl-baseline/compare/1.3.0...1.4.0) +[Full Changelog](https://github.com/dev-sec/ssl-baseline/compare/1.6.0...1.3.1) **Closed issues:** -- Ubuntu 14.04 unsupported? [\#20](https://github.com/dev-sec/ssl-baseline/issues/20) -- Control for ROBOT Attack [\#17](https://github.com/dev-sec/ssl-baseline/issues/17) - -**Merged pull requests:** - -- Bump version to 1.4.0 and switch to inspec 3 for check [\#26](https://github.com/dev-sec/ssl-baseline/pull/26) ([alexpop](https://github.com/alexpop)) -- Update issue templates [\#23](https://github.com/dev-sec/ssl-baseline/pull/23) ([rndmh3ro](https://github.com/rndmh3ro)) -- avoid inspec depricated warning in inspec version 1.51.18 [\#19](https://github.com/dev-sec/ssl-baseline/pull/19) ([Viktor-ret](https://github.com/Viktor-ret)) -- control for robotattack [\#18](https://github.com/dev-sec/ssl-baseline/pull/18) ([supergicko](https://github.com/supergicko)) -- v-update minimum inspec version to \>=1.21.0 [\#16](https://github.com/dev-sec/ssl-baseline/pull/16) ([supergicko](https://github.com/supergicko)) -- use recommended spdx license identifier [\#14](https://github.com/dev-sec/ssl-baseline/pull/14) ([chris-rock](https://github.com/chris-rock)) -- Add configurable attributes. [\#13](https://github.com/dev-sec/ssl-baseline/pull/13) ([rhass](https://github.com/rhass)) - -## [1.3.0](https://github.com/dev-sec/ssl-baseline/tree/1.3.0) (2017-05-08) -[Full Changelog](https://github.com/dev-sec/ssl-baseline/compare/v1.2.0...1.3.0) - -**Merged pull requests:** - -- Test for all [\#10](https://github.com/dev-sec/ssl-baseline/pull/10) ([supergicko](https://github.com/supergicko)) -- restrict ruby testing to version 2.3.3 [\#9](https://github.com/dev-sec/ssl-baseline/pull/9) ([atomic111](https://github.com/atomic111)) -- Added control check for disabled CBC [\#8](https://github.com/dev-sec/ssl-baseline/pull/8) ([supergicko](https://github.com/supergicko)) -- controls for export, des, aNULL, eNULL ciphers + md5 mac [\#4](https://github.com/dev-sec/ssl-baseline/pull/4) ([supergicko](https://github.com/supergicko)) - -## [v1.2.0](https://github.com/dev-sec/ssl-baseline/tree/v1.2.0) (2017-03-10) -[Full Changelog](https://github.com/dev-sec/ssl-baseline/compare/v1.1.3...v1.2.0) - -**Merged pull requests:** - -- Add only\_if to controls [\#7](https://github.com/dev-sec/ssl-baseline/pull/7) ([alexpop](https://github.com/alexpop)) -- Sslports bug [\#6](https://github.com/dev-sec/ssl-baseline/pull/6) ([supergicko](https://github.com/supergicko)) -- add common files [\#5](https://github.com/dev-sec/ssl-baseline/pull/5) ([atomic111](https://github.com/atomic111)) - -## [v1.1.3](https://github.com/dev-sec/ssl-baseline/tree/v1.1.3) (2017-02-03) -[Full Changelog](https://github.com/dev-sec/ssl-baseline/compare/v1.1.1...v1.1.3) - -**Merged pull requests:** - -- target addresses of listening ports and add control for troubleshooting [\#3](https://github.com/dev-sec/ssl-baseline/pull/3) ([alexpop](https://github.com/alexpop)) - -## [v1.1.1](https://github.com/dev-sec/ssl-baseline/tree/v1.1.1) (2016-09-14) -**Fixed bugs:** - -- Accept InSpec \>= 0.33.2 [\#2](https://github.com/dev-sec/ssl-baseline/pull/2) ([alexpop](https://github.com/alexpop)) +- Potentially dangerous settings [\#27](https://github.com/dev-sec/ssl-baseline/issues/27) **Merged pull requests:** -- Initial release [\#1](https://github.com/dev-sec/ssl-baseline/pull/1) ([alexpop](https://github.com/alexpop)) +- github actions [\#32](https://github.com/dev-sec/ssl-baseline/pull/32) ([micheelengronne](https://github.com/micheelengronne)) -\* *This Change Log was automatically generated by [github_changelog_generator](https://github.com/skywinder/Github-Changelog-Generator)* \ No newline at end of file +\* *This Changelog was automatically generated by [github_changelog_generator](https://github.com/github-changelog-generator/github-changelog-generator)* diff --git a/inspec.yml b/inspec.yml index 154d96c..e380f0c 100644 --- a/inspec.yml +++ b/inspec.yml @@ -1,3 +1,4 @@ +--- name: ssl-baseline title: DevSec SSL/TLS Baseline summary: Ensures a secure configuration for TCP ports @@ -5,7 +6,7 @@ maintainer: DevSec Hardening Framework Team copyright: DevSec Hardening Framework Team & Chef Software Inc. copyright_email: hello@dev-sec.io license: Apache-2.0 -version: 1.6.0 +version: 1.3.1 supports: - inspec_version: '>= 1.21.0' - os-family: unix