Commit Graph

1149 Commits

Author SHA1 Message Date
RoyalOughtness
a3b90c83fd fix: add back missing ujust completions (#605) 2024-11-22 11:32:14 -08:00
RoyalOughtness
261936654f chore: copy config from upstream and remove dep (#593) 2024-11-21 17:23:06 -08:00
spaceoden
5172baa133 fix: motd when no image tag is in use (#602) 2024-11-21 11:51:00 -08:00
spaceoden
f24e3432a6 fix: dns-selector: correct set_browser_policy prompt to match code (#597) 2024-11-18 10:03:59 -08:00
RoyalOughtness
85ca395515 feat: improved installation mechanism (#564) 2024-11-18 09:50:57 -08:00
RoyalOughtness
944a9e80b9 fix: motd for securecore images (#600) 2024-11-18 09:37:42 -08:00
spaceoden
45b74a9be8 fix: remove sushi and gnome photos from yafti (#596) 2024-11-18 09:24:44 -08:00
spaceoden
b99f3bc7d1 feat: audit-secureblue: add suggestions for new perm checks (#586) 2024-11-18 01:40:35 -08:00
graphenelover
c89ed738f9 docs: command correction for gpasswd (#538) 2024-11-18 01:14:50 -08:00
spaceoden
e8505c2eff fix: set variables to intended default if empty response is recieved (#599) 2024-11-18 00:46:40 -08:00
spaceoden
2e990be137 feat: harden-flatpak: add optional parameter to apply it to specific app (#567) 2024-11-17 15:57:24 -08:00
RoyalOughtness
ee71b84dcd chore: set trivy to also scan for misconfig (#592) 2024-11-17 13:13:18 -08:00
RoyalOughtness
d9765487dd fix: shorten faq link so that it fits inside the default ptyxis width (#590) 2024-11-15 17:15:05 -08:00
RoyalOughtness
de16e2d859 fix: skip rebasing if image is already signed (#587) 2024-11-15 15:30:49 -08:00
RoyalOughtness
8f376c66eb docs: add trivy badge (#585) 2024-11-15 14:54:52 -08:00
RoyalOughtness
ba5969e572 fix: grant trivy write access to security-events (#584) 2024-11-15 14:06:03 -08:00
RoyalOughtness
8d20457896 feat: add trivy scanning (#581) 2024-11-15 13:16:46 -08:00
RoyalOughtness
150b2c2b25 feat: numerous fixes and improvements (#580) 2024-11-15 12:13:44 -08:00
spaceoden
f8c909409f feat: audit-secureblue: add recommendations to warnings (#566) 2024-11-15 10:55:41 -08:00
RoyalOughtness
b0373417c0 feat: add link validation (#579) 2024-11-14 22:32:07 -08:00
spaceoden
897731d571 feat: audit-secureblue: add checks for device=all and absence of host-os:ro (#565) 2024-11-14 18:34:13 -08:00
Root
db3d24a835 feat: implement just dns-selector and add to post install (#571) 2024-11-14 17:39:54 -08:00
Mystrain
d5595b4860 fix: comment description whitespace 2024-11-14 12:48:29 -08:00
RadioAddition
770902be30 docs: add FAQ entry for upstream chromium bug (#574) 2024-11-14 12:36:10 -08:00
RoyalOughtness
ab60fbbd1e fix: ensure podman auto updates for system as well as uesr (#573) 2024-11-13 14:15:25 -08:00
RoyalOughtness
2c5142597e chore: add pull request build (#557) 2024-11-12 22:51:26 -08:00
RoyalOughtness
986f3fe109 chore: only lint justfiles if justfiles are modified (#570) 2024-11-12 16:59:23 -08:00
Mystrain
cd6f696142 feat: add ujust debug-info (#569) 2024-11-12 16:16:23 -08:00
RoyalOughtness
1b4b8bed49 docs: improve package installation instructions (#568) 2024-11-12 09:51:16 -08:00
mintpilo
033b39e964 chore: add cleanup for chrony state (#561)
From GrapheneOS: ntsdumpdir gradually creates stale state.

Co-authored-by: RoyalOughtness <129108030+RoyalOughtness@users.noreply.github.com>
2024-11-12 09:13:56 -08:00
RoyalOughtness
95e7b5a768 chore: add pull request justfile linting (#562) 2024-11-11 21:32:22 -08:00
mintpilo
a4a3b2f0cb chore: Update chrony.conf (#558) 2024-11-11 16:59:18 -08:00
RoyalOughtness
1a0e631f5e fix: move brew validation after brew is installed (#559) 2024-11-11 16:49:07 -08:00
RoyalOughtness
e86816d052 chore: switch to bluebuild's justfile module with validation (#556) 2024-11-11 16:11:37 -08:00
RoyalOughtness
702184e3d5 chore: create SECURITY.md (#555) 2024-11-11 15:55:27 -08:00
RoyalOughtness
d88efdfbb5 chore: remove build dependency on yq (#554) 2024-11-11 15:31:45 -08:00
RoyalOughtness
fdf48b2d32 feat: pin github actions to specific commits, following codacy suggestions 2024-11-11 13:27:14 -08:00
RoyalOughtness
a6025e2c4b breakfix: Revert "feat: audit-secureblue: check for filesystem=host:ro and device=all (#535)" (#550)
This reverts commit d376dd0180.
2024-11-11 11:20:56 -08:00
spaceoden
d376dd0180 feat: audit-secureblue: check for filesystem=host:ro and device=all (#535) 2024-11-11 09:04:12 -08:00
mintpilo
290d1ec895 fix: remove redundant pkexec line in kargs commands (#539)
Co-authored-by: RoyalOughtness <129108030+RoyalOughtness@users.noreply.github.com>
2024-11-10 17:28:25 -05:00
Bruno
29927c2db0 docs: fix dead links, add missing items (#544)
* docs: fix dead links, update descriptions

* docs: more emphasis on "unstable", less on "additional"

* docs: return an original word

* docs: grammar and brevity

* docs: verbosity
2024-11-10 17:23:45 -05:00
secretmango
c8eff2ca0b fix: remove duplicate blocked udf filesystem (#530)
fix: remove duplicate blocked udf filesystem (#530)
2024-11-07 10:18:10 -05:00
RoyalOughtness
0f04fc1d4e docs: clarify support.md (#529) 2024-11-06 22:50:47 -08:00
Malix
18b2a25af5 chore: docs dir (#527)
* chore: docs dir

* docs: feat support

---------

Co-authored-by: RoyalOughtness <129108030+RoyalOughtness@users.noreply.github.com>
2024-11-06 21:30:51 -08:00
Malix
4d03ea1951 feat: discord issue template (#526)
* feat: discord issue template

* fix
2024-11-06 21:26:40 -08:00
RoyalOughtness
708ff5ae88 docs: update steam recommendations (#524) 2024-11-04 12:36:50 -08:00
RoyalOughtness
d010c5914f docs: remove reference to asus images that no longer exist (#523) 2024-11-03 22:48:13 -08:00
RoyalOughtness
d9774b993b fix: audit script breaks without flatpaks present (#520)
* fix: audit script breaks without flatpaks present

* Update 70-secureblue.just
2024-11-03 18:21:30 -08:00
mintpilo
d3173bde02 docs: recommend fedora media writer (#516)
* docs: recommend fedora media writer

* docs: make recommendation briefer
2024-11-02 14:35:42 -07:00
RoyalOughtness
2026112eb4 docs: remove bluefin reference from bug_report.md (#518) 2024-11-02 14:34:54 -07:00