Skip to content

Conversation

@yu410621
Copy link
Contributor

Description:
The OVAL definition for account_disable_inactivity_password_auth incorrectly references the var_account_disable_post_pw_expiration variable instead of the correct var_account_disable_inactivity variable.

This PR corrects the var_ref and the external_variable ID to use the proper var_account_disable_inactivity variable. It also updates the metadata comment to accurately describe the rule's purpose and increments the definition version from 1 to 2.

Let's fix it.

@openshift-ci openshift-ci bot added the needs-ok-to-test Used by openshift-ci bot. label Jun 18, 2025
@openshift-ci
Copy link

openshift-ci bot commented Jun 18, 2025

Hi @yu410621. Thanks for your PR.

I'm waiting for a ComplianceAsCode member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Copy link
Collaborator

@jan-cerny jan-cerny left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @yu410621, I think that the linux_os/guide/system/accounts/accounts-restrictions/account_expiration/account_disable_inactivity_system_auth/oval/shared.xml has the same problem and needs to be changed as well.

@jan-cerny jan-cerny self-assigned this Jun 18, 2025
@jan-cerny jan-cerny added this to the 0.1.78 milestone Jun 18, 2025
@jan-cerny jan-cerny added the OVAL OVAL update. Related to the systems assessments. label Jun 18, 2025
@yu410621
Copy link
Contributor Author

Hi @yu410621, I think that the linux_os/guide/system/accounts/accounts-restrictions/account_expiration/account_disable_inactivity_system_auth/oval/shared.xml has the same problem and needs to be changed as well.

Thanks for catching that! I've added a new commit to apply the same fix to the system_auth rule.

@qlty-cloud-legacy
Copy link

Code Climate has analyzed commit 429447c and detected 0 issues on this pull request.

The test coverage on the diff in this pull request is 100.0% (50% is the threshold).

This pull request will bring the total coverage in the repository to 61.9% (0.0% change).

View more on Code Climate.

@yu410621 yu410621 changed the title Fix(OVAL): Correct variable reference in account_disable_inactivity_password_auth Fix(OVAL): Correct variable reference in account_disable_inactivity_* Jun 19, 2025
@yu410621
Copy link
Contributor Author

Hi @jan-cerny, I changed the PR title to "account_disable_inactivity_*". Is this more appropriate?

Copy link
Collaborator

@jan-cerny jan-cerny left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@jan-cerny jan-cerny merged commit cf384d9 into ComplianceAsCode:master Jun 19, 2025
113 of 120 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-ok-to-test Used by openshift-ci bot. OVAL OVAL update. Related to the systems assessments.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants