As announced yesterday, every @DevSecIO @chef #Inspec profiles migrated from `attribute` to `input` dropping support for Inspec v3 https://t.co/W9lTneIzwb
Because @chef #Inspec changed 'attribute' for 'input', we modified @DevSecIO profiles accordingly. Tell us if it breaks your builds. https://t.co/cb1anewyHg https://t.co/mr3fZZgkC6 https://t.co/lmMhhGqH17 https://t.co/MlPXQrNxxc
Thanks to @DevSecIO, there is a one-stop shop for all your DevSecOps hardening needs + inspection using InSpec + remediation using @ansible, @chef and puppet: https://t.co/HW2DejaXUM #devops#DevSecOps#automation
@journeyer We set some ufw rules as part of the sysctl configuration. Likely we do not have firewall setup as you expect. Contributions to crate a firewall role are welcome.
TIL about the "proc" file system on Linux. It gives you access to all process information.
I have used the @DevSecIO Hardening Framework. A day later my monitoring software couldn't get process statistics anymore. The total number of processes displayed was 2.
You were thinking what would make our @ansible server security roles even better? 🚀 We made it a lot easier to use them via ansible collections. Testing and quality are up! 🎉Thank you @zufallsheld and all contributors https://t.co/2pWAx2KOnq
@p35h4y It maybe an issue with inspec, the ssh_custom_path is an attribute with default value. Would you mind open an issue in github for the issues so that the community can help? In case you think documentation is missing, we are happy to accept PRs to add the information you need
Made a containerized custom Allure reporter for the @DevSecIO Inspec CIS benchmarks, as well as a containerized benchmark runner.
Allure gives a nice overview, compliance trend, and human readable test description/rationale.
Check it out!
https://t.co/venpoS70U1
🥳We had a great start into @haacktoberfest! Help us to fill the In-Progress column with your contribution 🏆. Let us make the world more secure place! Have a look at https://t.co/Kfvs5G0fmV for open issues. #opensource#security for #devops#devsec#ansible#chef#puppet#inspec
Help us to improve our open source #security automation! We participate in @hacktoberfest with our @ansible @chef @puppet and #inspec projects. See https://t.co/Ad3Sn5NkXr for more details.