summaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
* libseccomp: update to 2.4.0Armin Kuster2019-03-161-2/+2
| | | | | | | | Update the syscall table for Linux v5.0-rc5. also a security releated issue; https://github.com/seccomp/libseccomp/issues/139 Signed-off-by: Armin Kuster <akuster808@gmail.com>
* tpm2.0-tools: fix protocolArmin Kuster2019-03-161-1/+1
| | | | | | | A commit amend misstep didn't capture the https to git change in SRC_URI. Signed-off-by: Armin Kuster <akuster808@gmail.com>
* lynis: update to 2.7.2Armin Kuster2019-03-161-2/+2
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* tpm2-totp: add new packageArmin Kuster2019-03-162-0/+53
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* tpm2: move tpm2 apps to recipes-tpm2Armin Kuster2019-03-169-0/+0
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* tpm2-tss-engine: add new packageArmin Kuster2019-03-161-0/+23
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* tpm2.0-tools: update SRC_URIArmin Kuster2019-03-161-2/+2
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* tpm2-abrmd: updatet to 2.1.1Armin Kuster2019-03-161-2/+2
| | | | | | switch SRC_URI to upstream Signed-off-by: Armin Kuster <akuster808@gmail.com>
* suricata: update to 4.1.3Armin Kuster2019-03-123-5/+6
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* packagegroup-core-security: change fail2ban ptest to reg python pkgArmin Kuster2019-03-121-1/+1
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* tripwire: fix ptest so more tests passArmin Kuster2019-03-081-1/+2
| | | | | | replace relative path with abs path for binaries. Signed-off-by: Armin Kuster <akuster808@gmail.com>
* keyutils: improve ptestsArmin Kuster2019-03-081-1/+1
| | | | | | Tests need lsb Signed-off-by: Armin Kuster <akuster808@gmail.com>
* oe-scap: fix inconsistent indentationYi Zhao2019-03-081-6/+5
| | | | | Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* openscap-daemon: backport patch to fix build error with python 3.7Yi Zhao2019-03-082-1/+133
| | | | | | | | | | | | | | | | Fixes build error: | Traceback (most recent call last): | File "setup.py", line 25, in <module> | from openscap_daemon import version | File "/buildarea/build/tmp/work/core2-64-poky-linux/openscap-daemon/0.1.10-r0/git/openscap_daemon/__init__.py", line 22, in <module> | from openscap_daemon.system import System | File "/buildarea/build/tmp/work/core2-64-poky-linux/openscap-daemon/0.1.10-r0/git/openscap_daemon/system.py", line 29 | from openscap_daemon import async | ^ | SyntaxError: invalid syntax Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* scap-security-guide: use makefile generator instead of ninja for cmakeYi Zhao2019-03-081-0/+2
| | | | | | | | Fixes build error: | make: *** No rule to make target 'openembedded'. Stop. Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* swtpm: update to stable release 0.1.0Armin Kuster2019-03-061-9/+10
| | | | | | | | added PE split cuse into its own package Signed-off-by: Armin Kuster <akuster808@gmail.com>
* libtpm: upate to stable 0.6.0Armin Kuster2019-03-061-4/+4
| | | | | | | | Add PE This update include support for tpm2.0 Signed-off-by: Armin Kuster <akuster808@gmail.com>
* tpm2-abrmd: update to 2.1.0Armin Kuster2019-03-061-1/+2
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* tpm2.o-tss: update to 2.4.1Armin Kuster2019-03-061-4/+9
| | | | | | LIC_FILES_CHKSUM changed to do SPDX ref being removed. Signed-off-by: Armin Kuster <akuster808@gmail.com>
* tpm2.0-tools: update 3.1.3Armin Kuster2019-03-061-1/+1
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* keyutils: update to 1.6Armin Kuster2019-03-062-31/+2
| | | | | | | remove patch now included in update: keyutils-use-relative-path-for-link.patch Signed-off-by: Armin Kuster <akuster808@gmail.com>
* suricata: update to 4.0.6Armin Kuster2019-03-063-3/+3
| | | | | | includes: SMTP crash issue was fixed: CVE-2018-18956 Signed-off-by: Armin Kuster <akuster808@gmail.com>
* python-fail2ban: update 0.10.4.0Armin Kuster2019-03-063-1/+1
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* libmspack: update to 0.9.1Armin Kuster2019-03-061-4/+4
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* tripwire: update to 2.4.3.7Armin Kuster2019-03-061-1/+1
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* samhain: update to 4.3.2Armin Kuster2019-03-064-2/+2
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* xmlsec1: add PACKAGECONFIG disable-desChangqing Li2019-03-061-1/+2
| | | | | | Signed-off-by: Changqing Li <changqing.li@windriver.com> Reviewed-by: Tom Rini <trini@konsulko.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* libwhisker2-perl: fix QA messageArmin Kuster2019-02-111-0/+2
| | | | | | | | | | WARNING: libwhisker2-perl-2.5-r0 do_package: QA Issue: libwhisker2-perl: Files/directories were installed but not shipped in any package: /usr/share /usr/share/perl /usr/share/perl/5.28.1 /usr/share/perl/5.28.1/LW2.3pm Signed-off-by: Armin Kuster <akuster808@gmail.com>
* clamav: update llvm to 8.0Armin Kuster2019-02-111-1/+1
| | | | | | ERROR: Nothing PROVIDES 'llvm6.0' Signed-off-by: Armin Kuster <akuster808@gmail.com>
* scapy: restore ptest by going to github directlyArmin Kuster2019-02-114-3/+19
| | | | | | | The pypi package removed the tests so go to the git repo directly. Signed-off-by: Armin Kuster <akuster808@gmail.com>
* scapy: Fix shebang for python3Scott Ellis2019-02-111-0/+7
| | | | | | | | | Both scapy and UTscapy have python in the shebang line regardless of whether python3-scapy or python-scapy was built. Signed-off-by: Scott Ellis <scott@jumpnowtek.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* scapy: Add python-cryptography to RDEPENDSScott Ellis2019-02-111-1/+1
| | | | | Signed-off-by: Scott Ellis <scott@jumpnowtek.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* Upgrade scapy to 2.4.2Scott Ellis2019-02-114-16/+3
| | | | | | | | Upstream MANIFEST.in removed doc and test directories so remove ptest. Signed-off-by: Scott Ellis <scott@jumpnowtek.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* xmlsec1: upgrade 1.2.26 -> 1.2.27Adrian Bunk2019-02-111-2/+2
| | | | | Signed-off-by: Adrian Bunk <bunk@stusta.de> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* xmlsec1: Make the crypto libraries a PACKAGECONFIGAdrian Bunk2019-02-111-4/+6
| | | | | | | | | | | Usually one doesn't need variants for all 4 different crypto libraries installed at the same time. Also remove a libgpg-error DEPENDS that is not used directly by xmlsec1. Signed-off-by: Adrian Bunk <bunk@stusta.de> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* xmlsec1: Include libxmlsec1-*.so in the main packageAdrian Bunk2019-02-111-0/+5
| | | | | | | They can be dynamically loaded with xmlSecCryptoDLLoadLibrary(). Signed-off-by: Adrian Bunk <bunk@stusta.de> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* checksec: Remove old scriptScott Ellis2019-02-111-882/+0
| | | | | | | Should have been removed in previous patch. Signed-off-by: Scott Ellis <scott@jumpnowtek.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* apparmor: backport a patch to fix tool paths instead of seddingRoss Burton2019-01-172-2/+38
| | | | | | | | Sedding is ugly, and as upstream have already fixed this cherry-pick the patch instead. Signed-off-by: Ross Burton <ross.burton@intel.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* apparmor: if Perl is disabled remove perl-using scriptsRoss Burton2019-01-171-0/+5
| | | | | | | aa-notify uses the Perl bindings, so isn't usable when perl is disabled. Signed-off-by: Ross Burton <ross.burton@intel.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* apparmor: systemd.bbclas is useful even when disabledRoss Burton2019-01-171-7/+3
| | | | | | | | The systemd bbclass will remove any systemd files that have been installed if systemd is disabled, so always install the files and always inherit. Signed-off-by: Ross Burton <ross.burton@intel.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* apparmor: remove pointless ALLOW_EMPTYRoss Burton2019-01-171-2/+0
| | | | | | | ${PN} has content, so there's no need to set ALLOW_EMPTY_${PN}. Signed-off-by: Ross Burton <ross.burton@intel.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* apparmor: no need to conditionalise PACKAGESRoss Burton2019-01-171-1/+1
| | | | | | | | A package with no content is not generated, so there's no need to conditionalise assignments to PACKAGES. Signed-off-by: Ross Burton <ross.burton@intel.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* apparmor: use manpages classRoss Burton2019-01-171-3/+3
| | | | | | | | The manpages class handles enabling/disabling the man pages based on the api-documentation DISTRO_FEATURE, and ensures that mandb is called. Signed-off-by: Ross Burton <ross.burton@intel.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* apparmor: remove redundant SRoss Burton2019-01-171-2/+0
| | | | | | | This is the default value, so remove it. Signed-off-by: Ross Burton <ross.burton@intel.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* apparmor: enable static libraries neatlyRoss Burton2019-01-171-2/+1
| | | | | | | | No need to fiddle with the configure arguments as we can just neuter disable-static.inc. Signed-off-by: Ross Burton <ross.burton@intel.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* apparmor: add missing bash dependencyRoss Burton2019-01-171-1/+1
| | | | | | | | testsuite/parser/tst/minimize.sh is a bash script, so until it is reviewed add a bash dependency to apparmor-ptest. Signed-off-by: Ross Burton <ross.burton@intel.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* README: remove Saul from maintainersRoss Burton2019-01-171-1/+0
| | | | | Signed-off-by: Ross Burton <ross.burton@intel.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* README: add git-config tipsRoss Burton2019-01-171-0/+7
| | | | | Signed-off-by: Ross Burton <ross.burton@intel.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* Add recipe for ncrackScott Ellis2019-01-171-0/+18
| | | | | | | Ncrack is a network authentication cracking tool. Signed-off-by: Scott Ellis <scott@jumpnowtek.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* nikto: upgrade to 2.1.6 (v2)Scott Ellis2019-01-064-230/+134
| | | | | | | Source now on github. Signed-off-by: Scott Ellis <scott@jumpnowtek.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>