Skip to content

Commit 161edd4

Browse files
chore: use gemara v.0.7.0 (#348)
* chore: use gemara v.0.3.9 Signed-off-by: Travis Truman <[email protected]> * fix: adapt guideline mappings to new schema Signed-off-by: Travis Truman <[email protected]> * fix: adapt guideline mappings to new schema Signed-off-by: Travis Truman <[email protected]> * chore: bump gemara to v0.7.0 Signed-off-by: Travis Truman <[email protected]> --------- Signed-off-by: Travis Truman <[email protected]> Co-authored-by: CRob <[email protected]>
1 parent 369aa8d commit 161edd4

File tree

14 files changed

+1483
-1465
lines changed

14 files changed

+1483
-1465
lines changed

.gitignore

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,3 +4,6 @@ docs/_site
44

55
# generated output from go run ./... compile
66
checklist.md
7+
8+
# go build artifacts
9+
cmd/security-baseline

baseline/OSPS-AC.yaml

Lines changed: 147 additions & 145 deletions
Original file line numberDiff line numberDiff line change
@@ -18,57 +18,59 @@ controls:
1818
repository settings or accessing sensitive data.
1919
guideline-mappings:
2020
- reference-id: BPB
21-
identifiers:
22-
- CC-G-1
21+
entries:
22+
- reference-id: CC-G-1
2323
- reference-id: CRA
24-
identifiers:
25-
- 1.2d
26-
- 1.2e
27-
- 1.2f
24+
entries:
25+
- reference-id: 1.2d
26+
- reference-id: 1.2e
27+
- reference-id: 1.2f
2828
- reference-id: SSDF
29-
identifiers:
30-
- PO.3.2
31-
- PS.1
32-
- PS.2
29+
entries:
30+
- reference-id: PO.3.2
31+
- reference-id: PS.1
32+
- reference-id: PS.2
3333
- reference-id: CSF
34-
identifiers:
35-
- PR.A-02
36-
- PR.A-05
34+
entries:
35+
- reference-id: PR.A-02
36+
- reference-id: PR.A-05
3737
- reference-id: OpenCRE
38-
identifiers:
39-
- 486-813
40-
- 124-564
41-
- 347-352
42-
- 333-858
43-
- 152-725
44-
- 201-246
38+
entries:
39+
- reference-id: 486-813
40+
- reference-id: 124-564
41+
- reference-id: 347-352
42+
- reference-id: 333-858
43+
- reference-id: 152-725
44+
- reference-id: 201-246
4545
- reference-id: PSSCRM
46-
identifiers:
47-
- G2.6
48-
- P3.3
49-
- E1.2
50-
- E1.3
51-
- E1.4
52-
- E3.1
46+
entries:
47+
- reference-id: G2.6
48+
- reference-id: P3.3
49+
- reference-id: E1.2
50+
- reference-id: E1.3
51+
- reference-id: E1.4
52+
- reference-id: E3.1
5353
- reference-id: SAMM
54-
identifiers:
55-
- Operations -Environment Management -Configuration Hardening Lvl1
54+
entries:
55+
- reference-id: Operations -Environment Management -Configuration Hardening Lvl1
5656
- reference-id: PCIDSS
57-
identifiers:
58-
- 2.2.1
59-
- 8.2.1
60-
- 8.3.1
57+
entries:
58+
- reference-id: 2.2.1
59+
- reference-id: 8.2.1
60+
- reference-id: 8.3.1
6161
- reference-id: UKSSCOP
62-
identifiers:
63-
- 2.1
62+
entries:
63+
- reference-id: 2.1
6464
- reference-id: 800-161
65-
identifiers:
66-
- AC-4(21)
67-
- AC-17
68-
- CM-5
69-
- CM-6
70-
- IA-2
71-
- IA-5
65+
entries:
66+
- reference-id: AC-4(21)
67+
- reference-id: AC-17
68+
- reference-id: CM-5
69+
- reference-id: CM-6
70+
- reference-id: IA-2
71+
- reference-id: IA-5
72+
- reference-id: 1.2e
73+
- reference-id: 1.2f
7274
assessment-requirements:
7375
- id: OSPS-AC-01.01
7476
text: |
@@ -94,45 +96,45 @@ controls:
9496
limiting the permissions granted to new collaborators.
9597
guideline-mappings:
9698
- reference-id: CRA
97-
identifiers:
98-
- 1.2f
99+
entries:
100+
- reference-id: 1.2f
99101
- reference-id: SSDF
100-
identifiers:
101-
- PO.2
102-
- PO.3.2
103-
- PS.1
104-
- PS.2
102+
entries:
103+
- reference-id: PO.2
104+
- reference-id: PO.3.2
105+
- reference-id: PS.1
106+
- reference-id: PS.2
105107
- reference-id: CSF
106-
identifiers:
107-
- PR.AA-02
108-
- PR.AA-05
108+
entries:
109+
- reference-id: PR.AA-02
110+
- reference-id: PR.AA-05
109111
- reference-id: OpenCRE
110-
identifiers:
111-
- 486-813
112-
- 124-564
113-
- 802-056
114-
- 368-633
115-
- 152-725
112+
entries:
113+
- reference-id: 486-813
114+
- reference-id: 124-564
115+
- reference-id: 802-056
116+
- reference-id: 368-633
117+
- reference-id: 152-725
116118
- reference-id: PSSCRM
117-
identifiers:
118-
- P2.3
119-
- E1.2
120-
- E3.3
119+
entries:
120+
- reference-id: P2.3
121+
- reference-id: E1.2
122+
- reference-id: E3.3
121123
- reference-id: PCIDSS
122-
identifiers:
123-
- 2.2.1
124+
entries:
125+
- reference-id: 2.2.1
124126
- reference-id: UKSSCOP
125-
identifiers:
126-
- 2.1
127+
entries:
128+
- reference-id: 2.1
127129
- reference-id: 800-161
128-
identifiers:
129-
- AC-2
130-
- AC-3
131-
- AC-4(21)
132-
- AC-5
133-
- AC-6
134-
- CM-5
135-
- CM-7
130+
entries:
131+
- reference-id: AC-2
132+
- reference-id: AC-3
133+
- reference-id: AC-4(21)
134+
- reference-id: AC-5
135+
- reference-id: AC-6
136+
- reference-id: CM-5
137+
- reference-id: CM-7
136138
assessment-requirements:
137139
- id: OSPS-AC-02.01
138140
text: |
@@ -158,45 +160,45 @@ controls:
158160
of the project's repository by preventing unintentional modification.
159161
guideline-mappings:
160162
- reference-id: CRA
161-
identifiers:
162-
- 1.2f
163+
entries:
164+
- reference-id: 1.2f
163165
- reference-id: SSDF
164-
identifiers:
165-
- PO.3.2
166-
- PS.1
167-
- PS.2
166+
entries:
167+
- reference-id: PO.3.2
168+
- reference-id: PS.1
169+
- reference-id: PS.2
168170
- reference-id: CSF
169-
identifiers:
170-
- PR.A-02
171-
- PR.A-05
171+
entries:
172+
- reference-id: PR.A-02
173+
- reference-id: PR.A-05
172174
- reference-id: OpenCRE
173-
identifiers:
174-
- 486-813
175-
- 124-564
176-
- 152-725
175+
entries:
176+
- reference-id: 486-813
177+
- reference-id: 124-564
178+
- reference-id: 152-725
177179
- reference-id: Scorecard
178-
identifiers:
179-
- Branch-Protection
180+
entries:
181+
- reference-id: Branch-Protection
180182
- reference-id: PSSCRM
181-
identifiers:
182-
- P3.2
183-
- P3.5
184-
- E1.5
185-
- E3.1
183+
entries:
184+
- reference-id: P3.2
185+
- reference-id: P3.5
186+
- reference-id: E1.5
187+
- reference-id: E3.1
186188
- reference-id: PCIDSS
187-
identifiers:
188-
- 2.2.1
189+
entries:
190+
- reference-id: 2.2.1
189191
- reference-id: UKSSCOP
190-
identifiers:
191-
- 2.1
192-
- 2.2
192+
entries:
193+
- reference-id: 2.1
194+
- reference-id: 2.2
193195
- reference-id: 800-161
194-
identifiers:
195-
- AC-3
196-
- AC-5
197-
- CM-3
198-
- CM-3(2)
199-
- CM-5
196+
entries:
197+
- reference-id: AC-3
198+
- reference-id: AC-5
199+
- reference-id: CM-3
200+
- reference-id: CM-3(2)
201+
- reference-id: CM-5
200202
assessment-requirements:
201203
- id: OSPS-AC-03.01
202204
text: |
@@ -235,55 +237,55 @@ controls:
235237
pipelines.
236238
guideline-mappings:
237239
- reference-id: CRA
238-
identifiers:
239-
- 1.2d
240-
- 1.2e
241-
- 1.2f
240+
entries:
241+
- reference-id: 1.2d
242+
- reference-id: 1.2e
243+
- reference-id: 1.2f
242244
- reference-id: SSDF
243-
identifiers:
244-
- PO.2
245-
- PO.3.2
246-
- PS.1
247-
- PS.2
245+
entries:
246+
- reference-id: PO.2
247+
- reference-id: PO.3.2
248+
- reference-id: PS.1
249+
- reference-id: PS.2
248250
- reference-id: CSF
249-
identifiers:
250-
- PR.AA-02
251-
- PR.AA-05
251+
entries:
252+
- reference-id: PR.AA-02
253+
- reference-id: PR.AA-05
252254
- reference-id: OpenCRE
253-
identifiers:
254-
- 486-813
255-
- 124-564
256-
- 347-507
257-
- 263-284
258-
- 123-124
255+
entries:
256+
- reference-id: 486-813
257+
- reference-id: 124-564
258+
- reference-id: 347-507
259+
- reference-id: 263-284
260+
- reference-id: 123-124
259261
- reference-id: SLSA
260-
identifiers:
261-
- Producer - Choose an appropriate build platform
262-
- Build platform - Isolation strength - Isolated
262+
entries:
263+
- reference-id: Producer - Choose an appropriate build platform
264+
- reference-id: Build platform - Isolation strength - Isolated
263265
- reference-id: PSSCRM
264-
identifiers:
265-
- P3.2
266+
entries:
267+
- reference-id: P3.2
266268
- reference-id: SAMM
267-
identifiers:
268-
- Operations -Environment Management -Configuration Hardening Lvl1
269+
entries:
270+
- reference-id: Operations -Environment Management -Configuration Hardening Lvl1
269271
- reference-id: PCIDSS
270-
identifiers:
271-
- 2.2.1
272-
- 8.2.1
272+
entries:
273+
- reference-id: 2.2.1
274+
- reference-id: 8.2.1
273275
- reference-id: UKSSCOP
274-
identifiers:
275-
- 2.1
276-
- 2.2
276+
entries:
277+
- reference-id: 2.1
278+
- reference-id: 2.2
277279
- reference-id: 800-161
278-
identifiers:
279-
- AC-3(8)
280-
- AC-4
281-
- AC-4(6)
282-
- AC-6
283-
- AC-20
284-
- AC-20(1)
285-
- CM-5
286-
- CM-7
280+
entries:
281+
- reference-id: AC-3(8)
282+
- reference-id: AC-4
283+
- reference-id: AC-4(6)
284+
- reference-id: AC-6
285+
- reference-id: AC-20
286+
- reference-id: AC-20(1)
287+
- reference-id: CM-5
288+
- reference-id: CM-7
287289
assessment-requirements:
288290
- id: OSPS-AC-04.01
289291
text: |

0 commit comments

Comments
 (0)