Bruno
79471e2141
fix: audit script improvements (GHNS test, order of tests) ( #415 )
...
* only test GHNS if kdeglobals exist
* place faster tests before the slower flatpak audit
2024-08-30 13:45:15 -07:00
Bruno
e143c48e26
chore: several audit script improvements
2024-08-29 21:01:40 -07:00
Ivo Damjanović
fefc64baba
feat: stop overwriting 60-custom.just for better compatibility with upstream bluebuild and downstream user builds ( #409 )
...
* feat: create addjustconfig.sh to include custom commands at buildtime
* fix: 60-custom.just.readme.md to 61-custom.just.readme.md
* fix: Rename 60-custom.just to 61-custom.just
* feat: add just config script to enabled scripts
* fix: rename to 70-secureblue.just
* fix: Rename 61-custom.just.readme.md to 70-secureblue.just.readme.md
* fix: rename to 70-secureblue.just
2024-08-29 11:53:56 -07:00
qoijjj
a329524441
fix: justfile typo
2024-08-26 10:44:49 -07:00
qoijjj
e41d963841
feat: multiple securecore improvements
2024-08-26 09:45:20 -07:00
qoijjj
967c7551ad
feat: sgid reduction ( #392 )
...
* feat: also remove sgid bit
* Update yafti.yml
* Update yafti.yml
2024-08-23 14:13:22 -07:00
qoijjj
1b5e539ec2
fix: audit script cleanup
2024-08-22 12:03:22 -07:00
Rubiginosa
51ad84b1ad
feat: Add flatpak auditing to audit-secureblue ( #377 )
...
* increase spacing on print_status
* Merged audit-flatpak into audit-secureblue
* print flatpak remote success
---------
Co-authored-by: qoijjj <129108030+qoijjj@users.noreply.github.com >
2024-08-21 13:22:11 -07:00
qoijjj
7ff130f248
fix: typo in audit script
2024-08-20 18:43:21 -07:00
qoijjj
38cbf7715a
feat: add audit-secureblue just command ( #382 )
2024-08-20 15:08:18 -07:00
qoijjj
06c2883bb1
fix: improve usbguard just command
2024-08-19 18:21:50 -07:00
qoijjj
31b1339fa5
chore: disable yafti run on config change as it causes user confusion
2024-08-11 04:49:00 -07:00
qoijjj
3b927dc8ed
fix: check only the first string token when searching lsattr
2024-08-10 03:56:35 -07:00
qoijjj
872cb784ef
feat: add ujust command to lock bash environment files to mitigate LD… ( #365 )
2024-08-09 16:14:44 -07:00
SnuggleCovenant
4c85413563
remove gnome videos (totem) from yafti.yml ( #363 )
...
the totem app is abandoned
2024-08-07 14:53:34 -07:00
fiftydinar
e1a130f6f9
feat: Disable user Gnome extensions & user-installation of them ( #361 )
2024-08-06 17:14:30 -07:00
qoijjj
f75215cfdf
fix: set permissions for xwayland file in ujust command
2024-08-03 12:19:43 -07:00
spaceoden
c21a697252
Update 60-custom.just.readme.md to put new kargs in the correct section ( #357 )
...
the new kargs were added to set-kargs-hardening, not set-kargs-hardening-unstable
2024-08-02 13:01:52 -07:00
qoijjj
9f56f2ff06
feat: set additional kargs to override suboptimal defaults
2024-08-01 22:43:23 -07:00
qoijjj
084fe1a40c
fix: remove usbguard-dbus due to insufficient systemd sandboxing ( #352 )
2024-07-31 14:20:49 -07:00
qoijjj
eea350af56
fix: remove comments from harden-flatpak ujust command to fix just parsing
2024-07-30 16:26:34 -07:00
spaceoden
7c0976da7e
feat: add to harden-flatpak logic that applies the highest supported hwcap ( #346 )
2024-07-30 15:31:43 -07:00
qoijjj
298bbda019
fix: ujust command typos
2024-07-30 00:03:25 -07:00
qoijjj
b9fc6e4826
feat: remove xwayland by default ( #347 )
2024-07-29 23:02:10 -07:00
Root
9a843f3861
docs: add docs to JIT disable in Gnome ( #345 )
...
* Add docs to JIT disable in Gnome
* Properly add env file in ujust
2024-07-29 09:57:15 -07:00
Root
1a55f1549b
feat: add ujust to toggle Gnome JS JIT ( #344 )
...
* Add ujust to toggle Gnome JS JIT
* Disable Gnome JIT by default
2024-07-28 21:48:48 -07:00
qoijjj
0c1551df09
chore: bump dependencies and migrate to bluebuild 1.6
2024-07-21 14:33:53 -07:00