Skip to content

fix(publish): OpenSCAP STIG advisory for distroless + SSG build deps - #4

Merged
NWarila merged 1 commit into
mainfrom
fix/openscap-advisory
Jun 2, 2026
Merged

fix(publish): OpenSCAP STIG advisory for distroless + SSG build deps#4
NWarila merged 1 commit into
mainfrom
fix/openscap-advisory

Conversation

@NWarila

@NWarila NWarila commented Jun 2, 2026

Copy link
Copy Markdown
Owner

First publish run surfaced two issues, both fixed here: (1) the SSG source build needs xmllint (libxml2-utils) + xsltproc — added; (2) a full-host DISA RHEL9 STIG profile is structurally N/A to a distroless ubi-micro image, so OpenSCAP is now advisory (continue-on-error + non-failing scorecard) while still producing+uploading the ARF/HTML evidence. Hard CVE gates (Trivy + Grype, 0 fixable HIGH/CRITICAL) unchanged. Per compliance ADR decision. verify.py ci green; YAML valid.

… build deps

Two issues from the first publish run:
- The SSG source build failed: cmake needs xmllint (libxml2-utils) + xsltproc,
  which weren't installed. Added them.
- A full-host DISA RHEL9 STIG profile is structurally inapplicable to a
  distroless ubi-micro image (no auditd/sshd/partitions/PAM/kernel params), so
  gating the build on its rule results is meaningless. Per the compliance ADR
  decision, the OpenSCAP step is now ADVISORY: continue-on-error + a non-failing
  scorecard that still produces and uploads the ARF + HTML evidence. The hard
  CVE gates remain Trivy + Grype (0 fixable HIGH/CRITICAL).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@NWarila
NWarila merged commit 9a1cb1d into main Jun 2, 2026
@NWarila
NWarila deleted the fix/openscap-advisory branch June 2, 2026 18:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant