Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Initial STIG-IDs added to rule files.
New CCIs added to rules
New SRGs added to stig rules
Remove unneeded SRG
Removed CCI, SRG, STIG ID, and STIG tag
Added STIG ID to
Added new rule file
Add APPL-15-002023
added APPL-15-002024
fix[rules] removed tags for rules removed
removed tags from rules removed from cis
added os_time_server_enable back to cis
Update Gitignore
Updating CIS benchmark and tags in missed rules.
refactor[rules]ssh fips and sshd fips
Updated check and fix for ssh and sshd for FIPS
added check into sshd to not fix if proper
Fixed ODV regression for CIS
added missing path to grep
removed [ ]
Fix to not print, and fix multiple entries in .ssh/config
added dev null redirection, prevention of double entries
Fixed bin to dev and case insensitive sed
800-171 Rev 2 to Rev 3
Updated media sharing key
Updated STIG ID
merge from sequoia
refactor[rules] ssh fixes
Updated ssh fixes to match os_ssh_fips_compliant
slightly simplier fix. removed unneeded loop
slightly simplier fix. removed unneeded loop
Adjusting CIS numbering.
fix[rule] fixed path
Fixed path in system_settings_system_wide_preferences_configure
fixed path in system_settings_system_wide_preferences_configure
Added reference to os_sudo_log_enforce
Added os_mail_summary_disable
Added os_photos_enhanced_search_disable
Removed system_settings_cd_dvd_sharing_disable
Modified system_settings_improve_search_disable - updated title Modified system_settings_improve_siri_dictation_disable - updated title
renamed .yml to .yaml
changes for upcoming cis release
refactor - DISA STIG
references updated to sequoia for DISA STIG
baseline file created for disa stig
added os_sleep_and_display_sleep_apple_silicon_enable to all_rules
refactor[rules] CNSSI tags added
Added CNSSI1253 low, moderate, high tags
Updated cnssi1253 baseline files
Updated all_rules baseline file
Updated CIS baseline files
udpdated baseline files
[fix]system_settings_sleep_enforce sleep/displaysleep swap
updated title
fix[rule] remove cis tags and reference
remove cis ref & tag from system_settings_improve_search_disable
issue usnistgov#443
Adding arm64 tag to os_sleep_and_display_sleep_apple_silicon_enable
Fixing Sleep/displaysleep numbers based on CIS changes.
Fixing os_sleep_and_display_sleep_apple_silicon_enable
Removing DRAFT status from CIS
[fix]rule world writable library folder
os_world_writable_library_folder_configure
issue# 445
Replaced N/A CCEs for os_mail_summary_disable and os_photos_enhanced_search_disable
pwpolicy_custom_regex_enforce odv hint updated
Issue usnistgov#450
Removed 800-53 and 800-171 tags
Updated discussion to reflect NIST SP 800-63 and Executive Order M-22-09
Added rules to disable external intelligence features for 15.2
Issue STIG tag missing from system_settings_improve_assistive_voice_disable.yaml usnistgov/macos_security#450
updated pwpolicy
Added CCEs
Removed double stig tag
updated baseline files
updated changelog
removed rules/system_settings/system_settings_cd_dvd_sharing_disable.yaml
updated changelog
update[supplemental]: added 800-63 guidance
fix[supplemental]: update note about filevault unlock
refactor[rule] pwpolicy_special_character_enforce
Updated check to allow greater than ODV.
Issue usnistgov#451
Added mention of /usr/libexec/reset-ssh-configuration.
updated release date and version
Added uniq to prevent false negatives
updated authors
updated release date