diff --git a/.gitignore b/.gitignore index 1227c7d..a3ef680 100644 --- a/.gitignore +++ b/.gitignore @@ -4,9 +4,3 @@ /openscap-report-0.2.1.tar.gz /openscap-report-0.2.2.tar.gz /openscap-report-0.2.3.tar.gz -/openscap-report-0.2.4.tar.gz -/openscap-report-0.2.5.tar.gz -/openscap-report-0.2.6.tar.gz -/openscap-report-0.2.7.tar.gz -/openscap_report-0.2.9.tar.gz -/openscap_report-1.0.0.tar.gz diff --git a/.packit.yaml b/.packit.yaml index 1412932..bc74dae 100644 --- a/.packit.yaml +++ b/.packit.yaml @@ -10,8 +10,6 @@ files_to_sync: dest: plans/ - src: .fmf/ dest: .fmf/ - - src: generate_arf.sh - dest: generate_arf.sh # name in upstream package repository or registry (e.g. in PyPI) upstream_package_name: openscap-report diff --git a/README.packit b/README.packit index 766e300..49c9d4e 100644 --- a/README.packit +++ b/README.packit @@ -1,3 +1,3 @@ This repository is maintained by packit. https://packit.dev/ -The file was generated using packit 0.101.1.post1.dev8+ge78e9e3b. +The file was generated using packit 0.72.0.post2+g57b7cc3. diff --git a/generate_arf.sh b/generate_arf.sh index 9aed4e0..8305160 100755 --- a/generate_arf.sh +++ b/generate_arf.sh @@ -1,9 +1,5 @@ #!/usr/bin/env bash -# This script generates ARF results. -# Supported OS: -# - Fedora -# - RHEL8/9 -# - Centos8/9 +# This script generate ARF results. # Requirements: # - cmake # - make @@ -16,7 +12,8 @@ # - scap-security-guide # Usage: ./generate_arf MODE FETCH PRODUCT ARF_FILE SKIP_BUILD # MODE [latest, ssg] use scap-security-guide or latest content from github -# FETCH [yes, no] scanner fetch remote resources +# FETCH [yes, no] scanner fetch remote resources +# PRODUCT build or use security content for one specific product # ARF_FILE Writes results to a given ARF_FILE. # SKIP_BUILD [yes] Skip build of latest content(Have affect with mode latest). @@ -28,16 +25,13 @@ build_content() { product=$1 echo "Build - Start" - + git clone https://github.com/ComplianceAsCode/content.git cd content/ git checkout master - - cd build/ - cmake ../ - make -j4 "${product}" - - cd ../../ + + ./build_product "${product}" + cd .. echo "Build - Done" } @@ -49,49 +43,36 @@ run_oscap_scan() { oscap xccdf eval ${fetch} --profile "(all)" --results-arf ${file} ${ds} || EXIT_CODE=$? echo $EXIT_CODE if [ ! -f "$file" ]; then - echo "$file does not exist." >&2 + echo "$file does not exist." exit 2 fi } -get_product() { - cpe_name=$(grep "CPE_NAME=" < /etc/os-release | sed 's/CPE_NAME=//g' | sed 's/["]//g') - if [[ "${cpe_name}" =~ fedora ]]; then - echo "fedora" - elif [[ "${cpe_name}" =~ redhat ]]; then - version=$(grep VERSION_ID /etc/os-release | grep -o "[0-9]\+" | head -n1) - echo "rhel${version}" - elif [[ "${cpe_name}" =~ centos.*8 ]]; then - echo "centos8" - elif [[ "${cpe_name}" =~ centos ]]; then - version=$(grep VERSION_ID /etc/os-release | grep -o "[0-9]\+") - echo "cs${version}" - else - echo $cpe_name - echo "ERROR: Not supported OS!" >&2 - exit 1 - fi -} if [ "$1" = "" ]; then - echo "ERROR: Missing MODE parameter!" >&2 + echo "ERROR: Missing MODE parameter!" exit 1 fi if [ "$2" = "" ]; then - echo "ERROR: Missing FETCH parameter!" >&2 + echo "ERROR: Missing FETCH parameter!" exit 1 fi if [ "$3" = "" ]; then - echo "ERROR: Missing ARF_FILE parameter!" >&2 + echo "ERROR: Missing PRODUCT parameter!" exit 1 fi -file=$3 -product=$(get_product) +if [ "$4" = "" ]; then + echo "ERROR: Missing PRODUCT parameter!" + exit 1 +fi + +file=$4 +product=$3 fetch="--fetch-remote-resources" if [ "$2" = "no" ]; then @@ -100,7 +81,7 @@ fi if [ "$1" = "latest" ]; then - if [ "$4" != "yes" ]; then + if [ "$5" != "yes" ]; then build_content "${product}" fi run_oscap_scan "./content/build/ssg-${product}-ds.xml" "${fetch}" "${file}" diff --git a/openscap-report.spec b/openscap-report.spec index bf867d2..f72277e 100644 --- a/openscap-report.spec +++ b/openscap-report.spec @@ -1,29 +1,26 @@ %global pymodule_name openscap_report Name: openscap-report -Version: 1.0.0 -Release: 6%{?dist} +Version: 0.2.3 +Release: 1%{?dist} Summary: A tool for generating human-readable reports from (SCAP) XCCDF and ARF results # The entire source code is LGPL-2.1+ and GPL-2.0+ and MIT except schemas/ and assets/, which are Public Domain License: LGPLv2+ and GPLv2+ and MIT and Public Domain URL: https://github.com/OpenSCAP/%{name} -Source0: https://github.com/OpenSCAP/%{name}/releases/download/v%{version}/%{pymodule_name}-%{version}.tar.gz +Source0: https://github.com/OpenSCAP/%{name}/releases/download/v%{version}/%{name}-%{version}.tar.gz BuildArch: noarch BuildRequires: python3-devel -BuildRequires: python3-pytest BuildRequires: python3-sphinx BuildRequires: python3-sphinx_rtd_theme Provides: bundled(patternfly) = 4 Requires: python3-lxml -Recommends: redhat-display-fonts -Recommends: redhat-text-fonts - -Obsoletes: oval-graph +Requires: redhat-display-fonts +Requires: redhat-text-fonts %global _description %{expand: This package provides a command-line tool for generating @@ -33,13 +30,11 @@ human-readable reports from SCAP XCCDF and ARF results.} %prep -%autosetup -p1 -n %{pymodule_name}-%{version} +%autosetup -p1 -n %{name}-%{version} %generate_buildrequires -%pyproject_buildrequires -# test requirement listed only in tox.ini -echo "%{py3_dist jsonschema}" +%pyproject_buildrequires -t %build @@ -55,8 +50,7 @@ install -m 0644 -Dt %{buildroot}%{_mandir}/man1 _build_docs/oscap-report.1 %check -# test_store_file fails with FileNotFoundError: [Errno 2] No such file or directory: '/tmp/oscap-report-tests_result.html' -%pytest -k "not test_store_file" +%tox %files -f %{pyproject_files} %{_mandir}/man1/oscap-report.* @@ -66,150 +60,6 @@ install -m 0644 -Dt %{buildroot}%{_mandir}/man1 _build_docs/oscap-report.1 %changelog -* Fri Sep 19 2025 Python Maint - 1.0.0-6 -- Rebuilt for Python 3.14.0rc3 bytecode - -* Fri Aug 15 2025 Python Maint - 1.0.0-5 -- Rebuilt for Python 3.14.0rc2 bytecode - -* Thu Jul 24 2025 Fedora Release Engineering - 1.0.0-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild - -* Wed Jun 04 2025 Python Maint - 1.0.0-3 -- Rebuilt for Python 3.14 - -* Fri Jan 17 2025 Fedora Release Engineering - 1.0.0-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild - -* Fri Oct 04 2024 Packit - 1.0.0-1 -- Update to version 1.0.0 - -* Thu Jul 18 2024 Fedora Release Engineering - 0.2.9-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild - -* Sat Jun 08 2024 Python Maint - 0.2.9-2 -- Rebuilt for Python 3.13 - -* Tue Apr 23 2024 Packit - 0.2.9-1 -- Update to version 0.2.9 - -* Mon Jan 29 2024 Yaakov Selkowitz - 0.2.7-2 -- Avoid tox dependency - -* Fri Jan 26 2024 Packit - 0.2.7-1 -- 0.2.7 (Jan Rodak) -- Add tool tip to search bar (Jan Rodak) -- Enable search by reference (Jan Rodak) -- Add generation search infromation (Jan Rodak) -- Use macro for generation of list items (Jan Rodak) -- Create two-tier display of Evaluation Characteristics (Jan Rodak) -- Add title (Jan Rodak) -- Reduce complexity of function generate_referenced_endpoints (Jan Rodak) -- Use default dict (Jan Rodak) -- Fix JSON schema (Jan Rodak) -- Use correct orthography of addresses types acronyms (Jan Rodak) -- Add function to update known references (Jan Rodak) -- Change the presentation of referenced endpoints (Jan Rodak) -- Add new elements (Jan Rodak) -- Add onclick function (Jan Rodak) -- Add map of OVAL endpoints (Jan Rodak) -- Add target addresses to report (Jan Rodak) -- Add target addresses to model (Jan Rodak) -- Fix width of pre element (Jan Rodak) - -* Thu Jan 25 2024 Fedora Release Engineering - 0.2.6-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - -* Sun Jan 21 2024 Fedora Release Engineering - 0.2.6-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - -* Wed Dec 20 2023 Packit - 0.2.6-1 -- 0.2.6 (Jan Rodak) -- Extend the condition to account empty strings in href (Jan Černý) -- Add comments for the pylint tool (Jan Černý) -- Add special classes to table element (Jan Černý) -- Account for missing reference href attribute (Jan Černý) -- Add pragmas to avoid PEP8 warnings (Jan Černý) -- Present references in a table (Jan Černý) -- Collapse CPE tree when is true (Jan Rodak) -- Fix typo (Jan Rodak) -- Add titles (Jan Rodak) -- Fix performace of generation of graphs (Jan Rodak) -- Rearrange fields of rule detail and OVAL definition detail (Jan Rodak) -- Fix bugs in html (Jan Rodak) - -* Mon Sep 11 2023 Packit - 0.2.5-1 -- 0.2.5 (Jan Rodak) -- Show referenced OVAL State (Jan Rodak) -- Parse reference in filter (Jan Rodak) -- Show OVAL Variables and referenced OVAL endpoints in report (Jan Rodak) -- Remove UUID from headings (Jan Rodak) -- Move function (Jan Rodak) -- Display in report OVAL object that references to other OVAL Objects (Jan Rodak) -- Resolve parsing of referenced OVAL Objects and OVAL Variables (Jan Rodak) -- Add OVAL Variable structure and parser (Jan Rodak) -- Rework OVAL Object and State (Jan Rodak) -- Parse mapping between OVAL var and values and propagate them (Jan Rodak) -- Remove namesapace for attributes (Jan Rodak) -- Show OVAL states in report (Jan Rodak) -- Parse attributes of elements in OVAL state and Parse all OVAL states in OVAL test (Jan Rodak) -- Show OVAL objects in report (Jan Rodak) -- Parse attributes of elements in OVAL object (Jan Rodak) -- Removing the processing of collected objects (Jan Rodak) -- Use an empty string instead of None when the text of the set-value element is empty (Jan Rodak) -- Fix deprecation warning (Jan Rodak) -- Remove product detection from the tmt plan (Jan Rodak) -- Increase vm memory (Jan Rodak) -- Add python3 dependency (Jan Rodak) -- Adjust the build of content (Jan Rodak) -- Automatic product detection to build content by CPE identifier (Jan Rodak) -- Remove whitespaces (Jan Rodak) -- Show explanation of score computation in report (Jan Rodak) -- Add explanation of score computation (Jan Rodak) -- Parse system attribute from score element (Jan Rodak) - -* Thu Jul 20 2023 Fedora Release Engineering - 0.2.4-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild - -* Wed Jul 05 2023 Python Maint - 0.2.4-2 -- Rebuilt for Python 3.12 - -* Wed Jul 05 2023 Packit - 0.2.4-1 -- 0.2.4 (Jan Rodak) -- Rename field Result explained to Class explained (Jan Rodak) -- Add button back to top (Jan Rodak) -- Generate tooltip when hover the mouse over the OVAL operator (Jan Rodak) -- Fix persistance of checkboxes after refresh browser (Jan Rodak) -- Add functionality to buttons (Jan Rodak) -- Add buttons (Jan Rodak) -- Set logging severity from warning to info for missing fonts problem (Jan Rodak) -- Change fonts to week dependency (Jan Rodak) -- Disable scrollbar (Jan Rodak) -- Show tooltip for NOT (Jan Rodak) -- Add explanations (Jan Rodak) -- Generate tooltip (Jan Rodak) -- Set tooltip position for OVAL and CPE AL operators (Jan Rodak) -- Add new tooltip when user click on copy to clipboard (Jan Rodak) -- Rename tooltip class (Jan Rodak) -- Add new lines on end of file (Jan Rodak) -- Update eslint config (Jan Rodak) -- Implement clear button for search bar (Jan Rodak) -- Change title (Jan Rodak) -- Use the same title for the page title and report title (Jan Rodak) -- Using span element instead of link element when href is not available (Jan Rodak) -- Add non-breaking space (Jan Rodak) -- Add missing package (Jan Rodak) -- Update modules docs (Jan Rodak) -- Add documentation on how to run the test suite (Jan Rodak) -- Add usage from source (Jan Rodak) -- Add installation from source and PyPi (Jan Rodak) -- Update README (Jan Rodak) -- Sync generate_arf.sh (Jan Rodak) -- Remove execution of integration test on push to main (Jan Rodak) - -* Thu Jun 15 2023 Python Maint - 0.2.3-2 -- Rebuilt for Python 3.12 - * Fri Apr 14 2023 Packit - 0.2.3-1 - 0.2.3 (Jan Rodak) - Determine which product use (Jan Rodak) diff --git a/plans/integration.fmf b/plans/integration.fmf index eaebd17..9d9bb7e 100644 --- a/plans/integration.fmf +++ b/plans/integration.fmf @@ -1,8 +1,27 @@ summary: Test integration with latest versions of content discover+: filter: tag:integration -provision: - memory: 4096 +adjust: + - when: distro == fedora + environment: + PRODUCT: fedora + TO_BUILD_PRODUCT: fedora + - when: distro == rhel-9 + environment: + PRODUCT: rhel9 + TO_BUILD_PRODUCT: rhel9 + - when: distro == rhel-8 + environment: + PRODUCT: rhel8 + TO_BUILD_PRODUCT: rhel8 + - when: distro == centos-8 + environment: + PRODUCT: centos8 + TO_BUILD_PRODUCT: rhel8 + - when: distro == centos-9 or distro == centos-stream-9 + environment: + PRODUCT: cs9 + TO_BUILD_PRODUCT: rhel9 prepare: - name: Install packages require for generation ARF files how: install @@ -11,7 +30,6 @@ prepare: - make - openscap-utils - openscap-scanner - - python3 - python3-pyyaml - python3-jinja2 - python3-setuptools @@ -19,11 +37,11 @@ prepare: - scap-security-guide - name: Generate ARF files how: shell - script: - - ./generate_arf.sh ssg no ${TMT_PLAN_DATA}/arf.xml - - ./generate_arf.sh ssg yes ${TMT_PLAN_DATA}/arf_fetch-remote-resources.xml - - ./generate_arf.sh latest no ${TMT_PLAN_DATA}/arf-latest.xml - - ./generate_arf.sh latest yes ${TMT_PLAN_DATA}/arf_fetch-remote-resources-latest.xml yes + script: + - ./generate_arf.sh ssg no ${PRODUCT} ${TMT_PLAN_DATA}/arf.xml + - ./generate_arf.sh ssg yes ${PRODUCT} ${TMT_PLAN_DATA}/arf_fetch-remote-resources.xml + - ./generate_arf.sh latest no ${TO_BUILD_PRODUCT} ${TMT_PLAN_DATA}/arf-latest.xml + - ./generate_arf.sh latest yes ${TO_BUILD_PRODUCT} ${TMT_PLAN_DATA}/arf_fetch-remote-resources-latest.xml yes execute: how: tmt diff --git a/sources b/sources index 8d874ae..95e2336 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (openscap_report-1.0.0.tar.gz) = 6ca5a24798961cfc50112e9da9157f582732574fef4592a7fe5c8a98b4ed4b9aa3f7221427bd5e95a799a82468a22a2eddfb2262c6fc22cd2e4262540913db03 +SHA512 (openscap-report-0.2.3.tar.gz) = ec0d3cbefe44ff0c46de8c738b6ee1e8436c971bdea8135e8beb5616a3cea2012408e4c2e05d2a55f1d9764c174ea87b8612ac5a5ef19792f55faa61b326038e