diff --git a/.gitignore b/.gitignore index a3ef680..1227c7d 100644 --- a/.gitignore +++ b/.gitignore @@ -4,3 +4,9 @@ /openscap-report-0.2.1.tar.gz /openscap-report-0.2.2.tar.gz /openscap-report-0.2.3.tar.gz +/openscap-report-0.2.4.tar.gz +/openscap-report-0.2.5.tar.gz +/openscap-report-0.2.6.tar.gz +/openscap-report-0.2.7.tar.gz +/openscap_report-0.2.9.tar.gz +/openscap_report-1.0.0.tar.gz diff --git a/.packit.yaml b/.packit.yaml index bc74dae..1412932 100644 --- a/.packit.yaml +++ b/.packit.yaml @@ -10,6 +10,8 @@ files_to_sync: dest: plans/ - src: .fmf/ dest: .fmf/ + - src: generate_arf.sh + dest: generate_arf.sh # name in upstream package repository or registry (e.g. in PyPI) upstream_package_name: openscap-report diff --git a/README.packit b/README.packit index 49c9d4e..766e300 100644 --- a/README.packit +++ b/README.packit @@ -1,3 +1,3 @@ This repository is maintained by packit. https://packit.dev/ -The file was generated using packit 0.72.0.post2+g57b7cc3. +The file was generated using packit 0.101.1.post1.dev8+ge78e9e3b. diff --git a/generate_arf.sh b/generate_arf.sh index 8305160..9aed4e0 100755 --- a/generate_arf.sh +++ b/generate_arf.sh @@ -1,5 +1,9 @@ #!/usr/bin/env bash -# This script generate ARF results. +# This script generates ARF results. +# Supported OS: +# - Fedora +# - RHEL8/9 +# - Centos8/9 # Requirements: # - cmake # - make @@ -12,8 +16,7 @@ # - scap-security-guide # Usage: ./generate_arf MODE FETCH PRODUCT ARF_FILE SKIP_BUILD # MODE [latest, ssg] use scap-security-guide or latest content from github -# FETCH [yes, no] scanner fetch remote resources -# PRODUCT build or use security content for one specific product +# FETCH [yes, no] scanner fetch remote resources # ARF_FILE Writes results to a given ARF_FILE. # SKIP_BUILD [yes] Skip build of latest content(Have affect with mode latest). @@ -25,13 +28,16 @@ build_content() { product=$1 echo "Build - Start" - + git clone https://github.com/ComplianceAsCode/content.git cd content/ git checkout master - - ./build_product "${product}" - cd .. + + cd build/ + cmake ../ + make -j4 "${product}" + + cd ../../ echo "Build - Done" } @@ -43,36 +49,49 @@ run_oscap_scan() { oscap xccdf eval ${fetch} --profile "(all)" --results-arf ${file} ${ds} || EXIT_CODE=$? echo $EXIT_CODE if [ ! -f "$file" ]; then - echo "$file does not exist." + echo "$file does not exist." >&2 exit 2 fi } +get_product() { + cpe_name=$(grep "CPE_NAME=" < /etc/os-release | sed 's/CPE_NAME=//g' | sed 's/["]//g') + if [[ "${cpe_name}" =~ fedora ]]; then + echo "fedora" + elif [[ "${cpe_name}" =~ redhat ]]; then + version=$(grep VERSION_ID /etc/os-release | grep -o "[0-9]\+" | head -n1) + echo "rhel${version}" + elif [[ "${cpe_name}" =~ centos.*8 ]]; then + echo "centos8" + elif [[ "${cpe_name}" =~ centos ]]; then + version=$(grep VERSION_ID /etc/os-release | grep -o "[0-9]\+") + echo "cs${version}" + else + echo $cpe_name + echo "ERROR: Not supported OS!" >&2 + exit 1 + fi +} if [ "$1" = "" ]; then - echo "ERROR: Missing MODE parameter!" + echo "ERROR: Missing MODE parameter!" >&2 exit 1 fi if [ "$2" = "" ]; then - echo "ERROR: Missing FETCH parameter!" + echo "ERROR: Missing FETCH parameter!" >&2 exit 1 fi if [ "$3" = "" ]; then - echo "ERROR: Missing PRODUCT parameter!" + echo "ERROR: Missing ARF_FILE parameter!" >&2 exit 1 fi +file=$3 -if [ "$4" = "" ]; then - echo "ERROR: Missing PRODUCT parameter!" - exit 1 -fi - -file=$4 -product=$3 +product=$(get_product) fetch="--fetch-remote-resources" if [ "$2" = "no" ]; then @@ -81,7 +100,7 @@ fi if [ "$1" = "latest" ]; then - if [ "$5" != "yes" ]; then + if [ "$4" != "yes" ]; then build_content "${product}" fi run_oscap_scan "./content/build/ssg-${product}-ds.xml" "${fetch}" "${file}" diff --git a/openscap-report.spec b/openscap-report.spec index f72277e..bf867d2 100644 --- a/openscap-report.spec +++ b/openscap-report.spec @@ -1,26 +1,29 @@ %global pymodule_name openscap_report Name: openscap-report -Version: 0.2.3 -Release: 1%{?dist} +Version: 1.0.0 +Release: 6%{?dist} Summary: A tool for generating human-readable reports from (SCAP) XCCDF and ARF results # The entire source code is LGPL-2.1+ and GPL-2.0+ and MIT except schemas/ and assets/, which are Public Domain License: LGPLv2+ and GPLv2+ and MIT and Public Domain URL: https://github.com/OpenSCAP/%{name} -Source0: https://github.com/OpenSCAP/%{name}/releases/download/v%{version}/%{name}-%{version}.tar.gz +Source0: https://github.com/OpenSCAP/%{name}/releases/download/v%{version}/%{pymodule_name}-%{version}.tar.gz BuildArch: noarch BuildRequires: python3-devel +BuildRequires: python3-pytest BuildRequires: python3-sphinx BuildRequires: python3-sphinx_rtd_theme Provides: bundled(patternfly) = 4 Requires: python3-lxml -Requires: redhat-display-fonts -Requires: redhat-text-fonts +Recommends: redhat-display-fonts +Recommends: redhat-text-fonts + +Obsoletes: oval-graph %global _description %{expand: This package provides a command-line tool for generating @@ -30,11 +33,13 @@ human-readable reports from SCAP XCCDF and ARF results.} %prep -%autosetup -p1 -n %{name}-%{version} +%autosetup -p1 -n %{pymodule_name}-%{version} %generate_buildrequires -%pyproject_buildrequires -t +%pyproject_buildrequires +# test requirement listed only in tox.ini +echo "%{py3_dist jsonschema}" %build @@ -50,7 +55,8 @@ install -m 0644 -Dt %{buildroot}%{_mandir}/man1 _build_docs/oscap-report.1 %check -%tox +# test_store_file fails with FileNotFoundError: [Errno 2] No such file or directory: '/tmp/oscap-report-tests_result.html' +%pytest -k "not test_store_file" %files -f %{pyproject_files} %{_mandir}/man1/oscap-report.* @@ -60,6 +66,150 @@ install -m 0644 -Dt %{buildroot}%{_mandir}/man1 _build_docs/oscap-report.1 %changelog +* Fri Sep 19 2025 Python Maint - 1.0.0-6 +- Rebuilt for Python 3.14.0rc3 bytecode + +* Fri Aug 15 2025 Python Maint - 1.0.0-5 +- Rebuilt for Python 3.14.0rc2 bytecode + +* Thu Jul 24 2025 Fedora Release Engineering - 1.0.0-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + +* Wed Jun 04 2025 Python Maint - 1.0.0-3 +- Rebuilt for Python 3.14 + +* Fri Jan 17 2025 Fedora Release Engineering - 1.0.0-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + +* Fri Oct 04 2024 Packit - 1.0.0-1 +- Update to version 1.0.0 + +* Thu Jul 18 2024 Fedora Release Engineering - 0.2.9-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + +* Sat Jun 08 2024 Python Maint - 0.2.9-2 +- Rebuilt for Python 3.13 + +* Tue Apr 23 2024 Packit - 0.2.9-1 +- Update to version 0.2.9 + +* Mon Jan 29 2024 Yaakov Selkowitz - 0.2.7-2 +- Avoid tox dependency + +* Fri Jan 26 2024 Packit - 0.2.7-1 +- 0.2.7 (Jan Rodak) +- Add tool tip to search bar (Jan Rodak) +- Enable search by reference (Jan Rodak) +- Add generation search infromation (Jan Rodak) +- Use macro for generation of list items (Jan Rodak) +- Create two-tier display of Evaluation Characteristics (Jan Rodak) +- Add title (Jan Rodak) +- Reduce complexity of function generate_referenced_endpoints (Jan Rodak) +- Use default dict (Jan Rodak) +- Fix JSON schema (Jan Rodak) +- Use correct orthography of addresses types acronyms (Jan Rodak) +- Add function to update known references (Jan Rodak) +- Change the presentation of referenced endpoints (Jan Rodak) +- Add new elements (Jan Rodak) +- Add onclick function (Jan Rodak) +- Add map of OVAL endpoints (Jan Rodak) +- Add target addresses to report (Jan Rodak) +- Add target addresses to model (Jan Rodak) +- Fix width of pre element (Jan Rodak) + +* Thu Jan 25 2024 Fedora Release Engineering - 0.2.6-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Sun Jan 21 2024 Fedora Release Engineering - 0.2.6-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Wed Dec 20 2023 Packit - 0.2.6-1 +- 0.2.6 (Jan Rodak) +- Extend the condition to account empty strings in href (Jan Černý) +- Add comments for the pylint tool (Jan Černý) +- Add special classes to table element (Jan Černý) +- Account for missing reference href attribute (Jan Černý) +- Add pragmas to avoid PEP8 warnings (Jan Černý) +- Present references in a table (Jan Černý) +- Collapse CPE tree when is true (Jan Rodak) +- Fix typo (Jan Rodak) +- Add titles (Jan Rodak) +- Fix performace of generation of graphs (Jan Rodak) +- Rearrange fields of rule detail and OVAL definition detail (Jan Rodak) +- Fix bugs in html (Jan Rodak) + +* Mon Sep 11 2023 Packit - 0.2.5-1 +- 0.2.5 (Jan Rodak) +- Show referenced OVAL State (Jan Rodak) +- Parse reference in filter (Jan Rodak) +- Show OVAL Variables and referenced OVAL endpoints in report (Jan Rodak) +- Remove UUID from headings (Jan Rodak) +- Move function (Jan Rodak) +- Display in report OVAL object that references to other OVAL Objects (Jan Rodak) +- Resolve parsing of referenced OVAL Objects and OVAL Variables (Jan Rodak) +- Add OVAL Variable structure and parser (Jan Rodak) +- Rework OVAL Object and State (Jan Rodak) +- Parse mapping between OVAL var and values and propagate them (Jan Rodak) +- Remove namesapace for attributes (Jan Rodak) +- Show OVAL states in report (Jan Rodak) +- Parse attributes of elements in OVAL state and Parse all OVAL states in OVAL test (Jan Rodak) +- Show OVAL objects in report (Jan Rodak) +- Parse attributes of elements in OVAL object (Jan Rodak) +- Removing the processing of collected objects (Jan Rodak) +- Use an empty string instead of None when the text of the set-value element is empty (Jan Rodak) +- Fix deprecation warning (Jan Rodak) +- Remove product detection from the tmt plan (Jan Rodak) +- Increase vm memory (Jan Rodak) +- Add python3 dependency (Jan Rodak) +- Adjust the build of content (Jan Rodak) +- Automatic product detection to build content by CPE identifier (Jan Rodak) +- Remove whitespaces (Jan Rodak) +- Show explanation of score computation in report (Jan Rodak) +- Add explanation of score computation (Jan Rodak) +- Parse system attribute from score element (Jan Rodak) + +* Thu Jul 20 2023 Fedora Release Engineering - 0.2.4-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + +* Wed Jul 05 2023 Python Maint - 0.2.4-2 +- Rebuilt for Python 3.12 + +* Wed Jul 05 2023 Packit - 0.2.4-1 +- 0.2.4 (Jan Rodak) +- Rename field Result explained to Class explained (Jan Rodak) +- Add button back to top (Jan Rodak) +- Generate tooltip when hover the mouse over the OVAL operator (Jan Rodak) +- Fix persistance of checkboxes after refresh browser (Jan Rodak) +- Add functionality to buttons (Jan Rodak) +- Add buttons (Jan Rodak) +- Set logging severity from warning to info for missing fonts problem (Jan Rodak) +- Change fonts to week dependency (Jan Rodak) +- Disable scrollbar (Jan Rodak) +- Show tooltip for NOT (Jan Rodak) +- Add explanations (Jan Rodak) +- Generate tooltip (Jan Rodak) +- Set tooltip position for OVAL and CPE AL operators (Jan Rodak) +- Add new tooltip when user click on copy to clipboard (Jan Rodak) +- Rename tooltip class (Jan Rodak) +- Add new lines on end of file (Jan Rodak) +- Update eslint config (Jan Rodak) +- Implement clear button for search bar (Jan Rodak) +- Change title (Jan Rodak) +- Use the same title for the page title and report title (Jan Rodak) +- Using span element instead of link element when href is not available (Jan Rodak) +- Add non-breaking space (Jan Rodak) +- Add missing package (Jan Rodak) +- Update modules docs (Jan Rodak) +- Add documentation on how to run the test suite (Jan Rodak) +- Add usage from source (Jan Rodak) +- Add installation from source and PyPi (Jan Rodak) +- Update README (Jan Rodak) +- Sync generate_arf.sh (Jan Rodak) +- Remove execution of integration test on push to main (Jan Rodak) + +* Thu Jun 15 2023 Python Maint - 0.2.3-2 +- Rebuilt for Python 3.12 + * Fri Apr 14 2023 Packit - 0.2.3-1 - 0.2.3 (Jan Rodak) - Determine which product use (Jan Rodak) diff --git a/plans/integration.fmf b/plans/integration.fmf index 9d9bb7e..eaebd17 100644 --- a/plans/integration.fmf +++ b/plans/integration.fmf @@ -1,27 +1,8 @@ summary: Test integration with latest versions of content discover+: filter: tag:integration -adjust: - - when: distro == fedora - environment: - PRODUCT: fedora - TO_BUILD_PRODUCT: fedora - - when: distro == rhel-9 - environment: - PRODUCT: rhel9 - TO_BUILD_PRODUCT: rhel9 - - when: distro == rhel-8 - environment: - PRODUCT: rhel8 - TO_BUILD_PRODUCT: rhel8 - - when: distro == centos-8 - environment: - PRODUCT: centos8 - TO_BUILD_PRODUCT: rhel8 - - when: distro == centos-9 or distro == centos-stream-9 - environment: - PRODUCT: cs9 - TO_BUILD_PRODUCT: rhel9 +provision: + memory: 4096 prepare: - name: Install packages require for generation ARF files how: install @@ -30,6 +11,7 @@ prepare: - make - openscap-utils - openscap-scanner + - python3 - python3-pyyaml - python3-jinja2 - python3-setuptools @@ -37,11 +19,11 @@ prepare: - scap-security-guide - name: Generate ARF files how: shell - script: - - ./generate_arf.sh ssg no ${PRODUCT} ${TMT_PLAN_DATA}/arf.xml - - ./generate_arf.sh ssg yes ${PRODUCT} ${TMT_PLAN_DATA}/arf_fetch-remote-resources.xml - - ./generate_arf.sh latest no ${TO_BUILD_PRODUCT} ${TMT_PLAN_DATA}/arf-latest.xml - - ./generate_arf.sh latest yes ${TO_BUILD_PRODUCT} ${TMT_PLAN_DATA}/arf_fetch-remote-resources-latest.xml yes + script: + - ./generate_arf.sh ssg no ${TMT_PLAN_DATA}/arf.xml + - ./generate_arf.sh ssg yes ${TMT_PLAN_DATA}/arf_fetch-remote-resources.xml + - ./generate_arf.sh latest no ${TMT_PLAN_DATA}/arf-latest.xml + - ./generate_arf.sh latest yes ${TMT_PLAN_DATA}/arf_fetch-remote-resources-latest.xml yes execute: how: tmt diff --git a/sources b/sources index 95e2336..8d874ae 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (openscap-report-0.2.3.tar.gz) = ec0d3cbefe44ff0c46de8c738b6ee1e8436c971bdea8135e8beb5616a3cea2012408e4c2e05d2a55f1d9764c174ea87b8612ac5a5ef19792f55faa61b326038e +SHA512 (openscap_report-1.0.0.tar.gz) = 6ca5a24798961cfc50112e9da9157f582732574fef4592a7fe5c8a98b4ed4b9aa3f7221427bd5e95a799a82468a22a2eddfb2262c6fc22cd2e4262540913db03