UNCLASSIFIED

Merge branch 'hardening_manifest' into 'development'

Hardening manifest

See merge request !19
19 jobs for development in 18 minutes and 7 seconds (queued for 18 minutes and 16 seconds)
Status Job ID Name Coverage
  .Pre
passed #1685819
ironbank
load scripts

00:00:10

 
  Preflight
passed #1685820
ironbank
folder structure

00:00:08

passed #1685822
ironbank
hardening_manifest

00:00:14

passed #1685821
ironbank
hardening_manifest migration

00:00:05

 
  Lint
passed #1685823
ironbank
wl compare lint

00:00:16

 
  Import Artifacts
passed #1685824
ironbank
import artifacts

00:00:12

 
  Scan Artifacts
passed #1685825
ironbank
clamav scan

00:02:01

 
  Build
passed #1685826
ironbank-isolated
build

00:02:23

 
  Scanning
passed #1685830
ironbank
anchore scan

00:07:16

passed #1685827
ironbank
openscap compliance

00:01:22

passed #1685828
ironbank
openscap cve

00:04:25

passed #1685829
ironbank
twistlock scan

00:00:24

 
  Csv Output
passed #1685831
ironbank
csv output

00:01:09

 
  Check Cves
failed #1685832
ironbank allowed to fail
check cves

00:00:13

 
  Documentation
passed #1685833
ironbank
sign image

00:00:43

passed #1685834
ironbank
sign manifest

00:01:38

passed #1685835
ironbank
write json documentation

00:00:40

 
  Publish
passed #1685836
ironbank
upload to s3

00:01:43

 
  Vat
passed #1685837
ironbank
vat

00:00:44

 
Name Stage Failure
failed
check cves Check Cves
INFO: Whitelisted vulnerabilities: {'anchorecomp_c2e44319ae5b3b040044d8ae116d1c2f', 'oscapcomp_CCE-82959-8', 'anchorecve_CVE-2020-8284-libcurl-7.61.1-14.el8_3.1', 'anchorecve_CVE-2020-8286-libcurl-7.61.1-14.el8_3.1', 'anchorecve_CVE-2020-24370-lua-libs-5.3.4-11.el8', 'anchorecomp_bcd159901fe47efddae5c095b4b0d7fd', 'tl_CVE-2020-29361-p11-kit-0.23.14-5.el8_0', 'anchorecve_CVE-2020-15358-sqlite-libs-3.26.0-11.el8', 'oscapcomp_CCE-82267-6', 'anchorecve_CVE-2020-29363-p11-kit-trust-0.23.14-5.el8_0', 'tl_CVE-2020-29363-p11-kit-0.23.14-5.el8_0', 'anchorecve_CVE-2020-29361-p11-kit-0.23.14-5.el8_0', 'anchorecve_CVE-2020-27618-glibc-minimal-langpack-2.28-127.el8', 'anchorecve_CVE-2020-8286-curl-7.61.1-14.el8_3.1', 'oscapcomp_CCE-80938-4', 'anchorecomp_639f6f1177735759703e928c14714a59', 'tl_CVE-2020-29362-p11-kit-0.23.14-5.el8_0', 'oscapcomp_CCE-82949-9', 'anchorecve_CVE-2020-13776-systemd-libs-239-41.el8_3.1', 'tl_CVE-2020-8231-curl-7.61.1-14.el8_3.1', 'anchorecomp_68e630cef4a8533b139875aa5fc54da5', 'anchorecve_CVE-2019-25013-glibc-minimal-langpack-2.28-127.el8', 'tl_CVE-2021-23240-sudo-1.8.29-6.el8', 'oscapcomp_CCE-82360-9', 'tl_CVE-2020-8284-curl-7.61.1-14.el8_3.1', 'tl_CVE-2020-8285-curl-7.61.1-14.el8_3.1', 'anchorecomp_3456a263793066e9b5063ada6e47917d', 'anchorecve_CVE-2020-35512-dbus-libs-1.12.8-11.el8', 'anchorecve_CVE-2020-8231-curl-7.61.1-14.el8_3.1', 'anchorecve_CVE-2021-23240-sudo-1.8.29-6.el8', 'anchorecve_CVE-2020-27618-glibc-common-2.28-127.el8', 'anchorecve_CVE-2020-16135-libssh-config-0.9.4-2.el8', 'oscapcomp_CCE-82368-2', 'anchorecve_CVE-2020-26116-python3-libs-3.6.8-31.el8', 'oscapcomp_CCE-82220-5', 'oscapcomp_CCE-82979-6', 'anchorecomp_953dfbea1b1e9d5829fbed2e390bd3af', 'oscapcomp_CCE-80935-0', 'anchorecve_CVE-2020-8927-brotli-1.0.6-2.el8', 'anchorecomp_3e5fad1c039f3ecfd1dcdc94d2f1f9a0', 'anchorecve_CVE-2020-8231-libcurl-7.61.1-14.el8_3.1', 'anchorecomp_34de21e516c0ca50a96e5386f163f8bf', 'anchorecve_CVE-2020-24370-lua-5.3.4-11.el8', 'oscapcomp_CCE-82472-2', 'anchorecve_CVE-2020-35512-dbus-tools-1.12.8-11.el8', 'anchorecomp_698044205a9c4a6d48b7937e66a6bf4f', 'tl_CVE-2021-23239-sudo-1.8.29-6.el8', 'anchorecve_CVE-2020-13776-systemd-pam-239-41.el8_3.1', 'anchorecve_CVE-2020-35512-dbus-1.12.8-11.el8', 'anchorecve_CVE-2020-35512-dbus-common-1.12.8-11.el8', 'oscapcomp_CCE-82494-6', 'oscapcomp_CCE-82474-8', 'anchorecomp_abb121e9621abdd452f65844954cf1c1', 'anchorecomp_e7573262736ef52353cde3bae2617782', 'anchorecve_CVE-2020-8285-curl-7.61.1-14.el8_3.1', 'anchorecomp_320a97c6816565eedf3545833df99dd0', 'anchorecve_CVE-2020-24977-python3-libxml2-2.9.7-8.el8', 'anchorecve_CVE-2020-13434-sqlite-libs-3.26.0-11.el8', 'tl_CVE-2020-8927-brotli-1.0.6-2.el8', 'anchorecve_CVE-2019-25013-glibc-2.28-127.el8', 'anchorecve_CVE-2020-27619-platform-python-3.6.8-31.el8', 'anchorecve_CVE-2020-29362-p11-kit-0.23.14-5.el8_0', 'oscapcomp_CCE-82168-6', 'oscapcomp_CCE-82985-3', 'anchorecve_CVE-2020-13776-systemd-239-41.el8_3.1', 'anchorecve_CVE-2020-35512-dbus-daemon-1.12.8-11.el8', 'anchorecve_CVE-2020-27619-python3-libs-3.6.8-31.el8', 'anchorecve_CVE-2020-29361-p11-kit-trust-0.23.14-5.el8_0', 'anchorecve_CVE-2020-8285-libcurl-7.61.1-14.el8_3.1', 'anchorecve_CVE-2020-24977-libxml2-2.9.7-8.el8', 'tl_CVE-2019-25013-glibc-2.28-127.el8', 'tl_CVE-2020-13776-systemd-239-41.el8_3.1', 'anchorecve_CVE-2020-26116-platform-python-3.6.8-31.el8', 'oscapcomp_CCE-82395-5', 'oscapcomp_CCE-82473-0', 'anchorecomp_addbb93c22e9b0988b8b40392a4538cb', 'anchorecve_CVE-2019-25013-glibc-common-2.28-127.el8', 'anchorecve_CVE-2020-29363-p11-kit-0.23.14-5.el8_0', 'anchorecve_CVE-2020-29362-p11-kit-trust-0.23.14-5.el8_0', 'anchorecve_CVE-2020-28196-krb5-libs-1.18.2-5.el8', 'anchorecve_CVE-2021-23239-sudo-1.8.29-6.el8', 'anchorecve_CVE-2020-16135-libssh-0.9.4-2.el8', 'anchorecomp_c4ad80832b361f81df2a31e5b6b09864', 'tl_CVE-2020-8286-curl-7.61.1-14.el8_3.1', 'anchorecve_CVE-2020-27618-glibc-2.28-127.el8', 'anchorecve_CVE-2020-8284-curl-7.61.1-14.el8_3.1', 'anchorecomp_463a9a24225c26f7a5bf3f38908e5cb3'}
INFO: Vulnerabilities found in scanning stage: 73
INFO: {'tl_CVE-2021-3156-sudo-1.8.29-6.el8', 'oscapcomp_CCE-82168-6', 'oscapcomp_CCE-82985-3', 'tl_CVE-2021-23240-sudo-1.8.29-6.el8', 'oscapcomp_CCE-82959-8', 'anchorecve_CVE-2020-13776-systemd-239-41.el8_3.1', 'anchorecve_CVE-2020-35512-dbus-tools-1.12.8-11.el8', 'oscapcomp_CCE-82360-9', 'anchorecve_CVE-2020-35512-dbus-daemon-1.12.8-11.el8', 'tl_CVE-2020-8284-curl-7.61.1-14.el8_3.1', 'tl_CVE-2020-8285-curl-7.61.1-14.el8_3.1', 'anchorecve_CVE-2020-8284-libcurl-7.61.1-14.el8_3.1', 'anchorecve_CVE-2020-8286-libcurl-7.61.1-14.el8_3.1', 'anchorecve_CVE-2020-27619-python3-libs-3.6.8-31.el8', 'anchorecve_CVE-2020-29361-p11-kit-trust-0.23.14-5.el8_0', 'tl_CVE-2021-23239-sudo-1.8.29-6.el8', 'anchorecve_CVE-2020-8285-libcurl-7.61.1-14.el8_3.1', 'anchorecve_CVE-2020-24977-libxml2-2.9.7-8.el8', 'anchorecve_CVE-2020-24370-lua-libs-5.3.4-11.el8', 'anchorecve_CVE-2020-35512-dbus-libs-1.12.8-11.el8', 'anchorecve_CVE-2020-8231-curl-7.61.1-14.el8_3.1', 'anchorecve_CVE-2020-13776-systemd-libs-239-41.el8_3.1', 'tl_CVE-2020-29361-p11-kit-0.23.14-5.el8_0', 'anchorecve_CVE-2020-13776-systemd-pam-239-41.el8_3.1', 'anchorecve_CVE-2020-35512-dbus-1.12.8-11.el8', 'anchorecve_CVE-2020-35512-dbus-common-1.12.8-11.el8', 'anchorecve_CVE-2021-23240-sudo-1.8.29-6.el8', 'oscapcomp_CCE-82494-6', 'tl_CVE-2019-25013-glibc-2.28-127.el8', 'anchorecve_CVE-2020-27618-glibc-common-2.28-127.el8', 'anchorecve_CVE-2020-16135-libssh-config-0.9.4-2.el8', 'oscapcomp_CCE-82474-8', 'tl_CVE-2020-13776-systemd-239-41.el8_3.1', 'oscapcomp_CCE-82368-2', 'anchorecve_CVE-2020-26116-platform-python-3.6.8-31.el8', 'anchorecve_CVE-2020-27619-platform-python-3.6.8-31.el8', 'anchorecve_CVE-2020-15358-sqlite-libs-3.26.0-11.el8', 'anchorecve_CVE-2020-26116-python3-libs-3.6.8-31.el8', 'oscapcomp_CCE-82395-5', 'oscapcomp_CCE-82267-6', 'oscapcomp_CCE-82220-5', 'oscapcomp_CCE-82473-0', 'oscapcomp_CCE-82979-6', 'anchorecve_CVE-2020-29363-p11-kit-trust-0.23.14-5.el8_0', 'tl_CVE-2020-29363-p11-kit-0.23.14-5.el8_0', 'anchorecve_CVE-2020-29361-p11-kit-0.23.14-5.el8_0', 'anchorecve_CVE-2020-8285-curl-7.61.1-14.el8_3.1', 'anchorecve_CVE-2020-27618-glibc-minimal-langpack-2.28-127.el8', 'oscapcomp_CCE-80935-0', 'anchorecve_CVE-2019-25013-glibc-common-2.28-127.el8', 'anchorecve_CVE-2020-8927-brotli-1.0.6-2.el8', 'anchorecve_CVE-2020-29363-p11-kit-0.23.14-5.el8_0', 'anchorecve_CVE-2020-8231-libcurl-7.61.1-14.el8_3.1', 'anchorecve_CVE-2020-8286-curl-7.61.1-14.el8_3.1', 'anchorecve_CVE-2020-24977-python3-libxml2-2.9.7-8.el8', 'anchorecve_CVE-2020-29362-p11-kit-trust-0.23.14-5.el8_0', 'anchorecve_CVE-2020-28196-krb5-libs-1.18.2-5.el8', 'anchorecve_CVE-2020-13434-sqlite-libs-3.26.0-11.el8', 'anchorecve_CVE-2021-23239-sudo-1.8.29-6.el8', 'anchorecve_CVE-2020-16135-libssh-0.9.4-2.el8', 'tl_CVE-2020-8927-brotli-1.0.6-2.el8', 'oscapcomp_CCE-80938-4', 'tl_CVE-2020-8286-curl-7.61.1-14.el8_3.1', 'anchorecve_CVE-2019-25013-glibc-2.28-127.el8', 'anchorecve_CVE-2020-27618-glibc-2.28-127.el8', 'tl_CVE-2020-29362-p11-kit-0.23.14-5.el8_0', 'anchorecve_CVE-2020-8284-curl-7.61.1-14.el8_3.1', 'oscapcomp_CCE-82949-9', 'anchorecve_CVE-2020-24370-lua-5.3.4-11.el8', 'oscapcomp_CCE-82472-2', 'tl_CVE-2020-8231-curl-7.61.1-14.el8_3.1', 'anchorecve_CVE-2019-25013-glibc-minimal-langpack-2.28-127.el8', 'anchorecve_CVE-2020-29362-p11-kit-0.23.14-5.el8_0'}
ERROR: NON-WHITELISTED VULNERABILITIES FOUND
ERROR: Number of non-whitelisted vulnerabilities: 1
ERROR: The following vulnerabilities are not whitelisted:
ERROR: Twistlock CVE - CVE-2021-3156-sudo-1.8.29-6.el8
Cleaning up file based variables
ERROR: Job failed: command terminated with exit code 1