- Mar 03, 2020
-
-
Huang Huang authored
* Support parse boolean flag with no value * Add test for parse boolean flag with false value Co-authored-by:
Roberto Rojas <robertojrojas@gmail.com>
-
Abubakr-Sadik Nii Nai Davis authored
* Add initial commit for CIS GKE 1.0 benchmark * Update README with GKE instructions * Fix YAML linter issues * Set GKE benchmark k8s version to gke-1.0 * Add tests for gke-1.0 Co-authored-by:
Roberto Rojas <robertojrojas@gmail.com>
-
- Mar 02, 2020
-
-
Thorsten Schifferdecker authored
proykubeconfig -> proxykubeconfig
-
- Feb 18, 2020
-
-
Huang Huang authored
Fixes #582
-
- Feb 12, 2020
-
-
Huang Huang authored
* Fixes issue #574: change the PATH in container And change to use `/usr/local/mount-from-host/bin` as mount path. Fixes #574 * Fix integration tests
-
- Jan 28, 2020
-
-
Nick Smith authored
By setting all host-mounted volumes to be read-only we reduce the likelihood any host filesystem is modified by running kube-bench.
-
- Jan 22, 2020
-
-
LukasAuerbeck authored
Co-authored-by:
Liz Rice <liz@lizrice.com>
-
mustafa-rean authored
Co-authored-by:
Liz Rice <liz@lizrice.com>
-
- Jan 21, 2020
-
-
Roberto Rojas authored
* Adds Diff function: Fixes #559 * changes as per PR review
-
- Jan 14, 2020
-
-
Manuel Rüger authored
Co-authored-by:
Liz Rice <liz@lizrice.com>
-
- Jan 13, 2020
-
-
yoavrotems authored
goreleaser updated and got some functions deprecated. • ARCHIVES • DEPRECATED: `archive` should not be used anymore, check https://goreleaser.com/deprecations#archive for more info. • LINUX PACKAGES WITH NFPM • DEPRECATED: `nfpm` should not be used anymore, check https://goreleaser.com/deprecations#nfpm for more info. Co-authored-by:
Liz Rice <liz@lizrice.com> Co-authored-by:
Roberto Rojas <robertojrojas@gmail.com>
-
- Jan 09, 2020
-
-
Roberto Rojas authored
* Fixes #552: Improves performance and reliability. Co-Authored-By:
Liz Rice <liz@lizrice.com>
-
- Jan 07, 2020
-
-
Murali Paluru authored
* remove always true for logtostderr * update README for log collection instructions Co-authored-by:
Liz Rice <liz@lizrice.com>
-
Murali Paluru authored
-
- Jan 06, 2020
-
-
James Ward authored
* add yamllint command to travis CI installs and runs a linter across the YAML in the project to ensure consistency in the written YAML. this uses yamllint and the default yamllint config with "truthy" and "line-length" disabled. * run dos2unix on CRLF files * YAMLLINT: remove trailing spaces * YAMLLint: add YAML document start * YAMLLint: too many spaces around bracket * YAMLLint: fix indentation * YAMLLint: remove duplicate key * YAMLLint: newline at end of file * YAMLLint: Too few spaces after comma * YAMLLint: too many spaces after colon
-
- Jan 03, 2020
-
-
Liz Rice authored
- Tests that did not increase coverage and were redundant are removed. - New tests reflecting the meaning of the state as explained in the README are added. Co-authored-by:
s-nirali <25746945+s-nirali@users.noreply.github.com>
-
- Dec 20, 2019
-
-
Saurya Das authored
* Adding a section for Azure Kubernetes Service steps to run kube bench on AKS worker nodes * Update README.md * Update README.md Co-authored-by:
Roberto Rojas <robertojrojas@gmail.com> Co-authored-by:
Liz Rice <liz@lizrice.com>
-
Zeid Marouf authored
-
- Dec 13, 2019
-
-
Roberto Rojas authored
* Adds openshift to autodetect node type * detect okd node units * OCP fixes
-
Roberto Rojas authored
* isEtcd should not run on openshift 3.10/3.11 * adds openssl * fixed tests * fixes bugs * adds isEtcd tests
-
- Dec 12, 2019
-
-
Roberto Rojas authored
-
- Dec 10, 2019
-
-
Huang Huang authored
* Fix remediation of 2.2.3 in cis-1.3 * Fix remediation of 4.1.1 in cis-1.5
-
- Dec 09, 2019
-
-
Mateus Caruccio authored
* Adds openshift to autodetect node type * detect okd node units
-
- Dec 05, 2019
-
-
Roberto Rojas authored
* Initial commit. * Add master and node config. * Add section 5 of CIS 1.5.1. * Split sections into section files * Fix YAML issues. * adds target translation * adds target translation * adds cis-1.5 mapping * fixed tests * fixes are per PR * fixed intergration test * integration kind test file to appropriate ks8 version * fixed etcd text * fixed README * fixed text * etcd: fixed grep path * etcd: fixes * fixed error message bug * Update README.md Co-Authored-By:
Liz Rice <liz@lizrice.com> * Update README.md Co-Authored-By:
Liz Rice <liz@lizrice.com> * fixes as per PR review
-
- Dec 04, 2019
-
-
Huang Huang authored
-
- Dec 02, 2019
-
-
Liz Rice authored
* test: fix TestGetConfigFilePath This test wasn't correctly creating the test file due to the wrong directory permissions on the temp file. This wasn't detected due to a lack of error checking. Also, the code was only checking for file not exist rather than lack of permission to read file (or any other error). The combination of these two things means the test wasn't checking what it thought it was checking, and passed more by luck than judgment. * add getYamlFilesFromDir * add getTestYamlFiles and test * docs: Update master / node help text * return path + filename from getYamlFilesFromDir * subcommand run to run specific section files
-
- Nov 27, 2019
-
-
gy741 authored
-
Roberto Rojas authored
* Add kubeconfig location of kube-proxy for AKS * Add job for AKS node * Automate ca file permission check * removed job-aks.yaml as other PRs added needed features * fixed integration test due to merge changes
- Nov 26, 2019
-
-
Roberto Rojas authored
replaced calling docker directly by using "make build-docker"
-
- Nov 16, 2019
-
-
Roberto Rojas authored
* Fixes issue #439: Adds integration testing using KIND * try integration tests * started using ticker and timeouts * trying built container image * adds load image into KIND * adds comparison * fixes as per PR review
-
- Nov 13, 2019
-
-
John Schnake authored
If running these checks in a CI system it may be beneficial to output in a more standardized format such as JUnit for parsing by other tools in a consistent manner. Fixes #460 Signed-off-by:
John Schnake <jschnake@vmware.com>
-
- Nov 12, 2019
-
-
Roberto Rojas authored
* Fixes issue #517: Determines Kubernetes version using the REST API * fixes * fixes * adds tests * fixes * added more tests * kubernetes_version_test: Add a missing case for invalid certs Signed-off-by:
Simarpreet Singh <simar@linux.com> * kubernetes_version_test: Remove un-needed casts Signed-off-by:
Simarpreet Singh <simar@linux.com> * fixes as per PR review * fixes as per PR review
-
- Nov 06, 2019
-
-
Liz Rice authored
-
Jonathan Rau authored
* Change EKS Readme * Fix readme formatting * Update README.md Co-Authored-By:
Liz Rice <liz@lizrice.com> * Update README.md Co-Authored-By:
Liz Rice <liz@lizrice.com> * Update README.md
-
Sebastian Ehmann authored
As the length of a nil slice is defined as 0, the nil check is redundand. (suggested by golanci-lint/gosimple)
-
Sebastian Ehmann authored
-
Sebastian Ehmann authored
Using `buf.String()` instead of `fmt.Sprintf` is simpler
-
Liz Rice authored
Fixes: https://github.com/aquasecurity/kube-bench/issues/420 Signed-off-by:
Manuel Rüger <manuel@rueg.eu>
-
- Nov 05, 2019
-
-
Soumyadeep Sinha authored
* Fixed some typos * Fixed some typos * Fixed typo and capitalization of Kubernetes * Update README.md Co-Authored-By:
Liz Rice <liz@lizrice.com> * Update README.md Co-Authored-By:
Liz Rice <liz@lizrice.com> * Update docs/README.md Co-Authored-By:
Liz Rice <liz@lizrice.com> * Update docs/README.md Co-Authored-By:
Liz Rice <liz@lizrice.com> * Update README.md Co-Authored-By:
Liz Rice <liz@lizrice.com> * Update docs/README.md Co-Authored-By:
Liz Rice <liz@lizrice.com> * docs: trivial, reinstate capital K * docs: trivial, reinstate backticks * docs: trivial, reinstate "in order" for clarity * docs: trivial, reinstate capital K
-